Report an Incident Become a Partner Careers Contact
Book a Demo
Risk & compliance · ISO 27001

The certificate is
the easy part.

Getting to ISO 27001 is a project with a known shape. Keeping a management system alive through three years of surveillance audits is the part that catches organisations out, and it is the part we are built for.

ISMSyear 2, surveillance
SOAStatement of Applicability, currentheld
RISKRisk review completed and recordeddone
SOCMonitoring evidence, twelve monthscontinuous
NCCorrective action still opentracked
AUDITInternal audit, evidencedpassed
UKASCertificate from an accredited bodynot us
What you are actually building

A management system,
not a document set.

ISO 27001 certifies an information security management system: the way you identify risk, decide what to do about it, and demonstrate that it works. The controls are downstream of that.

The 2022 version puts 93 controls in Annex A across four themes, and the Statement of Applicability records which apply to you and why anything is excluded. That document is where an auditor goes first, and a weak one signals a programme that was written rather than run.

None of it is certified by us. Certification is issued by a body accredited by a national accreditation authority, UKAS in the UK, and the separation is deliberate: whoever builds your management system must not be the one attesting to it. We do the readiness, the build and the evidence, and we sit with you through both audit stages.

  • A risk assessment that drives control selection, rather than a control list applied blindly.
  • A Statement of Applicability that survives contact with an auditor.
  • Policies and procedures that describe what actually happens.
  • Evidence the system is operating, not just that it was documented.
  • Stage 1 and Stage 2 support, with the certificate coming from an accredited body.
The part that fails in year two

Certified once
is not certified.

The certificate lasts three years, with surveillance audits along the way. The common failure is not failing the initial audit. It is an ISMS that was built to pass one and then stopped being operated.

It is easy to see how it happens. A consultant builds the system, the organisation passes Stage 2, the consultant leaves, and the management reviews, risk reviews, internal audits and corrective actions quietly stop. Eleven months later somebody realises the surveillance audit is in three weeks and the last twelve months of evidence does not exist.

Where we run your SOC, a large part of that evidence is a by-product of the service. Monitoring coverage, incidents and their investigation records, response actions and supplier assessments are produced because the work is happening. The management system stays fed without anybody having to remember to feed it.

Third-party risk management

Surveillance audits come round
Annually, and they look for evidence from the period since the last one. A system that only runs before an audit produces a visible gap.
Monitoring evidence, continuously
Coverage, detections, tuning history and incident records answer a large part of Annex A directly, and they carry dates.
Supplier controls, already evidenced
The supplier-management controls are answered by a register, tiering rationale and assessment records rather than by a policy that says you have a process.
Corrective actions that close
Findings tracked through to closure with the reasoning recorded, which is the artefact an auditor asks for at the next visit.
How it runs

Gap, build,
evidence, audit.

Certification is a two-stage audit at the end of a programme with a known shape. Nothing here should be a surprise.

  1. 01

    Gap analysis

    Where you stand against the standard and against Annex A, producing a gap list with an order of work. For many organisations this is the whole first engagement.

  2. 02

    Scope and risk

    What the management system covers, the risk assessment that drives control selection, and the Statement of Applicability that records the decisions.

  3. 03

    Build it

    Controls, policies and procedures that describe what you actually do. Our consultants take the judgement calls; the platform we run for you carries the mapping and the document set.

  4. 04

    Operate and evidence

    The system has to run before it can be audited: internal audits, management review, corrective actions and the evidence that all of it happened.

  5. 05

    Stage 1 and Stage 2

    Stage 1 reviews the documented system, Stage 2 tests whether it operates. We are alongside you for both. The certificate is issued by the accredited body.

What drives the cost and the timeline

It depends on scope,
and anyone who says otherwise is guessing.

The second question everybody asks, usually right after how long it takes. Both have the same answer.

What the ISMS covers
One product and the team around it is a very different exercise from an entire group with multiple sites and jurisdictions. Scope is the single biggest lever and it is yours to set.
Where you are starting
An organisation already running monitoring, access control and incident response is largely evidencing what exists. One starting from nothing is doing the security work and the certification work at once.
How much is already written
Existing policies, a risk register and asset inventory shorten this considerably. Inheriting nothing means building the management system as well as the controls.
The certification body
Their audit days are billed separately from our work, priced on the size and complexity of your scope. We will tell you what to expect and introduce you to bodies we have worked with; you appoint them.
Surveillance, ongoing
The three-year cycle carries annual surveillance audits. Worth putting in the business case at the start rather than discovering in year two.

We scope it and then quote it. A figure offered before scope is agreed tells you nothing except that somebody wanted to look decisive.

Questions

ISO 27001, answered.

Can you certify us to ISO 27001?

No. Certificates are issued by a certification body accredited by a national accreditation authority, UKAS in the UK, and whoever builds your management system must not be the one certifying it. We do the readiness, the build and the evidence, and support you through both audit stages.

How much does ISO 27001 certification cost?

It depends on the scope of the management system, how much already exists and how complex your estate is. The certification body bills their audit days separately from our work. We scope it before quoting, because a number offered before scope is agreed is guesswork.

How long does it take?

Commonly six to twelve months from a standing start to Stage 2, less where monitoring, access control and incident response already run properly. The management system also has to operate for a period before it can be audited, which sets a floor no budget shortens.

What is a gap analysis?

An assessment of where you stand against the standard and Annex A, producing a prioritised list of what is missing. For many organisations it is the first engagement on its own: it turns an open-ended ambition into a scoped piece of work with a cost attached.

What happens at the Stage 1 and Stage 2 audits?

Stage 1 reviews your documented management system, including scope, risk assessment and Statement of Applicability, and flags anything that would fail. Stage 2 tests whether the system actually operates, through evidence and interviews. We are alongside you for both.

We are on the 2013 version. What changed in 2022?

Annex A was restructured into 93 controls across four themes rather than 114 in fourteen groups, with new controls covering threat intelligence, cloud services, data masking and secure coding. Existing certifications had to transition, and the Statement of Applicability needs remapping.

Does ISO 27001 help with SOC 2?

Yes, substantially. The control sets overlap heavily, so a second framework becomes a gap exercise rather than a new programme. The usual difference is evidence: SOC 2 Type II wants proof the controls operated across a defined window.

What happens after we are certified?

Surveillance audits annually and recertification every three years. That is the part organisations underestimate: the management system has to keep operating, with internal audits, management reviews and corrective actions evidenced throughout, not restarted three weeks before the auditor arrives.

Where to start

Start with a gap analysis
before anyone quotes a programme.

It turns an open-ended ambition into a scoped piece of work with a cost attached, and it is useful on its own even if nothing follows.