ISO/IEC 27001 support across the UK

ISO/IEC 27001 Consultant for UK SMEs

We manage the ISO/IEC 27001 implementation from ISMS scope, risk assessment and documentation through internal audit, management review and certification-audit support.

For established UK SMEs and contractors working across construction and related supply chains.

A clear first step

Send us your contractor’s or buyer’s requirement

We will use a free 15–20 minute initial call to clarify what has been requested and whether we are likely to be able to help. A detailed document review, gap analysis or written action plan is paid work with an agreed scope.

Responsibilities

What you provide and what we do

You provide accurate business information, access to relevant staff and records, management decisions and document approvals, and you operate the agreed processes. We manage the agreed implementation work: system design, documentation, implementation actions, internal audit, management review facilitation, certification-body selection support and preparation for Stage 1 and Stage 2.

You provide
  • Confirm the intended certification scope
  • Provide accurate information about systems, suppliers and risks and access to relevant staff and records
  • Make required risk-treatment and management decisions and approve the documents
  • Operate the agreed controls and retain evidence
  • Contract directly with the independent certification body
Barlow & Co provides
  • Complete the ISO/IEC 27001:2022 gap review and implementation plan
  • Structure the risk assessment, treatment process and Statement of Applicability
  • Design and prepare the proportionate ISMS documentation
  • Manage implementation actions, lead the internal audit and facilitate the management review
  • Help compare certification bodies and support Stage 1, Stage 2 and agreed corrective actions
Typical evidence

Documents commonly needed for ISO/IEC 27001

The exact list depends on your activities, size, application level and buyer requirements. We confirm the applicable scope before preparing documents.

  • ISMS scope and information security policy
  • Information security objectives and responsibilities
  • Information security risk assessment and treatment plan
  • Statement of Applicability
  • Asset, access, supplier and incident-management records
  • Internal audit, management review and corrective-action evidence
Plan the work

ISO/IEC 27001 cost, requirements and timescale

These are the practical questions to resolve before appointing a consultant or committing to an assessment.

Cost

How much does ISO/IEC 27001 support cost?

Our consultancy support starts from £2,350. The agreed fee depends on scope, sites, complexity, existing evidence and the work required. Certification body audit fees and the ISO standard are separate.

View indicative pricing →
Requirements

What will your business need?

You need accurate business information, evidence of controls that are genuinely in use and documents appropriate to the requested scope. The list above is a starting point, not a universal checklist.

Send the exact requirement →
How long

How long will the process take?

There is no responsible fixed answer before reviewing your starting point. Timing depends on missing evidence, implementation work, your team’s availability and the independent assessor or certification body.

Request an initial check →
UKAS

Do you need UKAS-accredited certification?

UKAS accredits certification bodies, not consultants or companies seeking ISO certification. If your buyer specifies UKAS-accredited certification, verify that the certification body’s current scope covers ISO/IEC 27001.

Check the UKAS directory →
Consultant

What should an accreditation consultant do?

A consultant should clarify the scope, identify gaps, prepare only the agreed documentation and help organise evidence. They should also explain what remains your responsibility and never imply that they control the assessor’s decision.

Discuss the scope with us →
Important distinction

Application support is separate from assessment

Barlow & Co is an independent consultancy. We do not issue certificates, memberships or approvals and are not the assessment body. The relevant scheme or certification body makes the final decision and controls its assessment timetable.

No guaranteed outcomeWe improve preparation but never promise approval.
Separate feesOur consultancy fee does not include scheme, membership or audit fees.
Agreed scopeDeliverables, assumptions and fees are confirmed before paid work begins.
FAQs

ISO/IEC 27001 application questions

Send the exact wording from your client, buyer or assessor if your situation is not covered here.

What is ISO/IEC 27001?

ISO/IEC 27001:2022 specifies requirements for an information security management system. It uses a risk-management approach to protect the confidentiality, integrity and availability of information.

How long does ISO/IEC 27001 certification take?

There is no reliable universal timescale. It depends on the certification scope, current controls, risk assessment, available evidence, implementation work and the certification body’s availability. We agree a preparation plan after reviewing your starting point.

What affects ISO/IEC 27001 consultancy cost?

The main factors are scope, sites, systems, suppliers, information risks, existing documentation and how much implementation support is required. Our indicative starting price excludes the standard and independent certification-body fees.

Does Barlow & Co issue ISO/IEC 27001 certificates?

No. We provide consultancy and preparation support. An independent certification body audits the management system and makes the certification decision.

What does UKAS-accredited certification mean?

UKAS accredits certification bodies rather than consultants or the businesses seeking ISO certification. If your buyer requires UKAS-accredited certification, check that the chosen certification body’s current UKAS scope includes ISO/IEC 27001.

Free 15–20 minute requirement check

What has your contractor or buyer asked for?

Paste the requirement or assessor query into the form. You can also email contact@barlowltd.co.uk, call 07840 039952 or use WhatsApp.

  • Clarify the requested scheme or level
  • Identify the likely next step
  • Agree scope and fees before paid work

Send your ISO/IEC 27001 requirement

Free 15–20 minute initial call. Scope and fee agreed before paid work starts.

Contact Barlow & Co on WhatsApp