Quick Answer

Coreitech implements ISO 27001 ISMS for London businesses — gap analysis, technical controls, documentation, staff training, and certification audit support. Call 0203 834 9728.

— ISO 27001 · ISMS Implementation · London

ISO 27001
ISMS
LONDON

Coreitech guides London businesses through ISO 27001 certification — from gap analysis and ISMS implementation to technical controls, documentation, and audit support. We act as your virtual CISO throughout the entire process.

ISO 27001 gap analysis & remediation roadmap
ISMS design and implementation
All 93 Annex A technical controls configured
Complete documentation suite (SoA, risk register, policies)
Staff security awareness training
Stage 1 & Stage 2 certification audit support
— Services

ISO 27001 services
for London businesses

Gap Analysis & Readiness

We assess your current IT controls against ISO 27001 requirements and produce a prioritised remediation roadmap with effort and cost estimates.

ISMS Implementation

Design and implementation of your Information Security Management System — policies, procedures, risk register, and asset inventory.

Technical Controls

Access controls, encryption, patch management, endpoint security, network segmentation, and backup — all configured to ISO 27001 Annex A standards.

Documentation

All mandatory ISO 27001 documentation: scope statement, SoA (Statement of Applicability), risk assessment, risk treatment plan, and 93 Annex A control evidence.

Staff Awareness Training

ISO 27001 requires documented staff security awareness training. We deliver and record training across your team to meet certification requirements.

Audit Support

We prepare your team for Stage 1 and Stage 2 certification audits, accompany you through the process, and address auditor findings.

— FAQ

ISO 27001 London —
questions answered

Q.What is ISO 27001 and does my London business need it?

ISO 27001 is the international standard for Information Security Management Systems (ISMS). It demonstrates to clients, prospects, and regulators that your organisation systematically manages information security risks. Many London professional services firms — particularly in legal, financial services, and technology — now require ISO 27001 certification from their suppliers as a condition of contract. It is also increasingly required for government contracts and regulated sector tendering.

Q.How long does ISO 27001 certification take?

For a London SME (20–200 employees), ISO 27001 certification typically takes 6–12 months with Coreitech managing the technical implementation: Months 1–2 — gap analysis and ISMS scoping; Months 2–5 — ISMS implementation and technical controls; Months 5–8 — documentation, risk assessment, and staff training; Months 8–10 — internal audit and management review; Months 10–12 — Stage 1 and Stage 2 certification audits.

Q.How much does ISO 27001 certification cost for a London SME?

ISO 27001 certification costs consist of certification body fees (typically £3,000–£8,000/year depending on scope and body), plus implementation costs. Coreitech provides fixed-price ISO 27001 implementation packages for London SMEs, covering technical controls, documentation, and audit preparation. Contact us for a quote based on your headcount and current security maturity.

Q.What is the difference between ISO 27001 and Cyber Essentials?

Cyber Essentials is a UK government-backed scheme covering five basic technical controls. It takes days to weeks to achieve and costs hundreds to low thousands of pounds. ISO 27001 is a comprehensive international management standard requiring a full ISMS, risk assessment, 93 security controls, and annual audits. ISO 27001 is significantly more rigorous and internationally recognised. Many London businesses achieve Cyber Essentials first, then progress to ISO 27001.

Q.Can Coreitech manage our ISO 27001 compliance ongoing?

Yes. Coreitech provides ongoing ISO 27001 managed compliance for London businesses — annual surveillance audits, monthly security reviews, patch management reports, incident logging, staff training records, and policy updates as the standard evolves. We act as your virtual CISO and ISO 27001 lead, keeping your certification current without requiring dedicated in-house security headcount.

Start your ISO 27001 journey
in London

Free ISO 27001 gap analysis — we'll assess your current security controls against the standard and give you a clear view of what's needed to achieve certification.