Certify to ISO 27001 with managed services built for London businesses

Build a working information security management system, then keep the technical controls and audit evidence current.

Meet the requirements you will be assessed against

Information security management system

You must establish, implement, maintain, and continually improve an ISMS — a systematic approach to managing sensitive information. This includes defined scope, documented policies, assigned roles, and a management review cycle.

Risk assessment and treatment

A formal risk assessment methodology must identify threats to your information assets, evaluate their likelihood and impact, and produce a risk treatment plan. Residual risks must be accepted by management with documented justification.

Annex A controls

The 2022 revision organises 93 controls across four themes: organisational, people, physical, and technological. You must produce a Statement of Applicability documenting which controls are implemented, which are excluded, and why.

Internal audit programme

Regular internal audits must assess whether the ISMS conforms to the standard and your own policies. Audits must be planned, conducted by competent auditors independent of the areas being reviewed, and produce actionable findings.

Management review

Top management must review the ISMS at planned intervals to ensure its continuing suitability, adequacy, and effectiveness. Reviews must consider audit results, incident trends, risk assessment updates, and stakeholder feedback.

Continuous improvement

The ISMS must improve over time. Nonconformities must be addressed through corrective actions. Preventive measures must be informed by monitoring, measurement, and analysis of security performance data.

A useful framework for managing information security

ISO 27001 is the international standard for an information security management system, or ISMS. It provides a structure for risk decisions, policies, responsibilities, controls, audits and continual improvement.

That structure overlaps with parts of Cyber Essentials, DORA, FCA operational resilience and other frameworks, but the standards are not interchangeable. ISO 27001 certification can support customer assurance and wider compliance work; it does not automatically satisfy another regime.

What ISO 27001:2022 actually requires

The standard works on two levels.

Clauses 4 to 10 set the management system requirements. Understand your context. Secure leadership commitment. Plan your approach to risk. Provide resources and competence. Run the operational controls. Measure performance through monitoring and audit. Improve continually. These clauses are mandatory and you cannot exclude any of them.

Annex A offers a reference set of 93 controls across four themes. The 2022 revision replaced the 2013 structure of 114 controls in 14 domains and added 11 new controls. Those cover threat intelligence (A.5.7), cloud security (A.5.23), ICT readiness for business continuity (A.5.30) and monitoring activities (A.8.16).

You do not have to implement all 93. You have to consider each one, implement what your risk profile calls for, and record the reasoning in a Statement of Applicability. For financial services firms, most will apply.

Use one management system to support several requirements

Regulated firms carry overlapping obligations. Each one uses its own vocabulary. Each one asks for evidence that controls exist and work.

ISO 27001 can organise evidence used across several workstreams. A risk method may support DORA ICT risk work; an incident procedure may support FCA or DORA processes; supplier controls may contribute to third-party oversight. Additional requirements still need to be assessed separately.

Skip the unifying structure and you get parallel workstreams, duplicated documents and controls that contradict each other. An ISMS gives you one system of record instead.

Focus on the Annex A controls auditors dwell on

Five control areas carry most of the weight for a London financial firm.

Access control (A.5.15–A.5.18, A.8.2–A.8.5) governs who reaches what, on what conditions, and how access gets reviewed and removed. If you hold client assets or sensitive financial data, expect auditors to start here.

Cryptography (A.8.24) protects data in transit and at rest. With hybrid working normal, encrypting endpoints, email and cloud storage is the baseline.

Operational security (A.8.7–A.8.16) covers malware protection, backup, logging, monitoring and vulnerability management. Your managed IT provider runs these daily.

Supplier relationships (A.5.19–A.5.22) ask for documented assessment and monitoring of third-party security. If you run on several SaaS platforms, an annual questionnaire will not carry it.

Incident management (A.5.24–A.5.28) needs a structured way to detect, report, assess and respond to security events. The 2022 revision added learning from incidents and preserving evidence.

Hand the technical half of Annex A to us

Your ISMS consultant or internal compliance lead owns policy, scope and governance. We take the technical controls that make those policies real.

Our managed IT support delivers the Annex A controls that live in the IT domain. We configure access controls, deploy and watch endpoint protection, run backup and recovery, maintain logging and monitoring, run vulnerability management and penetration testing, and assess your technology suppliers.

At the certification audit we hand over evidence packs for every technical control in your Statement of Applicability. Screen captures, configuration exports, log samples, test results and trend reports, ready for the auditor.

After certification we keep the evidence current through the same day-to-day service. When the surveillance auditor returns each year, nothing needs reassembling, because the controls never stopped running.

ISO 27001 is not a project. It is a management system that has to live with your business. We make sure the technology layer does.

Last updated:

FAQ

Frequently asked questions

How long does ISO 27001 certification take?

For a London financial services firm with 20-150 staff, a well-structured certification programme typically takes 6-12 months from initial gap analysis to certification audit. The timeline depends on your starting maturity, the scope of your ISMS, and how quickly policy and procedural gaps can be closed. Firms with an existing managed IT provider and good security hygiene can move faster.

What is the difference between ISO 27001:2022 and the previous version?

The 2022 revision restructured Annex A controls from 14 domains with 114 controls to 4 themes with 93 controls. It introduced 11 new controls covering areas including threat intelligence, cloud security, data masking, and secure development lifecycle. The core ISMS requirements in clauses 4-10 received minor updates for clarity. Organisations certified to the 2013 version had until 31 October 2025 to transition.

How does ISO 27001 map to DORA requirements?

ISO 27001 can support parts of a DORA programme because both address risk, incidents, access and suppliers. It does not provide DORA compliance on its own; DORA adds specific scope, reporting, testing and contractual requirements.

Do we need to be ISO 27001 certified, or just aligned?

That depends on customer, contractual and assurance needs. Certification provides independent verification; alignment uses the framework without a certificate. ISO 27001 may support regulatory and client due diligence, but it does not replace any applicable legal or regulatory obligation.

What does Nerdster's role look like during certification?

We implement and manage the technical controls that form the bulk of Annex A. This includes access management, endpoint security, network security, backup and recovery, logging and monitoring, and vulnerability management. We provide evidence packs for audit, support policy drafting with technical input, and ensure the IT environment meets the standard's requirements on an ongoing basis.

How much does ISO 27001 certification cost?

Costs vary by scope and firm size. For a London financial services firm with 30-100 staff, expect certification body fees of £5,000-£15,000 for the initial audit, plus annual surveillance audits at roughly half that cost. Consultancy support for ISMS development ranges from £10,000-£30,000. Managed IT services that maintain ongoing compliance are a separate, ongoing cost that most firms already incur.

Talk to our team about this standard

Tell us where you are with this standard. A London-based engineer replies within 2 hours during business hours.

We respond within 2 hours during business days. Your data is handled per our privacy policy.

Contact details

0330 043 7414

Mon-Fri 8am-6pm

[email protected]

We reply within 2 hours

71-75 Shelton Street

Covent Garden, London WC2H 9JQ

IT assessment

A review of your IT, your security posture and your compliance readiness, free of charge.

  • 30-minute consultation call
  • Infrastructure & security review
  • Compliance gap analysis
  • Custom recommendations report
Replies the same business day

Find out where you stand today

Book a compliance review. We assess your readiness against the current requirements and give you a priority order for closing the gaps.

  • No callout fees
  • No-obligation assessment