Skip to main content
    NixInfinity-AI
    Roadmap

    Cyber Essentials to ISO 27001: A 12-Month Roadmap for UK SMEs

    Published 21 July 2026

    Before you start: pre-requisites

    • Current CE certificate (and ideally CE Plus)
    • Named ISMS owner with board sponsorship
    • Realistic budget – internal time plus £8k–£15k external support and £10k–£20k audit fees
    • Defined ISMS scope (entity, location, services in scope)

    Month-by-month plan

    Month 1 – Scope and gap analysis

    • Define ISMS scope, boundaries and interfaces
    • Gap analysis against ISO 27001:2022 clauses 4–10 and Annex A 93 controls
    • Statement of Applicability (SoA) v0.1

    Month 2 – Information security policy + supporting set

    • Top-level information security policy signed by leadership
    • Acceptable use, access control, cryptography, supplier, BYOD policies
    • Records management and document control conventions

    Month 3 – Risk methodology and register

    • Risk assessment methodology (likelihood × impact, treatment criteria)
    • Initial information security risk register populated
    • Risk treatment plan with named owners and target dates

    Month 4 – Asset and information inventory

    • Information asset register (data sets, classifications, owners)
    • Hardware and software inventory with risk ratings
    • Supplier register tied to information assets

    Month 5 – Controls implementation, technical

    • Hardening baselines aligned to CE Plus + Annex A 8 (Technological)
    • Logging, monitoring and alerting evidence
    • Vulnerability management cadence proven over a full month

    Month 6 – Controls implementation, people and process

    • Joiners-movers-leavers process with evidence trail
    • Security awareness training rolled out and recorded
    • Confidentiality / NDA records for staff and contractors

    Month 7 – Business continuity and incident response

    • BCP with RTO/RPO per critical service
    • Tested DR plan with documented results
    • Incident response plan exercised at least once

    Month 8 – Supplier management and DPIAs

    • Supplier risk tiering complete (see our supplier assurance guide)
    • DPIAs for new processing activities recorded
    • Contracts updated with security and breach-notification clauses

    Month 9 – Internal audit programme

    • Internal auditor trained and independent of the controls audited
    • First full internal audit cycle complete
    • Nonconformities logged with corrective actions in motion

    Month 10 – Management review and SoA freeze

    • Documented management review covering all required inputs
    • SoA frozen at v1.0 with justifications for any excluded controls
    • Continual improvement register reviewed by leadership

    Month 11 – Stage 1 audit

    • UKAS-accredited certification body engaged
    • Stage 1 readiness audit complete
    • Findings remediated before Stage 2

    Month 12 – Stage 2 audit and certification

    • Stage 2 audit conducted, evidence presented
    • Minor nonconformities responded to within agreed timeline
    • Certificate issued, surveillance audit dates booked

    How CE and CA accelerate the journey

    CE Plus is a working substitute for a large slice of Annex A 8 (Technological controls). Cyber Assurance Level 2 covers organisational, people and physical controls in a format that maps directly to ISO. Doing CE + CA first typically cuts ISO 27001 internal effort by 30–40%.

    Common pitfalls

    • Trying to write every policy at once instead of pulling them as risks arise
    • Treating SoA as a paper exercise instead of an honest control inventory
    • Skipping internal audit cycle – Stage 1 will fail without it
    • Forgetting to evidence management review with proper minutes and actions

    Need a hand getting certified?

    Speak to an IASME-licensed assessor. Pre-check, plain-English support, certificates issued £320 + VAT.

    Frequently Asked Questions