Cibernetica.io

Compliance

ISO 27001

Build the management system, then pass the audit.

ISO 27001 is the international standard for an information security management system. It is not a technical checklist — it certifies that you have a systematic, documented, and reviewed approach to managing information security risk. That distinction is why organisations with good technical security still fail their first audit, and why organisations with modest technical security sometimes pass.

What certification actually requires

The standard requires you to define a scope, identify and assess information security risks, select controls to treat them, document how the system operates, and demonstrate that you review and improve it over time. Annex A lists reference controls, but the standard does not require you to implement all of them — it requires you to justify which apply to your risks and which do not. Certification is a two-stage external audit. Stage 1 reviews your documentation and readiness. Stage 2 tests whether the system operates as documented, through evidence and interviews. Certification lasts three years with annual surveillance audits in between. The audit must be performed by a certification body accredited to do so — in the UK, that means UKAS-accredited. That body must be independent of whoever helped you prepare. A consultant cannot build your ISMS and then certify it, and any offer that appears to bundle both is worth questioning closely. The most common cause of a difficult first audit is scope. A scope drawn too wide creates work that was never necessary; drawn too narrow, it fails to satisfy the customer who asked for the certificate in the first place.

Who needs it

  • Companies where enterprise customers require certification as a condition of contract
  • Businesses selling internationally, where ISO is more widely recognised than regional schemes
  • Organisations wanting a structured programme rather than ad-hoc security improvements
  • Companies preparing for investment or acquisition, where diligence increasingly expects it

What you get

Scope defined before work begins

Which parts of the business, which systems, and which locations fall inside the ISMS — the decision that determines the cost of everything that follows.

A gap analysis against the standard

What you already satisfy and what genuinely needs building, so the programme has a defined end point rather than running open-ended.

Consultant and certification body kept separate

We match you with consultants for the preparation. The certification audit is booked with an accredited body independently, as the standard requires.

Frequently asked questions

How much does ISO 27001 certification cost?

Three separate costs. Consultancy for preparation, which varies with how much needs building. The certification body's audit fees, priced by organisation size and scope, and recurring annually for surveillance. And internal time, which is consistently the most underestimated of the three — someone in your organisation will spend substantial hours on this regardless of how much help you buy.

How long does it take?

For an organisation starting without formal documentation, six to twelve months to certification is typical. Where reasonable practices already exist and mainly need documenting and evidencing, it can be shorter. The standard also expects evidence that the management system has been operating, which sets a floor on how fast it can be done honestly.

Can the consultant who helps us also certify us?

No. Certification must come from an accredited certification body independent of whoever helped you prepare, and that independence is a requirement of the accreditation itself. Treat any offer that appears to bundle preparation and certification as a signal to ask exactly who issues the certificate and under whose accreditation.

Is ISO 27001 worth it for a small company?

It depends entirely on whether someone is asking for it. If enterprise customers are making it a condition of contract, the commercial case is straightforward. If nobody has asked, a smaller organisation may get more security value from Cyber Essentials plus targeted technical work, at a fraction of the cost and time. Certification is a commercial instrument as much as a security one, and it is reasonable to treat it that way.