Skip to main content

INFORMATION SECURITY, GUIDED

ISO 27001 Guided.

£7,000 + VAT, fixed. Single entity, roughly fifty people or fewer in scope, and a named internal owner. Goldline builds the management system and directs the work. Your team executes it. The same standard as a full Sprint, because you are doing the half that does not need a practitioner.

Who this is for

You have a customer asking for ISO 27001 and an engineering team with capacity. You do not need somebody to collect your evidence and you are not going to pay senior practitioner rates for somebody to do it. What you need is the part you cannot get from a template: a scope boundary your buyers will actually accept, a Statement of Applicability that survives an auditor, a risk methodology that is yours rather than a sample, and somebody who tells you when what you have built will not pass.

Who this is not for

If nobody internally owns this, Guided will fail and it will cost you more than the Sprint would have. The programme runs on your team's hours. Before it starts we agree who owns it and how many hours they genuinely have, and if the answer is nobody we will say so and recommend the Sprint instead.

What Goldline builds

  • Scope boundary and Statement of Applicability
  • Risk methodology and the first risk assessment
  • The policy and procedure set, written to your operating model
  • Gap register with a named owner and a date on every line
  • Review and written correction of everything your team produces

What your team does

  • Populates the documents with your operational detail
  • Collects and uploads evidence
  • Implements and operates the controls
  • Attends a regular 90 minute working session

What this requires from you

A named internal owner, and 40 to 60 hours of your team's time across the engagement. Leadership available to approve policies and sit the management review. Access to the people who actually operate the controls.

Eligibility

Single legal entity. One site or cloud hosted. Under approximately 50 people. One product or service in scope. Above any of those, the engagement is a Sprint and is priced accordingly.

What is not included

  • Control implementation and configuration changes to your environment
  • Evidence collection
  • The clause 9.2 internal audit. Where Goldline has built your management system, the internal audit must be run independently and cannot be run by us. We tell you exactly what it has to cover. Budget separately for it.
  • Certification body audit fees, paid directly to the certification body
  • Stage 2 attendance, available separately as audit defence

You do not need a compliance platform

Drata, Vanta, Sprinto and the rest automate evidence collection well. They do not define your scope, run your risk assessment, write your Statement of Applicability or sit in front of an auditor. On a single entity under fifty people, a maintained spreadsheet meets the standard, and adding a platform subscription to a £7,000 engagement can double what you spend in year one.

Goldline is a partner across Drata, Thoropass and Sprinto and will deliver on any of them if you already run one or want one. It is not a condition of this engagement and we will tell you plainly when it is not worth the money.

WHO OWNS WHAT

Four phases, and who owns each one.

Guided runs on the Plan, Do, Check, Act cycle, delivered against a PECB Lead Implementer methodology. Goldline sets the direction and holds the standard. Your team does the build. The bar on each phase shows how the effort actually splits, and the accountable owner never moves. Phases are sequenced, not timed: a small single-entity scope can move through them considerably faster than twelve weeks.

  • Goldline directs, reviews and holds the standard
  • Your team builds, decides and evidences
  • Neither of us. Independent by requirement

SCROLL RIGHT TO FOLLOW THE PHASES →

PHASE 01 · PLAN

Set the boundary and the risk position

WHAT GETS PRODUCED

  • Scope and boundary, with interfaces named4.3
  • Interested parties and their requirements4.2
  • Information security policy, approved5.2
  • Risk assessment and treatment methodology6.1.2
  • Statement of Applicability, all 93 controls6.1.3 d
  • Measurable objectives and the plan to reach them6.2
GOLDLINE 70%YOU 30%

ACCOUNTABLE
Your top management. Scope and risk appetite are decisions only you can take.

PHASE 02 · DO

Build it and run it for real

WHAT GETS PRODUCED

  • Risk treatment plan with named owners6.1.3
  • Asset inventory and classificationA.5.9, A.5.12
  • Access control, joiners movers leaversA.5.15 to A.5.18
  • Supplier and cloud requirements, in contractA.5.19 to A.5.23
  • Incident management and business continuityA.5.24 to A.5.30
  • Awareness, competence and records7.2, 7.3, 7.5
GOLDLINE 25%YOU 75%

ACCOUNTABLE
Your named ISMS owner. This is the phase that sets the pace of the whole engagement.

PHASE 03 · CHECK

Prove it works, in front of someone

WHAT GETS PRODUCED

  • Monitoring and measurement results9.1
  • Internal audit across the whole ISMS9.2
  • Management review, minuted, with the required inputs9.3
  • Evidence pack assembled against the SoA
GOLDLINE 30%YOU 70%

Not Goldline. Clause 9.2 requires the internal audit to be independent of the work being audited. Goldline directed this build, so Goldline does not audit it. We hold a network of independent, credentialled auditors and will introduce one, or brief a competent person inside your own organisation to do it properly.

PHASE 04 · ACT

Close the findings and keep it alive

WHAT GETS PRODUCED

  • Nonconformities logged, with root cause10.2
  • Corrective actions closed and evidenced10.2
  • Continual improvement record10.1
  • Stage 1 readiness confirmed and the audit booked
  • Handover: the operating calendar
GOLDLINE 40%YOU 60%

ACCOUNTABLE
Your named ISMS owner. At handover the system is yours to run, and the operating calendar tells you how.

NEITHER OF US

Stage 1 and Stage 2 belong to your certification body

The certificate is issued by an accredited certification body, not by Goldline, and the audit is booked into their calendar. Their fee is paid to them direct and is separate from the £7,000, and carries no Goldline margin. Goldline is not a certification body and does not issue certificates, and will not sell implementation and certification to the same organisation for the same scope.

Why the split is the whole product

Guided is priced flat at £7,000 because the labour sits with you. If Goldline did the Do phase as well, that is a Sprint and it prices from £14,000. The qualifying test is a single entity, roughly fifty people or fewer inside the scope, and a named internal owner with the time to do the Do phase. Without that owner the split above does not hold, and the honest answer is a Sprint rather than a cheaper number. Pace is set by how fast your team can move through Phase 02, which is why the phases carry no fixed dates.

Delivered against the Plan, Do, Check, Act cycle by a PECB certified ISO/IEC 27001 Senior Lead Implementer. Every deliverable is keyed to a clause of ISO/IEC 27001:2022 or an Annex A control. Effort splits are typical for a Guided engagement and are confirmed at scoping.

Price

£7,000 + VAT, fixed, whatever your headcount inside the eligibility above. Single entity, roughly fifty people or fewer in scope, and a named internal owner. The ISO 27001 Readiness Assessment, from £1,950 + VAT, credits in full against this. This engagement credits in full against a subsequent Sprint if you decide part way through that you want it delivered rather than directed.

See the ISO 27001 Sprint

THE CHOICE

What you are actually choosing between

A consultant

Who does the work
Someone senior, billed by the day
What you get
Advice, and documents you then implement
Scope and Statement of Applicability
Usually included
Clause 9.2 internal audit
Only if independent of the build
Your team's time
Meetings, then the work lands with you
In the room at Stage 2
Depends on the engagement
Commercial shape
Day rate, open ended

A platform on its own

Who does the work
Your team, guided by the software
What you get
Evidence collection and continuous control monitoring
Scope and Statement of Applicability
Not produced. It records decisions only you can take
Clause 9.2 internal audit
Not performed. Software cannot audit itself
Your team's time
Substantial. The platform tracks tasks, it does not do them
In the room at Stage 2
No
Commercial shape
Annual licence

Goldline

Who does the work
The practitioner who scoped it, on a fixed scope
What you get
The management system, and the evidence to prove it operates
Scope and Statement of Applicability
Written and defended at audit
Clause 9.2 internal audit
Delivered independently, or an independent auditor introduced
Your team's time
A few hours a week during delivery
In the room at Stage 2
Yes
Commercial shape
Fixed scope, fixed fee, agreed before work starts

Certification body audit fees are billed separately and pass through at cost.

Already on a platform and not audit-ready?

TWO ROUTES

Two ways to get it done

ISO 27001 Guided

Who does the implementation
Your team, with direction
What you need to have
Engineers, and a named internal owner with time
Your team's time each week
Several hours
Scope and Statement of Applicability
Drafted with you
Policy framework
Templates plus review
Internal audit
Independent auditor introduced
Stage 2 attendance
Available
Best for
A team that has the people and wants the method

ISO 27001 Sprint

Who does the implementation
Goldline
What you need to have
A decision maker and access
Your team's time each week
A few hours
Scope and Statement of Applicability
Written for you
Policy framework
Written for your operating environment
Internal audit
Independent auditor introduced
Stage 2 attendance
Included
Best for
A team whose people are building the product

When to choose ISO 27001 Guided: you have engineers and a named internal owner with the time, and you want to come out of it understanding the management system well enough to run it yourselves.

When to choose the ISO 27001 Sprint: your team is building the product and cannot carve the time out, and you would rather the work sat with the practitioner.

Both routes deliver the same management system. The difference is who does the work and how much of your week it costs.

See what each route costs

Frequently asked

ISO 27001 Guided.

We use cookies and similar technologies to measure how this site is used, to see which organisations visit, and to measure our advertising. If you accept, we load Plausible, Google Analytics and Google Ads, Microsoft Clarity, which records session replays, and Apollo. Nothing loads until you accept. Read our Cookies policy.