Hael
Book a meeting
ISO 27001 · United Kingdom

UK ISO 27001 consultants

Hael · Published 7 August 2026 · Last reviewed 7 August 2026 · 7 min read
Key takeaways
  • Check the certification body is UKAS accredited. Unaccredited certificates cost less and are discounted by mature procurement teams.
  • ISO 27001 and Cyber Essentials are not alternatives. Cyber Essentials is a baseline technical scheme; ISO 27001 is a management system certification.
  • The certificate supports UK GDPR security of processing obligations but does not discharge them.
  • For FCA and PRA regulated firms, ISO 27001 supports operational resilience expectations without satisfying them on its own.
  • UK certification body fees commonly run £5,000 to £20,000 for the initial cycle, with implementation £15,000 to £50,000 separate.

UKAS accreditation

UK organisations pursue ISO 27001 for one dominant reason: customers ask for it. It is the default security credential in UK and European procurement, it produces a certificate you can publish, and a buyer can verify it without a confidentiality agreement.

A UK ISO 27001 consultant builds the information security management system and prepares you for audit. The certificate comes from an accredited certification body, which under ISO/IEC 17021 cannot be the same organisation.

UKAS is the national accreditation body for the United Kingdom. It accredits certification bodies to issue ISO 27001 certificates under ISO/IEC 17021.

The market also contains bodies operating without accreditation. Their certificates look similar and cost less. Mature procurement teams check which accreditation body sits behind the certificate, and an unaccredited one produces exactly the follow-up questions the certificate was supposed to end.

Ask any certification body to name its accreditation body and show its scope entry for ISO/IEC 27001.

How it sits with Cyber Essentials

These are frequently confused and they are not alternatives.

Cyber EssentialsISO 27001
What it isA UK government-backed scheme covering five technical control areasAn international management system certification
What it assessesSpecific technical configurationsHow you govern security risk across the organisation
EffortDays to weeksThree to six months
CostHundreds to low thousands of pounds£20,000 to £70,000 first year, all in
Who asks for itUK public sector contracts and some UK buyersInternational and enterprise buyers generally

Many UK organisations hold both. Cyber Essentials or Cyber Essentials Plus is often a contractual requirement for UK government work. ISO 27001 is what enterprise and international buyers ask for. Doing Cyber Essentials first is a reasonable stepping stone because several of its controls map onto Annex A, but it does not shorten the management system work in Clauses 4 to 10.

UK GDPR and security of processing

UK GDPR requires appropriate technical and organisational measures to secure personal data. ISO 27001 is the most widely recognised way of demonstrating that you have a systematic approach to it, and the Information Commissioner's Office treats certification as evidence of good practice.

It does not discharge the obligation. UK GDPR also covers lawful basis, data subject rights, transfers, records of processing and breach notification, none of which ISO 27001 addresses. The overlap is real but partial, and the sensible approach is to map the two once rather than maintain two documentation sets.

FCA and PRA regulated firms

For regulated financial services firms, ISO 27001 supports operational resilience and outsourcing expectations without satisfying them. Your supervisor asks about important business services, impact tolerances, third-party dependencies and your ability to recover. The ISMS produces much of the underlying evidence: asset inventory, supplier assessment, incident records, continuity testing, access governance.

What it does not do is make the regulatory judgements. Those remain yours, and they are shaped by your permissions and your business model rather than by the standard.

Where the firm is FCA regulated, this is native ground for Buckingham Capital Consulting, the partner firm we work alongside on regulated engagements, which has advised payment and e-money firms on FCA authorisation and compliance since 2013.

Cost in sterling

ComponentTypical UK range
Gap analysis£5,000 to £15,000
Implementation£15,000 to £50,000
Certification body, initial cycle, small to mid-sized organisation£5,000 to £20,000
Annual surveillance audit20% to 40% of the initial audit fee
Annual internal audit, outsourced£4,000 to £12,000

Cost is driven by scope, headcount within scope, number of sites and existing maturity rather than by revenue.

What a UK consultant should add

Beyond the six standard workstreams, three things specific to operating here.

They should check and be able to explain the accreditation status of any certification body they recommend.

They should map the ISMS to your UK GDPR security obligations so the same evidence serves both, rather than leaving you with parallel documentation.

They should ask which regulator supervises you, if any, and shape the evidence so it answers that regulator's questions as well as the auditor's. An FCA-regulated payments firm and an unregulated software company need the same certificate and different supporting narratives.

If your 2013 certificate lapsed

The transition window closed on 31 October 2025 and there is no transition audit route left. An organisation with a lapsed certificate is treated as a new applicant: full Stage 1 and Stage 2 against the 2022 edition, at full cost.

If that is your position, start with a gap analysis against the 2022 structure. The Annex A restructure means your old Statement of Applicability no longer maps, and the eleven newer controls are usually where the work sits.

What to do next

Contact two or three UKAS-accredited certification bodies early for availability and quotes, then scope the ISMS against what your buyers and your regulator actually ask for.

Our free readiness diagnostic gives a first view, and the ISO 27001 service page sets out how we run the programme.

References

FAQ

Do we need a UKAS-accredited certification body?

Not legally, but mature procurement teams check accreditation, and an unaccredited certificate tends to generate the questions you wanted it to prevent.

Is Cyber Essentials enough instead of ISO 27001?

For some UK public sector contracts, yes. For enterprise and international buyers, generally no. They assess different things at very different depths.

Does ISO 27001 satisfy UK GDPR?

It supports the security of processing obligation and is treated as evidence of good practice. It does not address lawful basis, data subject rights, transfers or breach notification.

Does it satisfy the FCA?

No. It supports operational resilience and outsourcing evidence but does not make the regulatory judgements your supervisor expects you to make.

What does it cost in the UK?

Certification body fees commonly £5,000 to £20,000 for the initial cycle, with implementation of £15,000 to £50,000 separate.

About Hael

Hael is an advisory firm specialising in AI governance and security compliance, built on fifteen years of UK and EU regulatory practice. We take companies through ISO 27001 from gap analysis to certificate and maintain the position afterwards. We are not a certification body and we take no commission from certification bodies. On engagements involving regulated financial services firms we work alongside Buckingham Capital Consulting, the partner firm that has advised UK payment and e-money firms on FCA authorisation and compliance since 2013.

This guide is general information and is not professional advice on your particular circumstances.

Free check

See where you stand on ISO 27001, free.

Answer a short set of questions and see what ISO 27001 expects of your AI systems and where you stand today. No sign-up to see your result.

Applicability

Whether ISO 27001 applies to how you use AI, and to which systems.

What is expected

Risk classification, governance, documentation and human oversight.

Where you stand

A banded result, pointed at the gaps that matter most.

What you get

On screen in about five minutes, pre-scoped to ISO 27001.

Or speak to us about your deadline. Book a meeting.