ISO 27001 certification, sized for your business.
ISO 27001 implementation, internal audit leadership, and certification preparation. Led by PECB-accredited Lead Auditors.
Overview
A management system standard, not a technical checklist.
ISO/IEC 27001 is the world's most widely respected information security certification — and the only ISO standard that organisations can be certified against. It specifies the requirements for establishing, implementing, and maintaining an Information Security Management System (ISMS), regardless of company size or sector.
The standard has two components. The management framework — 10 mandatory clauses covering how your organisation plans, implements, monitors, and improves its ISMS. Annex A — a reference set of 93 security controls across 4 domains (organisational, people, physical, technological) that you select, implement, and document based on your risk assessment. ISO 27001 does not prescribe a fixed set of controls; it requires you to identify your specific risks and justify your control choices in a Statement of Applicability.
Who ISO 27001 is for
Voluntary — but for a growing number of SMBs, commercially essential rather than merely advisable.
Technology & SaaS companies
Enterprise procurement processes increasingly mandate ISO 27001 as a minimum vendor qualification. Without it, you may be disqualified from tenders before technical evaluation.
Suppliers to financial services
Banks, insurers, and investment firms subject to DORA must extend security requirements down their supply chain. ISO 27001 is the most widely recognised way to meet that bar.
Healthcare & life sciences
Health data triggers GDPR, NIS2, and sector-specific obligations. ISO 27001 provides the governance framework that satisfies all three simultaneously.
Professional services firms
Law firms, accountants, consultancies handling confidential client data are increasingly expected to demonstrate certification to retain enterprise and regulated-sector clients.
Public-sector suppliers
EU and national procurement frameworks list ISO 27001 as a required qualification for IT and data-processing contracts — particularly those involving personal or sensitive public data.
Any business seeking cyber insurance
Insurers apply lower premiums and broader coverage to certified organisations. ISO 27001 is the single most recognised signal of mature security governance in underwriting.
The 10 management clauses
What every ISMS must demonstrate.
- 01Clause 4
Context of the organisation
Understanding your business environment, interested parties, and the ISMS scope.
- 02Clause 5
Leadership
Management commitment, the security policy, and assignment of roles and responsibilities.
- 03Clause 6
Planning
Risk assessment, risk treatment plan, and information security objectives.
- 04Clause 7
Support
Resources, competence, awareness training, communication, and documented information.
- 05Clause 8
Operation
Implementing the risk treatment plan, managing operational security processes and changes.
- 06Clause 9
Performance evaluation
Monitoring, measurement, internal audit (mandatory), and management review.
- 07Clause 10
Improvement
Addressing non-conformities, corrective actions, and continual improvement of the ISMS.
- 08Annex A
93 controls across 4 domains
Organisational (37), people (8), physical (14), technological (34). Selected and justified in your Statement of Applicability.
Consequences (non-fines)
No statutory penalties — but commercial cost compounds.
ISO 27001 is voluntary, so there are no statutory fines for non-certification. The cost of lacking certification, however, compounds: disqualification from procurement tenders, inability to meet client security requirements, loss of enterprise clients in regulated sectors, higher cyber-insurance premiums and reduced coverage, and inability to supply regulated financial institutions or public sector buyers.
Certified organisations also use ISO 27001 to meet 60–70% of NIS2, 40–55% of GDPR Article 32, 45–60% of DORA, and 40–50% of PCI DSS obligations — making it the most cost-effective single foundation for a multi-framework compliance program.
NIS2 coverage
60–70%
of NIS2 Article 21 obligations met by a well-scoped ISMS.
GDPR Art. 32
40–55%
of the technical and organisational security measures GDPR requires.
DORA coverage
45–60%
of DORA ICT risk management obligations.
Our approach
Certification, designed for SMB scale.
What we deliver
- Gap analysis against the 10 management clauses and Annex A — costed roadmap to certification
- ISMS design and scope definition — sized for your organisation, not enterprise-bloated
- Risk assessment, risk treatment plan, and Statement of Applicability
- Policy library written in language people will read and apply — not 200 pages of compliance text
- Mandatory awareness training (Clause 7.2/7.3) with audit-grade completion records
- Internal audit (mandatory before Stage 2) — led by PECB ISO 27001 Lead Auditors
- Pre-certification readiness review and corrective-action support
- Certification body selection guidance — body-independent across the EU (AFNOR in France, TÜV in Germany, TrustCB in the Netherlands, AENOR in Spain, CISQ in Italy, SGS in Switzerland, plus EU-operating bodies like Bureau Veritas, BSI, LRQA, DNV, SQS)
- Stage 1 / Stage 2 audit support and ongoing surveillance audit retainer
Typical timeline
6–12 months for most SMBs starting from a low baseline. Existing controls or prior compliance work make this faster.
Weeks 1–4
Gap analysis
Current state vs ISO 27001 requirements, ISMS scope definition, prioritised costed action plan.
Months 2–5
ISMS build
Risk assessment, treatment, policies, controls, Statement of Applicability, training program rollout.
Month 6
Internal audit
Independent internal audit against all clauses and selected Annex A controls. Corrective actions resolved.
Months 7–9
Certification audit
Stage 1 (document review) then Stage 2 (on-site assessment) with your chosen accredited certification body.
FAQ