OPMC

Proposal Generator

Proposal for Services Agreement

ISO 27001:2022 Implementation

Project Name: ISO 27001:2022 Implementation
Client Name/ Address: Acme Corporation
Level 4, Business Tower, Dubai, UAE
Proposal Reference: OPM-IS 20251113-01
Date: November 13, 2025
Validity: 30 Days

Introduction One Pro Management Consulting

INTRODUCTION

Greetings,

We are appreciative of your interest in our offerings. We are thrilled that you are considering One Pro Management Consulting as your consultancy firm partner. With great pleasure, we submit our Proposal for your kind review in the name of One pro Management Consulting office.

One Pro Management Consulting is a multi-specialist consultancy service provider. Our ISO Consultants are pioneers in the field of ISO Certification Consulting with immense knowledge and expertise in all ISO Standards, ISO Certification Compliance, and ISO training & Implementation process.

We are a specialized consultancy firm equipped to support organizations in implementing and aligning with the latest ISO standards and security frameworks. Our services include process design, documentation, training, and audit readiness across a wide range of standards, such as:

  • ISO 9001:2015 – Quality Management Systems
  • ISO 14001:2015 – Environmental Management Systems
  • ISO 45001:2018 – Occupational Health and Safety
  • ISO 22000:2018 – Food Safety Management
  • ISO 17025:2017 – Laboratory Competence
  • ISO 13485:2016 – Medical Devices Quality Management
  • ISO 50001:2018 – Energy Management Systems
  • ISO 20000:2018 – IT Service Management
  • ISO 27001:2022 – Information Security Management System
  • SOC 2 Type II – Service Organization Controls
  • Security Control Implementation: Custom frameworks for cybersecurity and risk management.

One Pro Management Consulting is committed to delivering a guaranteed long-term, measurable and positive impact on your business operations.

The current "General Business Conditions," which outline the terms of the commercial agreements between One Pro Management Consulting and you, are also enclosed.

To accept this proposal, please sign and return.

If you have any questions, please do not hesitate to contact us anytime at fidele.obeid@opmconsultancy.com. We are happy to answer all your questions.

On Behalf of One Pro Management Consulting


Objectives & Requirements One Pro Management Consulting

PROJECT OBJECTIVES & REQUIREMENTS

The client required a full implementation consultancy service in compliance with ISO 27001:2022 standard for certification purposes. The implementation covers the documentation phase, training and awareness phase, information security risk assessment and implementation of technical controls stated in the annex A (statement of Applicability) of the standard.

# Client Requirements
1Gap analysis to assess the existing system, infrastructure and security controls against the requirements of the ISO 27001:2022 standard.
2Draft all information security documentation to comply with the ISO 27001: 2022 standard requirements including the statement of Applicability.
3Conduct Awareness and training sessions for all team members on each SOP.
4Provide full support for the implementation of each security control as per the Annex A of the standard.
5Provide consultancy in defining and assessing risks related to information security and mitigation plan of these risks.
6Conduct internal audit and optimize the cybersecurity monitoring practice.
7Assistance during the ISO 27001:2022 external certification audit.

Deliverables One Pro Management Consulting

DELIVERABLES

Phase Number Phase Title/Definition Action Plan Duration
1 Gap Analysis for the Information Security Management System ISO 27001:2022& Report including corrective actions Review of the overall information security system including:
-Review of the existing IT controls and documentation: Data Hosting, Backup, Access control, disposal of media, data transfer, legal requirements, encryption, etc...
-Network topology including dependencies.
-Review of the asset inventory.
-Review of previous information security audits and assessments results including outstanding issues.
-Review of Vulnerabilities raised in previously conducted security testing reports.
-Review of security roles, authorities and responsibilities.
-Data Classification & Labelling.
3-5 Days (assessment and report)
2 Information Security Management System Documentation & Awareness/Training sessions Draft all ISMS documentation based on the results of the gap analysis and the requirements of the standard.
Draft ISMS Manual defining the scope and the context of the Organization and Statement of Applicability based on the established ISMS Policies and procedures.
Define yearly ISMS objectives.
Identifying key performance indicators (KPIs) to monitor ISMS progress and ensure alignment with overall business objectives.
Conduct training sessions to cover all documentation and SOP’s.
2 Months
3 Information Security Risk Assessment Conduct an information security risk assessment based on the existing infrastructure and assets. Propose best practices for mitigating identified risks and improving security status. 2 weeks
4 Security Controls Implementation A total of 93 technical controls should be implemented to ensure compliance with ISO 27001:2022.
The consultant will explain each security control as per Annex A of the Statement of Applicability and provide full support through the implementation.
2 months
5 Internal Audit & Controls Review Conduct an internal audit to check the conformance to the established ISMS Policies and procedures and ensure readiness for the external audit.
Draft a report of the audit results highlighting findings and corrective actions.
1 week
6 Management Review & External Audit Support Conduct a management review meeting as required by ISO 27001 to measure the effectiveness of the system, ensuring all key stakeholders are aligned.
Support during the external audit, assisting your team until the certification is successfully achieved
3 days

Profiles One Pro Management Consulting

A qualified assessor, who will accompany you throughout the consultancy process, undertakes together with you an initial review of the information security management system in a pre-assessment gap analysis audit. The consultant conducts a gap analysis of the existing management system, processes and procedures, risks, policies, and technical controls, and evaluates the effectiveness of documentation, inter process interaction, forms, and additional documentation and requirements for adequacy and compliance with the requirements of the standard. The assessor analyzes the readiness of your company to undergo a full assessment successfully and provides a plan accordingly.

The assessor will prepare defined Action Plans that indicate the existing gaps between the requirements of ISO 27001:2022 and the current management system (if available) at your company. Based on discussions with the company’s management, the Action Plans will define specific steps to be taken in order to rectify non conformities, set recommended steps, and determine time lines for completion and persons responsible. The consultant will provide all technical and managerial documents, as well as all necessary training and support to complete the consultancy and preparation of the management system to undergo a successful certification assessment.

PROFILES AND QUALIFICATIONS OF THE ASSIGNED TEAM

The team leading this project are certified as ISO 9001:2015 Lead Auditor Quality Management system with the qualification and experience stated below:

Name Role Experience Certification
Fidele Obeid Lead Auditor -20 years of experience in Quality Management System and many ISO standards certification process.
-Director of the Quality department for 19 years.
-Consultants for all ISO standards: ISO 9001:2015, ISO 45001:2018, ISO 14001:2015, ISO 27001:2022 and others.
-More than 14 years of experience in GMP/GDP/GLP.
-More than 5 years in leading ISO 27001 audit.
-ISO 9001:2015 lead Auditor.
-ISO 27001 Information Security Management System Lead Auditor.
-ISO 14001Certification
-ISO 45001
-GMP /GDP certifications.
Makkarim Molana SME -20 years of experience in IT Management, Information Security and Cybersecurity.
-Auditor for ISO 27001 with more than 10 years of experience. 10 years of experience in cloud management.
-20 Years of experience in infrastructure management.
-ISO 27001:2013 Internal auditor Certificate.
-Certified Information Security Manager CISM.
-GSEC, Security Essentials Certification.

Commercials One Pro Management Consulting

CONTRACT PRICE

Item Reference Description Unit Price (USD) Quantity Total Price (USD)
1 OPM-ISMS ISO 27001:2022 Information Security Management System standard requirements implementation (ISMS) Covering Phase 1-2-3-4-5-6 as stated in section 3 “Deliverables”. 15,000.00 1 15,000.00
Total 15,000.00

PAYMENT TERMS

Milestones Amount
Proposal Approval30%
Phase 1-2-3 Completion50%
Until Completing Phase 620%

Terms & Conditions One Pro Management Consulting

Terms & Reference: General Business Conditions

General: One Pro Management Consulting provides consultancy and gap analysis assessment services on behalf of its clients. Unless otherwise agreed in writing, the client accepts the General Business Conditions and pricing of One Pro Management Consulting as applicable at the time of order placement. Any contrary or deviating business conditions from the client shall only be binding if expressly accepted in writing by One Pro Management Consulting.

Service delivery: One Pro Management Consulting supports clients in developing and implementing management systems aligned with international standards. The process includes: Conducting a comprehensive gap analysis to assess the current state of the organization. Implementing all relevant standard requirements. Performing an internal audit to ensure readiness for external certification.

Consulting services are delivered either on-site or remotely, maintaining consistent quality. One Pro Management Consulting operates independently, neutrally, and objectively. The scope and extent of services are defined in writing at the time of order placement. Partial delivery is permitted. Any changes or expansions to the original scope must be agreed upon in writing by both parties. If such changes make it unreasonable for the client to continue under the original terms, the client may withdraw from the contract, subject to payment of agreed or reasonable fees for services already rendered.

Implementation of ISO 27001:2022 will be conducted remotely, with 1–2 on-site visits scheduled as mutually agreed.

Duties of the client: The client shall provide all necessary information and documentation completely, accurately, and in a timely manner. The client must proactively disclose any procedures or circumstances relevant to the delivery of services.

Confidentiality, copyright, data security: One Pro Management Consulting observes business confidentiality, taking precautions to ensure that written expertise or any other facts or documents made available in the context of service delivery regarding the client and the subject matter are not forwarded, exploited, or publicized without authorization. One Pro Management Consulting may copy written documents, which have been made available to it for review or during service provision, for its own records. In so far as written expertise, evaluation results, etc. have been created in the context of the order, which are subject to copyright protection, One Pro Management Consulting grants the client a non-exclusive, non-transferable right of use, as far as necessary in accord with the contractually prescribed purpose. No further rights are granted; in particular, the client is not authorized to modify written expertise, evaluation results, and the like. One Pro Management Consulting also processes and uses personal data for their own purposes only. In order to comply with the data security requirements of Article 32 of the General Data Protection Regulation (GDPR), One Pro Management Consulting has implemented measures of a technical and organizational nature designed to ensure the security of stored data and data processing. Employees involved in processing have committed themselves to strict adherence to all applicable provision of the GDPR and all relevant data security regulations.

Warranty: The warranty of One Pro Management Consulting covers only the services expressly stated in the order. For consultancy services, One Pro Management Consulting guarantees the completion of the gap analysis, full documentation, and support for implementing all clauses of the applicable standard.

Certification Guarantee: One Pro Management Consulting guarantees that, upon completion of the full implementation cycle and internal audit, the client will be fully prepared to obtain certification from an accredited external body. In the unlikely event that certification is not achieved due to deficiencies in the implementation process, One Pro Management Consulting will waive the final 20% of the agreed payment.

Liability: Irrespective of legal basis, One Pro Management Consulting its vicarious agents and auxiliary persons, may be held liable for damages only in case of intent or gross negligence, or in case of negligent breach of an essential contractual duty (“material duty”). In case of a breach of essential contractual duties, the liability of One Pro Management Consulting is always limited to the extent of the foreseeable damage typical for the contract at the time of its closing.

Terms of payment: Unless otherwise agreed, the current pricing of One Pro Management Consulting applies. Payment terms are outlined in Section 6 of the proposal. Interest may be charged at the prevailing bank rate for delayed payments.

Deadlines and due dates: A detailed project plan and timeline will be provided and executed as agreed. Multiple meetings may be required, with scheduling coordinated between One Pro Management Consulting and the client. Full implementation typically requires 4-6 months.

Duration and termination: The contract is valid from the date of order placement and remains in effect indefinitely. The client may terminate the contract with six weeks’ written notice prior to the end of any quarter, without stating a reason. In such cases, One Pro Management Consulting reserves the right to charge for services already delivered.


Approvals One Pro Management Consulting

APPROVALS:

For: Acme Corporation

Name and Function of authorized Representative:
Signature & Date

For: One Pro Management Consulting LLC

Name and Function:
Signature & Date

B01, Cloud Spaces, Level 3, The Mall, World Trade Center, AL Danah, Abu Dhabi, UAE.

Fidele.obeid@opmconsultancy.com | +971588009657