ISO 27001 Certification Consulting
End-to-end ISO 27001:2022 implementation — from scoping and risk assessment through to the certification audit room. Built for organisations that need real security governance, not a folder of templates.
Our Information Security Management workflow.
A clear, staged process — so you always know what's happening next and why.
Discovery & Scoping
We assess your current state, define the scope of your ISO 27001 management system, identify stakeholders, and map your operating context against the standard's requirements.
Gap Analysis & Roadmap
Clause-by-clause gap assessment, prioritised by risk and effort. Delivered as an actionable project plan with clear milestones and a realistic timeline.
Framework Implementation
We build your policies, procedures, risk registers, and controls library — tailored to your actual business and how it really operates, not a generic template.
Internal Audit & Review
A full internal audit simulating your Stage 2 certification audit. Non-conformances are found and closed before the real audit counts against you.
Certification Audit Support
We're in the room for Stage 1 and Stage 2 — managing auditor questions in real-time so nothing gets lost. Certificate issued.
Full scope, start to finish.
Not sure where you stand?
Run our free ISO 27001:2022 self-assessment for an instant readiness score and tailored improvement priorities — no sign-up required.
Start Free Assessment →Common questions.
How much does ISO 27001 certification cost?
It depends on your headcount, number of sites, and infrastructure complexity — small, cloud-native organisations sit at the lower end of the market, larger or multi-site businesses at the higher end. We quote fixed-price after a short scoping conversation, not hourly. See our full cost breakdown for indicative ranges.
How long does ISO 27001 certification take?
Most small-to-mid organisations move from kickoff to certificate in 8 to 16 weeks. The biggest factor isn't company size — it's how quickly your team turns around document reviews and evidence requests.
Do I need ISO 27001 or is SOC 2 enough?
It depends on who's asking. Australian, UK, EU, and government-adjacent clients typically mean ISO 27001 when they say "certified." US-based SaaS clients more often ask for SOC 2 specifically. See our ISO 27001 vs SOC 2 comparison for MSPs.
What's included in your ISO 27001 service?
End-to-end: gap analysis, risk assessment, policy and control development, the Statement of Applicability and full Annex A mapping, a full internal audit before the real one, and we're in the room for both Stage 1 and Stage 2 with your certification body.
Do you offer fixed-price ISO 27001 consulting?
Yes — every engagement is quoted fixed-price after scoping, not billed hourly. That's deliberate: hourly billing meeting a slow-moving project is the most common way ISO 27001 budgets blow out.