ISO/IEC 27001:2022 · Information Security

Certification that survives the auditor's scrutiny.

We build ISO 27001 information security management systems for UK and European businesses, led by senior consultants who also audit on behalf of certification bodies. We know exactly what your assessor will look for, because on other days of the week, we are the assessor.

We hold ourselves to the standards we audit: Cybercontrols is certified to
ISO/IEC 27001:2022Certified · SANCERT ISO/IEC 42001:2023Certified · SANCERT Cyber EssentialsCertified Government Commercial AgencyApproved Supplier · G-Cloud 15
What we deliver

One standard, three ways we can carry you through it.

Whether you are starting from a blank page, maintaining an established ISMS, or preparing for the 2022 transition, the engagement is shaped around your organisation, your risk profile, and your deadline, never a template.

01

ISMS Implementation

Full design and build of an ISO/IEC 27001:2022 management system, from scoping and risk assessment through the Statement of Applicability to embedded, operating controls. Documentation your people will actually use, and an ISMS built for certification from day one.

02

Internal Audit

An impartial internal audit programme delivered by qualified Senior Lead Auditors. We test your ISMS the way a certification body will, report findings in plain language, and leave you with a prioritised remediation plan rather than a pile of observations.

03

Surveillance & Maintenance

Certification is a licence to keep improving, not a finish line. We run management reviews, close out findings, maintain your risk register and keep the ISMS current through surveillance audits and recertification, quietly and without drama.

Why Cybercontrols

We have sat on both sides of the audit table.

Cybercontrols consultants hold Senior Lead Implementer and Senior Lead Auditor credentials and audit on behalf of multiple UK certification bodies. That dual perspective changes how we build: every control, every document, every risk decision is made knowing precisely how an assessor will test it. And we practise what we audit: Cybercontrols is itself certified to ISO/IEC 27001 and ISO/IEC 42001, holds Cyber Essentials, and is an approved Government Commercial Agency supplier.

Senior-led, always

No juniors learning on your engagement. You work directly with accredited lead auditors and implementers.

Certification-body fluent

We work across several UK certification bodies and speak their language, their processes, and their expectations.

The triangle of control

ISO 27001 integrates cleanly with ISO 27701 privacy and ISO 42001 AI governance: one management system, three certificates.

Certified ourselves

ISO 27001 and 42001 certified, Cyber Essentials, and a Government Commercial Agency supplier: we hold the certificates we help you earn.

How it works

From first scoping call to certificate, without surprises.

Step 1

Scoping & gap analysis

We establish what the ISMS must cover, benchmark your current position against all 93 controls of Annex A, and give you an honest reading of the distance to certification, in weeks, not consultancy-speak.

Step 2

Risk assessment & Statement of Applicability

A risk methodology your leadership can actually engage with, producing a Statement of Applicability that reflects your business rather than a copied template, the document your auditor will read first.

Step 3

Build & embed

Policies, processes and controls deployed alongside your team, inside your existing ways of working. Knowledge transfer throughout, so the ISMS belongs to you, not to your consultants.

Step 4

Internal audit & readiness

A full internal audit and management review, then a mock assessment run exactly as the certification body will run it. You enter stage 1 and stage 2 knowing what will be asked and what the answers are.

Step 5

Certification & beyond

Support through the certification audit itself, then ongoing surveillance, continual improvement, and, when you are ready, the natural extensions into ISO 27701 and ISO 42001.

Questions we hear most

ISO 27001, answered plainly.

How long does ISO 27001 certification take?

For most SMEs, four to six months from kick-off to stage 2 audit, depending on scope, existing maturity and how quickly decisions get made internally. We will give you a realistic timeline at the scoping stage, and we hold ourselves to it.

What does it cost?

Two budgets matter: our consultancy fee and the certification body's audit fee. Both scale with the size and complexity of your organisation. We scope both transparently up front, so there is one honest number, not an unfolding series of extras.

We are a small business. Is ISO 27001 realistic for us?

Yes, and increasingly it is commercially necessary, because enterprise customers now push the requirement down their supply chains. A well-scoped ISMS for a small business is lean: the standard requires what is appropriate to your risks, not an enterprise bureaucracy.

We are certified to the 2013 edition. What about the 2022 transition?

All certificates must transition to ISO/IEC 27001:2022. We run transition projects as a focused delta exercise, mapping your existing controls to the restructured Annex A and closing the genuinely new requirements, rather than rebuilding what already works.

Can ISO 27001 combine with ISO 27701 and ISO 42001?

That combination is our specialism, the triangle of control: information security, privacy and AI governance run as one integrated management system with shared risk management, internal audit and management review. One system, three certificates, considerably less overhead than three separate programmes.

Ready to know exactly where you stand?

A 30-minute scoping call with a senior lead auditor. No obligation, no juniors, and an honest answer about whether you are ready, even if the answer is "not yet".