WHAT IT IS
Information Security
The international standard for managing information security
CURRENT VERSION
ISO/IEC 27001:2022
93 Controls across 4 control categories
CERTIFIABLE?
Yes
Through an accredited certification body
BEST FOR
SaaS, Tech, MSPs
Anyone handling sensitive or customer data
STANDARD EXPLANATION
What is ISO 27001?
ISO 27001 is the international standard for information security. Rather than handing you a checklist of security tools to buy, it asks you to build something called an information security management system — an ISMS. That's just a structured way of deciding what information you need to protect, what could go wrong, and what you're going to do about it.
The current version is ISO/IEC 27001:2022. At its core sits a risk assessment: you identify your information security risks, decide how to treat them, and then select controls to manage them. The standard includes a reference set of 93 controls (in Annex A), grouped into four themes — organisational, people, physical, and technological. You don't have to apply all of them; you justify which ones are relevant to you in a document called the Statement of Applicability.
The part people underestimate is that ISO 27001 isn't a one-off project. Certification lasts three years, with a surveillance audit every year, and the standard expects you to keep running risk assessments, internal audits, and management reviews throughout. That's exactly why understanding your own system matters more than just passing the first audit.
The internal audit isn't optional. Clause 9.2 of the standard requires you to run internal audits of your ISMS at planned intervals — and you'll need evidence of them to certify and to keep certified. It's one of the most common things we're brought in to do.
WHY PEOPLE COME TO US FOR IT
Do you actually need ISO 27001?
ISO 27001 isn't a legal requirement — but it's frequently a commercial one. For most of the businesses we work with, the need shows up in one of a few familiar ways.
01
A customer is asking for it. An enterprise client or prospect has put ISO 27001 in their procurement requirements or security questionnaire, and a deal is waiting on it.
02
You're tired of bespoke security questionnaires. Certification gives you a single, recognised answer instead of filling in a different 200-row spreadsheet every prospect.
03
You want to mature, deliberately. You're handling more customer data than you used to, and you want a credible framework to manage the risk before something forces your hand
HOW WE HELP
Two ways in. Same principle throughout.
Whether we're independently auditing your ISMS or helping you build it, you stay involved and you walk away understanding it. Here's how that splits for ISO 27001.
Audit & Assessment · Independent
We check your system against the standard.
Impartial, evidence-based work — and kept separate from your certification body, so nobody's marking their own homework.
-
Gap analysis against ISO 27001:2022 before you commit
-
Internal audits to satisfy clause 9.2 (required to certify)
-
Supplier assessments to satisfy Supplier Management controls
-
Clear findings — conformities, nonconformities, observations
Implementation Support · Collaborative
We help you build the ISMS — alongside you.
Hands-on help with the parts that genuinely need it, with your team driving the work so you can run it afterwards.
-
Scoping your ISMS and defining what's in and out
-
Building the risk assessment and treatment plan
-
Writing policies and procedures with you, not for you
-
Producing the Statement of Applicability and prepping for audit
COMMON QUESTIONS
ISO 27001 questions we hear a lot
Is ISO 27001 a legal requirement?
No. ISO 27001 is not a law — it's an international standard you choose to certify against. In practice it's often a commercial requirement: enterprise customers, procurement teams, and security questionnaires frequently ask for it before they'll sign, so for many SaaS businesses and MSPs it becomes effectively mandatory to win larger deals.
Is an internal audit mandatory for ISO 27001?
Yes. Clause 9.2 requires you to run internal audits of your ISMS at planned intervals. You need evidence of internal audits both to achieve certification and to keep it at each surveillance visit. Using an independent auditor keeps those findings credible — and is exactly the kind of work we do.
What's the difference between a gap analysis and an internal audit?
A gap analysis is a starting-point exercise: it shows how far your current setup is from meeting the standard, so you know what to build. An internal audit is a formal check of an established system against the standard's requirements, producing documented findings. Most teams start with a gap analysis, build the system, then run internal audits once it's in place.
Do we issue the ISO 27001 certificate?
No — and that separation matters. The certificate is issued by an accredited certification body after their own Stage 1 and Stage 2 audits. We're independent of that process. We help you get ready and run the internal audits the standard requires, but we don't mark our own work or yours.
How long does it take to get ISO 27001 certified?
For a smaller business starting from scratch, three to six months of focused work is a realistic range before you're ready for the certification audit. It depends heavily on your starting point, how much already exists informally, and how much time your team can give it. A gap analysis up front gives you a far more accurate timeline.
Can a small company get ISO 27001 certified?
Yes. The standard scales to the size and complexity of your organisation. A ten-person SaaS company doesn't need the same controls as a multinational bank — what matters is that your information security management system is appropriate to your context and consistently followed.
RELATED STANDARDS
Often comes up alongside
ISO 27701
The standalone standard for managing personal data. Pairs naturally with your ISMS, though no longer dependent on it.
Privacy Information Management
ISO 42001
The newer standard for managing AI responsibly - increasingly relevant for tech companies handling data.
AI Management
SOC 2
The US-centric alternative often requested by American customers instead of or alongside ISO 27001.

