DIAGNOSE
Establish your ISO 27001 position before you commit to a programme.
A fixed-scope diagnostic covering your current information security posture against ISO 27001:2022, the scope you would certify, and what closing the gap actually requires. For organisations whose enterprise pipeline or supervisory review has surfaced ISO 27001 as the gate.
From £1,950 + VAT
THE ENGAGEMENT
Scope and evidence, tested before the programme starts.
Organisations routinely underestimate ISO 27001 scope and overestimate how much of their existing documentation will survive an audit. Both errors are expensive. Scope set too wide inflates the programme and the audit fee; documentation assumed to be adequate is often rewritten under time pressure weeks before Stage 2.
The assessment tests both. We work through the Annex A controls against how your organisation actually operates, propose the ISMS scope you would certify and the reasoning behind it, and read your existing policies, registers, and records against the standard a certification body applies. Findings carry severity ratings so remediation can be sequenced rather than attempted all at once.
You finish with a defensible view of the work in front of you and an indicative certification timeline based on your real starting position. Where you proceed, the fee credits in full against a subsequent ISO 27001 Sprint.
DELIVERABLES
What you receive.
Gap analysis against ISO 27001:2022 Annex A controls
Proposed ISMS scope and Statement of Applicability outline
Assessment of existing documentation against audit standard
Findings report with severity ratings
Prioritised remediation roadmap with indicative effort
Indicative certification timeline based on your starting position
FIT
Who this is for.
- An enterprise deal is paused on ISO 27001 and you need a credible date to give the buyer.
- Supply chain or supervisory pressure has made certification a requirement rather than an ambition.
- You are deciding between ISO 27001 and SOC 2 and want the decision evidenced against your buyer base.
This is not for organisations that have already completed a recent, credible gap analysis and simply need implementation. In that case the Sprint is the right starting point and the assessment would repeat work you have already paid for.
WHAT COMES NEXT
Where organisations go from here.
Once scope and the gap are settled, implementation follows directly. The roadmap from the assessment becomes the plan for the Sprint, and the assessment fee credits in full against it.
IMPLEMENTATION
ISO 27001 Sprint
Full information security management system implementation, Statement of Applicability, and certification body coordination. Fixed scope, timeline agreed at scoping.
Explore the ISO 27001 SprintASSURE
Pre-Certification Readiness Audit
Already implemented and heading for audit? A mock audit against Stage 1 and Stage 2 criteria, with findings before the certification body raises them.
Explore the readiness auditQUESTIONS
Common questions.
Establish the position.
A 45 minute scoping call establishes your likely ISMS scope, the right size of assessment, and the price. No sales pitch. If you are already past the point where an assessment adds value, we will tell you.
Prefer email? Write to info@goldlineconsultancy.co.uk.
