Solutions /  The situation

ISO 27001, driven by the deal date, not the audit calendar.

You did not wake up wanting a management system. A customer put certification in the contract, and now a standard written for large organisations has landed on a company that does not have a security team. The question you are asking is not "how do we get certified"; it is "what is the shortest honest path to the signature."

Get your free exposure assessment

ISO 27001 has become the default proof of trust in enterprise procurement, and your buyer's vendor policy does not have an exception for a 60-person company. The certificate is now a commercial prerequisite, priced into the deal you are trying to close.

What it is costing you

  • Revenue is gated behind a certificate you do not have, with a customer deadline you did not set.
  • A consultant-led project can absorb months of your CTO's calendar in workshops and document review.
  • A binder-and-certificate approach passes the audit and then decays: controls drift, and the next surveillance audit finds you.
  • Every month of delay is a month the competitor who already has the certificate is in the room and you are not.

What we do

01

Gap assessment against the deal, not the ideal

We measure where you are against Annex A and tell you the real distance to certification, and which parts your customer will accept as in-progress.

02

We scope it to what you sell

Scope is the single biggest lever on cost and time. We draw the ISMS boundary around the product and infrastructure your customer cares about, not around the whole company.

03

We build the ISMS and run it

Policies, risk register, asset inventory, supplier reviews, access reviews, internal audit, management review. We do the work; your people supply facts, not free time.

04

We take you through the certification audit

Stage 1 and Stage 2 with an accredited body, with us in the room. Findings are handled by us, not handed to you.

05

We keep it alive after the certificate

The ROC runs the ISMS continuously: evidence collected, reviews performed, drift caught between audits, so surveillance is a formality rather than a fire drill.

How long it takes. Most mid-market companies reach Stage 2 in six to nine months from a standing start. Anyone promising ISO 27001 in 30 days is selling you a document set, not a certificate.

How long does ISO 27001 certification take for a small company?

From a standing start, six to nine months to Stage 2 for a typical 50-500 person company. The sequence is fixed: gap assessment and scoping (2-4 weeks), building the ISMS (policies, risk register, asset inventory, supplier and access reviews, 2-4 months), an operating period where the controls actually run and produce evidence (usually at least 2-3 months, because the auditor must see the system working), then Stage 1 and Stage 2 audits. The operating period is why 30-day certification claims are not real.

How much does ISO 27001 certification cost?

Cost splits in two: the certification body (a fixed audit fee based on headcount and scope, paid to an accredited registrar) and the work of building and running the ISMS. Scope is the biggest lever. Certifying one product and its cloud environment costs materially less than certifying an entire company. The recurring cost is the part most companies miss: surveillance audits every year and the internal work to keep controls operating between them.

Is ISO 27001 enough to satisfy an enterprise customer?

Usually, for the trust question, but it does not remove the customer's own questionnaire, their contractual security terms, or their right to ask for evidence during the contract. A certificate proves a management system existed on the audit date. Enterprise buyers increasingly ask what happens between audit dates, which is why the evidence behind the certificate matters more than the certificate itself.

Find out how far you have drifted.

A free exposure assessment. We connect to what you already have, and show you what your dashboards are not showing you.

No obligation. Results in 10 business days.