
Building an ISMS that stands up to Stage 2, not just Stage 1.
We run the day-to-day work of implementing ISO/IEC 27001:2022 — scope, risk assessment, Statement of Applicability, policies and evidence — so your certification date is a realistic milestone, not a guess.
Most ISMS builds stall between policy and practice.
Plenty of organisations own a folder of ISO 27001 policy templates. Far fewer have an information security management system that a certification body will recognise, because a template set isn't a management system — it's a starting point that still needs risk assessment, ownership, evidence and review built around it.
The commercial trigger is usually a customer contract, a tender requirement or a board decision to formalise security governance. Whatever the driver, the deadline is often tighter than the internal resource available to meet it, and information security work competes with day-to-day operational priorities for the same people's time.
Clause 4 to 10 requirements — context, leadership, planning, support, operation, performance evaluation and improvement — get treated as paperwork rather than as the operating rhythm of the management system. That's a common reason Stage 1 audits raise findings even where the technical controls themselves are reasonably sound.
The risk assessment methodology is often the weakest point. Risk registers get populated quickly to satisfy an internal deadline, with generic risk statements, no consistent scoring and treatment decisions that don't trace back to specific Annex A controls or a documented Statement of Applicability rationale.
Ownership is the other recurring gap. Controls need named owners who can speak to an auditor about how a control actually operates, not just that a policy exists. Without that, interviews during Stage 2 expose a difference between what the documentation says and what people in the business actually do.
None of this means starting from zero is required. It usually means separating what's genuinely usable — existing IT controls, HR processes, supplier contracts — from what needs to be built or rewritten, and sequencing the work so certification readiness lands on a date the business can plan around.
- Policy documents that were never operationalised or assigned an owner
- Risk registers with no consistent methodology or Annex A traceability
- A scope statement that doesn't match what the business actually does
- Certification deadlines set by a customer contract rather than readiness
A defined build, run by consultants who've sat through the audits.
We start with scope: what's actually in the ISMS boundary — locations, services, systems, third parties — agreed with your leadership team and written so it stands up to an auditor's questions rather than reading as marketing copy.
From there we run risk assessment against a consistent methodology, build the risk treatment plan, and produce the Statement of Applicability with a clear, defensible rationale for every one of the 93 Annex A controls under all four themes — organisational, people, physical and technological.
Policies and procedures are drafted to match how your organisation actually operates, not generic templates with your logo added. We test them with the people who'll own them before they're finalised, because a policy nobody follows is a Stage 2 finding waiting to happen.
We build the evidence trail as we go rather than assembling it retrospectively — access reviews, training records, supplier due diligence, incident logs — so by the time you reach Stage 1 the management system has a working history, not a set of documents dated the week before the audit.
Fortnightly working sessions with a named internal lead keep the project moving and keep decisions with your business, where they belong. We facilitate and draft; you and your leadership team make the risk acceptance and treatment calls that are genuinely yours to make.
In the run-up to Stage 1 and Stage 2 we run internal review sessions structured the way a certification body auditor will structure theirs, so gaps are found and fixed by us, not by the auditor on the day.
- Scope statement and ISMS boundary agreed with leadership
- Risk assessment, treatment plan and Statement of Applicability built together
- Policy set drafted, tested with control owners and version controlled
- Evidence built continuously, not assembled the week before audit
Everything in the engagement, set out up front.
Fixed-scope work packages agreed before the engagement starts, delivered by senior consultants who work directly with your team rather than handing you a template pack.
Scoping and context
ISMS boundary, interested parties and context analysis under clause 4, agreed with leadership and documented clearly.
Risk assessment and treatment
A consistent risk methodology, populated risk register and treatment plan mapped to Annex A controls.
Statement of Applicability
All 93 controls across the four Annex A themes assessed, with a documented rationale for inclusion or exclusion.
Policy and procedure set
The core ISMS documentation drafted for your environment, reviewed with control owners before sign-off.
Evidence and records
Templates and working practices that build an audit trail continuously, rather than a scramble before Stage 1.
Audit preparation
Internal review sessions and mock interviews structured the way an accredited certification body runs Stage 1 and Stage 2.
What you receive.
- ISMS scope statement and context analysis
- Risk assessment methodology and populated risk register
- Risk treatment plan
- Statement of Applicability with control rationale
- Information security policy and supporting procedures
- Internal audit programme and first-cycle results
- Management review pack and agenda
- Supplier and third-party risk documentation
- Training and awareness materials
- Stage 1 and Stage 2 readiness review
Built for organisations that need the work done properly.
Organisations under contractual pressure
A customer or tender requires ISO 27001 within a defined window and internal capacity to deliver it is limited.
Businesses starting from an incomplete build
Some policies, a partial risk register or an earlier attempt exist but the ISMS isn't yet coherent or auditable.
Growing organisations without a security function
Headcount and infrastructure have outgrown informal security practices, and formal governance is now overdue.
Groups certifying a new site or business unit
An existing certified ISMS needs to be extended to a new legal entity, location or acquired business.
What changes once the work is done.
The outcome is a management system that operates as intended once we've stepped back, assessed by an accredited certification body on its merits.
Certification readiness
A complete, coherent ISMS package ready for Stage 1 submission to your chosen certification body.
Defensible risk decisions
A risk register and Statement of Applicability that trace clearly from identified risk to control to rationale.
Working documentation
Policies that match daily practice, so interviews confirm the documentation rather than contradict it.
Internal ownership
Control owners who understand what they're responsible for and can speak to it confidently in an audit.
Stronger customer assurance
A credible answer to security questionnaires and due diligence requests during the build, not just after certification.
A foundation for continual improvement
Management review, internal audit and metrics in place from day one, ready to run without us.
Certification is issued by an accredited body — we build what earns it.
We're straightforward about our role: Secure Chain is not a certification body and we don't issue ISO 27001 certificates. That decision sits with a UKAS-accredited certification body, and it should. Our job is to make sure the ISMS we build is ready to be assessed on its merits, without last-minute surprises.
That separation matters for credibility. An implementation partner who also certified your ISMS would have an obvious conflict of interest. Keeping the roles apart means the certification decision is independent, and it means we're motivated to build something that genuinely works rather than something that just looks compliant on the day of the audit.
We're also honest when a timeline isn't realistic. If a customer deadline requires cutting corners on risk assessment or control implementation, we'll say so plainly and set out the trade-off, rather than agreeing to a date we don't believe the work can support.
Delivery is UK-based, with senior consultants working directly with your team — in person where useful across Chesterfield, Sheffield, Derby, Nottingham, Leeds, Manchester, Birmingham and London, and remotely where that suits the engagement better. You get consistent people who know your business by the time Stage 2 arrives, not a rotating team.
Questions we are asked most often.
How long does ISO 27001 implementation support take?
Most organisations run a 4 to 9 month programme from kick-off to Stage 1 readiness, depending on scope, existing controls and how much internal capacity you can commit. We agree milestones at the outset and report against them, rather than working to an open-ended timeline.
Do you carry out certification audits?
No. Secure Chain is not an accredited certification body and does not issue certificates. We build the ISMS and prepare you for Stage 1 and Stage 2 audits carried out by a UKAS-accredited certification body of your choosing, and we can sit alongside you during those audits.
Do we need a gap analysis first?
It helps but isn't mandatory. If you've already had a gap analysis done, we start from that output and go straight into scoping and risk assessment. If not, we run a short scoping and baseline exercise in week one so the implementation plan is built on an accurate picture, not assumptions.
How much of our team's time does this take?
Expect a named internal lead spending several hours a week, plus input from control owners for evidence and interviews. We do the drafting, facilitation and evidence structuring; your team makes the risk decisions and owns the controls day to day, which is what an auditor expects to see.
What's the difference between this and your ISO 27001 consultancy service?
Implementation support is a defined build project that takes you from a standing start to certification readiness against a fixed set of deliverables. Consultancy is an ongoing, flexible advisory arrangement for organisations that already have a certified or near-complete ISMS and need senior input on an ad hoc or retained basis.
Which certification bodies do you work alongside?
We work alongside whichever UKAS-accredited certification body you choose or already use. We don't have a commercial relationship with any certification body, so our recommendations on scope and control design are made on their technical merit rather than to suit a particular auditor's preferences.
Can you support a Statement of Applicability we've already started?
Yes. We regularly pick up partially completed Statements of Applicability, risk registers and policy sets. We'll review what exists against Annex A and clauses 4 to 10, tell you plainly what's usable and what needs rework, and build from there rather than starting again unnecessarily.
What happens after certification?
Certification is the start of an ongoing management system, not the end of the work. Many clients move into our consultancy engagement for surveillance audit preparation, management review and continual improvement, or hand the ISMS fully to an internal owner with our documentation as the foundation.
Compliance support
Broader framework support across Cyber Essentials, NHS DSPT, PCI DSS and FCA-driven controls.
Managed security
Ongoing monitoring and operational security to support the controls your ISMS depends on.
Vulnerability management as a service
Continuous vulnerability management evidence to support Annex A technical controls.
Ready to put a realistic date on certification?
Tell us your target certification body, timeline and current state of readiness. We'll come back with a scoped plan, not a sales pitch.
Discuss your implementation