Secure

ISO 27001 & Compliance

Hands-on help to reach and hold ISO 27001, from gap analysis and policies through to audit. Security you can prove on paper.

ISO 27001 & Compliance

ISO 27001 opens doors with larger clients, but the process can feel overwhelming. We do the heavy lifting with you, from gap analysis through to audit, then help you keep the system running.

We begin with a gap analysis against the standard, then build the policies, risk assessment and statement of applicability with you rather than handing you a template. We support you through internal audit and certification, and help you keep the system running afterwards.

What is included

Gap analysis
Risk assessment
Policies and processes
Statement of Applicability
Internal audit
Audit support

How we deliver it

01

Gap analysis

We measure where you are against the standard.

02

Build

We write policies, risk assessment and statement of applicability with you.

03

Audit

We run internal audit and support you through certification.

04

Maintain

We keep the system running year on year.

Common questions

How long does it take to get ISO 27001 certified from a standing start?
For most small and medium firms it takes somewhere between six and twelve months, depending on how mature your processes already are and how much time your team can give it. The gap analysis and building the policies and risk assessment is the bulk of the early work, followed by a period of running the system so there is evidence to audit. We pace it around your business rather than forcing an unrealistic deadline.
Do we need ISO 27001 if we already have Cyber Essentials?
They do different jobs. Cyber Essentials proves you have five technical controls in place and is quick to achieve. ISO 27001 is a full management system covering how you assess risk, write policy, train staff and handle incidents across the whole business, and larger clients and tenders increasingly ask for it specifically. Many firms hold both, using Cyber Essentials as a foundation on the way to ISO 27001.
Will you write our policies, or do we have to do it ourselves?
We write them with you rather than handing over a generic template that does not match how you work. We draft the policies, risk assessment and Statement of Applicability based on your actual systems and processes, then refine them with you so they are accurate and you understand what you are signing up to. An auditor can tell the difference between a real system and a downloaded one, so this matters.

Want this looked after properly?

Book a short, no obligation call and we will tell you straight what we would do and what it would cost.

Book a consultation
Back to services