ISO 27001 CONSULTANCY
Get ready for ISO 27001 certification in 90 days.
- Personal ISO 27001 coaching
- Fixed Fee
- Fully remote worldwide
- First-pass guarantee
- Includes internal audit
I’m Alan Parker. For over 10 years, I’ve helped UK SMEs cut through the complexity of information security.
First Pass Guarantee · UK-Based, Remote-First · Templates Included · Cancel any time

Alan Parker, ISO 27001 Consultant
90
days
Typical certification window
£3,500
Fixed fee
5
sessions
1-to-1 with me, not a team
100
%
First-pass guarantee
WHY THIS WORKS
A 90-day programme built for SMEs that need to move
Most ISO 27001 guidance is written for large corporations. This is the opposite — a programme designed for B2B tech, SaaS, and professional services firms with a deadline.
You work with me directly
No juniors, no hand-offs, no offshore team.
I personally deliver every session.
Thirty years in IT governance — ITIL Expert, PRINCE2 Practitioner, CISMP — distilled into a plain-English programme.
Minimum viable compliance
Right-sized for SMEs.
The minimum to pass your first audit cleanly, with a foundation you can build on.
No bloated documentation. No theatre. Aligned to ISO/IEC 27001:2022 and the 93 Annex A controls.
A fraction of the cost
Traditional consultancy drags on for six months and costs five figures.
£3,500 fixed fee, three-month payment plan available, 20% discount for micro-organisations.
No day rates, no surprises.
Five private 1-to-1 checkpoint sessions (Zoom or Teams)
All mandatory ISO 27001 templates and worked examples
Unlimited support between sessions
Access to my online ISO 27001 course for up to 3 users
A vetted list of trusted, low-cost auditors
Pass guarantee — if you don’t pass, I fix it free
Internal audit is included as standard
30-day 100% credit toward toolkit or course upgrades
The process
Five focused workshops. One clear path.
Each session takes you through a chunk of the standard. Between sessions, you adapt my templates at your own pace. Most clients finish in 8–12 weeks.
Workshop 1 · Week 1–2
Kick-off & Scope review
We start by setting the foundations and agreeing on what’s in and out.
- Define your ISO 27001 scope and context
- Review existing policies and documents
- Draft your Information Security Policy
- Capture roles, responsibilities, and leadership objectives
- Agree on your project plan and certification timeline
Workshop 2 · Week 3–4
Risk review
Identify what could actually hurt the business and decide what to do about it.
- Create or refine your risk-assessment method
- Identify key risks: suppliers, ransomware, outages, attacks
- Build your risk treatment plan
- Align with Clause 6: Planning
Workshop 3 · Week 5–8
Controls & Statement of Applicability
Map Annex A’s 93 controls to your business — proportionate, justified, defensible.
- Walk through Annex A control groups
- Clarify inclusions and justified exclusions
- Finalise your SoA using my proven template
- Integrate Clause 7 (Support) and Clause 8 (Operation)
Workshop 4 · Week 9–10
Monitoring, performance & improvement
Show how your ISMS performs in practice — and that you can prove it.
- Key performance metrics and audit evidence
- Internal audit planning and sample audit records
- How to run an effective management review
- Clause 9 (Performance) and Clause 10 (Improvement)
Workshop 5 · Week 11–12
Internal Audit Review
I’ll perform an internal audit, per the requirements, and create your report.
- Verify every mandatory document is complete
- Confirm evidence of implementation exists
- Resolve any nonconformities before the audit
- Practise answering typical auditor questions
Real organisations, real certifications



PRICING
One fixed fee. Two ways to pay.
The full 90-day programme is £3,500 + VAT. Pay up front and save, or spread it over three months — same scope either way.
- £350 saving on a single payment
- All five sessions included
- Templates, course access & auditor list
- Cancel any time, pro-rata refund
- First-pass guarantee
- Month 1: £1,166
- Month 2: £1,166
- Month 3: £1,166
- Maximum flexibility, no discount
- Same scope, same guarantee
.
A 20% discount for micro-organisations (3 or fewer employees).
Typical auditor fees for SMEs range from £2,500 to £6,500 (not included). Fees depend on the type of accreditation, the auditor, and the scope of the ISMS. There must be a separation between the consultant and the auditor.
Engage with confidence
Two Guarantees
This method is tried and tested. If you follow it, you’ll pass. Here’s how I back that up.
Cancel any time for a pro-rata refund.
If the approach isn’t for you, walk away. I’ll refund a pro-rata amount based on the sessions remaining — you only ever pay for what you’ve used.
E.g. 2 out of 5 sessions taken → 60% refund
Pass, or I fix it for free
If your auditor identifies any nonconformities that prevent certification, I’ll work with you free of charge to resolve them and liaise with the auditor until you pass. That’s how confident I am in this method.
who this is for
A straight answer: is this right for you?
I work best with a specific kind of organisation. If you fit the left column, we’ll move fast. If you fit the right, you’d be better off elsewhere.
This works for you if…
You’re a B2B tech company, SaaS provider, startup, or professional-services firm
You have up to 250 employees
You can make decisions and changes quickly
You can find around 5 hours a week to work on it
You want to own your ISMS — not outsource it forever
You have a deadline from an enterprise customer
This isn’t for you if…
You’re a larger enterprise with more than 250 staff
Your organisation struggles with fast-paced change
You want someone to “just do it for you”
You can’t carve out time across 8–12 weeks
You need on-site, in-person delivery
A realistic 90 days
What the journey actually looks like
The quickest client got there in 20 days (non-accredited) and 68 days (UKAS-accredited). I recommend most clients target 90 days to be audit-ready with comfortable headroom.
| When | Milestone |
|---|---|
| Week 1-2 | Kick-Off & Scope Review |
| Week 3–4 | Risk Review |
| Week 5–8 | Statement of Applicability |
| Week 9–10 | Performance & Improvement |
| Week 11–12 | Internal Audit / Readiness Check |
| Week 12→ | Audit with Certification Body |
Optional Add-On:
Detailed Internal Audit
ISO 27001 requires an internal audit before certification. A risk-based internal audit is included as standard in the programme — covering key clauses and a selection of Annex A controls.
If you want more thorough coverage, the full audit upgrade is available:
| Option | What’s Covered | Price |
|---|---|---|
| Risk-based audit | Key clauses + selection of controls | Included |
| Full audit upgrade | Every clause + all 93 controls | +£1,500 + VAT |
Deliverables include an internal audit programme and method, a formal audit report, and a detailed list of findings and recommendations.
The normal rate for a standalone internal audit is £2,500.
Working With UK and International Clients
My ISO 27001 consultancy is based in the UK and delivered entirely remotely via Zoom or Microsoft Teams. I work regularly with organisations across London and the South East, as well as clients throughout the UK, Europe, USA, and beyond.
If you’re based in London or elsewhere in the UK and need ISO 27001 consultancy that fits around your team rather than the other way around, remote delivery means there’s no compromise on quality — and no travel costs inflating your bill.
FAQs
Where are you based?
I’m located in the UK. But the service is frequently delivered over video meetings.
Do you work with non-UK organisations?
Yes. I’ve worked with many companies across the world (Europe, USA, New Zealand).
Why are the auditor costs ‘estimates’?
I don’t control the auditors, and they don’t control me – there must be a separation between the consultant and the auditor to avoid a conflict of interest. The auditors will quote based on a variety of factors, so the above costs are estimates based on smaller organisations with <100 staff.
Can you do a UKAS certification in 3 months?
Just about. UKAS-accredited auditors require approximately 3 months of evidence build-up before certification. However, this doesn’t stop you from engaging and then running your ISMS for several months before the audit.
Will it be you, or someone else, working with us?
I personally work with every client and don’t hand you off to someone else.
Do you offer ISO 27001 consultancy in London?
Yes — although I’m based outside London, all consultancy is delivered remotely, which means London-based organisations get exactly the same service without the day-rate premium that comes with in-person consultancy. I work with several London and South East clients each year.
What are the full costs of ISO 27001?
I’ve written about those here. ISO 27001 Certification Costs.
Your Rapid Path to ISO 27001
Get certified quickly, cleanly, and without overspending on consultancy fees.
ISO 27001 certification isn’t about perfection on day one.
It’s about meeting the requirements, establishing a solid baseline, and building security maturity over time. I’ll guide you through my tried-and-tested consultancy framework so you can tailor it to your organisation’s needs.
Background
Alan Parker, is an ISO 27001 consultant and founder of Iseo Blue Limited. He helps UK SMEs achieve certification in 90 days or less, often without a dedicated security team or a large budget.
With over 30 years in IT governance and information security, Alan works with software companies, IT service providers, managed service providers, and professional services firms across the UK, Europe, and internationally.
Qualifications: Certified ISO 27001 Lead Auditor (ANAB-accredited certification), ITIL v3 Expert, ITIL v4 Bridge, PRINCE2 Practitioner. Named IT Project Expert of the Year (2024, UK). Alan writes in plain English for busy teams who need to get things done.
Connect on LinkedIn or Bluesky, or explore his free ISO 27001 tools and templates at iseoblue.com. B.Sc (Hons) Information Systems, CISMP certified.

