ISO Consultancy Services

ISO 27001, ISO 42001 and ISO 22301, plus SOC 2 readiness: from gap analysis to certificate.

Certification has become the price of entry: tenders demand ISO 27001, US enterprise buyers ask for a SOC 2 report, customers ask how your Artificial Intelligence (AI) is governed and boards want proof the business can survive disruption. Lexfield Digital Systems is an Irish consultancy that gets you certified. Our consultants have hands-on expertise designing, building and operating production systems, so our advice comes from practice, not templates.

Every engagement is delivered in plain English by Lead Auditor trained practitioners. The first call is free and carries no obligation.

Consultancy

Four frameworks. One way of working.

The three ISO standards share the same management system structure, so they integrate cleanly when you need more than one, without duplicating the scaffolding. None of them is a shortcut to another: each certificate is earned on its own, and plenty of organisations only ever need one. Whichever you are facing, the approach is the same: gap analysis, a roadmap, implementation at your pace and support all the way through the audit.

ISO/IEC 27001:2022

Information security

Implement an Information Security Management System (ISMS) and win the tenders and enterprise customers that require certification. The most trusted security standard in the world and increasingly the entry ticket to serious contracts.

Explore ISO 27001 consultancy →
ISO/IEC 42001:2023

AI governance

Implement an Artificial Intelligence Management System (AIMS), prepare for the European Union's AI Act and answer the AI governance questions your customers are starting to ask. Certified organisations are still rare; early movers stand out.

Explore ISO 42001 consultancy →
ISO 22301:2019

Business continuity

Implement a Business Continuity Management System (BCMS): business impact analysis, continuity and recovery plans, and exercises that prove your business survives disruption. A founding specialism of our practice.

Explore ISO 22301 consultancy →
AICPA SOC 2 · TYPE II

SOC 2 readiness

Prepare for a SOC 2 Type II attestation: control design mapped to the Trust Services Criteria, evidence collection and audit readiness for the report your US customers ask for. The attestation itself is issued by a licensed CPA firm; we get you ready for it.

Explore SOC 2 consultancy →

Independence protects your certificate: certification bodies expect the people who build your management system and the people who audit it to be different, and that separation is what gives your certificate its value. We focus on the consultancy. When you need external audit services, including the internal audits every standard requires, we connect you with independent audit firms, so every part of your certification journey is covered and your certificate keeps its full credibility.

Why Lexfield

Practitioner-led, auditor-trained, plainly priced

  • Built by people who know how you will be judged Our consultants are Lead Auditor trained in ISO/IEC 27001 and ISO/IEC 42001, so everything we implement is designed to withstand the audit that follows.
  • Engineers, not just advisors Our consultants have hands-on experience designing, building and operating production systems, including AI systems. Our advice reflects how technology actually runs, not just how the paperwork reads.
  • Fixed scope, fixed price One number after a scoping conversation, before you commit to anything. No day-rate meters running quietly in the background. If scope grows mid-engagement, the price is re-agreed with you first.
  • Plain English, lean documentation Enough documentation to satisfy an auditor, never so much that nobody reads it. Deliverables written for the people who must act on them.

FAQ

Questions we hear most often

Which standard should we start with?

For most organisations, ISO/IEC 27001: it is the one customers and tenders ask for most. It also builds the management system foundation the others extend. If AI is your product, ISO/IEC 42001 may come first. If your customers depend on your uptime, ISO 22301 may be the priority. The free introductory call exists to answer exactly this question for your situation.

Who do you work with?

Startups and growing companies, mostly between five and 250 people, in Ireland and across Europe. That focus is deliberate: smaller organisations get certified fastest when the consultancy is senior, direct and fixed-price, which is how we work. We are not an enterprise consultancy, so there are no procurement mazes and no junior-heavy delivery teams.

How long does ISO 27001 certification take?

It depends on your starting point, not on a template. A small company with modern cloud tooling and an engaged founder can be audit-ready in a few months, while organisations with more history take longer. Two parts of the timeline sit outside anyone's control: the certification body needs to schedule your Stage 1 and Stage 2 audits, and the standard expects evidence that your system has genuinely run. The gap analysis gives you a dated, honest plan rather than a promise.

What does certification cost?

Three components: our consultancy fee, the certification body's audit fees and any tooling you choose to adopt. Our fee is fixed after a scoping conversation, so you know the number before you commit, and we help you get comparable quotes from certification bodies. Try the cost calculator and we will send you a tailored estimate.

Can we do more than one standard at once?

Yes. It is often cheaper than doing them separately, because the standards share the same clause structure: one integrated management system can cover information security, AI governance and business continuity together, with one set of audits and one management review cycle.

Do you help with SOC 2?

Yes. We provide consultancy for SOC 2 readiness, including Type II: control design against the Trust Services Criteria, evidence collection and preparation for the examination. The attestation itself is issued by a licensed CPA firm, which mirrors the independence rule we apply to ISO work: we prepare you, an independent party examines you.

Do you audit or certify?

We are implementation consultants, by design. Certification is issued by accredited certification bodies, and audits come from someone independent of the building work, which is what makes your certificate worth having. We prepare you so thoroughly that the audit holds no surprises and connect you with independent audit specialists when you need them.

We have implemented a management system. What happens next?

Certification, in most cases. Once the system is built and has run long enough to produce real evidence, an accredited certification body examines it in two stages and, if satisfied, issues your certificate. We prepare you for that examination, help you choose the body and get comparable quotes.

Why does certification have to come from an external body?

Because the certificate's entire value is the independence of whoever issued it. Certification means an outside party with nothing at stake has confirmed your management system meets the standard. That is what lets a customer or tender panel accept the certificate instead of auditing you themselves.

Can we just certify ourselves?

You can declare that you conform to a standard, and nothing stops you designing a badge to go with it. The question is who would believe it. A self-issued certificate carries no independent assurance, so the tenders and enterprise customers that ask for certification will not accept it. Independence is the product; that is why accredited bodies exist.

What happens after we are certified?

Certification runs on a three-year cycle: surveillance audits in years one and two, then recertification. Between audits the management system has to keep running, through management reviews, objectives, internal audits and corrective actions. We stay involved as lightly or as closely as you want, from an annual health check to running the calendar with you. Internal audits must come from someone independent of us, which is why we refer that work out.

Do you only work with Irish organisations?

No. We are based in Co. Cork and work across Ireland, but the standards are international and most consultancy runs perfectly well remotely, with on-site days where they add value.

Get started

Tell us what you are trying to prove. We will map the route.

Whether it is a tender that demands ISO 27001, a customer asking about your AI or a board asking what happens if the systems go down: the first call is free, carries no obligation and requires no defined project.

Book a free introductory call