Gap analysis, a defensible Statement of Applicability, a full review of your policies and controls, and hands-on support through Stage 1 and Stage 2 audits with an accredited certification body, delivered by consultants who've actually taken organisations through certification before.
Companies pursuing ISO 27001 for the first time, usually because enterprise customers or a procurement process have made it a condition of doing business. Typically that means a software or services business somewhere between twenty and three hundred people, with a real engineering function, some existing security practice, and no dedicated compliance team. If you already hold certification and need help maintaining it, our internal audit and vCISO services are the better fit.
A control-by-control assessment against ISO 27001:2022 Annex A, scored and prioritised so you know exactly what to fix first.
A defensible SoA with justified inclusions and exclusions, one of the documents certification bodies scrutinise most closely.
A structured review of your existing ISMS documentation: whether each policy is valid against the standard, and whether your controls actually do what the policy says they do.
A working risk register and treatment plan your team can maintain after we leave, mapped directly to Annex A controls.
We help you brief and select an accredited certification body, and sit alongside you through Stage 1 and Stage 2 audits.
A dry-run review before your official Stage 1 and Stage 2 audits, catching gaps while there's still time to fix them.
ISO 27001 certifies a management system, not a product and not a set of technical controls in isolation. That distinction explains most of what surprises people. The standard cares whether you have identified your risks, decided what to do about them, assigned ownership, and can show the system operating over time. A company with strong engineering practices and no documented management system will fail. A company with modest technology and a well run management system will pass.
Certification is assessed in two stages. Stage 1 is largely a documentation review where the auditor checks whether your ISMS exists, is scoped sensibly, and covers the clauses of the standard. Stage 2 is the substantive audit, where the auditor tests whether what you documented is actually happening. Between the two there is usually a gap of several weeks in which you are expected to address anything Stage 1 raised.
After certification you are not finished. Surveillance audits happen annually and recertification every three years, and each one expects to see the management system continuing to operate: internal audits performed, management reviews held, risks reassessed, corrective actions closed.
ISO 27001:2022 restructured Annex A significantly. The previous fourteen control domains were reorganised into four themes covering organisational, people, physical and technological controls, and the total number of controls reduced from 114 to 93 through consolidation. Eleven controls were genuinely new, including threat intelligence, information security for cloud services, ICT readiness for business continuity, data masking, data leakage prevention and secure coding.
If you are certifying for the first time, you will certify against the 2022 version and none of this transition detail affects you directly. It matters mainly when you are reading older guidance or inheriting documentation written against the 2013 standard, which is still common and a frequent source of confusion in templates bought online.
Your ISMS scope determines how much work certification represents, and it is the decision most worth spending time on. Scope too broadly and you commit to evidencing controls across parts of the business that your customers never asked about. Scope too narrowly and you may end up with a certificate that does not actually cover the service your customers are buying, which defeats the purpose.
For most software companies the sensible scope is the development, operation and support of the product platform, including the people and infrastructure involved. Corporate functions with no access to customer data can often sit outside. The test we apply is simple: would the customer asking for your certificate be satisfied that the thing they care about is inside the boundary? If not, the scope is wrong regardless of how much easier it makes the audit.
We assess your current state against every applicable Annex A control and hand you a prioritised, scored remediation plan.
We review your policies and risk register against the standard, then check the evidence trail (access logs, change records, training records) auditors will sample and flag where it falls short.
We train your team to own their controls day-to-day. The fastest way ISMS programmes fail is a document nobody actually follows.
A full internal audit cycle before certification, catching nonconformities while you can still fix them without risking a failed Stage 2.
You get one round to close the gaps we identified. We re-review those items and issue the final readiness report.
We brief your chosen certification body, prepare your team for interviews, and support you through Stage 1 (documentation review) and Stage 2 (implementation audit).
After the gap analysis and readiness review, you get one round to close the gaps we identified. We then re-review those specific items and issue the final readiness report. The aim is that what your certification body sees at Stage 1 and Stage 2 is your corrected position, not the one we found at the start.
Generic documentation is easy to spot and creates an immediate credibility problem. Auditors ask questions about how a policy works in your business, and templated answers fall apart quickly.
A narrow scope that excludes the service your customers actually use produces a certificate that does not answer their question, and you will be asked to widen it later at greater cost.
Both are explicit requirements and both need to have genuinely happened before Stage 2. They cannot be manufactured retrospectively in a credible way.
Controls need to be evidenced over a period, not demonstrated on the day. Start capturing access reviews, change approvals and training records early rather than reconstructing them under pressure.
For a company starting with reasonable security practice but no formal management system, three to six months to certification readiness is realistic, followed by the certification body's own Stage 1 and Stage 2 process which typically adds four to eight weeks including the gap between stages. Companies starting from a lower base, or with complex multi entity structures, should plan for longer. Anyone promising certification in a few weeks is either relying on a very narrow scope or setting you up for a difficult Stage 2. We will give you a timeline after the gap analysis rather than before it, because that is the first point at which the estimate means anything.
We're consultants. We'll get your controls in shape and get you ready for the audit, but we don't hand out ISO 27001 certificates or sign SOC 2 reports, because the rules quite rightly don't let the firm that prepared you be the firm that passes you. That job goes to an independent certification body or CPA firm, and we'll help you find a good one. More on where exactly that line sits in our independence statement.
Sign a 2-year agreement with pricing locked in upfront, and your first year of any one service is completely free. Adding more than one service in year one? We give you the highest-value one free and a bundle discount on the rest. See how the offer works →
Most first-time clients reach certification readiness in 3 to 6 months depending on organisation size and existing control maturity. We'll give you a realistic timeline after the gap analysis, not a sales estimate.
No. ISO/IEC 17021-1, the standard accredited certification bodies operate under, prevents a body from certifying a management system it also consulted on. We prepare you and support you through the audit; an independent accredited certification body issues the certificate. Details in our independence statement.
Yes. We're happy to work with your existing choice, or recommend accredited bodies if you haven't selected one yet.
This service covers everything up to and through your first certification. Internal audit is the ongoing clause 9.2 requirement you'll need annually after certification. See our internal audit service, which comes with a first-year-free offer.
Not necessarily. Many clients maintain their ISMS with existing staff plus our internal audit service and occasional vCISO support. We'll size this honestly during scoping.
There are two separate costs: the preparation work, and the certification body's audit fees, which are billed directly by them and vary with your headcount and scope. Ask any consultancy to be explicit about which costs their quote includes. Ours covers preparation only, because we are not permitted to be your certification body.
ISO 27001 is the certifiable standard containing the requirements. ISO 27002 is guidance that explains how to implement the Annex A controls in practice. You certify against 27001; you read 27002 to understand what good looks like.
No. You assess each control's applicability against your risk assessment and record the decision in your Statement of Applicability. Excluding a control is entirely acceptable provided the justification is sound and consistent with your risks.
Yes, and most companies do. Controls over infrastructure you do not own are addressed through supplier management and your configuration of those services. ISO 27001:2022 added a specific control for information security in cloud services.
Look for genuine accreditation from a recognised national body such as UKAS in the UK or ANAB in the US. An unaccredited certificate costs less and is worth considerably less when a customer examines it. We will help you shortlist and brief them.
One remediation cycle is included as standard in every engagement. You get one round to apply fixes to what we raised, we re-check those specific findings, and the final report reflects your corrected state rather than the position we found at the start. What sits outside that is our engineers implementing the fixes on your behalf, rather than verifying yours, and any further rounds beyond the first. Both are quoted separately and transparently before any work starts.
Tell us your target date and current state. We'll come back with a fixed-scope proposal within two business days.
Book a discovery call