Confidentiality
Sensitive information is accessible only to those authorised to see it.
HEIC takes organisations from wherever they are now to a certified ISMS — with a structured process, practical documentation, and consultants who stay with you through the audit.
Enterprise clients demand ISO 27001 before signing contracts. Public-sector buyers require it in tender submissions. Financial institutions need it to meet regulatory expectations. For any business handling sensitive client data, the question from prospects is no longer "do you take security seriously?" — it's "are you certified?"
The 2025 IBM Cost of a Data Breach Report puts the US average at a record USD 10.22 million, driven by steeper regulatory fines and rising detection costs. Of organisations that managed a full recovery, 76% took more than 100 days. Organisations using security AI and automation cut breach costs by USD 1.9 million and contained incidents 80 days faster.
ISO 27001 certification is how you prove to clients, partners, and regulators that your organisation manages these risks in a structured, internationally recognised way.
ISO/IEC 27001 is the leading international standard for information security management, recognised in over 150 countries. It defines how to build an Information Security Management System (ISMS) — the policies, procedures, and controls that govern how your organisation identifies and reduces information security risk.
An ISMS pulls together your policies, processes, and technical controls into a single system. The goal is to make information security a deliberate, ongoing part of how your business operates — not something that only gets attention after an incident.
The three principles at the core of ISO 27001:
Sensitive information is accessible only to those authorised to see it.
Data remains accurate and complete, and cannot be altered without proper authorisation.
The people who need access to information and systems can get it when they need it.
Certification means an accredited, independent audit body has reviewed your ISMS against the standard's requirements. If successful, you receive a certificate valid for three years, subject to annual surveillance audits.
The 2022 revision simplified the framework while adding modern security requirements:
| ISO 27001:2013 | ISO 27001:2022 | |
|---|---|---|
| Total controls | 114 | 93 |
| Structure | 14 domains | 4 themes — People, Organisational, Technological, Physical |
| New controls | — | 11 new — cloud, threat intelligence, data masking & more |
| Status | Expired | Current standard |
The 11 new controls address modern threats your organisation faces today:
Many enterprise buyers, public bodies, and financial institutions require ISO 27001 from suppliers. Without it, you don't make the shortlist. Several of our clients have told us certification paid for itself within months by unlocking a single large contract.
Security questionnaires from prospects can take weeks. A valid ISO 27001 certificate replaces most of that back-and-forth with a single internationally recognised proof point — and procurement teams know exactly what it means.
ISO 27001 controls overlap substantially with GDPR, the NIS 2 Directive, and DORA. Organisations that implement ISO 27001 first typically find that meeting these additional obligations takes a fraction of the effort.
A functioning ISMS forces you to think about risks before they materialise. Organisations with one catch problems earlier, respond faster, and recover sooner — because the processes and procedures are already documented and tested.
An independent audit finding is worth more than any marketing claim. Certification tells your clients that a qualified third party has reviewed your security practices — and that you've committed to maintaining them year on year.
Every organisation starts from a different place. Some have policies scattered across departments. Others are starting from scratch. We meet you where you are and run a structured implementation that reaches certification without unnecessary complexity.
We map your business, your information assets, and your current security practices. We define the ISMS scope — the parts of your organisation the certificate will cover — and run a gap analysis against the standard's requirements. You'll know exactly what already meets the standard and what needs work.
Want to see where you stand first?
Our free ISO 27001 Self-Assessment Tool lets you evaluate your current security posture against the standard's requirements. You'll get an instant score, a downloadable PDF report, and a basic Statement of Applicability, gap register, and remediation map. No registration required. Try the free assessment →
We identify your information assets, the threats they face, and the potential business impact. Every risk is assessed, documented, and assigned a treatment — a specific control, a process change, insurance, or formal acceptance.
We work with your team to implement the controls from the risk treatment plan and build the documentation the standard requires. We don't hand over generic templates. Every policy and procedure reflects how your organisation actually operates, so it stays practical to use and maintain after certification.
Before the external auditors arrive, we run a full internal audit at the same level of rigour a certification body would apply. We close any remaining gaps and prepare your team for the Stage 1 (documentation review) and Stage 2 (implementation audit) certification audits.
We've guided over 500 organisations through ISO 27001 and other management system certifications. We know what auditors look for, where implementations stall, and what separates an ISMS that passes an audit from one that actually works day-to-day.
A 30-person software company doesn't need the same ISMS as a 500-person financial institution, and we won't build one as if it does. Smaller organisations often find certification more achievable than they expect, precisely because the scope can be kept lean.
If a document exists only to satisfy an audit checkbox and nobody will ever read it, we find a better way to meet the requirement.
Our engagement doesn't end when the documentation is done. We prepare your team, run the internal audit, and remain available through the certification process to handle whatever comes up.
"HEIC LTD made the implementation of ISO 27001 easy and understandable. They explained everything clearly, guided us step by step, and we passed the audit with an excellent score. As a result, we now have a stable risk management framework and a stronger information security culture. The certificate itself helps us with our customers, as we work in a very conservative and demanding industry. I have already recommended HEIC LTD to colleagues from other companies."
ISO/IEC 27001 is the international standard for information security management. It provides a framework for establishing and maintaining an Information Security Management System (ISMS) — a structured system of policies, processes, and controls that helps organisations protect sensitive information. It applies to businesses of any size and in any industry.
An ISMS (Information Security Management System) is the documented system at the heart of ISO 27001. It covers how your organisation identifies information security risks, decides how to address them, implements the necessary controls, and monitors whether those controls are working. Think of it as the operating manual for how your business handles security — not just the technology, but the people and processes too.
ISO 27001:2022 is the current, in-force version of the standard released in October 2022, replacing the 2013 version. It introduced 11 new controls covering areas like cloud security, threat intelligence, data masking, and secure coding, and restructured Annex A from 114 controls to 93, organised into four categories. The transition deadline from the 2013 version passed in October 2025; all ISO 27001 certificates issued today are against the 2022 standard.
ISO 27001 compliance means your organisation meets all the applicable requirements defined in the standard covering your ISMS documentation, risk management processes, security controls, internal audits, and management reviews. The standard identifies mandatory requirements with the word "shall": if a clause says something shall be done, it must be done. Compliance is the foundation for certification, but without an independent audit, it remains self-declared. Certification from an accredited body provides the third-party verification that clients and regulators typically require.
It depends on your starting point. An organisation with some existing security policies and practices in place can typically reach certification in 3 to 6 months. Larger or more complex organisations, or those starting from scratch, may need 6 to 12 months. The timeline is most influenced by how quickly your team can implement changes and how much internal resource you can dedicate.
The total cost has three components: consulting fees, certification body audit fees, and internal staff time. Consulting fees vary with the size and complexity of your organisation and the scope of your ISMS. Certification body fees depend on the auditor and the scale of the engagement. For most small and medium-sized businesses, the total investment is substantially less than the cost of a single data breach, and for organisations where certification enables new contracts or satisfies a regulatory requirement, the return is typically measurable within the first year. Contact us for a cost estimate based on your situation.
Technically, no. The standard doesn't require you to use a consultant. In practice, most organisations — particularly those going through certification for the first time — find that expert guidance saves significant time and prevents costly mistakes. A consultant who has been through the process many times knows what auditors expect, where organisations typically struggle, and how to avoid the common pitfalls.
ISO 27001 is the standard you certify against. It defines the requirements for your ISMS. ISO 27002 is a companion guide that provides detailed implementation advice for the security controls listed in ISO 27001's Annex A. You cannot get certified against ISO 27002 — it's a reference document, not a certification standard.
Yes. Common reasons include incomplete risk assessments, missing documentation, controls that haven't been properly implemented, and teams that can't demonstrate how the ISMS works in practice. If the auditor identifies major nonconformities, you'll typically have 90 days to address them before a follow-up visit. This is precisely why we conduct a thorough internal audit before the certification body arrives — so that any issues are found and resolved in advance.
Three years. During that period, you'll undergo annual surveillance audits (shorter reviews to confirm the ISMS is being maintained). At the end of the three years, a full recertification audit is required to renew the certificate.
Yes. The standard is designed to scale. It doesn't prescribe a fixed set of controls that every organisation must implement regardless of size. Instead, you select the controls that are relevant to your specific risks and operations. A 15-person startup will end up with a leaner, simpler ISMS than a multinational bank, and that's exactly how it's meant to work. In practice, smaller organisations often find certification easier to achieve because there are fewer processes to document and fewer people to train. Many of our clients are small and medium-sized businesses that pursued certification to unlock enterprise contracts or meet regulatory requirements.
In most countries and sectors, ISO 27001 is not a legal requirement. However, it can become a practical requirement through client contracts, public procurement frameworks, or sector-specific regulations. Some European regulatory frameworks, including NIS 2 and DORA, require robust information security practices that ISO 27001 is well-positioned to satisfy. The most common driver we see is commercial: a client requires it as a condition of doing business.
Our team has guided over 500 organisations to certification. Tell us about your situation and we'll give you an honest assessment of what's involved.
We'll get back to you within one business day.