Skip to content
DevTrios — Engineering Partner
ISO/IEC 27001:2022

The Certificate Enterprise Security Teams Ask For By Name

ISO 27001 is the international standard for information security management — and the fastest way to stop losing deals to security review.

When a buyer's risk team receives your questionnaire, they are deciding whether to trust your answers. A self-assessment is your word. An accredited ISO 27001 certificate is an independent auditor's word, and it typically collapses weeks of back-and-forth into a single attachment.

The standard has two halves: the management system itself, set out in clauses 4 to 10, and Annex A — 93 controls grouped into organizational, people, physical and technological themes. You do not have to implement all 93, but you do have to justify every one you exclude, in writing.

  • Scope set to the deals you want
  • A real risk assessment
  • Controls built into your stack
  • Stage 1 and Stage 2 support
Organizational37People8Physical14Technological34ISMS — clauses 4 to 1093 ANNEX A CONTROLS · FOUR THEMES
Standard
ISO/IEC 27001:2022
Typical timeline
4–12 months
Certificate valid
3 years
Annex A controls
93 across 4 themes
0

Annex A controls

0

Control themes

0

Years a certificate lasts

0

Surveillance audits in between

ISO/IEC 27001:2022 — the standard, not the sales pitch

Why this lands on your desk

The Security Questionnaire Is the New Sales Gate

Almost nobody pursues ISO 27001 for its own sake. They pursue it because something valuable is stuck behind it.

Questionnaires you answer by hand

Every enterprise prospect sends a different spreadsheet, each one taking days of engineering and leadership time. Your answers are still only your word for it, and the reviewer knows that.

Days per deal, repeated forever

Sales cycles that stretch

Security review sits between verbal agreement and signature. Without independent assurance it is a negotiation; with a certificate it is usually an attachment.

Quarters slipping, forecasts missed

Deals you are not invited to

Some buyers screen suppliers for certification before a conversation ever starts. You never see those opportunities, so the cost is invisible until you certify.

Pipeline you never knew existed

What ISO 27001 involves

What Getting Certified Actually Requires

Nine stages, in the order they happen. The early ones decide how long and how expensive the rest will be.

IN SCOPEProduct platformCustomer dataEngineeringCloud estateOut ofscopeA NARROW SCOPE THAT PASSES BEATS A WIDE ONE THAT STALLS

01 / 09

Defining the ISMS Scope

The decision that sets the price of everything after it.

Which products, teams, offices and cloud environments the certificate covers. We scope it to satisfy the buyers you are actually selling to — wide enough that the certificate is accepted, tight enough that the programme finishes.

The roadmap

What the Next Few Months Actually Look Like

Ranges, not a single number. Where you land inside them depends almost entirely on what already exists on day one.

  1. Phase 01

    Week 0 · free

    Gap analysis

    We assess what you already do against the standard and hand back a prioritised plan with effort and dates against every gap. You keep it whether or not you continue with us.

    We doAssess, document, price the work

    You doA few hours of interviews

  2. Phase 02

    Weeks 1–3

    Scope, risk and the paper foundation

    Certification scope agreed, risk methodology set, and the mandatory documents drafted — including the Statement of Applicability, the document auditors scrutinise hardest.

    We doDraft everything, run the risk workshops

    You doDecisions on scope and risk appetite

  3. Phase 03

    Weeks 3–12

    Implementing the controls

    The longest phase and the one that varies most. Controls are built into your real systems rather than described in a document, with our engineers working alongside yours where the gaps are technical.

    We doBuild, configure, evidence

    You doAccess, and engineering time where unavoidable

  4. Phase 04

    Concurrent

    Training and awareness

    Role-based training so the people an auditor interviews can answer confidently, plus a mock interview session so nobody meets these questions for the first time in the room.

    We doDeliver training, run the dry run

    You doGet your team in the room

  5. Phase 05

    Min. 3 months in

    Operate, internal audit, management review

    The system must run long enough to produce real evidence — certification bodies generally expect around three months of operation before Stage 2. We run the mandatory internal audit and management review and close what they raise.

    We doInternal audit, review, remediation

    You doLeadership attendance at the review

  6. Phase 06

    Then 30–60 days

    Stage 1, Stage 2, certificate

    Stage 1 reviews documentation and readiness. Stage 2, typically 30 to 60 days later, tests whether you genuinely operate the system. We prepare the evidence pack and attend both with you.

    We doPrepare evidence, manage the auditor, handle findings

    You doBe available for interviews

Where you land in the range depends on your starting point, your scope, and how much evidence already exists. Anyone quoting a fixed number of weeks before seeing your estate is guessing.

How it runs

How We Run an ISO 27001 Programme

Certification is the halfway point, not the finish line.

01

Scope & Gap

What the certificate covers and the honest distance to it.

02

Risk Assessment

Your real threats, assessed and recorded defensibly.

03

SoA & Policies

All 93 controls judged, justified and documented.

04

Implement

Controls built into your real systems with your engineers.

05

Operate & Audit

Evidence accumulates; internal audit finds gaps first.

06

Certify

Stage 1, Stage 2, certificate — then surveillance.

THEN BACK TO 01 — AND ROUND AGAIN, EVERY YEAR

Industries

Where ISO 27001 Is Asked For By Name

Information security certification carries most weight where the buyer is handing you their data, their customers' data, or their regulatory exposure.

SaaS & Technology

Where enterprise security review is the single biggest drag on the sales cycle, and ISO 27001 is asked for by name.

Financial Services

Banking, payments and fintech, where supplier assurance is a regulatory expectation rather than a preference.

Health & Life Sciences

Patient and trial data carries obligations that buyers will not take on trust from an unaudited supplier.

Public Sector & Defence

Frameworks and tenders that list certification as a pass-or-fail eligibility criterion before scoring begins.

Retail & E-Commerce

Payment data, large supply chains, and sustainability criteria appearing in more and more supplier scorecards.

Professional & Legal

Client confidentiality, continuity obligations, and the quality assurance that panel appointments increasingly require.

Working across

United KingdomEuropean UnionUnited StatesUAE & GCCAustralia & NZRemote worldwide
Who it's for

ISO 27001 Is For You If This Is Happening

Tick what applies.

00 OF 06

Worth understanding before a buyer forces the issue.

How we engage

Fixed Scope. Fixed Fee. No Surprises.

Compliance consultancy has a reputation for open-ended day rates and a bill that grows with the project. We price the work after the gap analysis, when both of us know what it involves.

What you get

  • A free gap analysis before you commit to anything
  • A fixed implementation fee, quoted once the scope is known
  • Senior consultants doing the work, not supervising juniors
  • Documentation written for your business, never a template pack
  • We attend Stage 1 and Stage 2 with you
  • Support through the surveillance years, not just to the certificate

What we will not do

  • Sell you a certificate — an accredited body issues that, independently
  • Bill by the hour for work we should have scoped properly
  • Promise certification in a number of weeks the standard does not allow
  • Hand over a policy binder and disappear before the audit
  • Take commission for recommending a certification body
  • Claim an ISO certificate makes you compliant with a law it does not cover

We prepare you. An accredited body certifies you.

Under ISO/IEC 17021-1, a certification body cannot certify a management system that it, or a related consultancy, designed. That separation is what makes the certificate worth anything to your buyer. We are firmly on the implementation side of that line.

  • We build the ISMS, the risk assessment, the SoA and the evidence
  • An independent accredited certification body runs Stage 1 and Stage 2
  • We help you choose that body and take no commission
  • Insist on UKAS-accredited certification — unaccredited certificates are frequently rejected in enterprise procurement
Why Devtrios

Built By People Who Build The Systems

We write software for a living. When the standard asks for secure development, logging or access control, we implement it — we do not write a paragraph describing someone else doing it.

Real controls, real infrastructureA defensible risk assessmentNo template Statement of ApplicabilityYour engineers stay productiveWe are there at Stage 2

WE DO NOT SELL YOU A POLICY PACK

AssessImplementCertify

Trusted by startups, enterprises, and governments worldwide

Technology Stack

The stack behind the platforms we build.

We choose tools for the outcome they deliver, not for the trend they follow.

Frontend

8 tools
React
Next.js
TypeScript
Tailwind CSS
Vue.js
Angular
Sass
Vite
Based on 0+ verified client reviews
4.9/ 5.0
4.9 on Google, 5.0 on Clutch and GoodFirms
0%
Client Satisfaction
0+
Verified Reviews
0%
Client Retention

“Knowledgeable, professional, and responsive — Devtrios added real value at every step of our project and delivered exactly what we needed.”

C
Connie Woo
Founder, Fintech Startup
Ratings & Reviews

Where Our Clients Rate Us 5 Stars

Our clients don't just work with us, they recommend us — 4.9 on Google, 5.0 on Clutch and GoodFirms. Every badge below links straight to the profile it comes from. Independent reviews keep pointing to the same three things: strong technical expertise, clear communication, and delivery you can rely on.

Recognised on

Verified reviews
Our Services
FAQ

Frequently Asked Questions

Everything you might want to know before we talk. Still unsure? A quick call clears it up.

Ask us anything

Four to six months if you already have solid security practices and documentation. Six to twelve months is realistic for a typical UK SME starting from a normal baseline, and starting genuinely from scratch can take longer. A structural constraint sets the floor: certification bodies generally expect the ISMS to have been operating for around three months before Stage 2, because the auditor needs real records to examine.

No. Annex A is a catalogue, not a mandate. Your risk assessment determines which controls apply. What you must do is account for all 93 in your Statement of Applicability — stating for each whether it is applicable, the justification, and its implementation status. Excluding a control is entirely acceptable; excluding it without a defensible reason is a finding.

Stage 1 is largely a documentation and readiness review — the auditor checks that your ISMS exists, is documented, and is ready to be tested, and flags anything that would cause you to fail. Stage 2 is the real audit: the auditor tests whether you actually do what your documents claim, through interviews, records, logs and samples. The two are typically 30 to 60 days apart, which gives you time to close Stage 1 findings.

Two separate bills. The certification body charges audit fees — for an SME, commonly a few thousand pounds in year one, plus roughly £1,500–£4,000 a year for surveillance. Implementation is the larger variable. Total year-one spend for most UK SMEs falls between about £6,000 and £25,000 depending on headcount, scope, and how much you already have in place. We fix our fee after the gap analysis.

No, though they overlap heavily. ISO 27001 is an international standard certifying that you operate an information security management system; SOC 2 is a US attestation report, issued by a CPA firm, on controls against the Trust Services Criteria. European and UK buyers usually ask for ISO 27001; US buyers often ask for SOC 2. Because the underlying controls overlap so much, doing the second after the first is far cheaper than doing it cold.

Yes, and it is a common reason people call us. Failed or heavily-findinged audits usually trace back to the same causes: a template Statement of Applicability that does not match reality, a risk assessment done as a formality, or no genuine internal audit and management review. Those are fixable, and the second attempt is generally much faster because the documentation skeleton already exists.

ISO/IEC 27001:2022 restructured Annex A, consolidating the previous 114 controls into 93 and regrouping them from 14 domains into four themes — organizational, people, physical and technological. It also introduced controls reflecting modern practice, including threat intelligence, cloud security, and secure coding. Organisations certified against the 2013 version were required to transition, and new certifications are issued against the 2022 version.

Free gap analysis

Find out how far you already are

Most teams are further along than they think — the gap is usually documentation and evidence, not security. The gap analysis tells you which, for free.

Contact

Start Your Next Project with Devtrios

Tell us about your idea or business needs. Our team will review your requirements and get back to you within one business day with a clear plan, timeline, and a free consultation call.

Contact Information
info@devtrios.com+44 7470 801776
Avenue Road, SE25 4DX, London, United Kingdom
Connect With Us

Let's Discuss Your Project