Everything you need to know about ISO 27001

Following the Jaguar Land Rover cyberattack back in 2025 (estimated to be the most damaging cyberattack in British history) more companies are understanding the importance of certification around Cyber Security, not only for their own peace of mind but for securing future investment.

While not created by the UK Government, ISO 27001 strictly aligns with recent legislation, is now recommended by the National Cyber Security Centre (NCSC) and is increasingly becoming a requirement for public-sector and corporate contracts.

Below, our Head of Service Delivery, Andy Potkins explains everything you need to know about this essential certification.

To find out more and how we could help you to gain certification contact us today.

What is ISO 27001 Certification?

ISO 27001 is the globally recognized protocol for Information Security Management Systems (ISMS). Achieving certification means an independent, third-party auditor has verified that your organisation's security practices meet the standard's rigorous requirements.

It ensures companies are protected and equipped to:

  • Manage information security risks.

  • Protect against sensitive data breaches (such as customer and employee records).

  • Comply with legal requirements like GDPR.

How do businesses get ISO 27001?

Gaining certification is not a tick-box exercise; it requires whole-business buy-in and evidence that your policies match your daily operations. The process involves reviewing and refining existing policies, identifying gaps, and assessing risk to determine which of the 92 Annex A controls are needed. And once certification is achieved, it doesn’t end there. Ongoing audits mean you need to embed good practice into day-to-day operations. ISO 27001 is as much about long-term cultural maturity as it is about passing an audit.

The process typically takes 9 to 12 months (though complex or larger enterprises may take up to 18 months).

Stage 1: Preparation and Implementation (2 to 9 Months)

  • Research & Risk Assessment: Understanding existing data/systems and uncovering potential security threats.

  • Implementation: Adding necessary security policies and technical controls (determining which of the 92 Annex A controls are needed).

  • Internal Audit: Trialing the ISMS for a 3-month period to gather data before the official audit.

Stage 2: Investigation and Certification (2 to 6 Months)

  • Documentation Review: An accredited body reviews all documentation, including the ISMS and the Statement of Applicability (SoA).

  • Main Audit: A rigorous investigation period involving testing systems and interviewing team members.

Key Benefits

  • Meets Rising Expectations: Larger organisations, supply chains, tenders, and cyber insurance providers increasingly demand robust security practices.

  • Drives Internal Clarity: Gives businesses a clearer view of how they operate, where risks lie, and how to mitigate them.

  • Builds Long-Term Maturity: Embeds good practice into day-to-day operations rather than just serving as a one-time test.

Is it Mandatory in the UK?

Currently, ISO 27001 is not a legal requirement in the UK. However, it is a prerequisite when it comes to competing for certain types of contracts;

  • Public Sector Work: Required by UK government departments and agencies handling sensitive data.

  • Regulated Industries: Strictly required in finance, healthcare, critical national infrastructure, nuclear, and professional services.

  • B2B & SaaS: Enforced by large B2B enterprises and SaaS providers as a strict condition to offset third-party supplier risk.

How SMEs can gain their ISO 27001 certification

We help small and medium-sized enterprises (SMEs) avoid the pitfall of "over-engineering" processes that do not work day-to-day. Having achieved the certification, ourselves with zero audit findings, our guidance is backed by real-world experience and CISSP (Certified Information Systems Security Professional) accreditation.

Our services include:

  • Initial gap analysis

  • Roadmap planning

  • Policy development

  • Technical controls implementation

  • Audit preparation

If you’re considering ISO 27001 or just want to understand what it might look like for your business, get in touch today.

Author biography

Andy Potkins, Head of Service Delivery, FACT3 | CISSP, FACT3

Previous
Previous

Myles’ challenge: month four - Lanzarote calling! Final prep for Race Day 

Next
Next

Myles’ challenge: month three - when the challenge gets real (and doubt creeps in)