Aivantis
ISO 27001

Information Security Management

The recognised standard for systematic information security.

What it covers

About ISO 27001:2022

ISO 27001:2022 specifies the requirements for establishing, implementing, maintaining, and continually improving an Information Security Management System (ISMS). It requires organisations to assess their information security risks and apply controls from Annex A — a library of 93 controls covering organisational, people, physical, and technological measures.

Certification demonstrates to customers, investors, and regulators that your approach to information security is systematic, audited, and independently verified — not a policy document that nobody reads.

Who asks for it

Typical demand drivers.

  • SaaS customers with information security procurement requirements
  • Enterprise clients in financial services, healthcare, and legal sectors
  • Investors and VCs as part of due diligence
  • Data processors and sub-processors handling regulated data
  • Government and public sector contractors
  • Organisations subject to UK GDPR, NIS2, or sector-specific regulation
Key clause references

Standard structure.

  • 4.2Understanding the needs of interested parties
  • 6.1.2Information security risk assessment
  • 6.1.3Information security risk treatment
  • 6.1.3 d)Statement of Applicability
  • 8.2Information security risk assessment (operational)
  • 9.1Monitoring, measurement, analysis, and evaluation
  • A.5Organisational controls (37 controls)
  • A.8Technological controls (34 controls)
Engagement scope

Responsibilities, clearly drawn.

What we do

  • Gap analysis against ISO 27001:2022 clauses and Annex A controls
  • Information security policy and ISMS scope definition
  • Asset register, threat and vulnerability assessment
  • Risk assessment and risk treatment plan (clause 6.1.2–6.1.3)
  • Statement of Applicability for all 93 Annex A controls
  • Control implementation guidance for applicable controls
  • Supplier and third-party security assessment framework
  • Incident management and business continuity procedures
  • Internal audit and management review
  • Staff information security awareness training
  • Stage 1 and Stage 2 audit attendance

What you do

  • Designate an ISMS owner with board-level sponsorship
  • Participate in risk assessment workshops (typically 2–3 sessions)
  • Confirm scope: which systems, services, and locations are in-scope
  • Review and sign off the Statement of Applicability
  • Implement technical controls where required (we advise; your IT team implements)
  • Conduct the management review
Certification path

From gap analysis to certificate.

  1. 01

    Gap analysis

    Clause-by-clause review of existing controls against ISO 27001:2022 requirements and Annex A. We produce a gap register and risk landscape summary.

  2. 02

    ISMS build

    Policy suite, asset register, risk assessment, Statement of Applicability, and control documentation. We cross-reference Annex A controls with your existing technical stack.

  3. 03

    Control implementation

    We advise on implementing applicable controls. Some controls require technical work from your team (e.g. MFA, logging, encryption at rest). We provide specifications and review outputs.

  4. 04

    Internal audit

    Internal audit against all applicable clauses and controls. Nonconformities raised and corrective action plans agreed before Stage 1.

  5. 05

    Stage 1 audit

    Documentation review by the certification body. We attend, handle queries, and manage any remediation before Stage 2.

  6. 06

    Stage 2 audit

    Live system audit. We attend and manage the corrective action register until the certificate is issued.

Common questions

Frequently asked.

Is ISO 27001 the same as Cyber Essentials?
No. Cyber Essentials is a UK government-backed baseline covering five technical controls. ISO 27001 is a full management system standard requiring risk assessment, 93 Annex A controls, and independent third-party audit. Many organisations hold both — Cyber Essentials as a baseline, ISO 27001 for enterprise sales requirements.
Do we need to implement all 93 Annex A controls?
No. The Statement of Applicability documents which controls apply to your organisation and which are excluded, with justification. Exclusions are legitimate — a company with no physical servers can exclude controls about physical media disposal, for example. The SoA must be complete and signed off.
We're a small engineering team. Is ISO 27001 realistic?
Yes. The standard scales to the organisation. A 20-person SaaS company will have a simpler ISMS than a 500-person enterprise. The scope can be limited to specific services, reducing the documentation burden without weakening the certification.
How does ISO 27001 relate to GDPR?
They overlap but are separate. ISO 27001 is a voluntary standard focused on information security management; GDPR is a legal obligation focused on personal data. A certified ISMS provides strong evidence of Article 32 compliance (security of processing), but GDPR also requires data protection by design, lawful basis for processing, and other obligations that fall outside the ISMS scope.
What happens if there's a data breach during the certification period?
A breach doesn't automatically invalidate certification. The certification body will assess whether your incident management procedure was followed, whether the breach was caused by a control failure covered by the ISMS, and whether you took appropriate corrective action. An ISMS that works as designed — including detecting and responding to incidents — is a certification asset, not a liability.
Independence note

Accredited certification bodies (BSI, Bureau Veritas, DNV, LRQA, SGS, NQA). We are independent and help you prepare; you select and engage your own certification body.

Ready to start on ISO 27001?

A gap analysis gives you a clear picture of where you are and what the certification project will involve.

Book a gap analysis