A clear, costed route to certification
ISO 27001 and Security Assessment
Independent ISO 27001 gap analysis and security assessment for UK scaling businesses.
We tell you exactly what stands between your current controls and certification, and what it will take to close the gap, delivered for your business by practising fractional CISOs.
BOOK A SECURITY CALL
What an ISO 27001 gap analysis actually means
An ISO 27001 gap analysis measures your current information security controls against the requirements of the standard, and tells you precisely what needs to change before an accredited body will certify you. It is not a generic security review with the ISO name attached, it is a structured comparison against the actual clauses and Annex A controls of the standard.
The value is in the specificity. A vague sense that "security could be better" does not get you certified and does not tell your board what to invest in. A proper gap analysis gives you a scored view of every control area, a realistic timeline, and a costed plan for closing the gaps that matter, in the order that matters.
This is exactly the work that sits inside a fractional CISO engagement, and for many businesses it is the first, concrete step toward one. Certification is a milestone, not the goal. The goal is a security posture your customers, your board, and your insurer can actually trust.
What we deliver
- Security assessment and gap analysis. An honest, scored read of where your security and your ISO 27001 readiness stand against every relevant clause and Annex A control, and exactly what needs to change.
- ISO 27001 implementation. We build the information security management system, the controls, and the policies, and get you audit-ready.
- Certification support. We take you through the accredited body's Stage 1 and Stage 2 audits with a senior hand on the tiller, so certification is not a scramble.
- Ongoing security leadership. Unlike a one-off consultant, your fractional CISO keeps leading security after the certificate, because the audit is the start, not the end.
- Risk and compliance. We manage security risk and wider compliance, such as SOC 2, Cyber Essentials, and DORA where they apply to your business, so it is owned by someone senior and accountable.
- Enterprise-sale and investor readiness. We get your security posture and evidence into the shape buyers and investors expect, so security accelerates deals instead of blocking them.
Who it is for?
- CEOs and boards who need ISO 27001 to win or keep enterprise, public sector, or regulated customers.
- Scaling businesses, roughly £5M to £50M revenue, that have never had a formal security assessment against the standard.
- Businesses preparing for investment, where a credible security posture is increasingly part of due diligence.
- Companies that bought a compliance tool and have realised that software does not lead security, people do.
- Leaders who want security owned by someone senior and accountable, not bolted on as a project.
Why Boardman?
Operators, not compliance-only consultants. Our assessments are led by practising fractional CISOs who have run real security programmes, not consultants who only work in audit documents.
Specific, not generic. You get a scored, evidenced view against the actual standard, with a costed plan attached, not a checklist of best practice.
Independent of any certification body. We have no commercial relationship with any accredited body, so our assessment of your readiness is honest, not designed to sell you a longer engagement.
Leadership, not a one-off certification project
Almost everyone who ranks for ISO 27001 in the UK is one of two things. A compliance consultancy that runs a project, gets you the certificate, and leaves. Or a piece of software that automates the evidence trail and calls that compliance.
Both have their place, and if all you need is the certificate, either might be enough. But neither of them leads your security. Nobody owns the risk, nobody sits in the board meeting when a customer's security questionnaire lands, and nobody is accountable when the surveillance audit comes round twelve months later and the controls have quietly drifted.
A fractional CISO is a different answer. A senior security leader who assesses where you stand, builds the management system, takes you through certification, and then keeps leading security because the audit was never the point. You get the certificate. You also get someone whose job it is to make sure it still means something next year.
If you have already bought a compliance platform and found it does not tell you what to do, this is usually the conversation you need to have.
How it works
- Security call. We understand your business, your risks, and why you need certification.
- Assessment and gap analysis. We establish exactly where you stand against every relevant clause and Annex A control of the standard.
- Roadmap. You get a prioritised, sequenced plan to close the gaps and reach certification, with realistic timelines.
- Implementation. Your fractional CISO leads the build of the ISMS, controls, and policies.
- Certification. We take you through the accredited body's Stage 1 and Stage 2 audits.
- Ongoing leadership. Your CISO keeps security led and the certification maintained, for as long as you need.
Let's talk about your security posture, without the jargon.
No pitch. An honest conversation about where you stand against ISO 27001, with someone who has run a real security programme.
Questions? Check out our FAQs.
What is an ISO 27001 gap analysis?
Do we need ISO 27001 certification?
How long does ISO 27001 certification take?
What is the difference between a security assessment and an ISO 27001 gap analysis?
Can you help us achieve certification, not just identify the gaps?
Do you carry out the ISO 27001 certification audit yourselves?
How much does ISO 27001 certification cost?
Do we need a consultant, a compliance tool, or a CISO?
Who carries out the ISO 27001 and security assessment?
The Boardman Newsletter
Actionable advice for mid-market leaders. Every Saturday.
Join 3,267 CEOs, CFOs and COOs.
By submitting, I agree to receive emails from Boardman and understand I can unsubscribe any time via the unsubscribe link at the bottom of all emails.