ISO 27001 Consultant for SMEs

ISO 27001 has a reputation for taking a year and a small department. However, the work behind readiness can be straightforward: a risk assessment, a management system that fits how you run, and the evidence to pass an external audit.

We bring direct experience of building and maintaining a certified ISMS for multiple years, including its annual surveillance audits.
metasploit
Metasploit
malwarebytes
Malwarebytes
fortinet
Fortinet
crowdstrike
Crowdstrike
bitwarden
Bitwarden
azure-intune
Intune
azure-entra-managed-identities
Entra
wireguard
Wireguard
sonicwall
SonicWall
openvpn
OpenVPN
microsoft-defender
Defender
microsoft-azure
Azure
sentinelone
SentinelOne
qualys
Qualys
okta
Okta
cisco-mono
Cisco
Vanta
Vanta
metasploit
Metasploit
malwarebytes
Malwarebytes
fortinet
Fortinet
crowdstrike
Crowdstrike
bitwarden
Bitwarden
azure-intune
Intune
azure-entra-managed-identities
Entra
wireguard
Wireguard
sonicwall
SonicWall
openvpn
OpenVPN
microsoft-defender
Defender
microsoft-azure
Azure
sentinelone
SentinelOne
qualys
Qualys
okta
Okta
cisco-mono
Cisco
Vanta
Vanta

ISO 27001 is proof you are doing what you say you are.

The myth is that ISO 27001 is a year of writing policies, it's not. You can write every policy in a fortnight and still fail, because the auditor is not marking your prose. They are checking whether the thing you wrote down is the thing you actually do. Every action you and your staff take should follow the procedures you set, if you say you run an access review every quarter you need to be able to prove it.

The most common way to fail: A folder full of policies that say one thing, while the business does another. (In our experience).

The ISO 27001 framework

ISO 27001 is the international standard for information security management.
It requires you to build an Information Security Management System (an ISMS), that identifies risks, applies appropriate controls and to ensure those controls keep working.

For certification, an independent certification body has to audit your ISMS and confirm it meets the standard. For UK businesses, this will usually be through a UKAS-accredited certification body.

What an ISMS needs

A working ISMS needs a clear scope, a proper risk assessment, documented controls and evidence that those controls are being followed.

ISO 27001:2022 includes 93 Annex A controls across four areas. Your Statement of Applicability records which controls apply, how they are implemented and why any are excluded.

You also need ongoing internal audits, management reviews and evidence that the system is being maintained.

How long until you are audit ready?

There is no fixed timescale, but with an experienced ISO 27001 consultant, for most businesses, ISO 27001 audit readiness takes weeks rather than months, however, your starting point makes a major difference.

A business that already has sensible security controls, documented processes and people following them consistently may already have much of the groundwork in place. If policies are missing, or responsibilities are unclear and processes exist only in someones head, there will be more to build.

Complexity matters. A single UK office is very different from an organisation operating across several countries, multiple cloud platforms, outsourced suppliers and several different technical environments.

The larger factor is your staff's availability, as ISO 27001 cannot be completed entirely by a consultant, decisions need to be made, evidence needs to be provided and people need to take ownership. If every decision takes a week, the project naturally takes longer.
0
Typical Turnaround

What does ISO 27001 cost?

There is no single number for certification cost, and anyone offering one before seeing your business is selling a starting point, not a final price. The cost splits into parts that behave very differently and depends on the level of work you need. The unavoidable part is certification body fees.

An accredited certification body charges according to the audit time required for the two-stage initial assessment and the surveillance visits that follow. The shrinkable part is getting ready: with someone who has been through it the wasted months evaporate, alone the cost is paid in time and false starts. The forgotten part is ongoing, the annual surveillance and the three-yearly re-certification, which is why a system built to be maintained cheaply is worth more than one crammed together to pass once. We will not be the lowest quote. We will be the one that gets you certified without the year, and leaves you with a system that does not cost a fortune to keep.
0
ISO 27001 Gap Analysis

What an ISO 27001 consultant actually does.

01. Scope and assess

Decide what the system covers, then look honestly at what could go wrong inside it. Get the scope wrong here and everything downstream is either pointless or enormous.
Scope definition
Risk assessment
Gap analysis
Asset & control mapping

02. Build the system

Assemble the ISMS to fit how you really operate, not a template of how a textbook company operates. Controls chosen for reasons you can defend out loud.
ISMS build
Policy set
Statement of Applicability
Annex A control selection

03. Make it run

A standard you only perform for the audit fails the audit. The habits go in and start producing the evidence an assessor will ask to see.
Internal audit
Management review
Evidence collection
Staff security awareness

04. Pass and keep it

Through the two-stage audit, then built to survive the years after it without becoming a second job. Certified, and still certified next year.
Stage 1 & 2 readiness
Certification body liaison
Surveillance support
Recertification plan

Rules Moving Under Your Feet

GDPR 72 Hours

The clock starts when you become aware of a personal data breach, so your incident plan needs to say who heads it up, and how fast.
Breach notification
Controller duties
Processor duties
Fallback comms

EU Cyber Resilience Act

If you make software or connected products for the EU, reporting duties began on 11 September 2026. It runs on its own notification sequence, separate from GDPR.
Incident reporting
SBOMs
Security updates
Support periods

EU AI Act

If AI is in your product or your daily work, someone must own the rules on it. Nobody should be pasting secrets into a chatbot.
AI use policy
Product testing
Data rules
Named owner

SOC 2 Readiness

ISO 27001 does not complete SOC 2, but a well-built policy set means you will not rewrite it all later. What is left is control mapping and time-based evidence.
Control mapping
Evidence period
Supplier monitoring
Change control

What to actually budget for.

WhatTypicalNotes
Certification body auditDay-rated, scaled to scopeStage 1 plus Stage 2, then a surveillance audit each year. The unavoidable external cost.
Getting readyWeeks with senior help, months aloneThe line a good consultant shrinks the most.
Internal timeReal hours, not zeroYour people gathering evidence, attending the audit, owning controls.
ToolingNothing, up to monthly softwareA spreadsheet runs a small ISMS perfectly well. Platforms help at scale.
Ongoing cycleYearly, then every third yearSurveillance audits, then full recertification. Budget for the badge you keep, not just the one you win.

What catches UK businesses out.

- The document trap. They write beautiful policies and assume that was the job. The auditor asks for evidence the policy was followed, and the room goes quiet.
- The scope dodge. Draw it too narrow and the certificate means nothing to the customer who asked. Too wide and you drown. Scope is a decision for your stakeholders, not a default.
- The unaccredited certificate. Not every "ISO 27001 certificate" comes from a properly accredited body. The cheap ones are not worth the frame, and the serious customers checking will know the difference.
- The forgotten rhythm. Internal audits and management reviews are mandatory, not optional, and they are the first thing missing when the surveillance auditor comes back.
- The version hangover. The standard moved to its 2022 shape. Anything still built the old way needs bringing across before it counts.
- The mix-up. ISO 27001 is the standard you certify against. ISO 27002 is the guidance. ISO 9001 certification is a different animal again: quality, not security. People buy the wrong document and wonder why nobody will audit them.

A perfect binder. An empty company.

Ask an AI to produce an ISMS and it gives you something remarkable: a full set of policies, a risk register, a Statement of Applicability, all polished, all overnight. It describes a beautifully secure organisation. The only flaw is that the organisation does not exist. ISO 27001 was never a test of whether you can produce the documents. It is a test of whether you do the things the documents claim. An auditor pulls one thread, asks to watch it happen, and the generated binder unravels in a sentence. The writing was always the easy part. Operating it, every day, when nobody is watching, is the part no model can do for you. Knowing the difference is the job.

What you will not get here.

No year of meetings to decide who attends the next meeting. No certificate from a body nobody serious recognises. No ISMS that lives in a folder and dies the day the auditor leaves. We will tell you if Cyber Essentials is genuinely all you need, even though it is the smaller job, because selling you a standard you do not require is the quickest way to be the consultant you never call again. The certificate has to mean something. We build the system that makes it true.
ISO-ready from 21 days
Built around your deadline
Audit-Ready
Truth Over Comfort
Whole-Business Diagnosis
Senior-Led Execution

ISO 27001 questions, answered

ISO 27001 - ISO 27001

What Is an ISO 27001 Consultant?

Someone who builds and runs the management system for you, or with you, and gets it through an external audit. The useful ISO consultants have held a live certificate themselves, not just advised on one. We have taken organisations through it solo, for years, including the annual audits that keep it.
The international standard for information security management. It asks you to build a system, an ISMS, that finds your risks, decides what to do about them, and proves you keep doing it. An accredited external body audits it, which is why customers trust it more than a self-assessment.
ISO 27001 is the standard you certify against: the requirements for the management system. ISO 27002 is the guidance that explains the controls in more depth. You are audited against 27001. 27002 just helps you build it. People buy the wrong one constantly.
Weeks of focused work with someone who has done it, longer if you start from nothing and have to build evidence from scratch. Already holding Cyber Essentials shortens it, because many controls overlap. The myth of a full year is mostly meetings, not work.
Three parts: the accredited auditor's day-rated fee (unavoidable), getting ready (the part a good consultant shrinks), and the ongoing surveillance and recertification cycle (the part people forget). There is no honest single number before someone has seen your scope. Anyone giving you one is quoting a package.
Often Cyber Essentials is enough, and we will say so. ISO 27001 earns its cost when large customers, regulated sectors or international deals demand it, or when a competitor who holds it is beating you to contracts. If nobody is asking, the cheaper certificate may serve you better. Other security standards and certifications, such as PCI certification, answer different questions.
It runs on a three-year cycle. An accredited body audits you initially, checks you each year with a surveillance audit, and fully recertifies you in year three. Skip the upkeep and you lose it, which is why a system built to be lived in beats one crammed together to pass once.
It can write every document overnight, and they will look immaculate. It cannot make your organisation actually do what they describe, and that is the only thing the auditor checks. A generated binder for a company that does not operate it fails on the first real question.
If you sell software or connected products into the EU, it applies wherever you are based. Reporting duties for actively exploited vulnerabilities and serious incidents began on 11 September 2026, with the wider product requirements following in December 2027. In practice that means an incident plan with its own notification route, separate from GDPR, a record of what sits inside your software, and a plan for security updates. If you only use software rather than sell it, the Act sits with your suppliers, though they may start asking you questions.
Yes, but it does not finish the job. A well-built ISMS gives you the policies, risk process and evidence habits that SOC 2 and other frameworks build on, so you are not starting again. SOC 2 still needs a formal control mapping, then evidence that the controls operated over a set period. Build the ISO 27001 system properly once and the next standard becomes a mapping exercise rather than a rewrite.
One senior person should head it up, with the authority to refuse a shortcut. Beneath them, each area needs a named owner: access, suppliers, incidents and so on. Some checks are weekly, others quarterly, and every change needs logging when it happens rather than at year end. Leave it with one person who also has a day job and it will quietly stall. Ownership is what turns a certificate into a habit.

AI will write you a flawless security policy overnight. The auditor will ask who actually follows it.

Find out if you even need it.

Most ISO enquiries start with a customer demand or a tender requirement, and a fair number of those turn out not to need the full standard at all. A short call is usually enough to tell you whether ISO 27001 is genuinely the thing being asked for, how far your existing security already carries you, and what an honest timeline looks like for your scope.