Get ISO 27001 certified without stalling the roadmap
A consulting engagement that builds the ISMS with your team and takes you through the accredited Stage 1 and Stage 2 audits — with a fixed scope and a firm price agreed before you commit.
- Built against ISO/IEC 27001:2022 and the current Annex A controls
- Scoped to a defined outcome with a fixed or capped fee
- Runs alongside your team — no binder of generic templates
- Support through the accredited certification audit
Where do you stand?
A quick self-check before you get in touch
ISO 27001 readiness check
Six quick questions, about a minute. You see the result straight away — no email required.
Why this comes up
ISO 27001 has become a standard entry requirement in enterprise procurement and public tenders. Certification requires an accredited body to assess your Information Security Management System in a two-stage audit, then re-check it at surveillance audits across a three-year cycle.
The management system also has to be seen to operate for a period before the Stage 2 audit — which is why the work usually needs to start well before the date a customer has asked for.
What the engagement covers
Scope and context
Agree the ISMS scope, interested parties and how information security objectives map to business objectives.
Risk assessment and treatment
Establish a repeatable risk method, run the first assessment, and produce the risk treatment plan and Statement of Applicability against Annex A.
Policies and controls
Draft and adapt the policies and controls your context needs, and support the teams that have to operate them.
Evidence and operation
Stand up evidence collection, internal audit, management review and corrective action so the ISMS is demonstrably running before the audit.
Certification audit support
Prepare for and attend the Stage 1 and Stage 2 audits with the certification body, and help close any findings.
How it runs
- 01
Gap assessment
Assess where you are against ISO/IEC 27001:2022 and turn it into a prioritised plan with owners and effort estimates.
- 02
Build the ISMS
Scope, risk method and assessment, Statement of Applicability, policies and the controls that need work.
- 03
Operate it
Run the ISMS for a period — evidence, internal audit, management review — so there is a track record to show.
- 04
Stage 1 audit
The certification body reviews documentation and readiness. We prepare for it and attend.
- 05
Stage 2 audit
The certification body tests the ISMS in operation. We support the audit and help close findings.
What you get
- ISMS scope statement and context analysis
- Risk assessment methodology, risk register and treatment plan
- Statement of Applicability (Annex A)
- Information security policy set tailored to your organisation
- Internal audit programme and first internal audit report
- Management review pack and audit-readiness review
Common questions
More detail on the ISO 27001 service page.
Frameworks and platforms we work across
Scope your ISO 27001 project
Book a short assessment call — we map where you are against the standard and agree the next step.
