Compliance

ISO 27001 Readiness and Implementation Support

A serious commitment that opens serious doors. We tell you honestly whether you need it, then build a management system proportionate to your size rather than a 300-page binder nobody maintains.

STANDARD
ISO/IEC 27001:2022
CONTROLS
93 Annex A Controls, 4 Themes
CYCLE
3-Year Certification, Annual Surveillance
TYPICAL EFFORT
6-12 Months to First Certification
In short

What is ISO 27001 and does a small business need it?

ISO 27001 is the international standard for an Information Security Management System — a documented, risk-driven framework for managing information security, independently certified and audited annually. Small businesses generally pursue it because enterprise or public sector customers require it, rather than for its own sake.

Do you actually need it?

This is the first question we ask, and the answer is often no. ISO 27001 is a significant undertaking — typically six to twelve months for a first certification, with real ongoing cost in audits, internal audit time and management review. It is worth it when a customer contract requires it, when you sell into enterprise or public sector procurement that demands it, or when you handle client data at a scale that makes formal governance genuinely necessary.

It is not worth it as a general signal of seriousness when Cyber Essentials plus a documented risk assessment would satisfy everyone actually asking. We would rather tell you that and do the smaller piece of work well.

What the standard actually requires

ISO 27001 certifies a management system, not a technology stack. The clauses require you to define scope and context, secure leadership commitment, run a repeatable risk assessment, select controls to treat those risks, measure whether they work, audit yourself, review at management level, and improve. The Annex A controls — 93 of them in the 2022 revision, grouped into organisational, people, physical and technological themes — are the menu you select from, justified in a Statement of Applicability.

That structure is why the standard is respected: it forces a business to decide what it is protecting and why, rather than buying products. It is also why certification bodies fail organisations that have excellent technology and no evidence that anyone reviews it.

  • Scope, context and interested parties defined
  • Documented, repeatable risk assessment and treatment methodology
  • Statement of Applicability justifying every included and excluded control
  • Measurable objectives with evidence they are monitored
  • Internal audit programme and documented management review
  • Corrective action and continual improvement records

Proportionate to your size

The standard does not require a large organisation's paperwork from a small one. It requires a management system appropriate to your context, and auditors accept that a fifteen-person company operates differently from a bank. The failure mode we see most often is a consultant delivering a template pack built for a large enterprise, which the client cannot possibly maintain and which collapses at the first surveillance audit.

We build documentation you will actually keep up to date, sized to the business, with the review cadence set at something realistic. A system that is honestly maintained will pass; an impressive one that nobody has opened since certification will not.

What you receive

Included in every engagement

Fixed scope, agreed in writing before we start. If the scope changes, we stop and re-quote rather than invoicing the difference.

Frequently asked questions

ISO 27001 — your questions answered

How long does ISO 27001 certification take?
Six to twelve months for a first certification is typical for an SME, depending on your starting maturity. The certification audit itself is split into Stage 1 (documentation review) and Stage 2 (implementation audit), usually a few weeks apart.
How much does ISO 27001 cost for a small business?
There are two costs: consultancy to build the ISMS, and certification body fees for the audits, which are priced by organisation size and scope. Certification body fees recur across a three-year cycle with annual surveillance audits. We quote our part fixed and help you tender the audit.
Is Cyber Essentials enough instead of ISO 27001?
For many UK SMEs, yes. Cyber Essentials covers technical baseline controls at a fraction of the cost and effort. ISO 27001 becomes necessary when a customer contractually requires it, or when you need formal governance over information risk across the whole business.
What changed in ISO 27001:2022?
Annex A was restructured from 114 controls into 93, grouped under four themes, with eleven new controls covering areas such as threat intelligence, cloud services, data leakage prevention and secure coding. Organisations certified to the 2013 version have had to transition.
Can you act as our certification body as well?
No, and nobody legitimately can. Consultancy and certification must be independent — a body that audits work it also built would not be accredited. We prepare you and help you select an accredited certification body.

Question not answered here? Call +44 7424 967568 or email support@cipherknights.com.

Ready to talk about iso 27001?

Book a free, no-obligation consultation with our Leicester team, or call us and we will point you in the right direction whether or not you become a client.