ISO 27001 Certification

The gold standard of information security for SaaS and Information Technology companies.

Reassure your clients that you can be trusted.

Get a Quote

Get a Quote
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.

Trusted by

What is ISO 27001?

ISO 27001 is the gold standard for information security. It is a recognised framework for managing information security and requires organisations to implement an Information Security Management System (ISMS) to protect client data.

To achieve ISO 27001 certification, a company must be audited by an accredited certification body. This is where Tempo Audits comes in - a boutique information security certification body dedicated to ISO 27001.

Reviews

ISO 27001 certification, delivered with the clarity, pace, and human approach modern teams expect.

Thanks to Tempo Audits for making our ISO 27001 audit such a smooth experience, clear, pragmatic and genuinely pleasant throughout.
Yannick, Director @ iWebDevelopment
We transferred to Tempo from one of the established certification bodies — and we are delighted with the choice. Our audit was one of the smoothest we’ve had in terms of collaboration and engagement.
Laurence, Director of IT & Client Services @ RDT
Tempo lives up to its name, as we were able to plan, prepare and carry out our ISO27001 audit within a very short time. No other company we contacted was faster or more straightforward during the process.
Lukas, CEO & Co-Founder @ Noreja Intelligence
If Carlsberg did auditors… We use Tempo for our ISO 27001 auditing and I'm thrilled that we were introduced. They ensured that the process dovetailed so smoothly with our ongoing operational activities that the impact was barely noticeable.
Jason, Director of Operations @ The Risk Factor
Alfonso was nothing short of brilliant. Having worked with many auditors over the years, he stood out for his clarity, professionalism, and kindness. He completely changed my view of auditors.
Amardeep, Director @ Blue Edge
I did a LOT of research into ISO 27001 UKAS certification bodies before I went with Tempo, and they were the best option by a long way, and really delivered on it!
Dominic, CEO @ TellJO
Tempo combine deep expertise with a highly pragmatic and customer-centric approach - especially valuable for early-stage tech companies navigating ISO 27001 for the first time.
Joe, CTO @ Flowzar
Is it weird to say I had a good time? We had worked with a more traditional auditor, but they didn't understand the needs/tech of our start-up. Tempo knew how to use our ISMS software and understood our business.
Jonny, Head of Engineering @ Nomio

Who needs 
ISO 27001?

More and more companies are pursuing ISO 27001! 

Industries commonly pursuing ISO 27001 include:

SaaS, IT, finance, fintech, law firms, legal tech, insurtech, insurance, healthtech, education, and edtech. 

We live in a world of frequent data breaches and cyberattacks, making information security increasingly important. While many organisations choose to build and operate an effective Information Security Management System (ISMS) to protect themselves, the push to become ISO 27001 certified is often driven by external stakeholders. 

Common drivers include customer requirements, procurement and tender processes, grant conditions, and insurance expectations.

Customer demand is the most common trigger we see. For example, a SaaS company may provisionally win a new client, only to find that ISO 27001 certification is required to pass procurement before the contract can proceed. This often creates urgency to certify within a short timeframe so the client can be activated.

This scenario is becoming increasingly common and is driving rapid growth in ISO 27001 adoption. According to the ISO Survey, the number of valid ISO/IEC 27001 certificates worldwide increased from 48,671 in 2023 to 96,709 in 2024, almost doubling in a single year.

How much does ISO 27001 cost?

The cost of an ISO 27001 audit is driven by the headcount of the company, combined with other relevant risk factors (e.g. number of sites, sensitivity of information, dependencies, level of software development), which allows the certification body to define the required audit length and therefore the cost. This process is regulated by ISO 27006.

Tempo Audits offers:

  • Fast quotations
  • Competitive pricing
  • A low-overhead audit model

ISO 27001 Pricing by Headcount

Our ISO 27001 audit pricing is based on the number of people operating under your ISMS, scope, complexity and risk profile.

The table below gives indicative pricing for typical SaaS and tech companies, including Stage 1, Stage 2, planning and report writing.

Headcount operating
under ISMS
Audit days including
Stage 1, Stage 2,
planning and report writing
Indicative
audit fee
1–103.5–5.5 days£3,500–£5,500
11–154.5–6.5 days£4,500–£6,500
16–255–7.5 days£5,000–£7,500
26–456–9 days£6,000–£9,000
46–657–11 days£7,000–£11,000
66–858–12 days£8,000–£12,000
86–1258.5–13 days£8,500–£13,000
126–1759.5–14 days£9,500–£14,000
176–27510–15 days£10,000–£15,000
276–42510.5–17 days£10,500–£17,000
426–62511.5–18 days£11,500–£18,000
Show larger organisation pricing
626–87512.5–19 days£12,500–£19,000
876–1,17513–20 days£13,000–£20,000
1,176–1,55014–21 days£14,000–£21,000
1,551–2,02515–22 days£15,000–£22,000
2,026–2,67516–23 days£16,000–£23,000
2,676–3,45017–24 days£17,000–£24,000
3,451–4,35018–25 days£18,000–£25,000
4,351–5,45019–26 days£19,000–£26,000
5,451–6,80020–27 days£20,000–£27,000

ISO 27001 Stage 1 vs ISO 27001 Stage 2

ISO 27001 certification audits are completed in two stages.

Stage 1 is a short readiness review, often 1 day, where the certification body checks your policies and ISMS design to confirm you are ready for the main audit.

Stage 2 is the core certification audit. It is more detailed and typically longer, ranging from 2 days to significantly more, depending on company size, and focuses on evidence that controls are operating effectively.

AreaStage 1Stage 2
PurposeReadiness assessmentCertification audit
Typical length~1 day2+ days
FocusPolicies and ISMS designEvidence of controls in operation
OutcomeApproval to proceedISO 27001 certification decision

Benefits of ISO 27001 compliance

Win more customers

More and more companies now require ISO 27001 certification from their vendors. Getting certified early helps you stay ahead of these requirements and unlock new opportunities across your client base.

Build your reputation

Being ISO 27001 certified is a badge of the maturity of your organisation and its processes. Displaying it proudly builds trust in what you do.

Get a competitive edge

If you’re competing against an uncertified provider, your ISO 27001 certification will give you a competitive edge in showing the maturity of your processes and the manner in which you protect your clients’ information.

Impress existing clients

ISO 27001 certification builds trust with existing clients and partners, allowing you to deepen and build on those relationships.

Reduce risk of data leaks

ISO 27001 reduces risks of data leaks and breaches by creating a framework of controls to prevent them. By avoiding data leaks, you can avoid potential hefty fines and also limit the risk of substantial reputational damage.

Strengthen data security

Implement a broad range of controls that strengthen your data security, ranging from Organisational, People, Technological, and Physical controls.

Secure your assets and IP

Protect the risk of valuable IP or code being lost or shared with competitors by implementing information security controls that protect them.

Resources

Audit Timeline

How long does ISO 27001 certification take? Explore audit timelines, preparation requirements, common delays, and certification expectations.

Stage 1 Audit

Understand ISO 27001 Stage 1 audit requirements, checklists, costs, and preparation steps. Learn how to assess ISMS readiness and progress confidently to Stage 2.

Stage 2 Audit

Learn how the ISO 27001 Stage 2 audit works, what evidence is required, common mistakes to avoid, and how to achieve certification.

Internal Audit

ISO 27001 internal audit guide covering Clause 9.2 requirements, audit planning, Annex A controls, checklists, evidence collection, and compliance.

Statement of Applicability

Learn what an ISO 27001 Statement of Applicability (SoA) is, what it must include, common audit expectations, and how to avoid certification delays.

Certification Scope

Learn how to define your ISO 27001 certification scope, what it should include, common mistakes to avoid, and what auditors expect during certification.

Controls

ISO 27001 controls explained: Annex A & the 93 controls (2026 guide)

Audit Preparation

Learn how to prepare for ISO 27001 certification with a practical guide to audit readiness, risk management, internal audits, and UKAS audits.

UKAS Accreditation

A practical guide to UKAS-accredited ISO 27001 certification, including audit stages, accreditation benefits, procurement requirements, and certification verification.

Requirements

Get audit-ready with our guide to ISO 27001 certification requirements, including mandatory clauses, controls, documentation, and certification steps.

Certification Cost

How much does ISO 27001 certification cost in the UK? Learn typical audit fees, pricing by company size, and the factors that influence certification costs.

Risk Assessment

ISO 27001 risk assessment explained. Learn the 5-step process, risk treatment methods, Statement of Applicability, and audit requirements.

Resources

Why Tempo Audits?

High standards

Built by a former lawyer turned tech founder, Tempo Audits delivers high-quality ISO 27001 certification in a fast, practical, and tech-centric way. We are UKAS-accredited, demonstrating the highest audit standards and giving your customers confidence they can trust your certification.


Fast-moving

When your business is moving fast, compliance shouldn’t slow you down. We accelerate the path from preparation to certification, respond quickly, start audits within days of enquiry,
and take a proactive approach — turning compliance into a launchpad, not a speed bump.


Helpful

Being audited may not be your idea of fun, but we make sure you feel supported at every step. Our auditors focus on helping you strengthen your security systems so you’re confident sharing them with customers. When we find issues, we explain them clearly and help you fix them. We speak plain English, not compliance jargon — because a high-quality audit should give you more than a certificate. It should give you a partner.


Collaborative auditors

Our auditors take a collaborative, tech-first approach. We work alongside your team, explain requirements in plain English, and are supportive so that you can resolve issues quickly, making the audit faster, clearer, and far less stressful than traditional compliance audits.


Tech-centric

Our founding team has built tech companies like yours. That’s why we don’t audit in a traditional way. Our approach is virtual, collaborative, and innovative - bringing the same agility and mindset you’d expect from a tech company.

Resources

01

Develop your management system

The first step is to build your Information Security Management System (ISMS) — the connected set of policies, processes, and procedures required to meet ISO 27001. This typically takes 3-12 months, though very fast-moving teams may complete it in 1-2 months.

For impartiality reasons, Tempo Audits cannot support with ISMS implementation. However, we’re happy to help you find a suitable platform or consultant. Book a chat with us and, once we understand your needs, we’ll make an introduction.

02

Audit application & planning

Once you’re ready - or even while you’re still preparing - share your company details, and we’ll put together a proposal. This will outline the audit timeline, based on your organisation’s size and ISMS complexity, along with clear pricing.

Once approved, we’ll schedule one of our tech-expert auditors to get started.

03

Stage 1 audit

Now we’re into the Audit! The first step is the Stage 1 audit. At this stage, our Lead Auditor reviews your documentation and verifies your readiness to move on to Stage 2.

As a fast-moving firm, Tempo Audits typically shares the Stage 1 report within a day of completion, clearly outlining anything that needs to be addressed before progressing.

04

Stage 2 audit

Stage 2 is the final part of the audit. We usually run it 2-3 weeks after Stage 1, rather than the 1-3 months typical of more traditional certification bodies. We move quickly when our clients want to move quickly.

During Stage 2, we validate that your processes are operating effectively and conform to the standard. To issue a certificate, Tempo Audits needs evidence of conformity against every applicable clause and control, and we work closely with you during the audit to gather this.

If any gaps are identified, we raise non-conformities for you to close after the audit. We make this remediation process as clear and fast-moving as possible so certification isn’t delayed.

05

Certification!

Once we’re finished, we’ll provide you with a final report which, once you’ve closed out any non-conformities raised in the audit, will result in certification for 3 years!

In most instances, we’re in a position to share the certificate and report with you about 3 to 7 days after the Stage 2 audit finishes.

At this stage, you can pop the ISO 27001 badge on your website and start using it to win new clients!

06

Annual audits – Surveillance and recertification

After certification, we support you in maintaining it through annual audits, as required by the standard. At 12 and 24 months, we carry out surveillance audits, and at 36 months, we complete a recertification audit. Once passed, we issue a new three-year certificate, keeping your certification continuous.

Our process

Book a call

No forms, no faff – just a conversation and a quote. Prefer to skip straight to it? Fill out the application form and we'll get moving.

Alternatively, if you have all the details,
fill out this form here.

Latest Articles

July 15, 2026

Case Study: How The Risk Factor achieved ISO 27001 certification in 4 weeks

ISO 27001
July 8, 2026

ISO 27001 Audit: What to Expect and How to Prepare

ISO 27001
July 5, 2026

ISO 27001 Remote Auditing: The Future Of Information Security Audits

ISO 27001
June 22, 2026

ISO 27001 vs. SOC 2: Which Certification is Right for Your Business?

ISO 27001, SOC 2
June 10, 2026

ISO 27001 Benefits for SaaS: Win Clients Faster

ISO 27001
May 12, 2026

What Is ISO 27001? A Complete Guide to Information Security Standards

ISO 27001
April 30, 2026

How to Get ISO 27001 Certified: A Step-by-Step Guide for 2026

ISO 27001
April 28, 2026

Why ISO 27001 Certification is Important for Small Businesses

ISO 27001
April 7, 2026

ISO 27001 Accreditation Bodies: A Complete Guide for Tech Companies

ISO 27001
April 7, 2026

ISO 27001 Stage 1 vs Stage 2: What's the Difference?

ISO 27001

FAQs

ISO 27001 can feel complicated at first. Here are the answers to the questions we hear most from growing teams.

It’s a standard created by the International Standards Organisation. At its core are 6 key clauses (Clauses 4-10) that define a structured process for identifying risks and selecting appropriate controls to manage and reduce them. These controls are typically drawn from ISO 27002.

ISO 27001 compliance is regulated by national IAF accreditation bodies, which authorise certification bodies to audit organisations and issue certificates. Increasingly, SaaS companies are required to evidence ISO 27001 compliance to demonstrate strong information security standards.

Companies must implement and operate an Information Security Management System that meets the requirements of the standard. Once in place, they can be audited by a certification body to evidence compliance and, if successful, receive an ISO 27001 certificate.

Some companies pursue ISO 27001 voluntarily to strengthen security, reduce the risk of data breaches, and increase credibility with customers. Where it becomes a requirement, it is usually driven by customer demand, as buyers increasingly expect vendors to evidence strong information security. Other common drivers include tender processes, partnerships, and grant requirements.

An ISO 27001 audit is carried out to validate compliance with the ISO 27001 standard. An external audit is conducted by a certification body and is required before an ISO 27001 certificate can be issued. Organisations can also perform an internal audit, which they arrange themselves as part of maintaining their Information Security Management System.

For external audits, there are several audit types: Stage 1 and Stage 2 audits, which together form the initial certification and result in a 3-year certificate. Over the following two years, organisations complete annual surveillance audits. At the end of the cycle, a recertification audit allows the organisation to renew its three-year certificate.

To be compliant, a company must operate an effective Information Security Management System and then undergo a certification audit to evidence compliance. 

During the audit, the company must demonstrate conformity with every applicable clause and control of the standard. If successful, the certification body issues an ISO 27001 certificate. Where auditors identify non-conformities, the company must close them acceptably before certification can be granted.

An ISO 27001 certificate is valid for 3 years, provided the company completes the required annual surveillance audits. In the third year, the company can extend certification for a further 3 years by successfully completing a recertification audit before the certificate expires.

The longest phase is implementing the management system, which can take 2-3 months or significantly longer, depending on maturity. Once a client reaches audit, the overall audit process can span a few weeks to a few months. The audit time itself is usually 3-10 days; most delays come from gaps between stages.

Tempo Audits prefers to move fast. A typical fast-track schedule is a prompt Stage 1, Stage 2 within a few weeks, and certificate issuance within a week of Stage 2 - around three weeks from Stage 1 to certificate. 

Some clients choose a slower pace, such as a 1-2 month gap between stages, and we’re happy to accommodate that.

The International Accreditation Forum (IAF) operates the IAF CertSearch database, which lets you verify certifications issued by IAF-approved certification bodies. 

Likewise, Tempo Audits is UKAS-accredited, and UKAS runs its own CertCheck service for verification.

Some providers offer unaccredited certification, meaning they lack approval from an IAF-recognised accreditation body. These certifications are harder to verify, and the quality of the underlying audit is less clear. That’s why most companies insist on accredited certification that they can trust and validate easily.

ISO 27001 is the standard that organisations certify against. ISO 27002 sits alongside it, providing the catalogue of controls that companies typically implement as part of ISO 27001 compliance.

There is also a wider ISO 27000 family of related standards, for example, ISO 27006, which guides how ISO 27001 audits are conducted.

However, in practice, ISO 27001 is the only standard in the family that organisations routinely certify against.

GDPR is a law and, therefore, a requirement for all companies operating in the EU. ISO 27001, by contrast, is an elective certification. It is not legally required, but many organisations choose to meet the standard voluntarily or because stakeholders demand it.

GDPR focuses on data privacy, while ISO 27001 focuses on information security, putting controls in place to prevent data breaches, leaks, and cyberattacks.