ISO 27001
An information security management system your business can actually operate — built for certification, not for a binder.
- Typical duration
- 4–9 months
- Primary audience
- CISOs & Boards
- You leave with
- Certification, and an ISMS that survives the year after it.
Three phases, start to finish.
- 01 Gap assessment Where you stand against Annex A and the 2022 control set, control by control, before a single policy is written. Every Annex A control assessed against evidence you already hold Scope boundary drawn so the ISMS stays operable Remediation plan sequenced by certification dependency
- 02 ISMS build Risk methodology, Statement of Applicability and the policy suite — written so your team can run them after we leave. Risk methodology your risk owners can apply without us in the room Statement of Applicability justified control by control Policy suite sized to the organisation, not to the binder
- 03 Audit and certification Internal audit, management review, then Stage 1 and Stage 2 with us sitting beside you. Internal audit run to the standard the certification body will apply Management review agenda, minutes and evidence pack We sit with you through Stage 1 and Stage 2
What certification actually requires
ISO 27001 is a management system standard. The Annex A controls get the attention, but certification turns on whether you can demonstrate that the system runs: risks assessed on a cadence, decisions recorded, internal audits performed, management reviewing the results and acting on them.
Our sequence
- Gap assessment against the 2022 control set, with an effort estimate per gap
- Risk methodology and register that your team can maintain without us
- Statement of Applicability with justified exclusions
- Policy suite written to be followed, not filed
- Internal audit and management review, run once with you before the real thing
- Stage 1 and Stage 2 attendance alongside your team
The year after
Surveillance audits are where under-built systems fail. We hand over a calendar, an evidence pipeline and an internal audit programme so year two is a formality rather than a second project.
ISO 27001: the questions we get asked.
How long does ISO 27001 certification take?
Four to nine months for most organisations, from gap assessment to Stage 2. The variable is rarely the control work — it is how long your management system has to be seen operating before a certification body will audit it, which is usually three months minimum.
Do you also act as our certification body?
No, and no one can do both. A certification body must be independent of the consultancy that built the ISMS. We prepare you, sit with you through Stage 1 and Stage 2, and are happy to introduce you to accredited bodies.
What is the difference between ISO 27001 and SOC 2?
ISO 27001 certifies a management system against an international standard and is recognised globally. SOC 2 is a US attestation report written by a CPA firm about your controls over a period. European and Canadian enterprise buyers tend to ask for ISO; US software buyers tend to ask for SOC 2. Organisations selling into both often need both, and roughly 60 to 70 per cent of the underlying work is shared.
Which version of the standard do you work to?
ISO/IEC 27001:2022, with the reorganised 93-control Annex A set — 11 new controls, 24 merged and 58 revised against the 2013 edition. The transition window for 2013 certificates closed on 31 October 2025, so a 2013 certificate is no longer current: if yours lapsed, the route back is a transition engagement rather than a fresh certification, and it is considerably shorter.
Other lines of work
All servicesTell us what triggered the search. We will scope to that.
We reply to every assessment request within one business day.
