Certification consulting

Your customer asked for the certificate. Here is how you actually earn it.

ISO/IEC 27001:2022 is the international standard for running an information security management system — the policies, risk decisions, controls and evidence that show security is managed rather than improvised. We are certified to it ourselves, which means we are not reading the clauses to you from a template. We build the ISMS with your team, run the internal audit and management review, prepare the evidence, and stay in the room for the certification audit.

Clay-style illustration of a navy certificate with a green seal beside policy folders
93
Annex A controls across 4 themes
3–6 months
Typical route to Stage 2 for an SME
3 years
Certificate validity, with annual surveillance

Sound familiar?

If two of these describe your week, this is the service that fixes it.

  • An enterprise customer or a tender has made ISO 27001 a condition of doing business, and the deadline is real.

  • You downloaded a policy pack, filled in your company name, and an auditor will see through it in ten minutes.

  • You started this once, the internal audit and management review never happened, and the project quietly died.

What the service covers

How the work is actually done, day to day.

01

Scope and gap analysis first

We define an honest ISMS scope — which entities, sites, systems and services are in — then measure you against clauses 4 to 10 and all 93 Annex A controls. You get a gap register with owners and effort estimates, not a red-amber-green picture with no plan behind it.

02

Risk assessment your auditor will believe

A documented methodology, a real asset and threat register, risk owners who know they own something, and a treatment plan tied to specific Annex A controls. The Statement of Applicability is then a consequence of the risk work rather than a form filled in afterwards.

03

Controls implemented, not just written down

Access reviews, logging, backup testing, supplier assessments, secure development, joiner-mover-leaver, incident response and awareness training — built into how your teams already work, and generating evidence automatically wherever we can.

04

Internal audit, management review and the audit itself

We run the internal audit programme, prepare the management review agenda and minutes, drill your team on likely auditor questions, and support you live through Stage 1 and Stage 2 — including drafting corrective actions if a nonconformity is raised.

What you receive

Documents you can hand to an auditor.

  • ISMS scope statement, information security policy and objectives
  • Risk assessment methodology, risk register and risk treatment plan
  • Statement of Applicability justifying every one of the 93 Annex A controls
  • Complete mandatory document set, internal audit reports and management review minutes
  • Certification-body shortlist, audit-day support and post-audit corrective action tracking

Platforms we work with

Fluent in the tools, loyal to none of them.

ISO/IEC 27001:2022 & 27002 guidanceNABCB / UKAS / ANAB accredited certification bodiesRisk register & SoA toolingEvidence automation on Microsoft 365 / Google WorkspaceInternal audit programme design

If you already hold licences, we operate them — no resale margin, no forced migration. When a change genuinely closes a gap or saves money, you see both cost models side by side before anyone recommends anything.

Onboarding

How iso 27001 certification goes live.

  1. 01

    A 45-minute conversation

    What you run, what worries you, and what a bad week has already cost you. No slides and no product pitch — we are working out whether we can genuinely help.

  2. 02

    Posture assessment

    We examine the estate, compare it against a recognised framework and hand you a prioritised list of gaps. The report is yours to keep whether or not you buy anything.

  3. 03

    Onboarding and a rehearsal

    Log sources, agents, access and escalation contacts are agreed, then we run a live drill of a real incident before we call the service live. Untested escalation paths are decoration.

  4. 04

    Steady-state operations

    Monitoring, response and reporting run to a written SLA, with a quarterly review that changes the plan whenever your business changes.

Questions

What buyers ask about iso 27001 certification.

Hand iso 27001 certification to people who do this daily.

Tell us how big the estate is and what deadline you are working to. Within three business days you will have a scope, a timeline and a flat monthly number — no discovery fee to get there.