ISO 27001 is the international standard for information security management. It provides a structured way to identify, treat and manage risk to the confidentiality, integrity and availability of information, whether that is customer data, intellectual property or commercially sensitive material.
Certification / Accreditation
ISO 27001 Information security management

At its core, it’s about a risk assessment and treatment process backed by a Statement of Applicability, your own justified selection from 93 reference controls. The 2022 edition is current; the 2013 edition’s transition deadline passed in October 2025, so this is now the only valid edition to certify against.
Who it’s for and what’s involved
Relevant if you are:
Achieving certification involves:
How Q! supports certification
Risk assessment, done properly
Risk assessment is where most ISO 27001 implementations succeed or fail. We make sure yours reflects how the business actually operates, not a generic checklist borrowed from somewhere else. We have also supported organisations through the 2013 to 2022 transition, where the real challenge was re-justifying control selection against the new Annex A, not simply relabelling an existing document.
Customers asking about your information security?
Mini FAQs
Relevant case studies
We’re proud of the service we provide and the feedback we get from our clients. but don’t just take our word for it.












