Scope
We agree the ISMS scope, the standard and the audit objectives, then confirm what evidence exists before we start — so the fieldwork is spent on findings, not on chasing documents.

Audits led by a certified ISO/IEC 27001 Lead Auditor — findings you can act on, evidence you can show.
An audit is only worth what you can do with it. Too many arrive as a spreadsheet of non-conformities with no sense of which ones would actually hurt, and no path to closing them.
Our assurance practice is led by a certified ISO/IEC 27001 Lead Auditor. We run gap analyses and readiness assessments against ISO/IEC 27001:2022, the internal audit programme the standard requires, second-party audits of your suppliers, Cyber Essentials and Cyber Essentials Plus readiness, and technical security testing. Every finding comes with a severity, a root cause and a remediation that a real team can deliver.
We also say plainly what we are not. We are not a UKAS-accredited certification body, and we do not issue ISO certificates. We get you ready for the certification audit, and we run the internal and supplier audits the standard requires — the certification decision belongs to an accredited body, which is exactly as it should be.
Your current position against ISO/IEC 27001:2022 clauses 4–10 and the 93 Annex A controls, with a prioritised route to a Stage 1 and Stage 2 certification audit.
The internal audit programme clause 9.2 requires — planned, executed and reported by a Lead Auditor, with non-conformities, corrective actions and management review inputs.
Audit your critical suppliers and processors against your own control bar, with a report you can put in front of a client, a regulator or an insurer.
The five technical controls assessed honestly, remediation scoped, and your estate prepared for the assessment rather than surprised by it.
Vulnerability assessment, application and infrastructure penetration testing, cloud configuration review and secure-architecture review — findings ranked by real exploitability.
A risk methodology and register that survive scrutiny, an ISMS policy set people will follow, and a Statement of Applicability with justified inclusions and exclusions.
We agree the ISMS scope, the standard and the audit objectives, then confirm what evidence exists before we start — so the fieldwork is spent on findings, not on chasing documents.
Document review, control testing, interviews and technical verification. Findings are raised as we go, so nothing in the final report is a surprise on the day.
Non-conformities and observations with severity, root cause, affected controls and a remediation plan — written for the team that has to fix it, with an executive summary for the board.
Corrective actions tracked to closure, evidence verified, and a re-audit or management-review pack ready for your certification body.
Not on the list? The constraint we design to is regulatory exposure, not sector — talk to us about yours.
Skyie Global is not a UKAS-accredited certification body and does not issue ISO certificates. We deliver readiness, internal audit and supplier audit services led by a certified ISO/IEC 27001 Lead Auditor; certification audits are carried out by an accredited certification body.
No — and nobody who is also your consultant should. Certification is issued by a UKAS-accredited certification body after a Stage 1 and Stage 2 audit. We prepare you for it, run the internal audits the standard requires, and support you through the certification audit itself.
A gap analysis measures you against the standard before you have an ISMS, to plan the work. An internal audit is a recurring clause 9.2 requirement once the ISMS exists, testing that your own controls operate as documented.
For a small, well-run organisation with good engineering practice, typically three to six months from gap analysis to Stage 2. Larger or less mature estates take longer — the honest constraint is usually evidence history, since auditors want to see controls operating over time.
Yes. Documentation audits alone miss real exposure, so we pair control testing with technical verification — vulnerability assessment, penetration testing and cloud configuration review — and reconcile the two in one report.
Architecture that holds when the load and the auditor arrive.
Strategy that survives contact with your operating model.
Artificial intelligence you can put in front of a regulator.
Vendor trust and compliance posture, continuously evidenced.
Encrypted document storage with keys that stay on UK soil.
Status and uptime monitoring with an audit trail you can show a regulator.
Ready when you are
Thirty focused minutes. Tell us the problem and the constraints, and we will tell you honestly whether we are the right people for it.