Skip to main content

DIAGNOSE

Establish your ISO 27001 position before you commit to a programme.

A fixed-scope diagnostic covering your current information security posture against ISO 27001:2022, the scope you would certify, and what closing the gap actually requires. For organisations whose enterprise pipeline or supervisory review has surfaced ISO 27001 as the gate.

From £1,950 + VAT

ISO 42001 Lead Implementer (PECB)ISO 42001 Lead Auditor (PECB)ISO 27001 Senior Lead Implementer (PECB)ISO 27001 Lead Auditor (PECB)CISSP

THE ENGAGEMENT

Scope and evidence, tested before the programme starts.

Organisations routinely underestimate ISO 27001 scope and overestimate how much of their existing documentation will survive an audit. Both errors are expensive. Scope set too wide inflates the programme and the audit fee; documentation assumed to be adequate is often rewritten under time pressure weeks before Stage 2.

The assessment tests both. We work through the Annex A controls against how your organisation actually operates, propose the ISMS scope you would certify and the reasoning behind it, and read your existing policies, registers, and records against the standard a certification body applies. Findings carry severity ratings so remediation can be sequenced rather than attempted all at once.

You finish with a defensible view of the work in front of you and an indicative certification timeline based on your real starting position. Where you proceed, the fee credits in full against a subsequent ISO 27001 Sprint.

DELIVERABLES

What you receive.

01

Gap analysis against ISO 27001:2022 Annex A controls

02

Proposed ISMS scope and Statement of Applicability outline

03

Assessment of existing documentation against audit standard

04

Findings report with severity ratings

05

Prioritised remediation roadmap with indicative effort

06

Indicative certification timeline based on your starting position

FIT

Who this is for.

  • An enterprise deal is paused on ISO 27001 and you need a credible date to give the buyer.
  • Supply chain or supervisory pressure has made certification a requirement rather than an ambition.
  • You are deciding between ISO 27001 and SOC 2 and want the decision evidenced against your buyer base.

This is not for organisations that have already completed a recent, credible gap analysis and simply need implementation. In that case the Sprint is the right starting point and the assessment would repeat work you have already paid for.

QUESTIONS

Common questions.

Establish the position.

A 45 minute scoping call establishes your likely ISMS scope, the right size of assessment, and the price. No sales pitch. If you are already past the point where an assessment adds value, we will tell you.

Prefer email? Write to info@goldlineconsultancy.co.uk.

We use cookies and similar technologies to measure how this site is used, to see which organisations visit, and to measure our advertising. If you accept, we load Plausible, Google Analytics and Google Ads, Microsoft Clarity, which records session replays, and Apollo. Nothing loads until you accept. Read our Cookies policy.