Our ISO 27001 products and services are designed to simplify certification, strengthen your information security, and support ongoing compliance for any organisation.
ISO 27001 Compliance
and Certification Support
All the expert support you need to plan, implement and maintain
an ISO 27001-compliant ISMS (information security management system)
Trusted by 7,600+ organisations worldwide
Trusted by teams including
In plain terms
What is ISO 27001?
ISO 27001 is the international standard for information security management, setting out the requirements for a risk-based ISMS covering organisational, people, physical and technological controls. We support you in building, implementing and certifying your ISMS to this standard, plus helping you continually improve it.

Benefits of ISO 27001 certification
Mitigate security risks
ISO 27001 provides a structured framework for identifying, evaluating and reducing information security risks, helping organisations protect sensitive data from threats.
Win bigger contracts
Many enterprise buyers now require ISO 27001 as a condition of doing business, using it to shortlist suppliers before a conversation even starts. Certification removes that barrier, opening the door to larger contracts and procurement processes that would otherwise be closed to you.
Simplify legal and regulatory compliance
ISO 27001 helps you meet the requirements of data protection laws and industry regulations by implementing risk-based, documented security controls.
How we tackle ISO 27001, step by step
The methodology we have refined over 20 years and more than 800 implementations, applied to whichever standard or regulation you are working towards.
Swipe to see the full approach
01
Project mandate and plan
Every implementation starts with a project leader and a mandate: what you want to achieve, how long it should take, who at the top is backing it and what resources it needs. We then turn that mandate into information security objectives, a project risk register, a plan and a team drawn from across the business.
What happens
- Project leader appointed and the mandate agreed with top management
- Information security objectives and a project risk register in place
- Project plan, responsibilities and RACI matrix agreed with your team
Output: project mandate, implementation plan and project risk register
02
ISMS initiation
A management system is driven by its policies and procedures, so we set the documentation structure up properly from the start: policies at the top, then procedures, work instructions and the records that prove you follow them. We also agree how the ISMS will keep improving once it is running.
What happens
- Four-tier structure of policies, procedures, work instructions and records
- Version control, approval routes and communication agreed
- Continual improvement method selected and built in
Output: documentation structure and continual improvement approach
03
Management framework and baseline
Clauses 4 and 5 set the groundwork. We formalise the internal and external issues affecting your ISMS, the interested parties it has to satisfy and, above all, its scope. Too narrow and information is left exposed; too wide and the system becomes unmanageable. We then record the security practices you already run as your baseline.
What happens
- Internal and external issues and interested parties identified
- ISMS scope agreed and the top-level policy signed off by top management
- Baseline security criteria set against the controls you already run
Output: scope statement, information security policy and baseline criteria
04
Risk management
Risk management sits at the heart of the ISMS. We build a repeatable methodology so that repeated assessments give consistent, comparable results, then work through identification, analysis and evaluation with the people who own the risks. Anything outside your appetite gets a treatment decision: modify, share, avoid or retain.
What happens
- Risk criteria, acceptance levels and methodology agreed
- Risks identified, analysed and evaluated with named owners
- Treatment decisions mapped to Annex A in your Statement of Applicability
Output: risk assessment, risk treatment plan and Statement of Applicability
05
Implementation
Now the ISMS processes and the risk treatment plan go live. We help you build the processes, put the controls in place and document them, then make sure the people running them are competent to do so. Staff are usually an organisation's weakest point, so awareness runs alongside the technical work rather than after it.
What happens
- ISMS processes and risk treatment plan put into operation
- Controls documented in policies, procedures and records
- Role-specific competence and organisation-wide awareness training delivered
Output: operating controls, updated documentation and training records
06
Review and certification
An ISMS only counts if it meets your objectives, so we agree metrics that produce comparable results, run internal audits across the whole system and take the findings to management review. With that evidence behind you, we prepare you for an accredited certification body and stay alongside you for surveillance.
What happens
- Performance measured against your information security objectives
- Internal audit programme run and nonconformities tracked to closure
- Management review held, then certification with an accredited body
Output: audit and review records, certification and a continual improvement cycle

Why choose GRC Solutions?
What our customers say
Having [GRC Solutions] on hand to guide our swift adoption of the ISO 27001 standard and provide ongoing expert support has been invaluable. They really understood the needs of a technology enterprise like ours.””
On behalf of myself and colleagues, a sincere thank you for all your input helping us achieve certification to the ISO 27001 standard. Here we are, just 6 months after we started the project and the outcome has been described by the auditor as ‘a delight to audit.”
I would have no hesitation in recommending [GRC Solutions] to others. The main advantage was their flexibility. [GRC Solutions] tailored their services, (whether it be training or consultancy) to our specific needs. ”
We brought [GRC Solutions] in to get Avayler through ISO 27001 certification, and they delivered a first-time pass with zero non-conformities: no small thing on a first attempt. What's kept us working with them for two years since is the consistency: their internal audits are thorough and genuinely challenging, which is exactly what you want from an auditor.”
View our top ISO 27001 picks
Certified ISO 27001:2022 ISMS Foundation Training Course
Information Security & ISO27001 Staff Awareness Course
ISO 27001 Toolkit
ISO 27001:2022 Gap Analysis Tool
ISO/IEC 27001 2022 Standard
ISO/IEC 27001:2022 – An introduction to information security and the ISMS standard
Works well alongside
Most of the evidence and policy work below carries over, so a second framework rarely means starting from zero.
Cyber Essentials
A lighter baseline many clients hold alongside ISO 27001 for government and supply chain work.
Learn more about Cyber EssentialsSOC 2
Shares most of its control set with ISO 27001, so it is useful if you sell into the US market.
Learn more about SOC 2Data Privacy & GDPR
Your ISMS risk register and policies map directly onto GDPR's accountability requirements.
Learn more about data privacy and GDPR
Get expert support for your ISO 27001 project
✅ ISO 27001 gap analysis and readiness assessment
✅ ISMS design, documentation and implementation
✅ Risk assessment and Annex A control selection
✅ Internal audits, training and certification support
ISO 27001 certification FAQ
Any organisation that needs to demonstrate effective information security should consider ISO 27001 certification. It is often a requirement for government contracts, and many organisations require ISO 27001 certification before engaging a supplier. Even where certification is not a formal requirement, it sets organisations apart from their competitors, proving that they take information security seriously.
GRC Solutions sells the latest version of the ISO 27001 and ISO 27002 standards, along with a wide range of support services from implementation to ongoing assurance.
The cost of the certification process will vary depending on the certification body you choose. The cost of implementing ISO 27001 largely depends on the size of your organisation, how mature your existing information security measures are, and how much support you need to achieve certification.
The amount of time it takes to implement ISO 27001 will depend on the size of your organisation and your existing information security and governance measures. Most small-to-medium enterprises (SMEs) can achieve certification within six months if backed by expert support. Larger organisations often already have a formal information security programme of some kind, and so can generally expect to achieve certification within one year.
An ISO 27001 information security management system (ISMS) is a structured, risk-based system for managing information security risk and protecting the confidentiality, integrity and availability of the information held by an organisation. Accredited ISO 27001 certification is internationally recognised as a marker of information security best practice.
Cyber Essentials is a UK-government led security scheme focused on five core controls that mitigate common cyber security risks. It is available in two different levels of assurance – Cyber Essentials, which is based on a self-assessment questionnaire, and Cyber Essentials Plus, which requires an external vulnerability assessment. While effective at ensuring a basic level of security, it does not provide a framework for managing information security risk across an organisation and is only recognised in the UK. It is a prerequisite for some UK government contracts.
Cyber Essentials is ideal for smaller UK organisations that need to demonstrate a basic level of cyber security or that are planning to tender for UK government contracts. ISO 27001 is suited to organisations looking to develop a structured, formal system for information security management.
ISO 27001 provides a structured approach to managing information security risk and protecting the confidentiality, integrity and availability of the information an organisation holds.
SOC 2 is used by service organisations to demonstrate the security, integrity and availability of their systems, and demonstrate compliance with the AICPA’s Trust Services Criteria (TSC).
ISO 27001 is ideal for organisations looking to develop a structured, formal system for information security management, and can support compliance with SOC 2’s security-focused TSC. SOC 2 is only suitable for service organisations that need to demonstrate compliance with the TSC.
Accredited ISO 27001 certification lasts for three years. As your certificate nears expiration, you can undergo a recertification audit to renew your certification for a further three years.