Govern & Assure
ISO 27001 Certification & Audit Support
ISO 27001 certification and audit support to help you prepare for independent certification, support the audit process, and respond to findings.
- Certification readiness review
- Internal audit support
- Audit preparation
- Support through the audit
- Findings and corrective action
ISO 27001 certification is the point where your ISMS has to stand up to independent scrutiny. We help make sure it does.
We review readiness, prepare your people and evidence, support you through the certification audit, and help address any findings that arise. The focus is on making the process clear and well organised, while ensuring the ISMS works in practice rather than only on paper.
Certification is carried out by an independent accredited certification body. We support the work around it, from readiness and internal audit through to the certification process and what comes afterwards.
Get a quote for ISO 27001 Certification & Audit Support
Tell us your scope and objectives, and we’ll come back with a clear, fixed proposal, usually the same working day.
Get a Quoteor call +44 (0) 203 393 7795- CREST-accredited
- UK-based specialists
- Crown Commercial Service supplier
How it works
- 01
Confirm where you are
We start by understanding how far the ISMS has progressed, what has already been implemented, and what remains before certification.
- 02
Review readiness
We review documentation, evidence, and operating practices to identify any areas that still need attention before the audit.
- 03
Complete internal audit activity
We carry out or support internal audit work to provide a clear view of whether the ISMS is working as intended.
- 04
Prepare the organisation
We help relevant stakeholders understand the audit process, make sure evidence is accessible, and resolve practical gaps before the audit begins.
- 05
Support the certification audit
We support your team during the audit, helping with evidence, clarification, and any questions that arise.
- 06
Address findings and move forward
Where findings are raised, we help you understand the issue, plan corrective action, and prepare the supporting evidence. After certification, support can continue into surveillance and ongoing ISMS management.
Ready for audit, not just ready on paper
The certificate is issued by an independent certification body, never by us; our job is to get you ready for them and stand beside you on the day. We prepare the evidence pack, brief the people who will be interviewed on what they will be asked, and attend the audit to handle the process while your team answers on their own subject.
Where the auditor raises findings, we help you respond: root cause, corrective action, and the evidence that closes it within the window the certification body allows.
What you get
Certification readiness review
A structured review of the implemented ISMS to identify anything that still needs attention before the certification audit.
Internal audit support
Independent internal audit activity to test whether the ISMS is operating as intended and whether key requirements are being met.
Audit preparation
We help prepare the people, evidence, and documentation involved so the organisation knows what to expect and can demonstrate how the ISMS works in practice.
Support through the audit
We stay involved during the certification process, helping with evidence, clarification, and questions as they arise.
Findings and corrective action
If the audit raises nonconformities or other issues, we help you understand what needs to change and support the resulting corrective action.
Evidence and audit coordination
We help organise the evidence, stakeholders, and audit activity so the certification process stays clear, structured, and easier to manage.
Frequently asked questions
Straight answers to what prospective clients ask us most.
Do we need an internal audit before certification?
Yes. Internal audit is an important part of operating an ISO 27001 ISMS and provides an independent view of whether the management system is working as intended.
We carry out internal audit activity as a one-off exercise or as part of a recurring programme.
What is the difference between a readiness review and the certification audit?
A readiness review is designed to identify weaknesses before the formal certification process begins. The certification audit is the formal assessment of whether the ISMS meets the requirements for certification.
Do you support us during the audit itself?
Yes. We support your team during the certification process, helping with evidence, clarification, and questions where needed.
What happens if the audit identifies issues?
We help you understand the findings, identify the underlying cause, and work through the corrective action needed. The aim is to deal with issues quickly and properly, rather than leaving your team to interpret findings on their own.
What happens after certification?
The ISMS still needs to operate, be reviewed, audited, and improved. We support surveillance preparation, recurring internal audits, management-system maintenance, and continual improvement after certification.
Related services
Ready to talk about iso 27001 certification & audit support?
Get a fixed-scope quote, usually the same working day.