Certification / Accreditation

ISO 27001 Information security management

ISO 27001 is the international standard for information security management. It provides a structured way to identify, treat and manage risk to the confidentiality, integrity and availability of information, whether that is customer data, intellectual property or commercially sensitive material.

At its core, it’s about a risk assessment and treatment process backed by a Statement of Applicability, your own justified selection from 93 reference controls. The 2022 edition is current; the 2013 edition’s transition deadline passed in October 2025, so this is now the only valid edition to certify against.

Who it’s for and what’s involved

Relevant if you are:

Handling client data as part of a service contract

Facing customer or investor due diligence on security

Bidding for contracts that require certification

Still working informally to the withdrawn 2013 edition

Achieving certification involves:

Carrying out a risk assessment and treatment process

Building your Statement of Applicability

Running internal audits and reviews

Passing an external certification audit

How Q! supports certification

Risk assessment, done properly

Risk assessment is where most ISO 27001 implementations succeed or fail. We make sure yours reflects how the business actually operates, not a generic checklist borrowed from somewhere else. We have also supported organisations through the 2013 to 2022 transition, where the real challenge was re-justifying control selection against the new Annex A, not simply relabelling an existing document.

Customers asking about your information security?

Mini FAQs

It depends less on company size than people expect, and more on whether your risk assessment is done properly. A thin, generic risk assessment will get found out at audit. A thorough one, reflecting how the business actually handles information, tends to make the rest of the standard fall into place.
Annex A was reorganised from 114 controls across 14 categories to 93 controls across four themes. More significant in practice were the new controls: threat intelligence, cloud services security, data masking and ICT readiness for business continuity. Most of the work in transitioning was rebuilding the Statement of Applicability, not relabelling documents.
Often, yes, particularly for businesses handling client data where a security incident would be commercially damaging. Certification forces a level of discipline around information security that many businesses benefit from regardless of whether a customer has formally requested it, and it puts you ahead of the request when it eventually comes.
Yes. ISO 27001 shares its Harmonised Structure with ISO 9001, ISO 14001, ISO 45001 and ISO 50001, making integration into a single management system practical for businesses already certified elsewhere. The wider ISO 27000 series also includes standards for drilling into specific sub-topics, such as ISO 27017 for cloud security and ISO 27701 for privacy information management, useful if a particular area needs deeper treatment than Annex A alone provides.
ISO 42001 covers AI management systems, a closely related but distinct set of risks. The two standards are increasingly relevant together for technology businesses developing or deploying AI.
Plenty of technically capable teams can write policies and select controls themselves. Where a consultant earns their place is in the risk assessment itself, pressure-testing whether it reflects the business, and in preparing for audit so nothing comes as a surprise on the day.

Relevant case studies

We’re proud of the service we provide and the feedback we get from our clients. but don’t just take our word for it.

Client: QFactorial

Our own B Corp journey: practising what we preach

Read more

Whatever business stage you are at…

We’re
here.

Starting up

Foundations, framework, roadmap

Growing up

Strategies for growth and resilience

Shaking up

Managing change to mitigate and maximise

Stepping up

Compliance without tears

Opening up

Assurance and confidence

Speeding up

Performance improvement

Selling up

Exit value, the ultimate return


Want to know if ISO 27001 is right for your business?

Book a free discovery call and we will establish where you are and what the path to certification actually involves.

Our Services:

Our sectors of expertise: