Eye On Bits
Compliance · ISO 27001

ISO 27001 Certification, Made Straightforward

ISO/IEC 27001 is the international standard for information security management. We help you build the ISMS, implement the right controls, and get audit-ready, led by certified ISO 27001:2022 Lead Auditors.

What is ISO 27001?

ISO/IEC 27001 is the international standard for an Information Security Management System (ISMS). It sets out a risk-based framework for identifying, assessing and treating information security risks across people, process and technology.

Certification is issued by an independent, accredited certification body after a two-stage audit - Eye On Bits prepares your organisation for that audit; we do not issue the certificate ourselves, which is what keeps it credible to your customers and regulators.

What's included

Gap Assessment

Gap assessment against ISO/IEC 27001:2022 and Annex A controls.

Risk Treatment Plan

Risk assessment methodology and risk treatment plan.

ISMS Documentation

ISMS documentation - policies, procedures and the Statement of Applicability.

Staff Awareness & Audit

Staff awareness training and internal audit.

Certification Audit Support

Certification audit (Stage 1 and Stage 2) readiness support.

Surveillance Audit Support

Post-certification surveillance audit support and continual improvement.

Our approach - Plan, Do, Check, Act

The same continuous-improvement cycle behind every compliance programme we run.

Plan

Identify objectives, secure management support, define the scope and method of risk assessment, and inventory the assets that need protecting.

Do

Manage risk with a treatment plan, implement the required controls and policies, and train staff to follow them.

Check

Monitor how the management system is actually running, and prepare the organisation for its certification or attestation audit.

Act

Run the audit, then keep improving through continual, corrective and preventive action.

Other compliance frameworks

ISO 27701

Privacy Information Management System, extending ISO 27001 for GDPR/DPDPA alignment.

Learn more →

ISO 22301

International standard for Business Continuity Management.

Learn more →

SOC 2

Independent attestation of security, availability and confidentiality controls.

Learn more →

GDPR

EU regulation governing the processing of personal data.

Learn more →

Questions we get asked first

How long does ISO 27001 certification take?

Typically 8–16 weeks depending on how much of the ISMS already exists and how quickly evidence can be gathered - a gap assessment gives an accurate timeline for your organisation.

Do you issue the ISO 27001 certificate?

No. We prepare your ISMS and support you through the audit; the certificate itself is issued by an independent, accredited certification body.

What happens after certification?

ISO 27001 certification is valid for three years, with annual surveillance audits by your certification body. We can continue supporting your ISMS through those cycles.

Ready to get audit-ready for ISO 27001?

Tell us where you're starting from and we'll come back with a scoped proposal within two working days.