Gap analysis and scoping
Where your firm stands against the standard today, what is in scope, and a realistic route to certification — agreed before any work starts.
Gap analysis, ISMS build, controls implemented hands-on and support through the certification audit — from a team that has implemented ISO 27001 inside regulated businesses, not just written policies about it.
Fixed-price engagements · No long tie-in contracts · An honest view on whether ISO 27001 is the right step yet.
ISO 27001 has become the question larger clients, frameworks and due diligence questionnaires ask by default. For a growing firm, one required certification on one important contract is usually what starts the clock.
Done badly, ISO 27001 is a binder of policies nobody follows and a certificate that barely survives its first surveillance audit. Done properly, the ISMS is simply how the firm manages information risk — and the certificate is the by-product. We build the second kind.
A complete route to ISO 27001 for firms without an in-house compliance team, scoped and priced before work starts.
Where your firm stands against the standard today, what is in scope, and a realistic route to certification — agreed before any work starts.
A structured information security risk assessment for your firm, with a treatment plan that reflects your real exposure — not a generic template.
The information security management system itself: policies, processes, the Statement of Applicability and control selection — written to be used, not filed.
The technical and organisational controls put genuinely in place across your systems, suppliers and people — the same hands-on work we do for Cyber Essentials, at ISO depth.
Evidence gathered as you go, internal audits run before the external one, and the gaps closed while they are still cheap to fix.
Preparation for the certification body audit, support during it, and help resolving findings — then ongoing maintenance through surveillance audits year after year.
They answer different questions. Cyber Essentials proves the technical basics are in place; ISO 27001 proves the firm manages information security as a system. Many firms hold both — and the gap analysis will tell you honestly which your firm needs now.
Agree what the ISMS covers, review how your firm operates, and set a realistic plan and fixed price for the route to certification.
Run the risk assessment, map your current controls against the standard, and prioritise the gaps that actually matter.
Implement the ISMS: policies, processes and controls put in place and evidenced — with your team involved, so it survives contact with real work.
Internal audit, then the certification body audit with support throughout — and ongoing maintenance so surveillance audits are routine, not a scramble.
ISO/IEC 27001 is the international standard for information security management. Rather than a fixed checklist of technical settings, it certifies that your firm runs a working information security management system (ISMS): you understand your risks, you have chosen and implemented controls to treat them, and you can evidence that the system operates day to day. Certification is issued by an independent, accredited certification body after an audit.
Cyber Essentials is a UK baseline covering five technical controls — excellent value, and often the right starting point. ISO 27001 goes much further: it covers governance, people, processes, suppliers and physical security as well as technology, and it is independently audited and internationally recognised. Many firms hold both — Cyber Essentials as the technical floor, ISO 27001 as the management system clients and tenders increasingly ask for.
The usual triggers are commercial: a major client requires it of suppliers, a tender scores it, or due diligence questionnaires keep asking for it. For regulated and professional firms it is also the most credible way to demonstrate information security governance to boards, insurers and regulators. If those pressures have not reached you yet, Cyber Essentials may be the more proportionate step — we will tell you honestly which fits.
An independent certification body — not us, and that separation is the point. Our role is to build the ISMS with you, implement the controls, run the internal audits and support you through the certification audit. We recommend using a UKAS-accredited certification body so the certificate carries full weight with clients and tenders.
It depends on your size, your current maturity and the scope you choose — which is exactly what the gap analysis establishes. Our support is fixed-price once scoping shows what your firm needs, with no long tie-in contracts. The certification body charges its own audit fees separately, based on the size and scope of your organisation.
A no-obligation call to review your scope, your current maturity and the realistic route — including whether Cyber Essentials is the smarter first step.
Prefer to talk? Call 0330 223 7404