Disclaimer
Read this as the terms on which everything else here is published.
What this site is not
iso27001partners.co.uk is not a certification body. It is not accredited by UKAS or by any other accreditation body, it does not audit management systems, and it cannot issue, arrange, expedite or influence any certificate. Only a certification body can issue a certificate, and you appoint one yourself.
It is not a consultancy. Nothing here is advice on your own information security management system, your scope, your risk assessment or your Statement of Applicability. General information about what a standard requires is not the same thing as advice about what your organisation should do, and only the second one is worth relying on.
It is not an accreditation body, not affiliated with ISO, IEC, UKAS, the IAF or any certification body, and not endorsed by any of them. Standard numbers and clause references appear here for identification, which is what they are for.
It is not a referral service. We do not rank, score, vet or recommend consultancies, and we do not attempt to match an enquiry to the “right” firm. Enquiries go to consultancies advertising for that sector without independent review by this site.
How this site is paid for
Consultancies pay a fixed advertising fee for each enquiry we pass on. The fee is agreed in advance. It does not vary with the size of any engagement, with what a consultancy charges you, with whether you go on to certify, or with anything else about the outcome. We are paid the same whether an enquiry turns into a large engagement, a small one, or nothing at all, and the same whichever consultancy receives it.
That structure is the reason the comparison tables on this site can be read at face value: no version of them pays us more than any other. It is also the reason we publish figures that argue against buying anything, such as when Cyber Essentials is the proportionate answer and ISO 27001 is not yet.
The limits of the figures
Audit-day counts, the surveillance and recertification fractions, the adjustment ceiling, the Annex A control counts and the clause quotations are read from the standards and rules named beside them, and the edition year is printed with every count. Those are as accurate as the source. Every monetary figure on this site is an estimate, is shown as a range rather than a single number, and is labelled. There is no published day rate for UK certification bodies, and no compliance-automation platform publishes a price, so nobody — including us — can state those as fact. The methodology page names the rates used and shows the arithmetic so you can substitute your own.
Standards are revised, prices move and accreditation status changes. Every page carries the date its sources were last checked. A figure you are relying on months later is worth re-checking against the source we link.
Your data
If you send an enquiry, the details you give are passed to no more than three ISO 27001 consultancies advertising for your sector, so that they can contact you about the work you described. That is the only thing we do with them. You can withdraw consent at any time by replying to any message you receive, or by writing to contact@iso27001partners.co.uk, and we will delete your details on request.
No relationship is created
Sending an enquiry does not engage us, any consultancy or any certification body, and creates no contract with anyone. You decide who, if anyone, you speak to, and any engagement that follows is between you and that firm on their terms.