Assure · ISO/IEC 27001:2022

ISO 27001 certification, built to last

We help you design, implement and run an information security management system that passes the certification audit and keeps working after it. Practical, proportionate and delivered by a team that holds ISO 27001 itself.

ISO 27001 supports you in winning public-sector, defence and enterprise contracts.

The standard

What is ISO 27001?

ISO/IEC 27001 is the international standard for an information security management system, or ISMS.

An ISMS is the set of policies, processes, people and technical controls you use to protect the confidentiality, integrity and availability of your information. The standard is risk-based: you identify what could go wrong, decide how to treat it, and show that you review and improve those decisions over time.

Conformance

Your ISMS meets the standard and you can evidence it through internal audit or an independent review. Useful when customers ask for alignment rather than a certificate.

Certification

A UKAS-accredited certification body audits your ISMS and issues a certificate. This is what most tenders, public-sector buyers and enterprise supply chains ask for.

We prepare you for certification. The certification audit itself is carried out by an independent accredited body, which keeps the certificate credible.

How we help

Start where you are, not from a template

Each engagement is fixed-price once scope is agreed. Take one, or run them in sequence.

Gap analysis

A structured review of where you stand against every clause and Annex A control, with a prioritised plan and an honest estimate of the effort to certify.

Best for

Starting out, or unsure how far away certification is.

Implementation

We work alongside your team to scope the ISMS, run the risk assessment, write proportionate policies and put the controls in place.

Best for

Ready to build, with a target certification date.

Internal audit

An independent internal audit and management review, so you go into Stage 1 and Stage 2 knowing what the auditor will find.

Best for

An ISMS in place, heading for certification or surveillance.

Ongoing ISMS support

Risk reviews, internal audits, surveillance-audit preparation and control changes, handled with you through the three-year cycle.

Best for

Already certified, without a full-time ISMS manager.

The engagement

From scope to certificate

Most organisations reach certification in 6 to 9 months, depending on size and how much is already in place.

  1. Scope and context

    We define what the ISMS covers: sites, teams, systems, suppliers and the interested parties whose requirements it must meet.

  2. Gap analysis

    We assess your current practice against clauses 4 to 10 and Annex A, and agree a prioritised plan.

  3. Risk assessment and Statement of Applicability

    We run the risk assessment with you, choose treatments, and record which Annex A controls apply and why.

  4. Policies and controls

    We write proportionate policies and help your team implement the technical and organisational controls, using our own engineers where fixes are technical.

  5. Internal audit and management review

    An independent internal audit tests the ISMS end to end, followed by the management review the standard requires.

  6. Certification audit

    We support you through the Stage 1 documentation review and the Stage 2 audit with your chosen certification body, and help close any findings.

Why Layer 7

Why work with

Certified Ourselves

We hold ISO 27001, ISO 9001 and ISO 14001. The advice comes from running an ISMS day to day, not from a template library.

Engineers, Not Just Documents

When a control needs a technical fix, our cloud and security engineers can make it. The ISMS reflects what your systems actually do.

Defence and Public Sector

We work with government, defence and regulated clients through G-Cloud 14, DOS 7 and CCS frameworks, where ISO 27001 is often a requirement.

One Control Set

ISO 27001 maps onto Cyber Essentials, DCC and the NCSC CAF. We align them so you evidence a control once and reuse it.

Common questions

ISO 27001 FAQs

Do you issue the ISO 27001 certificate?

No. Certification is carried out by an independent, UKAS-accredited certification body. We prepare you for the audit, support you through Stage 1 and Stage 2, and help you close any findings.

How long does it take?

It depends on your size, scope and starting point. Most organisations we work with certify in 6 to 9 months. The gap analysis gives you a realistic timeline.

How long does certification last?

Three years. The certification body runs surveillance audits in years one and two, and a recertification audit before the certificate expires.

Which version of the standard applies?

ISO/IEC 27001:2022. It has 93 Annex A controls grouped into four themes: organisational, people, physical and technological. Certificates to the 2013 version have now expired.

What is a Statement of Applicability?

A mandatory document listing every Annex A control, whether it applies to you, and why. Auditors use it to understand how your risk assessment drives your controls.

We already have Cyber Essentials. Does that help?

Yes. Cyber Essentials covers several Annex A technical controls, and we are a Cyber Essentials Certification Body, so we reuse that evidence rather than starting again.

Can you help if we already have an ISMS?

Yes. We can audit it, fill the gaps, prepare you for surveillance or recertification, or take on ongoing ISMS support.

Get ISO 27001 certified

Start with a gap analysis. You'll know where you stand, what it will take and how long, with a fixed price for the next step.