Cyber Security » ISO 27001
ISO 27001 Consultant for SMEs
ISO 27001 has a reputation for taking a year and a small department. However, the work behind readiness can be straightforward: a risk assessment, a management system that fits how you run, and the evidence to pass an external audit.
We bring direct experience of building and maintaining a certified ISMS for multiple years, including its annual surveillance audits.
We bring direct experience of building and maintaining a certified ISMS for multiple years, including its annual surveillance audits.
ISO 27001 is proof you are doing what you say you are.
The myth is that ISO 27001 is a year of writing policies, it's not. You can write every policy in a fortnight and still fail, because the auditor is not marking your prose. They are checking whether the thing you wrote down is the thing you actually do. Every action you and your staff take should follow the procedures you set, if you say you run an access review every quarter you need to be able to prove it.
The most common way to fail: A folder full of policies that say one thing, while the business does another. (In our experience).
The most common way to fail: A folder full of policies that say one thing, while the business does another. (In our experience).
The ISO 27001 framework
ISO 27001 is the international standard for information security management.
It requires you to build an Information Security Management System (an ISMS), that identifies risks, applies appropriate controls and to ensure those controls keep working.
For certification, an independent certification body has to audit your ISMS and confirm it meets the standard. For UK businesses, this will usually be through a UKAS-accredited certification body.
It requires you to build an Information Security Management System (an ISMS), that identifies risks, applies appropriate controls and to ensure those controls keep working.
For certification, an independent certification body has to audit your ISMS and confirm it meets the standard. For UK businesses, this will usually be through a UKAS-accredited certification body.
What an ISMS needs
A working ISMS needs a clear scope, a proper risk assessment, documented controls and evidence that those controls are being followed.
ISO 27001:2022 includes 93 Annex A controls across four areas. Your Statement of Applicability records which controls apply, how they are implemented and why any are excluded.
You also need ongoing internal audits, management reviews and evidence that the system is being maintained.
ISO 27001:2022 includes 93 Annex A controls across four areas. Your Statement of Applicability records which controls apply, how they are implemented and why any are excluded.
You also need ongoing internal audits, management reviews and evidence that the system is being maintained.
How long until you are audit ready?
There is no fixed timescale, but with an experienced ISO 27001 consultant, for most businesses, ISO 27001 audit readiness takes weeks rather than months, however, your starting point makes a major difference.
A business that already has sensible security controls, documented processes and people following them consistently may already have much of the groundwork in place. If policies are missing, or responsibilities are unclear and processes exist only in someones head, there will be more to build.
Complexity matters. A single UK office is very different from an organisation operating across several countries, multiple cloud platforms, outsourced suppliers and several different technical environments.
The larger factor is your staff's availability, as ISO 27001 cannot be completed entirely by a consultant, decisions need to be made, evidence needs to be provided and people need to take ownership. If every decision takes a week, the project naturally takes longer.
A business that already has sensible security controls, documented processes and people following them consistently may already have much of the groundwork in place. If policies are missing, or responsibilities are unclear and processes exist only in someones head, there will be more to build.
Complexity matters. A single UK office is very different from an organisation operating across several countries, multiple cloud platforms, outsourced suppliers and several different technical environments.
The larger factor is your staff's availability, as ISO 27001 cannot be completed entirely by a consultant, decisions need to be made, evidence needs to be provided and people need to take ownership. If every decision takes a week, the project naturally takes longer.
0
Typical Turnaround
What does ISO 27001 cost?
There is no single number for certification cost, and anyone offering one before seeing your business is selling a starting point, not a final price. The cost splits into parts that behave very differently and depends on the level of work you need. The unavoidable part is certification body fees.
An accredited certification body charges according to the audit time required for the two-stage initial assessment and the surveillance visits that follow. The shrinkable part is getting ready: with someone who has been through it the wasted months evaporate, alone the cost is paid in time and false starts. The forgotten part is ongoing, the annual surveillance and the three-yearly re-certification, which is why a system built to be maintained cheaply is worth more than one crammed together to pass once. We will not be the lowest quote. We will be the one that gets you certified without the year, and leaves you with a system that does not cost a fortune to keep.
An accredited certification body charges according to the audit time required for the two-stage initial assessment and the surveillance visits that follow. The shrinkable part is getting ready: with someone who has been through it the wasted months evaporate, alone the cost is paid in time and false starts. The forgotten part is ongoing, the annual surveillance and the three-yearly re-certification, which is why a system built to be maintained cheaply is worth more than one crammed together to pass once. We will not be the lowest quote. We will be the one that gets you certified without the year, and leaves you with a system that does not cost a fortune to keep.
0
ISO 27001 Gap Analysis
What an ISO 27001 consultant actually does.
01. Scope and assess
Decide what the system covers, then look honestly at what could go wrong inside it. Get the scope wrong here and everything downstream is either pointless or enormous.
Scope definition
Risk assessment
Gap analysis
Asset & control mapping
02. Build the system
Assemble the ISMS to fit how you really operate, not a template of how a textbook company operates. Controls chosen for reasons you can defend out loud.
ISMS build
Policy set
Statement of Applicability
Annex A control selection
03. Make it run
A standard you only perform for the audit fails the audit. The habits go in and start producing the evidence an assessor will ask to see.
Internal audit
Management review
Evidence collection
Staff security awareness
04. Pass and keep it
Through the two-stage audit, then built to survive the years after it without becoming a second job. Certified, and still certified next year.
Stage 1 & 2 readiness
Certification body liaison
Surveillance support
Recertification plan
Rules Moving Under Your Feet
GDPR 72 Hours
The clock starts when you become aware of a personal data breach, so your incident plan needs to say who heads it up, and how fast.
Breach notification
Controller duties
Processor duties
Fallback comms
EU Cyber Resilience Act
If you make software or connected products for the EU, reporting duties began on 11 September 2026. It runs on its own notification sequence, separate from GDPR.
Incident reporting
SBOMs
Security updates
Support periods
EU AI Act
If AI is in your product or your daily work, someone must own the rules on it. Nobody should be pasting secrets into a chatbot.
AI use policy
Product testing
Data rules
Named owner
SOC 2 Readiness
ISO 27001 does not complete SOC 2, but a well-built policy set means you will not rewrite it all later. What is left is control mapping and time-based evidence.
Control mapping
Evidence period
Supplier monitoring
Change control
What to actually budget for.
| What | Typical | Notes |
|---|---|---|
| Certification body audit | Day-rated, scaled to scope | Stage 1 plus Stage 2, then a surveillance audit each year. The unavoidable external cost. |
| Getting ready | Weeks with senior help, months alone | The line a good consultant shrinks the most. |
| Internal time | Real hours, not zero | Your people gathering evidence, attending the audit, owning controls. |
| Tooling | Nothing, up to monthly software | A spreadsheet runs a small ISMS perfectly well. Platforms help at scale. |
| Ongoing cycle | Yearly, then every third year | Surveillance audits, then full recertification. Budget for the badge you keep, not just the one you win. |
What catches UK businesses out.
- The document trap. They write beautiful policies and assume that was the job. The auditor asks for evidence the policy was followed, and the room goes quiet.
- The scope dodge. Draw it too narrow and the certificate means nothing to the customer who asked. Too wide and you drown. Scope is a decision for your stakeholders, not a default.
- The unaccredited certificate. Not every "ISO 27001 certificate" comes from a properly accredited body. The cheap ones are not worth the frame, and the serious customers checking will know the difference.
- The forgotten rhythm. Internal audits and management reviews are mandatory, not optional, and they are the first thing missing when the surveillance auditor comes back.
- The version hangover. The standard moved to its 2022 shape. Anything still built the old way needs bringing across before it counts.
- The mix-up. ISO 27001 is the standard you certify against. ISO 27002 is the guidance. ISO 9001 certification is a different animal again: quality, not security. People buy the wrong document and wonder why nobody will audit them.
- The scope dodge. Draw it too narrow and the certificate means nothing to the customer who asked. Too wide and you drown. Scope is a decision for your stakeholders, not a default.
- The unaccredited certificate. Not every "ISO 27001 certificate" comes from a properly accredited body. The cheap ones are not worth the frame, and the serious customers checking will know the difference.
- The forgotten rhythm. Internal audits and management reviews are mandatory, not optional, and they are the first thing missing when the surveillance auditor comes back.
- The version hangover. The standard moved to its 2022 shape. Anything still built the old way needs bringing across before it counts.
- The mix-up. ISO 27001 is the standard you certify against. ISO 27002 is the guidance. ISO 9001 certification is a different animal again: quality, not security. People buy the wrong document and wonder why nobody will audit them.
A perfect binder. An empty company.
Ask an AI to produce an ISMS and it gives you something remarkable: a full set of policies, a risk register, a Statement of Applicability, all polished, all overnight. It describes a beautifully secure organisation. The only flaw is that the organisation does not exist. ISO 27001 was never a test of whether you can produce the documents. It is a test of whether you do the things the documents claim. An auditor pulls one thread, asks to watch it happen, and the generated binder unravels in a sentence. The writing was always the easy part. Operating it, every day, when nobody is watching, is the part no model can do for you. Knowing the difference is the job.
What you will not get here.
No year of meetings to decide who attends the next meeting. No certificate from a body nobody serious recognises. No ISMS that lives in a folder and dies the day the auditor leaves. We will tell you if Cyber Essentials is genuinely all you need, even though it is the smaller job, because selling you a standard you do not require is the quickest way to be the consultant you never call again. The certificate has to mean something. We build the system that makes it true.
ISO-ready from 21 days
Built around your deadline
Audit-Ready
Truth Over Comfort
Whole-Business Diagnosis
Senior-Led Execution
ISO 27001 questions, answered

What Is an ISO 27001 Consultant?
Someone who builds and runs the management system for you, or with you, and gets it through an external audit. The useful ISO consultants have held a live certificate themselves, not just advised on one. We have taken organisations through it solo, for years, including the annual audits that keep it.
What Is ISO 27001?
The international standard for information security management. It asks you to build a system, an ISMS, that finds your risks, decides what to do about them, and proves you keep doing it. An accredited external body audits it, which is why customers trust it more than a self-assessment.
What's the Difference Between ISO 27001 and ISO 27002?
ISO 27001 is the standard you certify against: the requirements for the management system. ISO 27002 is the guidance that explains the controls in more depth. You are audited against 27001. 27002 just helps you build it. People buy the wrong one constantly.
How Long Does ISO 27001 Certification Take?
Weeks of focused work with someone who has done it, longer if you start from nothing and have to build evidence from scratch. Already holding Cyber Essentials shortens it, because many controls overlap. The myth of a full year is mostly meetings, not work.
How Much Does ISO 27001 Certification Cost?
Three parts: the accredited auditor's day-rated fee (unavoidable), getting ready (the part a good consultant shrinks), and the ongoing surveillance and recertification cycle (the part people forget). There is no honest single number before someone has seen your scope. Anyone giving you one is quoting a package.
Do UK Businesses Need ISO 27001, or Is Cyber Essentials Enough?
Often Cyber Essentials is enough, and we will say so. ISO 27001 earns its cost when large customers, regulated sectors or international deals demand it, or when a competitor who holds it is beating you to contracts. If nobody is asking, the cheaper certificate may serve you better. Other security standards and certifications, such as PCI certification, answer different questions.
Does ISO Certification Expire?
It runs on a three-year cycle. An accredited body audits you initially, checks you each year with a surveillance audit, and fully recertifies you in year three. Skip the upkeep and you lose it, which is why a system built to be lived in beats one crammed together to pass once.
Can AI Build My ISMS?
It can write every document overnight, and they will look immaculate. It cannot make your organisation actually do what they describe, and that is the only thing the auditor checks. A generated binder for a company that does not operate it fails on the first real question.
What Does the EU Cyber Resilience Act Mean for UK Businesses?
If you sell software or connected products into the EU, it applies wherever you are based. Reporting duties for actively exploited vulnerabilities and serious incidents began on 11 September 2026, with the wider product requirements following in December 2027. In practice that means an incident plan with its own notification route, separate from GDPR, a record of what sits inside your software, and a plan for security updates. If you only use software rather than sell it, the Act sits with your suppliers, though they may start asking you questions.
Does ISO 27001 Help With SOC 2 and Other Standards?
Yes, but it does not finish the job. A well-built ISMS gives you the policies, risk process and evidence habits that SOC 2 and other frameworks build on, so you are not starting again. SOC 2 still needs a formal control mapping, then evidence that the controls operated over a set period. Build the ISO 27001 system properly once and the next standard becomes a mapping exercise rather than a rewrite.
Who Should Own ISO 27001 Inside My Business?
One senior person should head it up, with the authority to refuse a shortcut. Beneath them, each area needs a named owner: access, suppliers, incidents and so on. Some checks are weekly, others quarterly, and every change needs logging when it happens rather than at year end. Leave it with one person who also has a day job and it will quietly stall. Ownership is what turns a certificate into a habit.
AI will write you a flawless security policy overnight. The auditor will ask who actually follows it.
Find out if you even need it.
Most ISO enquiries start with a customer demand or a tender requirement, and a fair number of those turn out not to need the full standard at all. A short call is usually enough to tell you whether ISO 27001 is genuinely the thing being asked for, how far your existing security already carries you, and what an honest timeline looks like for your scope.