You build an information security management system (ISMS), document it, prove it works, then have a UKAS-accredited certification body (CB) audit it in two stages. Most small UK tech companies finish in three to six months. A founder doing it part-time alongside a day job can manage it in four months if the company has fewer than 20 people and a simple cloud stack.
The process below is what we walk founders through when they ask us to draw the path on the back of a napkin. It maps to the actual requirements in ISO/IEC 27001:2022 Clauses 4 through 10 and the audit process defined in ISO/IEC 17021-1 [1][2].
Get the standard and read it once
Buy a copy of ISO/IEC 27001:2022 from the BSI shop or iso.org for roughly £115 to £125 [5] — it is 30 pages, not 300, and you can read it in an afternoon. Pair it with ISO/IEC 27002:2022 if you want implementation guidance for the 93 Annex A controls, though that one is longer and more expensive.
Do not rely on blog summaries (including this one) as a substitute for the actual standard. Auditors assess you against the text, not the internet's paraphrase of it.
Define your scope
Clause 4.3 asks you to decide what is inside your ISMS and what is outside. For a 15-person SaaS company whose product runs on AWS and whose staff work from home, the scope is probably "the provision and operation of [Product] including supporting infrastructure, development, and corporate IT". Write it in one or two sentences.
The scope determines how long your audit takes. The wider you draw it, the more auditor days you need, and the more controls you have to justify. Keep it honest but do not make it broader than your actual operation.
Identify interested parties
Clause 4.2. List the people and organisations that care about your information security — customers, regulators (the ICO, if you process personal data), employees, investors, suppliers — and write down what they expect from you. Half a page is enough.
Run a risk assessment
Clause 6.1.2 requires a risk assessment methodology, and most people overcomplicate it. You need a way to identify information security risks, assess their likelihood and impact, and decide what to do about each one — a spreadsheet with 15 to 40 rows is normal for a small company, while a risk register with 300 rows means nobody is making decisions.
Pick a method (asset-based, scenario-based, or a hybrid), document it, and then actually do it. The output feeds directly into your Statement of Applicability (SoA) and your risk treatment plan.
Write the Statement of Applicability
The SoA is a table of all 93 Annex A controls with a column for "applicable or not" and your justification either way [5]. It is the single most important document in your ISMS, because it is the document the auditor checks everything else against.
We once opened a Stage 2 with a client whose SoA listed 114 controls against the 2022 standard, which only has 93. That is a bad start to a Tuesday. Make sure you are working from the current Annex A, not the 2013 version.
Implement the controls
This is where the actual work is, though for a cloud-native company most of the 93 controls map to things you are probably already doing — access control, encryption in transit, vulnerability management, onboarding checklists, laptop encryption — and the gap is usually documentation, not practice.
Write the policies and procedures you need. The mandatory documents are fewer than people think: an information security policy, risk assessment and treatment documentation, the SoA, and records of your internal audit, management review, and corrective actions. Beyond that, write what is proportionate. A 40-page access control policy that nobody reads is worse than two paragraphs in your acceptable use policy.
Internal audit
Clause 9.2. Before your CB arrives, you need to audit yourself — the internal audit checks whether you are doing what your ISMS says you are doing, and you can do it in-house (provided the auditor is independent of the area being audited) or hire someone.
A common mistake is treating the internal audit as a box to tick the week before the external audit — give yourself time to find things and fix them, because that is the point.
Management review
Clause 9.3. Your leadership team reviews the ISMS at least once — the results of the risk assessment, the internal audit findings, any incidents, metrics, and whether the whole thing is working — and writes up the minutes, which is one of the first things a Stage 1 auditor asks for.
Choose a UKAS-accredited certification body
In the UK, a credible ISO 27001 certificate comes from a CB accredited by UKAS (the United Kingdom Accreditation Service), which is the national accreditation body recognised by the IAF [3]. You can check a CB's accreditation status on the UKAS website.
Some non-accredited outfits will sell you a certificate for less. That certificate is worth exactly what your customer's procurement team decides it is worth, which in our experience is not much. Enterprise buyers and regulated industries almost always require UKAS (or equivalent IAF MLA) accreditation.
Get quotes from two or three CBs — fees vary by the size of your scope and the number of auditor days required, which are guided by the IAF MD 5 tables [4]. For a small tech company, expect certification body fees of £4,000 to £12,000 for the initial three-year cycle (Stage 1, Stage 2, and two surveillance audits). At Calibre, we scope in hours rather than weeks and publish our pricing on request.
Stage 1 audit (documentation review)
The Stage 1 is a readiness check. The auditor reviews your documentation, confirms your scope makes sense, checks that your risk assessment produced a coherent SoA, and looks at whether the mandatory processes (internal audit, management review) have actually happened. It is usually done remotely and takes half a day to a full day for a small company.
If the auditor finds something missing, they will raise it and give you time to fix it before Stage 2. A Stage 1 finding is not a failure, it is the system working as intended.
Think of it as the theory test before the practical.
Stage 2 audit (implementation audit)
This is the real audit. The auditor comes (on-site, remotely, or a mix) and checks whether your ISMS is actually implemented and effective. They sample controls, interview staff, look at evidence, and verify that what your documents say matches what your organisation does.
Stage 2 usually happens four to eight weeks after Stage 1 and takes one to two days for a small company. The auditor will raise any nonconformities (major or minor) and opportunities for improvement (OFIs): a major nonconformity means a fundamental gap that you will need to fix, with evidence, before the certificate is issued, while a minor means something is not quite right but the system broadly works. OFIs are suggestions, not requirements.
Certificate issued
If Stage 2 goes well (no open major nonconformities), the CB issues your ISO 27001 certificate. It is valid for three years, subject to annual surveillance audits in years one and two, and a full recertification audit in year three.
The certificate is not a trophy you put on the shelf. It means your ISMS is a living system, and you need to keep running it: risk reviews, internal audits, management reviews, corrective actions when things go wrong, and continual improvement. The surveillance audits check that you are still doing it, not just that you did it once.
A realistic timeline
| Phase | Time (small UK tech company) |
|---|---|
| Read the standard and plan | 1-2 weeks |
| Scope, risk assessment, SoA | 2-4 weeks |
| Implement controls and write policies | 4-8 weeks |
| Internal audit and management review | 1-2 weeks |
| Stage 1 audit | Half day to 1 day |
| Gap between Stage 1 and Stage 2 | 4-8 weeks |
| Stage 2 audit | 1-2 days |
| Certificate decision | 1-2 weeks after Stage 2 |
Total: roughly three to six months. A determined founder with a simple business can compress it to eight weeks. A 200-person company with legacy infrastructure and multiple offices should plan for six to twelve months.
FAQ
No. Plenty of companies do it themselves, especially smaller ones with technically capable teams. A consultant can save you time and help you avoid common mistakes, but the standard does not require one. Just remember that your CB cannot also be your consultant, as that is an impartiality breach under ISO/IEC 17021-1 [2]. If you do hire a consultant, expect to pay £800 to £1,500 per day.
Three to six months for a small UK tech company doing it properly. We have seen it done in six weeks by a very focused team, and we have seen it take 18 months at a company that kept starting and stopping.
No. The transition deadline was 31 October 2025 [6]. Any remaining 2013 certificates are now void. New certifications must be against ISO/IEC 27001:2022.
UKAS accreditation means the CB itself has been audited and found competent by the UK's national accreditation body, which is recognised internationally through the IAF Multilateral Recognition Arrangement [3]. A non-accredited certificate has no independent oversight of the auditor's competence or process.
No. Cyber Essentials is a UK government-backed scheme focused on five basic technical controls. ISO 27001 is an international management system standard covering organisational, people, physical, and technological controls across 93 Annex A items. They complement each other, but ISO 27001 is significantly broader.
Sources
- 1.ISO/IEC. (2022). "ISO/IEC 27001:2022 Information security, cybersecurity and privacy protection - Information security management systems - Requirements". https://www.iso.org/standard/27001
- 2.ISO/IEC. (2015). "ISO/IEC 17021-1:2015 Conformity assessment - Requirements for bodies providing audit and certification of management systems". https://www.iso.org/standard/61651.html
- 3.UKAS. (2026). "About UKAS". https://www.ukas.com/about/
- 4.International Accreditation Forum. (2023). "IAF MD 5:2023 Determination of Audit Time of Quality, Environmental, and Occupational Health & Safety Management Systems". https://iaf.nu/en/iaf-documents/
- 5.ISO/IEC. (2022). "ISO/IEC 27002:2022 Information security, cybersecurity and privacy protection - Information security controls". https://www.iso.org/standard/75652.html
- 6.International Accreditation Forum. (2023). "IAF Resolution 2023-17: Transition to ISO/IEC 27001:2022". https://iaf.nu/en/iaf-resolutions/
- 7.Department for Science, Innovation and Technology. (2026). "Cyber Security Breaches Survey 2025/2026". GOV.UK. https://www.gov.uk/government/statistics/cyber-security-breaches-survey-20252026

