# ISO 27001 consultancy.

> ISO 27001 consultancy in London: gap analysis, ISMS implementation, internal audit and support through certification.

Canonical: https://cybersecuritylondon.com/iso-27001


ISO 27001 shows clients you manage information security properly. Our consultants help you build an information security management system that fits how you work, and get it certified.

Covers: Gap analysis, ISMS implementation, Internal audit, Certification support.

## Overview

ISO 27001 is the international standard for information security management. Certification is increasingly expected by larger clients, especially in finance, technology and professional services.

We keep it practical. Rather than a pile of generic templates, we build policies and processes around how your business already runs, so the system is useful as well as certifiable.

### A good fit if

- Clients or tenders are asking for ISO 27001
- You want a structured, recognised security framework
- You already have Cyber Essentials and want to go further
- A previous ISO project stalled

## What's included

- **Gap analysis**: Where you stand today against the standard.
- **Risk assessment**: The information security risk assessment at the heart of ISO 27001.
- **ISMS documentation**: Policies, procedures and the Statement of Applicability, written to fit your business.
- **Control implementation**: Practical help putting the Annex A controls in place.
- **Internal audit**: An independent internal audit before the certification audit.
- **Certification support**: Preparation for and support during the external audit.

## How it works

1. **Gap analysis**: Compare where you are with the standard.
2. **Build**: Create the ISMS and implement controls.
3. **Audit**: Run the internal audit and management review.
4. **Certify**: Support through the certification body's audit.

## How we can help

- **Full implementation**: From gap analysis to certification, with our consultants alongside you.
- **Gap analysis only**: A clear report of what is needed and how long it will take.
- **Internal audit service**: Independent internal audits to keep your certification on track.
- **Ongoing ISMS support**: Help with surveillance audits, changes and the 2022 transition.

## What affects the cost

- **Size and scope**: The number of people, locations and systems in your ISMS scope.
- **Starting point**: Existing policies and controls reduce the work needed.
- **Support level**: Full implementation or targeted help where you need it.
- **Certification body**: The external audit fee is separate and set by the certification body.

After a gap analysis we give you a clear breakdown of ISO 27001 certification cost: our fees and the expected certification body fee.

## Frequently asked questions

### What is ISO 27001?

An international standard for managing information security. It requires a risk-based management system (an ISMS) covering people, processes and technology.

### How much does ISO 27001 certification cost?

It depends on the size and complexity of your business and how much is already in place. There are consultancy costs and a separate certification body fee. A gap analysis gives you an accurate figure.

### How long does ISO 27001 take?

Typically several months for a small to medium business, depending on your starting point and the time your team can give.

### What changed in ISO 27001:2022?

The Annex A controls were reorganised into four themes and some new controls were added, such as threat intelligence and cloud security. We help existing certificate holders transition.

## Related services

- [Cyber Essentials](https://cybersecuritylondon.com/cyber-essentials)
- [Security Audits](https://cybersecuritylondon.com/security-audits)
- [GDPR & Data Protection](https://cybersecuritylondon.com/gdpr-consultancy)

## Contact

Email letstalk@networklondon.co.uk or use the enquiry form at https://cybersecuritylondon.com/#contact. Cyber Security London, The Leather Market, London Bridge, London.
