ISO 27001 Certification Support
Get ISO 27001 certified with an information security management system your team can run. Gap analysis, risk assessment, Statement of Applicability and audit preparation.
Service Details
ISO 27001 certification shows customers and partners that you manage information security properly, and our ISO 27001 support gets you there with a management system your team can actually run. You get controls that work, risks that are genuinely managed and evidence an auditor accepts, rather than a shelf of policies nobody reads.
ISO/IEC 27001:2022 is the international standard for an information security management system (ISMS). It is often the first credential enterprise buyers ask for, and the audit most organisations struggle with when they treat it as a documentation exercise.
INFO
We prepare you for certification and support you through the audits. The certificate itself is issued by an independent certification body, which keeps it credible with your customers.
Who ISO 27001 is for
ISO 27001 is voluntary. No law requires it, but contracts often do. You are likely to need it if you sell to enterprises, public bodies or regulated firms, handle sensitive client data, or keep answering the same security questionnaires.
It suits organisations of any size and sector, because you set the scope. A software company might certify its product and hosting; a professional services firm might certify the whole business. It is common in financial services, insurance, private equity and manufacturing supply chains.
What the standard requires
In plain English, ISO 27001 asks you to run information security as a managed process, not a one-off project. The requirements fall into two parts.
- The management system (clauses 4 to 10) — You define your scope, get leadership commitment, assess and treat risks, set objectives, train people, monitor performance, run internal audits and management reviews, and fix what you find. These clauses are mandatory.
- Annex A controls — A reference set of 93 controls in four themes: organisational, people, physical and technological. You choose which apply based on your risk assessment and record the decisions in your Statement of Applicability (SoA).
Certification follows a three-year cycle: a two-stage initial audit, annual surveillance audits, then recertification.
ISO 27001 without the consultancy theatre
You keep running your business while we carry the programme. Policies and processes are written around how you already work, so they hold up when an auditor asks your staff how things are done.
Your team learns the system well enough to maintain it after we step back, so certification does not depend on us.

How we get you certified
Four phases, each with a clear exit:
Gap Analysis
Where you stand against the management system clauses and Annex A controls, and exactly what needs building.
Risk & SoA
A risk assessment method you can repeat, plus a Statement of Applicability grounded in your real risks.
Implementation
Policies, processes and technical controls built with your team, not for them.
Audit Support
Internal audit, management review, and support through the Stage 1 and Stage 2 audits until you are certified.
The risk work draws on our risk management service, and technical controls can be tested through penetration testing before the auditor arrives.
Certification that survives surveillance
The certificate starts a three-year cycle, with surveillance audits every year. Controls decay without ownership, so we hand over a management system your team runs confidently, with the option of retained support for internal audits and continual improvement.
Scope
A boundary that covers what matters
Programme
Phased delivery around your operations
Maintain
Handover plus optional retained audits
Keeping certified between audits
Many clients combine retained ISMS support with security posture reviews to check the technical controls between audits. Access control is one of the areas auditors test hardest, and our identity and access service keeps joiners, leavers and privileged accounts in order with records to prove it.
Related frameworks and services
ISO 27001 pairs well with Cyber Essentials for a technical baseline and UK GDPR for data protection. Its controls also map to NIST, CIS Controls, DORA, NIS2 and PCI DSS, so one set of evidence can serve several frameworks.
Our compliance support team keeps multi-framework programmes coherent, and assurance uses your certificate to speed up customer due diligence. see how these fit together in our end-to-end compliance programme, or browse all our governance services.
Frequently asked questions
Find out how far you are from certification
Tell us what you want certified and why. You get an honest view of the gap, a sensible scope and a realistic timeline before you commit to anything.