ISO 27001 Readiness and Implementation Support
A serious commitment that opens serious doors. We tell you honestly whether you need it, then build a management system proportionate to your size rather than a 300-page binder nobody maintains.
What is ISO 27001 and does a small business need it?
ISO 27001 is the international standard for an Information Security Management System — a documented, risk-driven framework for managing information security, independently certified and audited annually. Small businesses generally pursue it because enterprise or public sector customers require it, rather than for its own sake.
Do you actually need it?
This is the first question we ask, and the answer is often no. ISO 27001 is a significant undertaking — typically six to twelve months for a first certification, with real ongoing cost in audits, internal audit time and management review. It is worth it when a customer contract requires it, when you sell into enterprise or public sector procurement that demands it, or when you handle client data at a scale that makes formal governance genuinely necessary.
It is not worth it as a general signal of seriousness when Cyber Essentials plus a documented risk assessment would satisfy everyone actually asking. We would rather tell you that and do the smaller piece of work well.
What the standard actually requires
ISO 27001 certifies a management system, not a technology stack. The clauses require you to define scope and context, secure leadership commitment, run a repeatable risk assessment, select controls to treat those risks, measure whether they work, audit yourself, review at management level, and improve. The Annex A controls — 93 of them in the 2022 revision, grouped into organisational, people, physical and technological themes — are the menu you select from, justified in a Statement of Applicability.
That structure is why the standard is respected: it forces a business to decide what it is protecting and why, rather than buying products. It is also why certification bodies fail organisations that have excellent technology and no evidence that anyone reviews it.
- Scope, context and interested parties defined
- Documented, repeatable risk assessment and treatment methodology
- Statement of Applicability justifying every included and excluded control
- Measurable objectives with evidence they are monitored
- Internal audit programme and documented management review
- Corrective action and continual improvement records
Proportionate to your size
The standard does not require a large organisation's paperwork from a small one. It requires a management system appropriate to your context, and auditors accept that a fifteen-person company operates differently from a bank. The failure mode we see most often is a consultant delivering a template pack built for a large enterprise, which the client cannot possibly maintain and which collapses at the first surveillance audit.
We build documentation you will actually keep up to date, sized to the business, with the review cadence set at something realistic. A system that is honestly maintained will pass; an impressive one that nobody has opened since certification will not.
Included in every engagement
Fixed scope, agreed in writing before we start. If the scope changes, we stop and re-quote rather than invoicing the difference.
ISO 27001 — your questions answered
How long does ISO 27001 certification take?
How much does ISO 27001 cost for a small business?
Is Cyber Essentials enough instead of ISO 27001?
What changed in ISO 27001:2022?
Can you act as our certification body as well?
Question not answered here? Call +44 7424 967568 or email support@cipherknights.com.
You might also need
Ready to talk about iso 27001?
Book a free, no-obligation consultation with our Leicester team, or call us and we will point you in the right direction whether or not you become a client.