Information Security Management
The recognised standard for systematic information security.
About ISO 27001:2022
ISO 27001:2022 specifies the requirements for establishing, implementing, maintaining, and continually improving an Information Security Management System (ISMS). It requires organisations to assess their information security risks and apply controls from Annex A — a library of 93 controls covering organisational, people, physical, and technological measures.
Certification demonstrates to customers, investors, and regulators that your approach to information security is systematic, audited, and independently verified — not a policy document that nobody reads.
Typical demand drivers.
- SaaS customers with information security procurement requirements
- Enterprise clients in financial services, healthcare, and legal sectors
- Investors and VCs as part of due diligence
- Data processors and sub-processors handling regulated data
- Government and public sector contractors
- Organisations subject to UK GDPR, NIS2, or sector-specific regulation
Standard structure.
4.2Understanding the needs of interested parties6.1.2Information security risk assessment6.1.3Information security risk treatment6.1.3 d)Statement of Applicability8.2Information security risk assessment (operational)9.1Monitoring, measurement, analysis, and evaluationA.5Organisational controls (37 controls)A.8Technological controls (34 controls)
Responsibilities, clearly drawn.
What we do
- Gap analysis against ISO 27001:2022 clauses and Annex A controls
- Information security policy and ISMS scope definition
- Asset register, threat and vulnerability assessment
- Risk assessment and risk treatment plan (clause 6.1.2–6.1.3)
- Statement of Applicability for all 93 Annex A controls
- Control implementation guidance for applicable controls
- Supplier and third-party security assessment framework
- Incident management and business continuity procedures
- Internal audit and management review
- Staff information security awareness training
- Stage 1 and Stage 2 audit attendance
What you do
- Designate an ISMS owner with board-level sponsorship
- Participate in risk assessment workshops (typically 2–3 sessions)
- Confirm scope: which systems, services, and locations are in-scope
- Review and sign off the Statement of Applicability
- Implement technical controls where required (we advise; your IT team implements)
- Conduct the management review
From gap analysis to certificate.
- 01
Gap analysis
Clause-by-clause review of existing controls against ISO 27001:2022 requirements and Annex A. We produce a gap register and risk landscape summary.
- 02
ISMS build
Policy suite, asset register, risk assessment, Statement of Applicability, and control documentation. We cross-reference Annex A controls with your existing technical stack.
- 03
Control implementation
We advise on implementing applicable controls. Some controls require technical work from your team (e.g. MFA, logging, encryption at rest). We provide specifications and review outputs.
- 04
Internal audit
Internal audit against all applicable clauses and controls. Nonconformities raised and corrective action plans agreed before Stage 1.
- 05
Stage 1 audit
Documentation review by the certification body. We attend, handle queries, and manage any remediation before Stage 2.
- 06
Stage 2 audit
Live system audit. We attend and manage the corrective action register until the certificate is issued.
Frequently asked.
- Is ISO 27001 the same as Cyber Essentials?
- No. Cyber Essentials is a UK government-backed baseline covering five technical controls. ISO 27001 is a full management system standard requiring risk assessment, 93 Annex A controls, and independent third-party audit. Many organisations hold both — Cyber Essentials as a baseline, ISO 27001 for enterprise sales requirements.
- Do we need to implement all 93 Annex A controls?
- No. The Statement of Applicability documents which controls apply to your organisation and which are excluded, with justification. Exclusions are legitimate — a company with no physical servers can exclude controls about physical media disposal, for example. The SoA must be complete and signed off.
- We're a small engineering team. Is ISO 27001 realistic?
- Yes. The standard scales to the organisation. A 20-person SaaS company will have a simpler ISMS than a 500-person enterprise. The scope can be limited to specific services, reducing the documentation burden without weakening the certification.
- How does ISO 27001 relate to GDPR?
- They overlap but are separate. ISO 27001 is a voluntary standard focused on information security management; GDPR is a legal obligation focused on personal data. A certified ISMS provides strong evidence of Article 32 compliance (security of processing), but GDPR also requires data protection by design, lawful basis for processing, and other obligations that fall outside the ISMS scope.
- What happens if there's a data breach during the certification period?
- A breach doesn't automatically invalidate certification. The certification body will assess whether your incident management procedure was followed, whether the breach was caused by a control failure covered by the ISMS, and whether you took appropriate corrective action. An ISMS that works as designed — including detecting and responding to incidents — is a certification asset, not a liability.
Accredited certification bodies (BSI, Bureau Veritas, DNV, LRQA, SGS, NQA). We are independent and help you prepare; you select and engage your own certification body.
Ready to start on ISO 27001?
A gap analysis gives you a clear picture of where you are and what the certification project will involve.