ISO 27001 support

ISO 27001 is the international standard for an information security management system, and the level of assurance larger clients, the public sector and regulators ask for. We take you from gap analysis to certification, and we run the standard ourselves. We are certified to it by a UKAS-accredited certification body, so we know what an assessment expects.

Verified
ISO 27001 & 9001Certified by a UKAS-accredited certification body Cyber EssentialsCertification body NCSC AssuredCyber Advisor CISSPHeld by Daniel McClure Fisher MCIISChartered Institute of Information Security, Full Member, held by Daniel McClure Fisher
ISO 27001 and ISO 9001 certified, via a UKAS-accredited certification body

Certified to ISO 27001 and ISO 9001

We run the standards we consult on. Our information security and quality management systems are certified by a UKAS-accredited certification body, and audited to keep that certification. We sit the audits you are facing.

The team behind the certificates
ISO 27001 / 01 · What it is

What ISO 27001 certifies

ISO 27001 does not check a fixed list of controls. It certifies that you run a working system for deciding which risks matter, choosing controls, assigning ownership and reviewing the whole thing over time. The current version is ISO 27001:2022.

01An ISMSA documented information security management system, run and reviewed continuously.
02Risk ledControls chosen from Annex A to address the risks that apply to you.
03Two stage auditAn external audit in two stages by a certification body, then ongoing surveillance.
04Months, not weeksPlan it as a programme: commonly several months to over a year to certify.
ISO 27001 / 02 · What we do

From gap analysis to certification

A longer road than Cyber Essentials, and that is the point: the work is building a system that runs, not passing a single test. We run the technology underneath it too, so the management system describes what is in place rather than an aspiration.

01

Scope and gap analysis

We define what the ISMS covers and assess the gap to the standard, so the programme is realistic from the start.

02

Build the ISMS

We develop the policies, procedures and risk treatment plan, and select the Annex A controls that fit your risks. Documents people will follow, not shelfware.

03

Operate and audit

You run the system long enough to produce evidence, with the internal audit and management review the standard requires before certification.

04

Certify and maintain

We prepare you for the two stage external audit and stand with you through it, then keep the system live through the surveillance audits.

We hold the certificate too. Our own ISO 27001 certificate is issued by a UKAS-accredited certification body, so we build your management system knowing what the audit asks for.
ISO 27001 / 03 · Read the clause

Certified, aligned and equivalent

This is where suppliers get caught out. An auditor knows the difference, so answer the question that was asked.

If your contract says "ISO 27001 or equivalent", confirm with the buyer what they will accept before you commit to the larger programme.

CertifiedAudited and issuedAn accredited certification body has assessed you and granted a certificate.
AlignedWorking to the standardYou meet the standard without holding the certificate. Say that, not certified.
EquivalentConfirm what countsAsk the buyer what they accept before committing to the full programme.
FAQ

Common questions

What is ISO 27001?

ISO 27001 is the international standard for an information security management system, or ISMS. Rather than checking a fixed list of controls, it certifies that you run a working system for assessing risk, choosing controls, assigning ownership and reviewing the whole thing over time. The current version is ISO 27001:2022, and a certificate from a UKAS-accredited body carries weight with enterprise and public sector buyers.

How long does ISO 27001 certification take?

Plan it as a programme rather than a quick project. It commonly takes several months to over a year, because you have to build the management system, run it long enough to produce evidence, and then pass a two stage external audit. The timeline depends on the size of your organisation, the scope of the ISMS, and how much groundwork is already in place. A gap analysis gives you a realistic picture up front.

What is the difference between certified and aligned to ISO 27001?

They are materially different. Certified means an accredited certification body has audited you and issued a certificate. Aligned, or equivalent, means you work to the standard without holding the certificate. Be careful not to claim you are certified when you are aligned, because an auditor will know the difference. If a contract says "or equivalent", confirm with the buyer what they will accept before committing.

Do I need Cyber Essentials before ISO 27001?

You do not have to, but it often helps. The five Cyber Essentials controls map onto controls within ISO 27001's Annex A, so certifying to Cyber Essentials first gives you a clean technical baseline and early evidence. Many firms hold both: Cyber Essentials as the fast, public baseline, ISO 27001 underneath as the governance layer.

Are you ISO 27001 certified yourselves?

Yes. We run an information security management system and are certified to ISO 27001 by a UKAS-accredited certification body. It means we know what an assessment expects, so the system we build with you is shaped by experience rather than a template. We keep our own status and the service we offer you clearly separate.

Plan your ISO 27001 programme

Tell us what you need to satisfy, a contract, a regulator or the sensitivity of your data, and we will set out what it takes, how long it runs, and whether you need ISO 27001, Cyber Essentials or both.

Reading, Berkshire  /  ISO 27001, certified by a UKAS-accredited body  /  reply within one working day