Govern & Assure
ISO 27001
ISO 27001 support from initial scoping and gap assessment through to implementation, audit readiness, and ongoing ISMS management.
- A clear ISMS scope
- A practical view of your current position
- Prioritised gaps and next steps
- Support through implementation
- Readiness for certification
Your route to ISO 27001 compliance
Scoping
ISO 27001 scoping to define the boundaries of your ISMS, clarify what needs to be included, and establish a practical basis for implementation and certification.
Gap Analysis & Readiness
Measure your ISMS against ISO 27001 as it stands today, and get a prioritised route to certification with a date you can commit to.
Certification & Audit Support
ISO 27001 certification and audit support to help you prepare for independent certification, support the audit process, and respond to findings.
Ongoing Support
Ongoing ISO 27001 support to help you keep the ISMS operating, prepare for surveillance audits, and maintain the governance, evidence, and improvement activity that certification depends on.
Most organisations do not struggle with ISO 27001 because the standard is impossible to understand. They struggle because the ISMS is too broad, ownership is unclear, documentation does not reflect how the business actually works, or the project becomes a paper exercise rather than a useful management system.
Done properly, ISO 27001 gives you a structured way to manage information security: defining responsibilities, managing risk, selecting and operating controls, and demonstrating that those arrangements are working. Certification then adds independent assurance that can help build trust with customers, partners, and other stakeholders.
We start by getting those foundations right. That means defining the ISMS scope, understanding the certification objective, reviewing your current controls and documentation, and identifying gaps against ISO 27001:2022. The assessment covers the management system requirements in clauses 4–10 as well as the relevant Annex A controls.
From there, we help you build or improve the ISMS, prioritise the work, prepare for internal and external audits, and support your team through certification. The independent certification body makes the final certification decision. Our role is to make sure you are ready for that process and that the ISMS is working in practice, not just on paper.
For many organisations, especially in B2B markets, certification is also commercially useful. It can strengthen tender responses, reduce friction in supplier due diligence, and help differentiate you where security maturity matters in the buying decision.
Certification is only one milestone. We can also stay involved afterwards to support internal audits, ongoing ISMS activities, evidence, continual improvement, and preparation for future surveillance or recertification.
Get a quote for ISO 27001
Tell us your scope and objectives, and we’ll come back with a clear, fixed proposal, usually the same working day.
Get a Quoteor call +44 (0) 203 393 7795- CREST-accredited
- UK-based specialists
- Crown Commercial Service supplier
What you get
A clear ISMS scope
We help define what the management system needs to cover, which parts of the organisation are in scope, and where the boundaries sit.
A practical view of your current position
We assess your existing documentation, controls, and working practices against ISO 27001:2022 so you know what is already in place and what is missing.
Prioritised gaps and next steps
You get a clear view of the work required, including where the biggest effort lies and what to tackle first.
Support through implementation
We work with your team to turn the gap assessment into a working ISMS, not just a list of findings.
Readiness for certification
We help you prepare the ISMS, evidence, and people for the certification audit, and support you throughout the process.
Ongoing ISMS support
After certification, we can stay involved to support internal audits, recurring reviews, evidence, and continual improvement.
Frequently asked questions
Straight answers to what prospective clients ask us most.
We want ISO 27001, but we are not sure where to start. What should we do first?
Start with scope and readiness. We help you define what the ISMS needs to cover, understand the certification objective, and assess your current position before you commit effort to implementation.
What if ISO 27001 certification is not the right objective?
Certification is useful when you need formal, independent assurance, but it is not the only route. We can use ISO 27001 principles, or a broader risk and controls approach, to assess your position, improve control maturity, and build a structured security programme without certification.
Do we need a gap assessment before we start implementing?
Not always, but it is usually the best starting point if your current position is unclear. A gap assessment shows what is already in place, what is missing, and where the effort is likely to sit.
Can you help us build the ISMS, or do you only assess it?
We do both. We can deliver a focused gap assessment on its own, work with your team through implementation and audit readiness, or stay involved through the wider certification programme.
Do you issue the ISO 27001 certificate?
No. An independent certification body carries out the certification. We help you prepare for the audit, close gaps, and support you through the certification process.
What will you need from us?
Access to the people who understand the organisation, systems, risks, and existing controls, plus any relevant policies, procedures, and evidence. We agree the exact input at the start.
What happens if the gap assessment finds a lot of work?
We prioritise it, showing what matters most, what can be dealt with quickly, and where more substantial work is needed, so the implementation plan is realistic.
Can you work with an ISMS we have already started?
Yes. You do not need to start again. We review what is already in place, identify gaps, and help you move the existing work towards certification.
What happens after certification?
The ISMS still needs to operate. Internal audit, management review, risk treatment, evidence, and continual improvement continue after the certificate is issued. We can support those activities on an ongoing basis, including through our Clarity managed platform, where structured tracking and visibility are useful.
Do we need ISO 27001 certification, or can we just use the standard informally?
Not every organisation needs formal certification. Some use ISO 27001 as a framework to improve security governance, risk management, and control without undergoing an external audit.
Certification becomes more valuable where customers, tenders, or other stakeholders want independent assurance. In B2B markets, a recognised certificate can also make it easier for buyers to trust your security arrangements and set you apart from suppliers who cannot show the same assurance.
If certification is not required, we can still use ISO 27001 to structure and improve your ISMS.
Related services
Ready to talk about iso 27001?
Get a fixed-scope quote, usually the same working day.