Skip to main content
ISO 27001

ISO 27001 for UK Defence Suppliers: The Practical Guide

By Goldline Consultancy

11 min read

Contents

    UK defence primes are no longer asking whether their supply chain holds ISO 27001. They are asking when, which scope, and how you demonstrate ongoing compliance. If you supply into BAE Systems, MBDA, Thales, Leonardo, Babcock, Rolls-Royce, or the MOD directly, you have either answered this question already or you will answer it inside the next twelve months.

    This guide is for Tier 2 and Tier 3 defence suppliers with between twenty and two hundred and fifty employees. It assumes you already hold Cyber Essentials Plus, because that is where most of the market sits today. It covers what prime contractors are actually asking, how JOSCAR evaluates the evidence, how to budget and plan an implementation from a CE Plus baseline, and the traps that turn a twelve-week engagement into a twelve-month one.

    Why primes are mandating ISO 27001 now

    Three forces have converged over the last eighteen months.

    The first is flow-down contract language. Defence primes are receiving increasingly specific security obligations from the MOD via DEFCON clauses, particularly DEFCON 658 for cyber, and they are passing those obligations down to their supply chain with a fidelity they did not five years ago. ISO 27001:2022 certification is one of the clearest ways a prime can evidence that their subcontractors are operating within a recognised information security management system, and they are asking for it accordingly.

    The second is JOSCAR. The Joint Supply Chain Accreditation Register operated by Hellios on behalf of the UK defence and aerospace sector is where primes look first when assessing supply chain risk. JOSCAR assessors have adjusted their scoring to give meaningful weight to ISO 27001 certification above and beyond Cyber Essentials Plus. A JOSCAR reassessment that downgrades a supplier for lacking ISO 27001 closes doors at the next bid cycle.

    The third is the incoming UK Cyber Security and Resilience Bill. The Bill will impose higher baseline cyber obligations on operators of essential services and their supply chains, with enforcement powers that exceed NIS 2018. Defence supply chain organisations sit within scope by virtue of the sectors they serve. Holding ISO 27001 ahead of Bill implementation positions a supplier as already having done the structural work the Bill will demand.

    None of these forces are temporary. The direction of travel is toward more compliance, not less, and earlier demonstration of it, not later.

    What primes actually ask for

    The common misconception is that primes want an ISO 27001 certificate. What they actually want is evidence that the certificate means something in your specific operating context.

    A prime's supplier assurance team will typically ask for four things.

    They ask for the certificate itself, with scope statement clearly visible. A certificate scoped to "UK headquarters only" when the relevant contract work happens at a satellite site is grounds for rejection. The scope must match the work.

    They ask for your Statement of Applicability. This single document tells them which of the ninety-three Annex A controls you have selected as applicable, which you have excluded, and why. Primes' assurance teams read this carefully. Excluding supplier management (A.5.19) while simultaneously holding a subcontracting-heavy contract raises questions immediately.

    They ask for evidence of internal audit and management review. ISO 27001 is a management system standard, not a control checklist. The primes know this. They want to see that you are auditing yourself regularly and that your senior leadership is reviewing the output of those audits. A certificate without a functioning management review cycle is a certificate held in name only.

    They ask for your last surveillance audit report. This is the continuous-assurance test. A three-year-old certificate with no surveillance audit evidence signals a dormant ISMS. Primes factor that into their scoring.

    A certificate without a functioning management review cycle is a certificate held in name only. Primes read the Statement of Applicability carefully, and they score surveillance audit activity, not just the certificate.

    How JOSCAR evaluates the evidence

    JOSCAR's cyber assessment is scored by Hellios's assessors against a documented rubric. ISO 27001 evidence feeds specific sections of that rubric, and the scoring is not binary.

    An organisation with ISO 27001:2022 certification scoped to the full business, evidence of annual internal audit, a management review held in the last twelve months, and no significant non-conformities at last surveillance will score highly. An organisation with a certificate scoped to a single department, no visible management review cycle, and a two-year gap since the last audit will score materially lower even while technically certified.

    The practical implication is that certification alone is not the goal. A certificate achieved through a rushed implementation, with thin documentation and minimal management engagement, will pass a JOSCAR reassessment poorly. A certificate achieved through a properly structured implementation, with genuine management engagement and documented audit evidence, will score well and continue to score well.

    This is one of the reasons open-ended ISO 27001 consultancy engagements work badly for defence suppliers. If the engagement ends at certification, the ongoing rhythm required to maintain a credible ISMS is not established, and the JOSCAR scoring suffers at the first reassessment.

    Building from a Cyber Essentials Plus baseline

    Most Tier 2 and Tier 3 defence suppliers already hold Cyber Essentials Plus. This is the right starting position. A meaningful share of the technical controls ISO 27001 expects are already implemented and evidenced.

    The overlap is real. Access control, patch management, malware protection, secure configuration, and boundary protection are foundational to both frameworks. For organisations with a functioning CE Plus programme, those controls are already in place and documented.

    What CE Plus does not provide is the management system layer. ISO 27001 requires a documented risk assessment framework, a Statement of Applicability justifying every Annex A control decision, a supplier management process, an incident response plan tested through exercise, business continuity and disaster recovery capability, an internal audit programme, a management review cycle, and a staff awareness programme. None of these are CE Plus concerns.

    The gap is not starting from zero. It is formalising what exists into a management system that meets ISO 27001's governance and continual improvement requirements. For most organisations with CE Plus in place, this is six to twelve weeks of structured work, not the six to twelve months typical of starting from scratch. A realistic comparison between the two standards is covered in ISO 27001 vs Cyber Essentials Plus: What Really Differs.

    Scoping the implementation correctly

    The single most expensive mistake defence suppliers make on ISO 27001 is scoping badly at day one.

    Too narrow a scope, say a specific department or only the head office, saves implementation cost but creates two downstream problems. The first is that primes reject narrow scopes that do not cover the business unit doing the contract work. The second is that JOSCAR assessors score narrow scopes lower. A certificate achieved on a saved budget that fails its first commercial test was money saved badly.

    Too broad a scope, the entire organisation, all sites, all business units, multiplies implementation cost without always adding commercial value. A defence subcontracting business with a civil engineering division that never touches defence work does not need the civil division in scope. Adding it inflates the implementation, the surveillance audits, and the ongoing management overhead.

    The right scope is the scope your buyer asks for, plus a modest margin for realistic growth. If primes are asking for ISO 27001 certification covering your defence work and the shared IT infrastructure supporting that work, scope to that. Do not under-scope to save money. Do not over-scope to look comprehensive.

    A good gap assessment on day one establishes the right scope before any implementation effort begins. Changing scope mid-implementation adds cost and time and risks re-scoping surveillance audits later.

    What a realistic implementation timeline looks like

    For a Tier 2 or Tier 3 defence supplier with twenty to two hundred and fifty employees, holding Cyber Essentials Plus, with a scope calibrated to their actual defence work, a realistic timeline looks like this.

    Weeks one to three: gap assessment. Current-state review against ISO 27001:2022 clauses four through ten and Annex A, mapped against existing CE Plus posture. Prioritised remediation roadmap. Scope confirmation. Fixed price for implementation phase.

    Weeks four to sixteen: ISMS implementation. Policy set authored and approved. Risk assessment framework operational, with risk register, treatment plan, and Statement of Applicability signed off. Supplier management framework in place. Incident response plan documented and tested through tabletop exercise. Business continuity and disaster recovery frameworks documented. Internal audit programme launched with first internal audit completed. Management review cycle established, with first management review held. Staff awareness programme rolled out.

    Weeks sixteen to twenty: Stage 1 audit preparation. External auditor engaged. Stage 1 audit held, typically a documentation review. Any findings addressed before Stage 2.

    Weeks twenty to twenty-four: Stage 2 audit and certification. Stage 2 audit held, the main evidential audit. Any non-conformities addressed. Certificate issued.

    This is a compressed schedule. It assumes executive commitment, reasonable availability of documentation, and an implementation led by someone with genuine ISO 27001 delivery experience. It assumes nothing unusual in your operating context, no multi-site complexity, no overseas entities, no active incident response that consumes internal bandwidth. Where complexity exists, add weeks honestly at the start rather than discovering them at week eight.

    Ongoing compliance after certification

    The certificate is the start of ongoing assurance, not the end of it.

    Surveillance audits happen annually. Your certification body visits, reviews evidence that the ISMS has remained operational since the last audit, and looks specifically at the management review cycle, the internal audit programme, risk treatment progress, and any incidents. Non-conformities at surveillance audit can suspend the certificate. A suspended certificate is a material commercial event for a defence supplier; it triggers prime contractor notifications and JOSCAR re-reviews.

    Recertification happens every three years. This is a full audit, equivalent in scope to the original Stage 2. The evidential burden is higher than surveillance and the risk of non-conformity is higher if the ISMS has drifted.

    Between audits, your ISMS must continue operating. Risk assessments updated when the business changes. Supplier reviews performed on new suppliers. Incident response plans tested at least annually. Internal audit covering the full scope on a rolling cycle. Management review held at a documented cadence. Staff awareness training refreshed.

    Organisations that treat ISO 27001 as a box-ticking exercise struggle at surveillance. Organisations that treat it as a management discipline, which is what the standard is designed to be, do not.

    Closing

    ISO 27001 is no longer optional for UK defence suppliers. The question is not whether you will hold it but when, at what scope, and how credibly you can evidence it when your primes and JOSCAR assessors test the certificate.

    The organisations getting this right scope realistically, build from their Cyber Essentials Plus baseline, implement with genuine management engagement, and treat the certificate as the start of an ongoing assurance cadence rather than a one-off project. The organisations getting it wrong rush to a narrow scope, build an ISMS on paper, and discover at first surveillance that a certificate and a functioning ISMS are different things.

    If you are preparing to scope an ISO 27001 implementation for your defence work and want a practitioner-led gap assessment before you commit to a timeline, we run scoped Phase 1 Gap Assessments for organisations in this position.

    Goldline Consultancy is led by an ISO 27001 Lead Implementer (PECB) and delivers ISO 27001 implementation as a fixed-scope engagement for UK defence supply chain and regulated organisations. Take our free ISMS maturity self-assessment or book a free 45 minute diagnostic.

    We use cookies and similar technologies to measure how this site is used, to see which organisations visit, and to measure our advertising. If you accept, we load Plausible, Google Analytics and Google Ads, Microsoft Clarity, which records session replays, and Apollo. Nothing loads until you accept. Read our Cookies policy.