Home / Services / ISO 27001 Certification Preparation
ISO 27001:2022

ISO 27001 certification, without the 40-page policy nobody reads.

Gap analysis, a defensible Statement of Applicability, a full review of your policies and controls, and hands-on support through Stage 1 and Stage 2 audits with an accredited certification body, delivered by consultants who've actually taken organisations through certification before.

Certification-ReadyGap analysis to Stage 2
Annex A-mapped ISMS
UK · US · EU consultants
Who it's for

Who this is for

Companies pursuing ISO 27001 for the first time, usually because enterprise customers or a procurement process have made it a condition of doing business. Typically that means a software or services business somewhere between twenty and three hundred people, with a real engineering function, some existing security practice, and no dedicated compliance team. If you already hold certification and need help maintaining it, our internal audit and vCISO services are the better fit.

What's included

Scope, in plain terms.

CP-01 Scope

Gap Analysis

A control-by-control assessment against ISO 27001:2022 Annex A, scored and prioritised so you know exactly what to fix first.

CP-02 Scope

Statement of Applicability

A defensible SoA with justified inclusions and exclusions, one of the documents certification bodies scrutinise most closely.

CP-03 Scope

Policy & Procedure Review

A structured review of your existing ISMS documentation: whether each policy is valid against the standard, and whether your controls actually do what the policy says they do.

CP-04 Scope

Risk Assessment & Treatment Plan

A working risk register and treatment plan your team can maintain after we leave, mapped directly to Annex A controls.

CP-05 Deliverable

Certification Body Selection

We help you brief and select an accredited certification body, and sit alongside you through Stage 1 and Stage 2 audits.

CP-06 Deliverable

Stage 1 & 2 Readiness Review

A dry-run review before your official Stage 1 and Stage 2 audits, catching gaps while there's still time to fix them.

What ISO 27001 certification actually involves

ISO 27001 certifies a management system, not a product and not a set of technical controls in isolation. That distinction explains most of what surprises people. The standard cares whether you have identified your risks, decided what to do about them, assigned ownership, and can show the system operating over time. A company with strong engineering practices and no documented management system will fail. A company with modest technology and a well run management system will pass.

Certification is assessed in two stages. Stage 1 is largely a documentation review where the auditor checks whether your ISMS exists, is scoped sensibly, and covers the clauses of the standard. Stage 2 is the substantive audit, where the auditor tests whether what you documented is actually happening. Between the two there is usually a gap of several weeks in which you are expected to address anything Stage 1 raised.

After certification you are not finished. Surveillance audits happen annually and recertification every three years, and each one expects to see the management system continuing to operate: internal audits performed, management reviews held, risks reassessed, corrective actions closed.

The 2022 revision and what changed

ISO 27001:2022 restructured Annex A significantly. The previous fourteen control domains were reorganised into four themes covering organisational, people, physical and technological controls, and the total number of controls reduced from 114 to 93 through consolidation. Eleven controls were genuinely new, including threat intelligence, information security for cloud services, ICT readiness for business continuity, data masking, data leakage prevention and secure coding.

If you are certifying for the first time, you will certify against the 2022 version and none of this transition detail affects you directly. It matters mainly when you are reading older guidance or inheriting documentation written against the 2013 standard, which is still common and a frequent source of confusion in templates bought online.

Scoping decisions that shape everything else

Your ISMS scope determines how much work certification represents, and it is the decision most worth spending time on. Scope too broadly and you commit to evidencing controls across parts of the business that your customers never asked about. Scope too narrowly and you may end up with a certificate that does not actually cover the service your customers are buying, which defeats the purpose.

For most software companies the sensible scope is the development, operation and support of the product platform, including the people and infrastructure involved. Corporate functions with no access to customer data can often sit outside. The test we apply is simple: would the customer asking for your certificate be satisfied that the thing they care about is inside the boundary? If not, the scope is wrong regardless of how much easier it makes the audit.

Engagement process

How the work actually happens.

01

Gap analysis

We assess your current state against every applicable Annex A control and hand you a prioritised, scored remediation plan.

02

Assess the ISMS

We review your policies and risk register against the standard, then check the evidence trail (access logs, change records, training records) auditors will sample and flag where it falls short.

03

Embed & train

We train your team to own their controls day-to-day. The fastest way ISMS programmes fail is a document nobody actually follows.

04

Internal audit

A full internal audit cycle before certification, catching nonconformities while you can still fix them without risking a failed Stage 2.

05

Remediation round and re-review

You get one round to close the gaps we identified. We re-review those items and issue the final readiness report.

06

Certification audit support

We brief your chosen certification body, prepare your team for interviews, and support you through Stage 1 (documentation review) and Stage 2 (implementation audit).

Included as standard

One remediation cycle is built into every engagement

After the gap analysis and readiness review, you get one round to close the gaps we identified. We then re-review those specific items and issue the final readiness report. The aim is that what your certification body sees at Stage 1 and Stage 2 is your corrected position, not the one we found at the start.

What goes wrong

Common mistakes we are asked to fix.

Buying a template pack and treating it as an ISMS

Generic documentation is easy to spot and creates an immediate credibility problem. Auditors ask questions about how a policy works in your business, and templated answers fall apart quickly.

Scoping to make the audit easy

A narrow scope that excludes the service your customers actually use produces a certificate that does not answer their question, and you will be asked to widen it later at greater cost.

Leaving the internal audit and management review to the end

Both are explicit requirements and both need to have genuinely happened before Stage 2. They cannot be manufactured retrospectively in a credible way.

Underestimating evidence retention

Controls need to be evidenced over a period, not demonstrated on the day. Start capturing access reviews, change approvals and training records early rather than reconstructing them under pressure.

Timelines

Timing and what to expect

For a company starting with reasonable security practice but no formal management system, three to six months to certification readiness is realistic, followed by the certification body's own Stage 1 and Stage 2 process which typically adds four to eight weeks including the gap between stages. Companies starting from a lower base, or with complex multi entity structures, should plan for longer. Anyone promising certification in a few weeks is either relying on a very narrow scope or setting you up for a difficult Stage 2. We will give you a timeline after the gap analysis rather than before it, because that is the first point at which the estimate means anything.

One thing worth being clear about

We're consultants. We'll get your controls in shape and get you ready for the audit, but we don't hand out ISO 27001 certificates or sign SOC 2 reports, because the rules quite rightly don't let the firm that prepared you be the firm that passes you. That job goes to an independent certification body or CPA firm, and we'll help you find a good one. More on where exactly that line sits in our independence statement.

Offer

Your first year of service is free

Sign a 2-year agreement with pricing locked in upfront, and your first year of any one service is completely free. Adding more than one service in year one? We give you the highest-value one free and a bundle discount on the rest. See how the offer works →

Common questions

Frequently asked questions

How long does ISO 27001 certification typically take?

Most first-time clients reach certification readiness in 3 to 6 months depending on organisation size and existing control maturity. We'll give you a realistic timeline after the gap analysis, not a sales estimate.

Do you perform the certification audit yourselves?

No. ISO/IEC 17021-1, the standard accredited certification bodies operate under, prevents a body from certifying a management system it also consulted on. We prepare you and support you through the audit; an independent accredited certification body issues the certificate. Details in our independence statement.

Can you work with a certification body we've already chosen?

Yes. We're happy to work with your existing choice, or recommend accredited bodies if you haven't selected one yet.

What's the difference between this and the internal audit service?

This service covers everything up to and through your first certification. Internal audit is the ongoing clause 9.2 requirement you'll need annually after certification. See our internal audit service, which comes with a first-year-free offer.

Do we need a full-time security hire to maintain this afterward?

Not necessarily. Many clients maintain their ISMS with existing staff plus our internal audit service and occasional vCISO support. We'll size this honestly during scoping.

How much does ISO 27001 certification cost in total?

There are two separate costs: the preparation work, and the certification body's audit fees, which are billed directly by them and vary with your headcount and scope. Ask any consultancy to be explicit about which costs their quote includes. Ours covers preparation only, because we are not permitted to be your certification body.

What is the difference between ISO 27001 and ISO 27002?

ISO 27001 is the certifiable standard containing the requirements. ISO 27002 is guidance that explains how to implement the Annex A controls in practice. You certify against 27001; you read 27002 to understand what good looks like.

Do we need to implement all 93 Annex A controls?

No. You assess each control's applicability against your risk assessment and record the decision in your Statement of Applicability. Excluding a control is entirely acceptable provided the justification is sound and consistent with your risks.

Can we certify if we use cloud providers for everything?

Yes, and most companies do. Controls over infrastructure you do not own are addressed through supplier management and your configuration of those services. ISO 27001:2022 added a specific control for information security in cloud services.

How do we choose a certification body?

Look for genuine accreditation from a recognised national body such as UKAS in the UK or ANAB in the US. An unaccredited certificate costs less and is worth considerably less when a customer examines it. We will help you shortlist and brief them.

Is remediation included, or is that charged separately?

One remediation cycle is included as standard in every engagement. You get one round to apply fixes to what we raised, we re-check those specific findings, and the final report reflects your corrected state rather than the position we found at the start. What sits outside that is our engineers implementing the fixes on your behalf, rather than verifying yours, and any further rounds beyond the first. Both are quoted separately and transparently before any work starts.

Related services

Often scoped alongside this.

Ready to scope this?

Tell us your target date and current state. We'll come back with a fixed-scope proposal within two business days.

Book a discovery call