ACloud.Solutions

ISO 27001 and compliance

ISO 27001 implementation small business guide for the volunteered

The message arrives on a Tuesday. A customer's procurement team has asked whether you hold ISO 27001, the answer is no, and the deal is large enough that somebody senior has decided the answer should become yes. You are the person who knows about security, in the sense that you are the person who knows about everything, and the project is now yours.

Iso 27001 implementation small business projects nearly always start like that. Not from a strategic decision about information security, but from a sales conversation, which matters because it sets a deadline before anyone has established what the work involves.

What iso 27001 implementation small business projects actually involve

The standard has two halves and people spend their effort on the wrong one.

Clauses 4 to 10 are the management system. Understanding your context and interested parties. Leadership commitment, which means real decisions by real managers, recorded. Planning, including the risk assessment and the objectives. Support: resources, competence, awareness, documented information. Operation. Performance evaluation, which is monitoring, internal audit and management review. Improvement, meaning nonconformities and corrective action.

Annex A is 93 controls across four themes: organisational, people, physical and technological. You consider each one, apply the ones relevant to your risks, and justify the exclusions in a Statement of Applicability.

Everybody starts with Annex A because it looks like a checklist and checklists feel tractable. Then the auditor spends the morning asking how the risk assessment method was chosen and whether management review produced any decisions, and the controls turn out to be the easy part. The clauses are the system; the controls are evidence that the system does something.

A realistic timeline

For one person, part time, in a company of a few dozen people with reasonable technical hygiene already in place, six to nine months to certification is achievable. Three months is not, and the reason is not effort.

Two constraints are structural. Stage 2 requires evidence that controls have operated over a period, so you cannot compress the operating window by working harder. And clause 9 requires an internal audit and a management review to have happened before the certification audit, both of which need scheduling around other people's diaries.

A shape that works:

Months 1 to 2. Scope, context, interested parties, gap analysis. Decide what is in and out and write it down properly, because scope shapes everything downstream.

Months 2 to 4. Risk assessment and treatment plan, then the Statement of Applicability derived from it. Policies written and approved during this period.

Months 4 to 6. Implement whatever the treatment plan requires. Start generating evidence deliberately rather than incidentally.

Months 6 to 7. Internal audit, then management review. Fix what the internal audit finds, which is the point of doing it.

Month 7 onward. Stage 1, close the findings, Stage 2.

If the deadline you have been given is shorter than this, the conversation to have now is about which quarter certification lands in rather than about working faster. That conversation goes better in month one than in month five.

Where the time actually goes

Not where people budget it.

The risk assessment, because a defensible one is harder than a complete one. A 200-row register produced in a week will not be maintained and will not survive questioning. A 30-row register with real owners, a stated method and clear links to the controls you selected will. The risk assessment note covers what an auditor actually asks.

Policies and their lifecycle. Writing a policy takes an afternoon. Getting it approved by the right person, acknowledged by staff, and reviewed on a schedule, with evidence of each, takes months of calendar time even though it is hours of work.

Evidence. This is the one that catches everybody. Controls are fine; proving they operated across a period is the work, and it is not retrospective. An access review you performed in February without recording it did not happen as far as the audit is concerned.

The practical consequence: start capturing evidence in month one, before the controls are finished, because the period being sampled at Stage 2 includes the months when you were still building. Scheduled evidence collection pays back more than any other automation in the project.

What to do in the first fortnight

Four things, in this order, none of which require a decision from anybody else.

Write the scope statement. One paragraph naming what is included, what is excluded, and the interfaces and dependencies. This is clause 4.3 and it is the document everything else refers back to.

Do a gap analysis against Annex A. Honestly, in a spreadsheet, with three values per control: in place, partial, absent. Do not fix anything yet. The output is the size of the project, which is what you need for the timeline conversation.

Book the internal auditor. Seriously, in the first fortnight. Independence is the hardest constraint to satisfy at this scale, availability is worse than you expect, and discovering in month six that you cannot arrange it is a delay you cannot recover. The internal audit note covers the options.

Get leadership commitment recorded. Not a conversation, a recorded decision: a management meeting with the scope, the objectives and the resource commitment minuted. Clause 5 requires it, an auditor will ask for it, and it is far easier to obtain in the enthusiasm of month one.

Getting the standard

You need to read the standard, and it is not free. ISO/IEC 27001:2022 is available from ISO and from national standards bodies. Budget for it. Working from summaries and blog posts, including this one, is how you end up confidently wrong about a clause.

Questions

Can one person really do this?

Yes, with two caveats. Internal audit needs somebody who is not you, and leadership decisions need actual managers. Everything else can be done by one competent person alongside another job, over the timeline above.

How much does certification cost?

The certification body's fee depends on headcount and scope and is quoted per engagement, so any figure here would be invented. Get three quotes; they vary more than you would expect. Budget separately for the standard itself and for whatever the treatment plan requires you to buy.

Do I need a consultant?

Not necessarily, and the honest test is whether you have time rather than whether you have knowledge. A consultant compresses the calendar and brings pattern recognition about what auditors accept. If you have nine months and reasonable technical foundations, doing it yourself produces a system you understand, which matters more in year two than in year one.

Is ISO 27001 the right certification?

Not always. If your customers are UK public sector or SME, Cyber Essentials may be what they actually want and it is a fraction of the effort. The comparison note covers which buyers ask for what. Find out what the customer who triggered this actually requires before committing to nine months.

What happens after certification?

A surveillance audit each year and recertification every three. Year two is the one that catches people, because the controls that lapse are the annual ones nobody diarised. The surveillance note covers it.