ISO 27001 support

ISO 27001 that works in practice — not just on paper.

Gap analysis, ISMS build, controls implemented hands-on and support through the certification audit — from a team that has implemented ISO 27001 inside regulated businesses, not just written policies about it.

Fixed-price engagements · No long tie-in contracts · An honest view on whether ISO 27001 is the right step yet.

Implemented, not advisedHands-on ISO 27001 inside regulated firms
21 yearsInside regulated financial services
A working ISMSBuilt to be used, not filed
Fixed priceQuoted after gap analysis, no tie-ins
Why this matters

The badge clients ask for — and the system behind it

ISO 27001 has become the question larger clients, frameworks and due diligence questionnaires ask by default. For a growing firm, one required certification on one important contract is usually what starts the clock.

Done badly, ISO 27001 is a binder of policies nobody follows and a certificate that barely survives its first surveillance audit. Done properly, the ISMS is simply how the firm manages information risk — and the certificate is the by-product. We build the second kind.

What's included

From gap analysis to certificate — and every year after

A complete route to ISO 27001 for firms without an in-house compliance team, scoped and priced before work starts.

Gap analysis and scoping

Where your firm stands against the standard today, what is in scope, and a realistic route to certification — agreed before any work starts.

Risk assessment and treatment

A structured information security risk assessment for your firm, with a treatment plan that reflects your real exposure — not a generic template.

ISMS build

The information security management system itself: policies, processes, the Statement of Applicability and control selection — written to be used, not filed.

Controls implemented

The technical and organisational controls put genuinely in place across your systems, suppliers and people — the same hands-on work we do for Cyber Essentials, at ISO depth.

Internal audit and evidence

Evidence gathered as you go, internal audits run before the external one, and the gaps closed while they are still cheap to fix.

Certification audit support

Preparation for the certification body audit, support during it, and help resolving findings — then ongoing maintenance through surveillance audits year after year.

Which standard?

Cyber Essentials or ISO 27001 — or both

They answer different questions. Cyber Essentials proves the technical basics are in place; ISO 27001 proves the firm manages information security as a system. Many firms hold both — and the gap analysis will tell you honestly which your firm needs now.

Cyber Essentials
  • Five technical controls, UK government-backed
  • Fast, proportionate baseline for most SMEs
  • Answers insurer and public-sector questions
  • The sensible first step for most firms
ISO 27001
  • A full information security management system
  • Covers governance, people, process and suppliers
  • Independently audited, internationally recognised
  • What major clients and tenders increasingly require
How it works

Four stages to certified — then business as usual

01

Scope

Agree what the ISMS covers, review how your firm operates, and set a realistic plan and fixed price for the route to certification.

02

Assess

Run the risk assessment, map your current controls against the standard, and prioritise the gaps that actually matter.

03

Build

Implement the ISMS: policies, processes and controls put in place and evidenced — with your team involved, so it survives contact with real work.

04

Certify & maintain

Internal audit, then the certification body audit with support throughout — and ongoing maintenance so surveillance audits are routine, not a scramble.

Honest answers

ISO 27001 — common questions

What is ISO 27001?

ISO/IEC 27001 is the international standard for information security management. Rather than a fixed checklist of technical settings, it certifies that your firm runs a working information security management system (ISMS): you understand your risks, you have chosen and implemented controls to treat them, and you can evidence that the system operates day to day. Certification is issued by an independent, accredited certification body after an audit.

How is ISO 27001 different from Cyber Essentials?

Cyber Essentials is a UK baseline covering five technical controls — excellent value, and often the right starting point. ISO 27001 goes much further: it covers governance, people, processes, suppliers and physical security as well as technology, and it is independently audited and internationally recognised. Many firms hold both — Cyber Essentials as the technical floor, ISO 27001 as the management system clients and tenders increasingly ask for.

Does my firm need ISO 27001?

The usual triggers are commercial: a major client requires it of suppliers, a tender scores it, or due diligence questionnaires keep asking for it. For regulated and professional firms it is also the most credible way to demonstrate information security governance to boards, insurers and regulators. If those pressures have not reached you yet, Cyber Essentials may be the more proportionate step — we will tell you honestly which fits.

Who actually certifies us?

An independent certification body — not us, and that separation is the point. Our role is to build the ISMS with you, implement the controls, run the internal audits and support you through the certification audit. We recommend using a UKAS-accredited certification body so the certificate carries full weight with clients and tenders.

How long does it take, and what does it cost?

It depends on your size, your current maturity and the scope you choose — which is exactly what the gap analysis establishes. Our support is fixed-price once scoping shows what your firm needs, with no long tie-in contracts. The certification body charges its own audit fees separately, based on the size and scope of your organisation.

Scoping call

Find out what ISO 27001 would actually take for your firm.

A no-obligation call to review your scope, your current maturity and the realistic route — including whether Cyber Essentials is the smarter first step.

Book a scoping call

Prefer to talk? Call 0330 223 7404