Gap analysis
Where you stand today against the standard.
ISO 27001 shows clients you manage information security properly. Our consultants help you build an information security management system that fits how you work, and get it certified.
Last reviewed

ISO 27001 is the international standard for information security management. Certification is increasingly expected by larger clients, especially in finance, technology and professional services.
We keep it practical. Rather than a pile of generic templates, we build policies and processes around how your business already runs, so the system is useful as well as certifiable.
Where you stand today against the standard.
The information security risk assessment at the heart of ISO 27001.
Policies, procedures and the Statement of Applicability, written to fit your business.
Practical help putting the Annex A controls in place.
An independent internal audit before the certification audit.
Preparation for and support during the external audit.
Compare where you are with the standard.
Create the ISMS and implement controls.
Run the internal audit and management review.
Support through the certification body's audit.
From gap analysis to certification, with our consultants alongside you.
A clear report of what is needed and how long it will take.
Independent internal audits to keep your certification on track.
Help with surveillance audits, changes and the 2022 transition.
The number of people, locations and systems in your ISMS scope.
Existing policies and controls reduce the work needed.
Full implementation or targeted help where you need it.
The external audit fee is separate and set by the certification body.
After a gap analysis we give you a clear breakdown of ISO 27001 certification cost: our fees and the expected certification body fee.
Get a quoteAn international standard for managing information security. It requires a risk-based management system (an ISMS) covering people, processes and technology.
It depends on the size and complexity of your business and how much is already in place. There are consultancy costs and a separate certification body fee. A gap analysis gives you an accurate figure.
Typically several months for a small to medium business, depending on your starting point and the time your team can give.
The Annex A controls were reorganised into four themes and some new controls were added, such as threat intelligence and cloud security. We help existing certificate holders transition.
A short call, no obligation. We'll listen, ask a few questions and suggest a sensible first step.
Tell us a little about your business. We'll arrange a short, no-obligation conversation and suggest a sensible first step.
The Leather Market
London Bridge