ISO/IEC 27001 Information Security Management
The international standard for an information security management system (ISMS). It sets out how you identify information security risk and put controls in place to manage it.
Who asks for it
Payment and remittance companies, fintech and digital-asset platforms, IT service providers, SaaS vendors, professional services firms, and anyone whose clients have started asking.
Typical duration
3–6 months
What a readiness engagement produces
- A written gap analysis with priorities
- Documentation written for your operation
- Training so staff can explain the system
- Internal audit and management review
- An evidence pack ready for the auditor
The two fees
The certification fee is charged by the accredited certification body that audits you and issues the certificate. Our consultancy fee covers gap analysis, documentation, training, internal audit and audit support.
Consultancy fee refund commitment
If your organisation is not recommended for certification at the first certification audit, we refund our consultancy fee in full.
Conditions: the agreed corrective actions are completed, the required records and evidence are provided, and the audit is conducted by an accredited certification body within three months of our readiness sign-off. The commitment covers our consultancy fee only, not the certification body's fees.
Preparing for ISO/IEC 27001?
Tell us the scope and we will give you a written quotation.