Guided runs on the Plan, Do, Check, Act cycle, delivered against a PECB Lead Implementer methodology. Goldline sets the direction and holds the standard. Your team does the build. The bar on each phase shows how the effort actually splits, and the accountable owner never moves. Phases are sequenced, not timed: a small single-entity scope can move through them considerably faster than twelve weeks.
- Goldline directs, reviews and holds the standard
- Your team builds, decides and evidences
- Neither of us. Independent by requirement
SCROLL RIGHT TO FOLLOW THE PHASES →
PPHASE 01 · PLAN
Set the boundary and the risk position
WHAT GETS PRODUCED
- Scope and boundary, with interfaces named4.3
- Interested parties and their requirements4.2
- Information security policy, approved5.2
- Risk assessment and treatment methodology6.1.2
- Statement of Applicability, all 93 controls6.1.3 d
- Measurable objectives and the plan to reach them6.2
GOLDLINE 70%YOU 30%
ACCOUNTABLE
Your top management. Scope and risk appetite are decisions only you can take.
DPHASE 02 · DO
Build it and run it for real
WHAT GETS PRODUCED
- Risk treatment plan with named owners6.1.3
- Asset inventory and classificationA.5.9, A.5.12
- Access control, joiners movers leaversA.5.15 to A.5.18
- Supplier and cloud requirements, in contractA.5.19 to A.5.23
- Incident management and business continuityA.5.24 to A.5.30
- Awareness, competence and records7.2, 7.3, 7.5
GOLDLINE 25%YOU 75%
ACCOUNTABLE
Your named ISMS owner. This is the phase that sets the pace of the whole engagement.
CPHASE 03 · CHECK
Prove it works, in front of someone
WHAT GETS PRODUCED
- Monitoring and measurement results9.1
- Internal audit across the whole ISMS9.2
- Management review, minuted, with the required inputs9.3
- Evidence pack assembled against the SoA
GOLDLINE 30%YOU 70%
Not Goldline. Clause 9.2 requires the internal audit to be independent of the work being audited. Goldline directed this build, so Goldline does not audit it. We hold a network of independent, credentialled auditors and will introduce one, or brief a competent person inside your own organisation to do it properly.
APHASE 04 · ACT
Close the findings and keep it alive
WHAT GETS PRODUCED
- Nonconformities logged, with root cause10.2
- Corrective actions closed and evidenced10.2
- Continual improvement record10.1
- Stage 1 readiness confirmed and the audit booked
- Handover: the operating calendar
GOLDLINE 40%YOU 60%
ACCOUNTABLE
Your named ISMS owner. At handover the system is yours to run, and the operating calendar tells you how.
NEITHER OF US
Stage 1 and Stage 2 belong to your certification body
The certificate is issued by an accredited certification body, not by Goldline, and the audit is booked into their calendar. Their fee is paid to them direct and is separate from the £7,000, and carries no Goldline margin. Goldline is not a certification body and does not issue certificates, and will not sell implementation and certification to the same organisation for the same scope.
Why the split is the whole product
Guided is priced flat at £7,000 because the labour sits with you. If Goldline did the Do phase as well, that is a Sprint and it prices from £14,000. The qualifying test is a single entity, roughly fifty people or fewer inside the scope, and a named internal owner with the time to do the Do phase. Without that owner the split above does not hold, and the honest answer is a Sprint rather than a cheaper number. Pace is set by how fast your team can move through Phase 02, which is why the phases carry no fixed dates.
Delivered against the Plan, Do, Check, Act cycle by a PECB certified ISO/IEC 27001 Senior Lead Implementer. Every deliverable is keyed to a clause of ISO/IEC 27001:2022 or an Annex A control. Effort splits are typical for a Guided engagement and are confirmed at scoping.