top of page

ISO 27001 Certification Support

ISO 27001 is the international "gold standard" for information security. If your organisation has outgrown Cyber Essentials and Cyber Assurance, or a customer or contract now asks for ISO 27001 specifically, Regola can help you prepare for it and work with our partners to take you through to certification.

What is ISO 27001?

ISO 27001, in its current 2022 version, is the international standard for an Information Security Management System (ISMS). It sets out a risk-based framework for protecting the confidentiality, integrity and availability of your information, supported by a set of security controls in Annex A. Certification is awarded by an accredited international certification body.

​How ISO 27001 relates to Cyber Assurance

Cyber Essentials

Core Technical Controls

Cyber Assurance

Governance & Resilience

ISO 27001

International Standard

For most small and medium organisations, IASME Cyber Assurance is the natural starting point, and ISO 27001 is the step beyond it. If you already hold Cyber Assurance Level 2, you have done much of the groundwork, and ISO 27001 is only a small hill to climb from there. The key difference is who awards it.

 

Cyber Assurance is UK-developed and certified through IASME. ISO 27001 sits outside IASME, and the body awarding certification is an international standards organisation rather than a UK Government scheme. That international recognition is often exactly why organisations pursue it.

How Regola Helps

We are honest about our role here. Regola is an IASME certification body, so we certify Cyber Essentials and Cyber Assurance directly. For ISO 27001, we help you get audit-ready and our trusted partners carry out the certification itself.

That means we can:

Assess where you are against the ISO 27001 requirements and identify the gaps.

Prepare your documentation, processes and people for an audit by an international standards certification body.

Build on the governance, policies and controls you already have from Cyber Essentials and Cyber Assurance.

 Introduce and work alongside our partners who take you through to certification.

Where We Work

We're based in Torquay and operate across the UK, with many clients both in and outside Devon, including:

North Devon

Exeter

Taunton

Barnstaple

Cullompton

Mid Devon

Plymouth

Honiton

Torquay

Crediton

South Devon

Newton Abbot

Where to start

If you are not yet certified to Cyber Essentials or Cyber Assurance, that is usually the most cost-effective place to begin, and it lays a solid foundation for ISO 27001 later. If you already know ISO 27001 is your target, we can plan the whole route with you from the outset.

Not sure whether ISO 27001 is the right target for you, or whether Cyber Assurance would do the job? Give us a shout and we will talk it through honestly.

Frequently Asked Questions About ISO

bottom of page