Need ISO 27001 to win a contract?
Tell us what's driving it, your size and your deadline. We'll introduce you to up to three UK consultants who handle projects like yours.
- Free for your business. Consultants pay us a fee for introductions.
- No obligation. Compare approaches and quotes, then decide.
- Takes about a minute.
Get matched
Four quick questions.
Request sent
Thanks. We'll email you within one working day with the consultants we think fit best.
How it works
Tell us what you need
Your reason, size and deadline shape which consultants make sense.
We introduce up to three
Consultants with experience at your size and timeline get in touch directly.
You choose
Compare their approach and price. There's no obligation and no cost to you.
What affects the cost of ISO 27001?
- ScopeHow many people, sites and systems are included.
- Where you're starting fromExisting policies, controls or Cyber Essentials reduce the work.
- How much help you wantFull implementation costs more than gap analysis and audit preparation.
- Your deadlineTight timelines need more consultant time up front.
Consultancy is one cost. The certification audit itself is carried out separately by an accredited certification body, so budget for both.
How ready are you?
Tick what's already in place.
Common questions
How long does ISO 27001 certification take?
It depends on your size, scope and starting point. Many smaller businesses take several months from starting work to passing the certification audit. A consultant can give you a realistic plan once they understand your setup.
What's the difference between ISO 27001 and Cyber Essentials?
Cyber Essentials is a UK government-backed scheme covering a set of basic technical controls. ISO 27001 is an international standard for running an information security management system across your whole business. Some customers ask for one, some for both.
Is this really free?
Yes, for businesses looking for a consultant. Consultants pay us a fee when we introduce them to you. That never changes what you pay them.
Do I have to go with one of the consultants?
No. You can talk to them, compare quotes and decide not to go ahead.
Are you an ISO 27001 consultant?
We introduce UK businesses that have a real reason to certify, with their size and deadline already confirmed. Get in touch to join the network.
Privacy notice
Last updated: October 2026
Who we are
Certpath is run by Wes Lewis, a sole trader based in England, who is the data controller for the information you give us. Contact: consultant@certpath.co.uk.
What we collect
When you use the form, we collect your name, work email, company name, phone number if you give it, your answers about why you need ISO 27001, your company size and timeline, and any notes you add.
Why we use it
We use your details to respond to your request and introduce you to up to three ISO 27001 consultants. Our lawful basis is legitimate interests: you've asked us to make these introductions, and we only use your details for that purpose. We won't add you to a mailing list without asking.
Who we share it with
We share your details with the consultants we introduce you to, who will contact you directly. Once they have your details, they're responsible for how they use them. We also use service providers to run this site and our email: Netlify (website hosting and form handling) and Google Workspace (email). These providers may process data outside the UK under appropriate safeguards. This site loads fonts from Google, which means Google receives your IP address. We never sell your details.
How long we keep it
We keep your enquiry for 12 months, then delete it.
Your rights
You can ask to see the information we hold about you, correct it, delete it, restrict or object to how we use it, or get a copy to move elsewhere. Email consultant@certpath.co.uk and we'll respond within one month. If you're unhappy with how we've handled your information, you can complain to the Information Commissioner's Office at ico.org.uk.
Cookies
This site doesn't set its own cookies or use tracking.