ISO 27001 consultant in Durham

We are based at Belmont Business Park in Durham. Work with a practitioner who can sit in your office for the workshops that matter and run everything else remotely — finishing with a live management system in your own workspace, not a folder of documents.

What we do for Durham organisations

On-site or remote gap analysis

A clause-by-clause and Annex A assessment against ISO/IEC 27001:2022, delivered at your office or over video, with a phased plan and named owners.

Risk assessment run with your team

A working risk register built in session — assets, threats, treatments and owners — not a template left for you to interpret.

Policies and Statement of Applicability

AI-assisted drafting reviewed line by line, so wording reflects how your organisation actually operates rather than a generic pack.

Internal audit and management review

Clauses 9.2 and 9.3 run properly before the certification body arrives, with findings closed and evidence verified.

Stage 1 and stage 2 attendance

Preparation sessions, evidence rehearsal and someone alongside your team during the certification assessment.

The platform after handover

Risks, controls, owners and evidence stay in your own workspace, so surveillance year one is maintenance rather than another project.

Local scope and coverage

Our office is at Portland House, Belmont Business Park, Belmont, Durham DH1 1TW. Most County Durham sites are within 30 minutes, so on-site workshops, evidence walkthroughs and audit days do not carry travel charges.

  • Durham city and Belmont
  • Chester-le-Street and Consett
  • Bishop Auckland and Newton Aycliffe
  • Darlington and Teesside
  • Newcastle, Gateshead and Sunderland
  • Remote across the rest of the UK

Prefer to talk first? Call +44 7876 191172 or use the contact page.

Regional work we have delivered

Client names are withheld under NDA; these are anonymised summaries of engagements in the North East.

Software company, Durham

Certified to ISO 27001:2022 in five months from a standing start, with the risk register, Statement of Applicability and evidence maintained in one workspace afterwards.

Professional services, County Durham

Lapsed management system recovered ahead of a surveillance visit; 14 nonconformities closed and internal audit brought back onto a rolling programme.

Public-sector supplier, Teesside

ISO 27001 and Cyber Essentials Plus aligned to a single control set so tender questionnaires could be answered from one evidence base.

Other standards supported locally

Working outside the North East? Remote ISO consultancy covers the rest of the UK on the same methodology.

Free ISO 27001 readiness assessment for Durham organisations

Instant download, no sales call. We reply within one business day.

Answers buyers, procurement and auditors want

Do you actually visit sites in Durham?+

Yes. The office is at Portland House, Belmont Business Park, so kick-off, risk workshops, internal audit fieldwork and stage 2 attendance can all be delivered in person across County Durham without travel charges. Routine implementation sessions are usually run over video because they are quicker for both sides.

How much does ISO 27001 certification cost in Durham?+

Certification body fees for a UK organisation under 50 people typically fall between £4,000 and £9,000 over the three-year cycle, with consultancy quoted separately per phase. Our cost guide breaks the line items down; nothing about the pricing changes because you are in the North East.

How long will certification take?+

Three to four months from kick-off to stage 1 is realistic for a team under 50 with reasonable existing practice, and around six months where policies, risk management and evidence all need building. Your availability for evidence collection is the main variable.

Can you help with ISO 9001 or ISO 42001 at the same time?+

Yes. Context, leadership, internal audit and management review clauses are shared, so running an integrated management system is materially cheaper than sequential projects. We support ISO 9001, ISO 42001 and ISO 20000-1 alongside ISO 27001.

Can you also be our certification body?+

No — and no legitimate consultant can. Accreditation rules prevent a certification body from certifying a management system it helped build. We work alongside UKAS-accredited bodies and prepare you for their assessment.

Do we have to buy the software as well?+

No. The consultancy stands alone. Most clients keep the platform because it holds the risk register, controls, owners and evidence produced during the project, which makes surveillance audits far less work.

AI-enabled — privacy-respecting

AI does the drafting. You keep the control — and the data.

How we handle data →
  • AI that assists — not replaces

    Assisted drafting for policies, risks, controls and buyer questionnaires. Every AI suggestion is reviewed and approved by you before it lands in the record.

  • Opt-in, workspace-scoped

    AI features run only when you invoke them, only against the workspace you're in. We never mine your data to answer someone else's prompt.

  • Your data stays yours

    Prompts routed via the AI Gateway to model providers whose API terms exclude your content from model training. Nothing is sold or shared for advertising.

  • Isolated by design

    Row-level security enforces workspace boundaries at the database. MFA, SSO, audit logs and least-privilege roles govern who sees what.

We never sell personal information, never share it for advertising, and never use your workspace content to train third-party models. Full sub-processor list and Acceptable Use Policy on the Trust page.

MM
Michael McCarroll
Founder · 25+ years
IT governance · Information security · AI
Why this platform exists

Enterprise-grade governance — built for the SMEs and consultants enterprise GRC forgets.

I've spent 25 years in corporate governance — aligning technology, controls and compliance with what the business is actually trying to do. Time and again, the same pattern: the organisations that win new clients aren't the ones with the biggest GRC budget. They're the ones who can demonstrate trust on demand. This platform is the tool I wanted for the SMEs and consultants I've worked with — institutional-grade governance without an institutional price tag, built on the way audits and buyer reviews actually happen.