ISO 27001 support
ISO 27001 is the international standard for an information security management system, and the level of assurance larger clients, the public sector and regulators ask for. We take you from gap analysis to certification, and we run the standard ourselves. We are certified to it by a UKAS-accredited certification body, so we know what an assessment expects.
Certified to ISO 27001 and ISO 9001
We run the standards we consult on. Our information security and quality management systems are certified by a UKAS-accredited certification body, and audited to keep that certification. We sit the audits you are facing.
The team behind the certificatesWhat ISO 27001 certifies
ISO 27001 does not check a fixed list of controls. It certifies that you run a working system for deciding which risks matter, choosing controls, assigning ownership and reviewing the whole thing over time. The current version is ISO 27001:2022.
From gap analysis to certification
A longer road than Cyber Essentials, and that is the point: the work is building a system that runs, not passing a single test. We run the technology underneath it too, so the management system describes what is in place rather than an aspiration.
Scope and gap analysis
We define what the ISMS covers and assess the gap to the standard, so the programme is realistic from the start.
Build the ISMS
We develop the policies, procedures and risk treatment plan, and select the Annex A controls that fit your risks. Documents people will follow, not shelfware.
Operate and audit
You run the system long enough to produce evidence, with the internal audit and management review the standard requires before certification.
Certify and maintain
We prepare you for the two stage external audit and stand with you through it, then keep the system live through the surveillance audits.
Certified, aligned and equivalent
This is where suppliers get caught out. An auditor knows the difference, so answer the question that was asked.
If your contract says "ISO 27001 or equivalent", confirm with the buyer what they will accept before you commit to the larger programme.
Common questions
What is ISO 27001?
ISO 27001 is the international standard for an information security management system, or ISMS. Rather than checking a fixed list of controls, it certifies that you run a working system for assessing risk, choosing controls, assigning ownership and reviewing the whole thing over time. The current version is ISO 27001:2022, and a certificate from a UKAS-accredited body carries weight with enterprise and public sector buyers.
How long does ISO 27001 certification take?
Plan it as a programme rather than a quick project. It commonly takes several months to over a year, because you have to build the management system, run it long enough to produce evidence, and then pass a two stage external audit. The timeline depends on the size of your organisation, the scope of the ISMS, and how much groundwork is already in place. A gap analysis gives you a realistic picture up front.
What is the difference between certified and aligned to ISO 27001?
They are materially different. Certified means an accredited certification body has audited you and issued a certificate. Aligned, or equivalent, means you work to the standard without holding the certificate. Be careful not to claim you are certified when you are aligned, because an auditor will know the difference. If a contract says "or equivalent", confirm with the buyer what they will accept before committing.
Do I need Cyber Essentials before ISO 27001?
You do not have to, but it often helps. The five Cyber Essentials controls map onto controls within ISO 27001's Annex A, so certifying to Cyber Essentials first gives you a clean technical baseline and early evidence. Many firms hold both: Cyber Essentials as the fast, public baseline, ISO 27001 underneath as the governance layer.
Are you ISO 27001 certified yourselves?
Yes. We run an information security management system and are certified to ISO 27001 by a UKAS-accredited certification body. It means we know what an assessment expects, so the system we build with you is shaped by experience rather than a template. We keep our own status and the service we offer you clearly separate.
Plan your ISO 27001 programme
Tell us what you need to satisfy, a contract, a regulator or the sensitivity of your data, and we will set out what it takes, how long it runs, and whether you need ISO 27001, Cyber Essentials or both.



