ISO/IEC 27001 · Information Security

Get ISO 27001 certified and win the contracts that require it.

More and more tenders and enterprise customers will only buy from ISO 27001 certified suppliers. Lexfield Digital Systems is an Irish consultancy that takes you from wherever you are today to certification: we design and implement your Information Security Management System (ISMS), prepare you for the certification audit, and stay with you all the way to the certificate. Our consultants are Lead Auditor trained, so your ISMS is built by people who know precisely how it will be judged.

Certification is issued by an independent accredited certification body; our job is to get you through their audit first time. Looking for an auditor rather than a consultant? We will refer you to independent audit specialists.

Why ISO/IEC 27001

Certification that pays for itself in won contracts

More and more tenders, enterprise procurement processes and regulated customers now treat ISO/IEC 27001 as the entry ticket. Beyond the badge, a well-built ISMS gives you a working system for finding and treating security risk before it becomes an incident.

Win and keep business

Answer security questionnaires in minutes instead of weeks, qualify for tenders that require certification, and give enterprise buyers the assurance they ask for before they sign.

Meet legal obligations

A certified ISMS supports your compliance with the General Data Protection Regulation (GDPR) and with the contractual security commitments you make to customers and partners.

Reduce real risk

Risk assessment, defined controls and continual improvement mean fewer surprises: you know what your critical information assets are, where they are exposed, and who owns the fix.

Build customer trust

Certification is independent proof that your security is managed to an international standard, not a claim on your website. It protects your customers' data and your reputation with it.

Working out your route? The first call is free and carries no obligation: clear, practical advice either way.

Book a free introductory call

Services

What our ISO 27001 consultancy includes

We do one thing here: implementation consultancy, delivered by Lead Auditor trained practitioners. Advisory and audit stay in separate hands, which is what keeps your certificate fully credible. When you need an auditor, we connect you with independent specialists.

Consultancy

Implementation and certification support

For organisations building an ISMS from scratch or getting an existing one ready for certification.

  • Gap analysis against ISO/IEC 27001 with a prioritised roadmap
  • Risk assessment and risk treatment planning
  • Policy and documentation development, written for your business rather than copied from templates
  • Statement of Applicability (the document that records which Annex A controls apply to you and why)
  • Annex A control implementation across organisational, people, physical and technological themes
  • Management review and internal communication support
  • Stage 1 and Stage 2 certification audit preparation, including liaison with your certification body
  • Nonconformity remediation support after audits, turning findings into closed actions

Two ways to work with us

Both are fixed-price. Pick the balance that suits your team, or move between them as the project runs.

Option 1 We build with you

We take the lead on drafting and building, and you review, decide and approve. The fastest route when your team is stretched.

Option 2 We coach, you build

Your team does the building while we guide, review and course-correct. More of the knowledge stays in-house, and the fee reflects the lighter touch.

Independence protects your certificate: certification bodies expect the people who build your management system and the people who audit it to be different, and that separation is what gives your certificate its value. We handle the building. When you need external audit services, including the internal audits the standard requires, we connect you with independent audit firms, so every part of your certification journey is covered and your certificate keeps its full credibility.

Process

From first conversation to certificate

  1. Gap analysis

    We review your current security practices against every clause of the standard: interviews with the people who run things, a look at how you actually work and a review of your existing documentation and records. You get a plain-English report: what you already have, what is missing and how long the journey will realistically take.

  2. Risk assessment and planning

    Together we identify your information assets, assess the risks to their confidentiality, integrity and availability, and agree a treatment plan that reflects your actual business, not a generic checklist.

  3. Build the ISMS

    Policies, controls, training and records take shape, at a pace your team can absorb. We keep documentation lean: enough to satisfy an auditor, never so much that nobody reads it.

  4. Internal audit and management review

    Before any certification body sees your ISMS, an independent auditor puts it through the internal audit the standard requires. We help you engage one, support you through the audit, close out its findings, and guide your leadership team through the management review.

  5. Certification: Stage 1 and Stage 2

    We support you through both stages of the certification audit, from the Stage 1 documentation review to the Stage 2 assessment of your ISMS in operation, and stay with you through any findings.

Who you work with

Practitioner-led, auditor-trained

Lexfield's consultants bring hands-on experience designing, building and operating digital systems. Security is not theory for us: it is how we have delivered real systems, and our consultancy is led by practitioners with formal auditor training.

  • ISO/IEC 27001 Lead Auditor training Certified Lead Auditor training completed with SEQM, covering audit planning, execution and reporting to the standard certification bodies apply.
  • ISO/IEC 42001 Lead Auditor training Lead Auditor training in ISO/IEC 42001, the international standard for Artificial Intelligence Management Systems, for clients whose security programme now has to cover AI.
  • Hands-on systems experience Our consultants have hands-on experience designing, building and operating production systems, so our audit findings and implementation advice reflect how technology actually runs, not just how the paperwork reads.
  • Built for small and medium businesses Fixed-scope engagements, plain-English deliverables and a documentation style sized for teams without a full-time compliance department.

The standard explained

What is ISO 27001?

ISO/IEC 27001 is the international standard for Information Security Management Systems (ISMS), published jointly by the International Organization for Standardization (ISO) and the International Electrotechnical Commission (IEC). The current version is ISO/IEC 27001:2022. It defines how an organisation should establish, implement, maintain and continually improve a management system that protects the confidentiality, integrity and availability of its information. Certification means an accredited certification body has independently audited your ISMS and confirmed it meets the standard.

Clauses 4 to 10 contain the mandatory requirements every certified organisation must meet. In plain English, they require the following:

  • Clause 4: Context of the organisation Define what your ISMS covers, the internal and external issues that affect it, and what your customers, regulators and other interested parties expect of it.
  • Clause 5: Leadership Top management must own information security: set the policy and objectives, resource the system, and assign clear responsibilities. Security cannot be delegated into a corner.
  • Clause 6: Planning Run a documented risk assessment, decide how each risk will be treated, and record which Annex A controls apply to you and why in a Statement of Applicability.
  • Clause 7: Support Provide the resources, competence, awareness and controlled documentation the system needs. People must know the policy and their part in it.
  • Clause 8: Operation Run the controls day to day, keep evidence that they operate, manage changes, and keep risk assessments current as the business changes.
  • Clause 9: Performance evaluation Monitor and measure the system, run internal audits, and hold management reviews. This is where independent auditors come in every year.
  • Clause 10: Improvement Deal with nonconformities properly: find the root cause, fix it, check the fix worked, and keep improving the system rather than letting it fossilise.

When the risk assessment finds something

The standard gives you four honest options for every risk, and the auditor wants to see a documented decision, not an accident:

Mitigate

Reduce the risk with controls. Annex A’s 93 controls are the menu, from access management to encryption and training.

Accept

A documented decision that the risk sits within your appetite, reviewed as the business changes.

Transfer

Move the risk to someone better placed to carry it, such as insurance or a specialist supplier.

Avoid

Stop doing the risky thing: retire the system, change the process or decline the activity.

The audits

The audits you will meet, and who conducts them

Certification is a cycle of audits, each with its own job. We prepare you for every one of them, and each is conducted by a party independent of us, which is what keeps your certificate credible.

  • Internal auditIndependent auditor Required by Clause 9.2 at least annually: your own check that the ISMS works, done before any external auditor arrives. We connect you with independent providers and get you ready for it.
  • Stage 1: documentation reviewCertification body The certification body reviews your ISMS documentation, confirms the scope makes sense and tells you whether you are ready for Stage 2.
  • Stage 2: certification auditCertification body The full assessment of your ISMS in operation: interviews, evidence and control testing. A successful Stage 2 wins the certificate.
  • Surveillance auditsCertification body Shorter annual visits in years one and two, confirming the system keeps running and improving between certifications.
  • RecertificationCertification body A fuller reassessment every three years that renews the certificate and restarts the cycle.

Also from Lexfield

Business continuity, from the same discipline

Information security keeps your data safe; business continuity keeps your business running when something goes wrong anyway. We provide consultancy for ISO 22301, the international standard for Business Continuity Management Systems: business impact analysis, continuity and recovery planning, and exercising your plans so they work under pressure, not just on paper. Business continuity is a founding specialism of our practice, and ISO 27001 itself requires continuity controls, so the two engagements reinforce each other. Ask us about ISO 22301.

FAQ

Questions we hear most often

How long does ISO/IEC 27001 certification take?

For most small and medium organisations, between four and nine months from gap analysis to certificate, depending on how much of the groundwork already exists and how quickly decisions get made. We give you a realistic timeline after the gap analysis, not a sales estimate before it.

How much does ISO 27001 certification cost?

Two costs are involved. Consultancy fees for implementation support typically range from 10,000 to 20,000 euro in the Irish market, depending on the size and complexity of the organisation. The certification body's own audit fees are separate and quoted by them. We work fixed-scope and fixed-price: after a scoping conversation you get one number, before you commit to anything. If the scope changes mid-engagement, the price is re-agreed with you before any extra work happens, never discovered on an invoice.

Is ISO 27001 a legal requirement?

No. ISO 27001 is voluntary. In practice, though, it is increasingly a commercial requirement: many tenders and enterprise customers require certification before awarding business. It also provides strong supporting evidence for legal obligations you do have, such as the security requirements of the General Data Protection Regulation (GDPR).

Is ISO 27001 worth it for a small business?

If your customers or target tenders require it, yes, unambiguously: certification is the entry ticket. If not, the honest answer is that it depends on what your information is worth and who you want to sell to. A right-sized ISMS costs far less than most owners expect and often pays for itself the first time a security questionnaire arrives. We will tell you plainly in the first call if we think you do not need it yet.

Do you issue the certificate yourselves?

Certificates come from an independent accredited certification body after a two-stage audit; that independence is exactly what makes yours valuable. We prepare you for that audit, help you choose a certification body, and help you engage an independent auditor for the internal audits the standard requires along the way.

We are already certified. What can you do for us?

Certified organisations must keep the ISMS alive: internal audits, management reviews and yearly surveillance visits. On the consultancy side, we help you close findings, improve controls and keep documentation current between surveillance audits. For the audits themselves, we refer you to independent audit specialists.

What is the difference between an internal audit and the certification audit?

The certification audit is performed by the certification body and decides whether you gain or keep the certificate. An internal audit is one your own organisation must arrange, under Clause 9.2 of the standard, to check the ISMS is working. Internal audits can be outsourced to a qualified external auditor. Lexfield deliberately does not offer this, so consultancy and audit never mix. We can refer you to independent providers.

What happens if the audit finds problems?

Almost every audit finds something, and the grading matters more than the finding. Minor nonconformities are isolated slips that you correct within an agreed window; certification proceeds. Major nonconformities are gaps in the system itself and must be closed before the certificate is issued or retained. Observations and opportunities for improvement carry no penalty at all. Our preparation runs you through the same checks beforehand, so what the auditor finds is small, expected and already half-fixed.

Get started

Tell us where you are. We will map the route.

Whether you are starting from a blank page or preparing for next year's surveillance audit, the first call is free, carries no obligation, and you do not need a defined project to have it. Early clarity prevents wasted months later.

Book a free introductory call