UK ISO 27001 consultants
- Check the certification body is UKAS accredited. Unaccredited certificates cost less and are discounted by mature procurement teams.
- ISO 27001 and Cyber Essentials are not alternatives. Cyber Essentials is a baseline technical scheme; ISO 27001 is a management system certification.
- The certificate supports UK GDPR security of processing obligations but does not discharge them.
- For FCA and PRA regulated firms, ISO 27001 supports operational resilience expectations without satisfying them on its own.
- UK certification body fees commonly run £5,000 to £20,000 for the initial cycle, with implementation £15,000 to £50,000 separate.
UKAS accreditation
UK organisations pursue ISO 27001 for one dominant reason: customers ask for it. It is the default security credential in UK and European procurement, it produces a certificate you can publish, and a buyer can verify it without a confidentiality agreement.
A UK ISO 27001 consultant builds the information security management system and prepares you for audit. The certificate comes from an accredited certification body, which under ISO/IEC 17021 cannot be the same organisation.
UKAS is the national accreditation body for the United Kingdom. It accredits certification bodies to issue ISO 27001 certificates under ISO/IEC 17021.
The market also contains bodies operating without accreditation. Their certificates look similar and cost less. Mature procurement teams check which accreditation body sits behind the certificate, and an unaccredited one produces exactly the follow-up questions the certificate was supposed to end.
Ask any certification body to name its accreditation body and show its scope entry for ISO/IEC 27001.
How it sits with Cyber Essentials
These are frequently confused and they are not alternatives.
| Cyber Essentials | ISO 27001 | |
|---|---|---|
| What it is | A UK government-backed scheme covering five technical control areas | An international management system certification |
| What it assesses | Specific technical configurations | How you govern security risk across the organisation |
| Effort | Days to weeks | Three to six months |
| Cost | Hundreds to low thousands of pounds | £20,000 to £70,000 first year, all in |
| Who asks for it | UK public sector contracts and some UK buyers | International and enterprise buyers generally |
Many UK organisations hold both. Cyber Essentials or Cyber Essentials Plus is often a contractual requirement for UK government work. ISO 27001 is what enterprise and international buyers ask for. Doing Cyber Essentials first is a reasonable stepping stone because several of its controls map onto Annex A, but it does not shorten the management system work in Clauses 4 to 10.
UK GDPR and security of processing
UK GDPR requires appropriate technical and organisational measures to secure personal data. ISO 27001 is the most widely recognised way of demonstrating that you have a systematic approach to it, and the Information Commissioner's Office treats certification as evidence of good practice.
It does not discharge the obligation. UK GDPR also covers lawful basis, data subject rights, transfers, records of processing and breach notification, none of which ISO 27001 addresses. The overlap is real but partial, and the sensible approach is to map the two once rather than maintain two documentation sets.
FCA and PRA regulated firms
For regulated financial services firms, ISO 27001 supports operational resilience and outsourcing expectations without satisfying them. Your supervisor asks about important business services, impact tolerances, third-party dependencies and your ability to recover. The ISMS produces much of the underlying evidence: asset inventory, supplier assessment, incident records, continuity testing, access governance.
What it does not do is make the regulatory judgements. Those remain yours, and they are shaped by your permissions and your business model rather than by the standard.
Where the firm is FCA regulated, this is native ground for Buckingham Capital Consulting, the partner firm we work alongside on regulated engagements, which has advised payment and e-money firms on FCA authorisation and compliance since 2013.
Cost in sterling
| Component | Typical UK range |
|---|---|
| Gap analysis | £5,000 to £15,000 |
| Implementation | £15,000 to £50,000 |
| Certification body, initial cycle, small to mid-sized organisation | £5,000 to £20,000 |
| Annual surveillance audit | 20% to 40% of the initial audit fee |
| Annual internal audit, outsourced | £4,000 to £12,000 |
Cost is driven by scope, headcount within scope, number of sites and existing maturity rather than by revenue.
What a UK consultant should add
Beyond the six standard workstreams, three things specific to operating here.
They should check and be able to explain the accreditation status of any certification body they recommend.
They should map the ISMS to your UK GDPR security obligations so the same evidence serves both, rather than leaving you with parallel documentation.
They should ask which regulator supervises you, if any, and shape the evidence so it answers that regulator's questions as well as the auditor's. An FCA-regulated payments firm and an unregulated software company need the same certificate and different supporting narratives.
If your 2013 certificate lapsed
The transition window closed on 31 October 2025 and there is no transition audit route left. An organisation with a lapsed certificate is treated as a new applicant: full Stage 1 and Stage 2 against the 2022 edition, at full cost.
If that is your position, start with a gap analysis against the 2022 structure. The Annex A restructure means your old Statement of Applicability no longer maps, and the eleven newer controls are usually where the work sits.
What to do next
Contact two or three UKAS-accredited certification bodies early for availability and quotes, then scope the ISMS against what your buyers and your regulator actually ask for.
Our free readiness diagnostic gives a first view, and the ISO 27001 service page sets out how we run the programme.
References
FAQ
Do we need a UKAS-accredited certification body?
Not legally, but mature procurement teams check accreditation, and an unaccredited certificate tends to generate the questions you wanted it to prevent.
Is Cyber Essentials enough instead of ISO 27001?
For some UK public sector contracts, yes. For enterprise and international buyers, generally no. They assess different things at very different depths.
Does ISO 27001 satisfy UK GDPR?
It supports the security of processing obligation and is treated as evidence of good practice. It does not address lawful basis, data subject rights, transfers or breach notification.
Does it satisfy the FCA?
No. It supports operational resilience and outsourcing evidence but does not make the regulatory judgements your supervisor expects you to make.
What does it cost in the UK?
Certification body fees commonly £5,000 to £20,000 for the initial cycle, with implementation of £15,000 to £50,000 separate.
About Hael
Hael is an advisory firm specialising in AI governance and security compliance, built on fifteen years of UK and EU regulatory practice. We take companies through ISO 27001 from gap analysis to certificate and maintain the position afterwards. We are not a certification body and we take no commission from certification bodies. On engagements involving regulated financial services firms we work alongside Buckingham Capital Consulting, the partner firm that has advised UK payment and e-money firms on FCA authorisation and compliance since 2013.
This guide is general information and is not professional advice on your particular circumstances.