- Confirm the intended certification scope
- Provide accurate information about systems, suppliers and risks and access to relevant staff and records
- Make required risk-treatment and management decisions and approve the documents
- Operate the agreed controls and retain evidence
- Contract directly with the independent certification body
ISO/IEC 27001 Consultant for UK SMEs
We manage the ISO/IEC 27001 implementation from ISMS scope, risk assessment and documentation through internal audit, management review and certification-audit support.
For established UK SMEs and contractors working across construction and related supply chains.
Send us your contractor’s or buyer’s requirement
We will use a free 15–20 minute initial call to clarify what has been requested and whether we are likely to be able to help. A detailed document review, gap analysis or written action plan is paid work with an agreed scope.
What you provide and what we do
You provide accurate business information, access to relevant staff and records, management decisions and document approvals, and you operate the agreed processes. We manage the agreed implementation work: system design, documentation, implementation actions, internal audit, management review facilitation, certification-body selection support and preparation for Stage 1 and Stage 2.
- Complete the ISO/IEC 27001:2022 gap review and implementation plan
- Structure the risk assessment, treatment process and Statement of Applicability
- Design and prepare the proportionate ISMS documentation
- Manage implementation actions, lead the internal audit and facilitate the management review
- Help compare certification bodies and support Stage 1, Stage 2 and agreed corrective actions
Documents commonly needed for ISO/IEC 27001
The exact list depends on your activities, size, application level and buyer requirements. We confirm the applicable scope before preparing documents.
- ISMS scope and information security policy
- Information security objectives and responsibilities
- Information security risk assessment and treatment plan
- Statement of Applicability
- Asset, access, supplier and incident-management records
- Internal audit, management review and corrective-action evidence
ISO/IEC 27001 cost, requirements and timescale
These are the practical questions to resolve before appointing a consultant or committing to an assessment.
How much does ISO/IEC 27001 support cost?
Our consultancy support starts from £2,350. The agreed fee depends on scope, sites, complexity, existing evidence and the work required. Certification body audit fees and the ISO standard are separate.
View indicative pricing →What will your business need?
You need accurate business information, evidence of controls that are genuinely in use and documents appropriate to the requested scope. The list above is a starting point, not a universal checklist.
Send the exact requirement →How long will the process take?
There is no responsible fixed answer before reviewing your starting point. Timing depends on missing evidence, implementation work, your team’s availability and the independent assessor or certification body.
Request an initial check →Do you need UKAS-accredited certification?
UKAS accredits certification bodies, not consultants or companies seeking ISO certification. If your buyer specifies UKAS-accredited certification, verify that the certification body’s current scope covers ISO/IEC 27001.
Check the UKAS directory →What should an accreditation consultant do?
A consultant should clarify the scope, identify gaps, prepare only the agreed documentation and help organise evidence. They should also explain what remains your responsibility and never imply that they control the assessor’s decision.
Discuss the scope with us →Application support is separate from assessment
Barlow & Co is an independent consultancy. We do not issue certificates, memberships or approvals and are not the assessment body. The relevant scheme or certification body makes the final decision and controls its assessment timetable.
ISO/IEC 27001 application questions
Send the exact wording from your client, buyer or assessor if your situation is not covered here.
What is ISO/IEC 27001?
ISO/IEC 27001:2022 specifies requirements for an information security management system. It uses a risk-management approach to protect the confidentiality, integrity and availability of information.
How long does ISO/IEC 27001 certification take?
There is no reliable universal timescale. It depends on the certification scope, current controls, risk assessment, available evidence, implementation work and the certification body’s availability. We agree a preparation plan after reviewing your starting point.
What affects ISO/IEC 27001 consultancy cost?
The main factors are scope, sites, systems, suppliers, information risks, existing documentation and how much implementation support is required. Our indicative starting price excludes the standard and independent certification-body fees.
Does Barlow & Co issue ISO/IEC 27001 certificates?
No. We provide consultancy and preparation support. An independent certification body audits the management system and makes the certification decision.
What does UKAS-accredited certification mean?
UKAS accredits certification bodies rather than consultants or the businesses seeking ISO certification. If your buyer requires UKAS-accredited certification, check that the chosen certification body’s current UKAS scope includes ISO/IEC 27001.
What has your contractor or buyer asked for?
Paste the requirement or assessor query into the form. You can also email contact@barlowltd.co.uk, call 07840 039952 or use WhatsApp.
- Clarify the requested scheme or level
- Identify the likely next step
- Agree scope and fees before paid work
