Skip to main content

Display options

These change how this site looks in your browser and are remembered on this device. They do not replace your own browser or device settings, which apply everywhere and will usually do more.

Text size
Reading
Colour and clarity
Movement and controls
Accessibility statement
SectorsAboutBlogNewsContactCall 01444 222889Book a Consultation

ISO 27001 Consultancy and Certification Preparation

Achieve ISO/IEC 27001:2022 with confidence.

ISO 27001 Preparation

ISO 27001 is the international standard for information security management, and achieving it is a clear signal to clients and partners that you take security seriously. But the path to certification can feel daunting. We provide practical, hands-on preparation, from understanding the requirements through to pre-certification readiness, so you arrive at your certification audit with confidence. Vinula is an independent consultancy, not a certification body. Certification itself is arranged through our partner, the British Assessment Bureau, at additional cost.

What preparation involves

We help you understand the standard, scope your information security management system, build the policies and procedures it requires, and work through risk assessment and the controls. The level you choose determines how much we do with you, from foundational templates and guidance up to full implementation support.

How certification works

We prepare you; an accredited certification body certifies you. We are clear about this distinction because it matters. We get you ready, and certification is arranged through our partner the British Assessment Bureau, which keeps the assessment independent, as it should be.

Why pursue ISO 27001

Beyond the security benefits, certification is increasingly required to win contracts, particularly with larger and public sector clients. It is a recognised, credible way to prove your security is well managed.

Post-certification support

Certification is not the finish line. We can help you maintain your certification by supporting your management reviews and internal audits, so the management system keeps working and your surveillance audits hold no surprises.

What changed in ISO 27001:2022

The current version of the standard is ISO/IEC 27001:2022. The transition period for organisations certified to the 2013 version ended on 31 October 2025, so certification today is to the 2022 edition. The biggest change is in Annex A, the reference set of security controls. It now holds 93 controls grouped into four themes: organisational, people, physical and technological. A number of older controls were merged, and new ones were added covering areas such as threat intelligence, the use of cloud services, data masking and secure coding. As your ISO 27001 consultant, we work from the 2022 version throughout, so the policies, risk assessment and Statement of Applicability we build with you line up with the controls your auditor will actually be checking.

Risk assessment and the Statement of Applicability

ISO 27001 is built on risk. Before choosing controls, you identify the information you hold, the threats and weaknesses that could affect it, and how likely and serious each risk is. You then decide how to treat each one, whether by reducing it with controls, avoiding it, sharing it or accepting it, and record those decisions in a risk treatment plan. The Statement of Applicability follows from this work. It lists the Annex A controls, says whether each one is included and why, and shows whether it is in place. Auditors rely on it heavily, so it needs to be honest and consistent with your risk register. Depending on the level you choose, we provide a methodology and guidance, carry out the risk assessment and asset inventory with you, or build the full risk treatment plans alongside your team.

The certification audit, stage by stage

Certification is carried out by an accredited certification body in two stages. The stage 1 audit looks mainly at your documentation and readiness: your scope, policies, risk assessment and Statement of Applicability, and whether you are prepared to move on. The stage 2 audit then checks that the management system is working in practice, through interviews, records and evidence that controls operate as described. If the auditor raises nonconformities, you agree and carry out corrective actions, and major nonconformities must be resolved before a certificate can be issued. A certificate lasts three years, with surveillance audits at least once a year in between and a recertification audit before it expires. Our certification support gets you ready for each stage, and at Gold level we can support you during the audits themselves. The audits are arranged through our partner, the British Assessment Bureau.

What decides how long ISO 27001 takes

There is no standard timetable, because a handful of factors make the biggest difference. Scope comes first: certifying one office or service is a smaller job than certifying the whole organisation. Your starting point matters too. If you already have documented policies, an asset list and some form of risk management, much of the groundwork exists. Complexity plays a part, including how many sites, systems and suppliers are involved. So does the time your own people can give, because the management system has to be run by you, not by us. Finally, the certification body will want evidence that the system has been operating, including an internal audit and a management review, before the stage 2 audit. We look at all of this in the scoping workshop and then give you a realistic timeline.

Where we work

We work with organisations across the UK. Much of our work is delivered remotely, so we support clients wherever they are based, with particular strength in London and the Southeast. We are based in Haywards Heath, West Sussex, and the areas we cover include London, Brighton and Hove, Crawley, Horsham, Haywards Heath, Burgess Hill, Worthing, Guildford, Tunbridge Wells, Reading, Slough, Newbury, Swindon and Bristol.

Client feedback

What our clients say

Rated 5.0 out of 5 on Google, from 2 reviews

Uniqodo has worked with Ben and Vinula for over eight years, and throughout that time, they have been a trusted partner in helping us maintain and strengthen our information security posture.

Vinula has supported our ISO 27001 certification efforts through annual internal audits, management reviews, and ongoing compliance guidance. Their expertise has helped ensure we not only meet the requirements of the standard but also continue to improve our security practices year after year.

Beyond ISO 27001, Vinula provides valuable insight into the evolving information security landscape, helping us stay informed about emerging threats, changing regulations, and industry best practices. Their team combines deep technical knowledge with a pragmatic, business-focused approach, making complex security challenges easier to understand and address.

We value Vinula's professionalism, responsiveness, and expertise, and would highly recommend them to any organisation looking for a trusted partner in information security and compliance.

Julius SomoyeUniqodoGoogle review

Want to know if this is the right fit for your organisation? We will talk it through with you, with no obligation.

Get in touch

Practical guidance, hands-on implementation and pre-certification readiness to prepare you for ISO 27001. Vinula is an independent consultancy, not a certification body. Certification itself is arranged through our partner the British Assessment Bureau at additional cost.

Please note: Vinula is an independent consultancy, not a certification body. Certification is arranged through our partner British Assessment Bureau at additional cost.

Pricing and tiers

Bronze
£1,900
  • Introduction to ISO 27001 requirements and scoping workshop (half-day, online)
  • Basic ISO 27001 policy and procedure templates
  • Guidance on risk assessment methodology and documentation
Silver
Enquire for pricing
  • Full gap analysis and risk assessment including asset inventory
  • Customised policies, procedures and Statement of Applicability
  • Half-day workshop on implementing ISO 27001 controls
  • Guidance on internal audit planning and certification preparation
Gold
Enquire for pricing
  • Complete implementation support including risk treatment plans
  • Fully customised documentation for certification readiness
  • On-site or virtual support during certification audits
  • Internal audit training and first internal audit facilitation
  • Post-certification maintenance plan and annual review

Ready to get started?

Book a consultation and we will tailor this service to your organisation and the risks it faces.

Book a consultation
Questions

Frequently asked questions

No, and that is deliberate. We are an independent consultancy that prepares you for certification. The certification itself is carried out by an accredited body, arranged through our partner the British Assessment Bureau, which keeps the process properly independent.

It varies with your size, complexity, and starting point. After an initial scoping workshop we can give you a realistic timeline. The Gold level includes full implementation support for organisations that want us alongside them throughout.

If certification is not being asked of you, an Information Security Health Check may be a better starting point. If clients or contracts require ISO 27001, preparation is the route. We are happy to advise which fits your situation.

Certification is not the finish line. We can help you maintain your certification by supporting your management reviews and internal audits, so the management system keeps working and your surveillance audits hold no surprises.

An ISO 27001 consultant helps you build an information security management system that meets the standard and prepares you for the certification audit. That usually means scoping, gap analysis, risk assessment, policies, the Statement of Applicability and internal audit. We provide this ISO 27001 consultancy to organisations in Sussex, London and across the UK, with much of the work delivered remotely.

There are two separate costs. Our preparation starts with the Bronze level at £1,900, while Silver and Gold are priced on enquiry because they depend on how much support you need. The certification audits are a separate fee, set by the certification body for your scope and arranged through our partner the British Assessment Bureau.

No. There is no general legal requirement for UK organisations to hold ISO 27001. In practice, though, it is often asked for by customers, in tenders and in supply chain contracts, particularly by larger and public sector clients. Many organisations also adopt it simply because it gives them a clear, recognised framework for managing information security well.

An ISO 27001 certificate is valid for three years. During that time the certification body carries out surveillance audits, at least once a year, to confirm the management system is still working. Before the three years are up, a recertification audit renews the certificate for another cycle. Keeping up internal audits and management reviews between visits is what makes those audits straightforward.

Cyber Essentials is a UK government backed scheme that checks a focused set of technical controls: firewalls, secure configuration, user access control, malware protection and security updates. ISO 27001 is an international standard for a whole management system, covering risk, people, processes and suppliers, with continual improvement built in. Many organisations hold both. Vinula is itself Cyber Essentials certified, and we can advise which suits your customers' requirements.

Interested in ISO 27001 Preparation?

Book a consultation and we will tailor the right level of support to your organisation.

Book a Consultation