top of page

ISO/IEC 27001

Independent internal audits, gap analyses, and hands-on implementation support for the information security standard most of your enterprise customers are asking about. We help you get certified — and actually understand the system once you are.

WHAT IT IS

Information Security

The international standard for managing information security

CURRENT VERSION

ISO/IEC 27001:2022

93 Controls across 4 control categories

CERTIFIABLE?

Yes

Through an accredited certification body

BEST FOR

SaaS, Tech, MSPs

Anyone handling sensitive or customer data

STANDARD EXPLANATION

What is ISO 27001?

ISO 27001 is the international standard for information security. Rather than handing you a checklist of security tools to buy, it asks you to build something called an information security management system — an ISMS. That's just a structured way of deciding what information you need to protect, what could go wrong, and what you're going to do about it.

The current version is ISO/IEC 27001:2022. At its core sits a risk assessment: you identify your information security risks, decide how to treat them, and then select controls to manage them. The standard includes a reference set of 93 controls (in Annex A), grouped into four themes — organisational, people, physical, and technological. You don't have to apply all of them; you justify which ones are relevant to you in a document called the Statement of Applicability.

The part people underestimate is that ISO 27001 isn't a one-off project. Certification lasts three years, with a surveillance audit every year, and the standard expects you to keep running risk assessments, internal audits, and management reviews throughout. That's exactly why understanding your own system matters more than just passing the first audit.

The internal audit isn't optional. Clause 9.2 of the standard requires you to run internal audits of your ISMS at planned intervals — and you'll need evidence of them to certify and to keep certified. It's one of the most common things we're brought in to do.

WHY PEOPLE COME TO US FOR IT

Do you actually need ISO 27001?

ISO 27001 isn't a legal requirement — but it's frequently a commercial one. For most of the businesses we work with, the need shows up in one of a few familiar ways.

01

A customer is asking for it. An enterprise client or prospect has put ISO 27001 in their procurement requirements or security questionnaire, and a deal is waiting on it.

02

You're tired of bespoke security questionnaires. Certification gives you a single, recognised answer instead of filling in a different 200-row spreadsheet every prospect.

03

You want to mature, deliberately. You're handling more customer data than you used to, and you want a credible framework to manage the risk before something forces your hand

HOW WE HELP

Two ways in. Same principle throughout.

Whether we're independently auditing your ISMS or helping you build it, you stay involved and you walk away understanding it. Here's how that splits for ISO 27001.

Audit & Assessment · Independent

We check your system against the standard.

Impartial, evidence-based work — and kept separate from your certification body, so nobody's marking their own homework.

  • Gap analysis against ISO 27001:2022 before you commit

  • Internal audits to satisfy clause 9.2 (required to certify)

  • Supplier assessments to satisfy Supplier Management controls

  • Clear findings — conformities, nonconformities, observations

Implementation Support · Collaborative

We help you build the ISMS — alongside you.

Hands-on help with the parts that genuinely need it, with your team driving the work so you can run it afterwards.

  • Scoping your ISMS and defining what's in and out

​​

  • Building the risk assessment and treatment plan

  • Writing policies and procedures with you, not for you

  • Producing the Statement of Applicability and prepping for audit

COMMON QUESTIONS

ISO 27001 questions we hear a lot

Is ISO 27001 a legal requirement?

No. ISO 27001 is not a law — it's an international standard you choose to certify against. In practice it's often a commercial requirement: enterprise customers, procurement teams, and security questionnaires frequently ask for it before they'll sign, so for many SaaS businesses and MSPs it becomes effectively mandatory to win larger deals.

Is an internal audit mandatory for ISO 27001?

Yes. Clause 9.2 requires you to run internal audits of your ISMS at planned intervals. You need evidence of internal audits both to achieve certification and to keep it at each surveillance visit. Using an independent auditor keeps those findings credible — and is exactly the kind of work we do.

What's the difference between a gap analysis and an internal audit?

A gap analysis is a starting-point exercise: it shows how far your current setup is from meeting the standard, so you know what to build. An internal audit is a formal check of an established system against the standard's requirements, producing documented findings. Most teams start with a gap analysis, build the system, then run internal audits once it's in place.

Do we issue the ISO 27001 certificate?

No — and that separation matters. The certificate is issued by an accredited certification body after their own Stage 1 and Stage 2 audits. We're independent of that process. We help you get ready and run the internal audits the standard requires, but we don't mark our own work or yours.

How long does it take to get ISO 27001 certified?

For a smaller business starting from scratch, three to six months of focused work is a realistic range before you're ready for the certification audit. It depends heavily on your starting point, how much already exists informally, and how much time your team can give it. A gap analysis up front gives you a far more accurate timeline.

Can a small company get ISO 27001 certified?

Yes. The standard scales to the size and complexity of your organisation. A ten-person SaaS company doesn't need the same controls as a multinational bank — what matters is that your information security management system is appropriate to your context and consistently followed.

RELATED STANDARDS

Often comes up alongside

ISO 27701

The standalone standard for managing personal data. Pairs naturally with your ISMS, though no longer dependent on it.

Privacy Information Management
ISO 42001

The newer standard for managing AI responsibly - increasingly relevant for tech companies handling data.

AI Management
SOC 2

The US-centric alternative often requested by American customers instead of or alongside ISO 27001.

Service Organisation Controls

If you need a clear view of where you stand - let's talk.

A 30-minute discovery call costs nothing. We'll tell you whether we're the right fit, what the work would involve, and what you'd get out of it. No pitch, no pressure.

bottom of page