ISO 27001
Certification

End-to-end support to design your ISMS, run the risk assessment, write the policies, and pass your Stage 1 and Stage 2 audits — then maintain certification through surveillance audits.

Overview

Certification that reflects real security.

ISO 27001 is the international standard for information security management and the certification enterprise customers ask for most. We take you from gap analysis to certificate as a single accountable partner.

We design your ISMS around how you actually operate, run an ISO 27005-aligned risk assessment, build the Statement of Applicability and policies, and coordinate with your certification body through Stage 1 and Stage 2 — then support surveillance and continual improvement.


Scope

What we deliver.

The full ISO 27001 lifecycle, from gap analysis to surveillance.

Framework: ISO/IEC 27001:2022 ISO/IEC 27005 Annex A controls Auditor coordination

FAQ

ISO 27001 FAQ

The questions we're asked most about scope, cost, and timing.

How much does ISO 27001 certification cost?
Our ISO 27001 consulting is typically €2,500–4,000 per month over a 3–6 month implementation, separate from the certification body’s audit fees. Use our estimator for a tailored figure.
How long does ISO 27001 certification take?
Most organisations reach certification in 3 to 6 months, depending on maturity, scope, and how quickly evidence can be produced.
What is the difference between ISO 27001 and SOC 2?
ISO 27001 is an international certification of a management system; SOC 2 is a US-oriented attestation report. The underlying controls overlap heavily and we can run them together.
Do you perform the certification audit?
No — for independence the audit is performed by an accredited certification body. We prepare you fully and coordinate with the auditor through both stages.
Do you help maintain certification afterwards?
Yes — we support annual surveillance audits, internal audits, and continual improvement so the certificate stays valid.
Do we need to be a certain size for ISO 27001?
No — the ISMS scales to your size and scope. We right-size the controls so small teams are not buried in process.
Which version do you work to?
The current ISO/IEC 27001:2022 standard, including the updated Annex A controls.
Can we scope ISO 27001 to one product or team?
Yes — the certification scope can be limited to a specific product, service, or business unit to keep effort focused.
How much of our team’s time does it take?
Less than most expect — we do the heavy lifting and need focused input from your key people during workshops and evidence gathering.
How do we choose a certification body?
We help you select an accredited certification body and coordinate the audit; the auditor must be independent from us.

Related services

Explore more.

Ready to start ISO 27001?

A 30-minute scoping call costs nothing. A failed audit costs considerably more.

Book a meeting Send an email