The Certificate Enterprise Security Teams Ask For By Name
ISO 27001 is the international standard for information security management — and the fastest way to stop losing deals to security review.
When a buyer's risk team receives your questionnaire, they are deciding whether to trust your answers. A self-assessment is your word. An accredited ISO 27001 certificate is an independent auditor's word, and it typically collapses weeks of back-and-forth into a single attachment.
The standard has two halves: the management system itself, set out in clauses 4 to 10, and Annex A — 93 controls grouped into organizational, people, physical and technological themes. You do not have to implement all 93, but you do have to justify every one you exclude, in writing.
- Scope set to the deals you want
- A real risk assessment
- Controls built into your stack
- Stage 1 and Stage 2 support
- Standard
- ISO/IEC 27001:2022
- Typical timeline
- 4–12 months
- Certificate valid
- 3 years
- Annex A controls
- 93 across 4 themes
Annex A controls
Control themes
Years a certificate lasts
Surveillance audits in between
ISO/IEC 27001:2022 — the standard, not the sales pitch
The Security Questionnaire Is the New Sales Gate
Almost nobody pursues ISO 27001 for its own sake. They pursue it because something valuable is stuck behind it.
Questionnaires you answer by hand
Every enterprise prospect sends a different spreadsheet, each one taking days of engineering and leadership time. Your answers are still only your word for it, and the reviewer knows that.
Days per deal, repeated forever
Sales cycles that stretch
Security review sits between verbal agreement and signature. Without independent assurance it is a negotiation; with a certificate it is usually an attachment.
Quarters slipping, forecasts missed
Deals you are not invited to
Some buyers screen suppliers for certification before a conversation ever starts. You never see those opportunities, so the cost is invisible until you certify.
Pipeline you never knew existed
What Getting Certified Actually Requires
Nine stages, in the order they happen. The early ones decide how long and how expensive the rest will be.
01 / 09
Defining the ISMS Scope
The decision that sets the price of everything after it.
Which products, teams, offices and cloud environments the certificate covers. We scope it to satisfy the buyers you are actually selling to — wide enough that the certificate is accepted, tight enough that the programme finishes.
What the Next Few Months Actually Look Like
Ranges, not a single number. Where you land inside them depends almost entirely on what already exists on day one.
- Phase 01
Week 0 · free
Gap analysis
We assess what you already do against the standard and hand back a prioritised plan with effort and dates against every gap. You keep it whether or not you continue with us.
We doAssess, document, price the work
You doA few hours of interviews
- Phase 02
Weeks 1–3
Scope, risk and the paper foundation
Certification scope agreed, risk methodology set, and the mandatory documents drafted — including the Statement of Applicability, the document auditors scrutinise hardest.
We doDraft everything, run the risk workshops
You doDecisions on scope and risk appetite
- Phase 03
Weeks 3–12
Implementing the controls
The longest phase and the one that varies most. Controls are built into your real systems rather than described in a document, with our engineers working alongside yours where the gaps are technical.
We doBuild, configure, evidence
You doAccess, and engineering time where unavoidable
- Phase 04
Concurrent
Training and awareness
Role-based training so the people an auditor interviews can answer confidently, plus a mock interview session so nobody meets these questions for the first time in the room.
We doDeliver training, run the dry run
You doGet your team in the room
- Phase 05
Min. 3 months in
Operate, internal audit, management review
The system must run long enough to produce real evidence — certification bodies generally expect around three months of operation before Stage 2. We run the mandatory internal audit and management review and close what they raise.
We doInternal audit, review, remediation
You doLeadership attendance at the review
- Phase 06
Then 30–60 days
Stage 1, Stage 2, certificate
Stage 1 reviews documentation and readiness. Stage 2, typically 30 to 60 days later, tests whether you genuinely operate the system. We prepare the evidence pack and attend both with you.
We doPrepare evidence, manage the auditor, handle findings
You doBe available for interviews
Where you land in the range depends on your starting point, your scope, and how much evidence already exists. Anyone quoting a fixed number of weeks before seeing your estate is guessing.
How We Run an ISO 27001 Programme
Certification is the halfway point, not the finish line.
Scope & Gap
What the certificate covers and the honest distance to it.
Risk Assessment
Your real threats, assessed and recorded defensibly.
SoA & Policies
All 93 controls judged, justified and documented.
Implement
Controls built into your real systems with your engineers.
Operate & Audit
Evidence accumulates; internal audit finds gaps first.
Certify
Stage 1, Stage 2, certificate — then surveillance.
THEN BACK TO 01 — AND ROUND AGAIN, EVERY YEAR
Where ISO 27001 Is Asked For By Name
Information security certification carries most weight where the buyer is handing you their data, their customers' data, or their regulatory exposure.
SaaS & Technology
Where enterprise security review is the single biggest drag on the sales cycle, and ISO 27001 is asked for by name.
Financial Services
Banking, payments and fintech, where supplier assurance is a regulatory expectation rather than a preference.
Health & Life Sciences
Patient and trial data carries obligations that buyers will not take on trust from an unaudited supplier.
Public Sector & Defence
Frameworks and tenders that list certification as a pass-or-fail eligibility criterion before scoring begins.
Retail & E-Commerce
Payment data, large supply chains, and sustainability criteria appearing in more and more supplier scorecards.
Professional & Legal
Client confidentiality, continuity obligations, and the quality assurance that panel appointments increasingly require.
Working across
ISO 27001 Is For You If This Is Happening
Tick what applies.
00 OF 06
Worth understanding before a buyer forces the issue.
Fixed Scope. Fixed Fee. No Surprises.
Compliance consultancy has a reputation for open-ended day rates and a bill that grows with the project. We price the work after the gap analysis, when both of us know what it involves.
What you get
- A free gap analysis before you commit to anything
- A fixed implementation fee, quoted once the scope is known
- Senior consultants doing the work, not supervising juniors
- Documentation written for your business, never a template pack
- We attend Stage 1 and Stage 2 with you
- Support through the surveillance years, not just to the certificate
What we will not do
- Sell you a certificate — an accredited body issues that, independently
- Bill by the hour for work we should have scoped properly
- Promise certification in a number of weeks the standard does not allow
- Hand over a policy binder and disappear before the audit
- Take commission for recommending a certification body
- Claim an ISO certificate makes you compliant with a law it does not cover
We prepare you. An accredited body certifies you.
Under ISO/IEC 17021-1, a certification body cannot certify a management system that it, or a related consultancy, designed. That separation is what makes the certificate worth anything to your buyer. We are firmly on the implementation side of that line.
- We build the ISMS, the risk assessment, the SoA and the evidence
- An independent accredited certification body runs Stage 1 and Stage 2
- We help you choose that body and take no commission
- Insist on UKAS-accredited certification — unaccredited certificates are frequently rejected in enterprise procurement
Built By People Who Build The Systems
We write software for a living. When the standard asks for secure development, logging or access control, we implement it — we do not write a paragraph describing someone else doing it.
Real controls, real infrastructure◆A defensible risk assessment◆No template Statement of Applicability◆Your engineers stay productive◆We are there at Stage 2
WE DO NOT SELL YOU A POLICY PACK
Trusted by startups, enterprises, and governments worldwide










































































































The stack behind the platforms we build.
We choose tools for the outcome they deliver, not for the trend they follow.
Frontend
8 tools“Knowledgeable, professional, and responsive — Devtrios added real value at every step of our project and delivered exactly what we needed.”
Where Our Clients Rate Us 5 Stars
Our clients don't just work with us, they recommend us — 4.9 on Google, 5.0 on Clutch and GoodFirms. Every badge below links straight to the profile it comes from. Independent reviews keep pointing to the same three things: strong technical expertise, clear communication, and delivery you can rely on.
Recognised on
Verified reviewsFrequently Asked Questions
Everything you might want to know before we talk. Still unsure? A quick call clears it up.
Ask us anythingFour to six months if you already have solid security practices and documentation. Six to twelve months is realistic for a typical UK SME starting from a normal baseline, and starting genuinely from scratch can take longer. A structural constraint sets the floor: certification bodies generally expect the ISMS to have been operating for around three months before Stage 2, because the auditor needs real records to examine.
No. Annex A is a catalogue, not a mandate. Your risk assessment determines which controls apply. What you must do is account for all 93 in your Statement of Applicability — stating for each whether it is applicable, the justification, and its implementation status. Excluding a control is entirely acceptable; excluding it without a defensible reason is a finding.
Stage 1 is largely a documentation and readiness review — the auditor checks that your ISMS exists, is documented, and is ready to be tested, and flags anything that would cause you to fail. Stage 2 is the real audit: the auditor tests whether you actually do what your documents claim, through interviews, records, logs and samples. The two are typically 30 to 60 days apart, which gives you time to close Stage 1 findings.
Two separate bills. The certification body charges audit fees — for an SME, commonly a few thousand pounds in year one, plus roughly £1,500–£4,000 a year for surveillance. Implementation is the larger variable. Total year-one spend for most UK SMEs falls between about £6,000 and £25,000 depending on headcount, scope, and how much you already have in place. We fix our fee after the gap analysis.
No, though they overlap heavily. ISO 27001 is an international standard certifying that you operate an information security management system; SOC 2 is a US attestation report, issued by a CPA firm, on controls against the Trust Services Criteria. European and UK buyers usually ask for ISO 27001; US buyers often ask for SOC 2. Because the underlying controls overlap so much, doing the second after the first is far cheaper than doing it cold.
Yes, and it is a common reason people call us. Failed or heavily-findinged audits usually trace back to the same causes: a template Statement of Applicability that does not match reality, a risk assessment done as a formality, or no genuine internal audit and management review. Those are fixable, and the second attempt is generally much faster because the documentation skeleton already exists.
ISO/IEC 27001:2022 restructured Annex A, consolidating the previous 114 controls into 93 and regrouping them from 14 domains into four themes — organizational, people, physical and technological. It also introduced controls reflecting modern practice, including threat intelligence, cloud security, and secure coding. Organisations certified against the 2013 version were required to transition, and new certifications are issued against the 2022 version.
Find out how far you already are
Most teams are further along than they think — the gap is usually documentation and evidence, not security. The gap analysis tells you which, for free.
Start Your Next Project with Devtrios
Tell us about your idea or business needs. Our team will review your requirements and get back to you within one business day with a clear plan, timeline, and a free consultation call.



