Roadmap
Cyber Essentials to ISO 27001: A 12-Month Roadmap for UK SMEs
Published 21 July 2026
Before you start: pre-requisites
- Current CE certificate (and ideally CE Plus)
- Named ISMS owner with board sponsorship
- Realistic budget – internal time plus £8k–£15k external support and £10k–£20k audit fees
- Defined ISMS scope (entity, location, services in scope)
Month-by-month plan
Month 1 – Scope and gap analysis
- Define ISMS scope, boundaries and interfaces
- Gap analysis against ISO 27001:2022 clauses 4–10 and Annex A 93 controls
- Statement of Applicability (SoA) v0.1
Month 2 – Information security policy + supporting set
- Top-level information security policy signed by leadership
- Acceptable use, access control, cryptography, supplier, BYOD policies
- Records management and document control conventions
Month 3 – Risk methodology and register
- Risk assessment methodology (likelihood × impact, treatment criteria)
- Initial information security risk register populated
- Risk treatment plan with named owners and target dates
Month 4 – Asset and information inventory
- Information asset register (data sets, classifications, owners)
- Hardware and software inventory with risk ratings
- Supplier register tied to information assets
Month 5 – Controls implementation, technical
- Hardening baselines aligned to CE Plus + Annex A 8 (Technological)
- Logging, monitoring and alerting evidence
- Vulnerability management cadence proven over a full month
Month 6 – Controls implementation, people and process
- Joiners-movers-leavers process with evidence trail
- Security awareness training rolled out and recorded
- Confidentiality / NDA records for staff and contractors
Month 7 – Business continuity and incident response
- BCP with RTO/RPO per critical service
- Tested DR plan with documented results
- Incident response plan exercised at least once
Month 8 – Supplier management and DPIAs
- Supplier risk tiering complete (see our supplier assurance guide)
- DPIAs for new processing activities recorded
- Contracts updated with security and breach-notification clauses
Month 9 – Internal audit programme
- Internal auditor trained and independent of the controls audited
- First full internal audit cycle complete
- Nonconformities logged with corrective actions in motion
Month 10 – Management review and SoA freeze
- Documented management review covering all required inputs
- SoA frozen at v1.0 with justifications for any excluded controls
- Continual improvement register reviewed by leadership
Month 11 – Stage 1 audit
- UKAS-accredited certification body engaged
- Stage 1 readiness audit complete
- Findings remediated before Stage 2
Month 12 – Stage 2 audit and certification
- Stage 2 audit conducted, evidence presented
- Minor nonconformities responded to within agreed timeline
- Certificate issued, surveillance audit dates booked
How CE and CA accelerate the journey
CE Plus is a working substitute for a large slice of Annex A 8 (Technological controls). Cyber Assurance Level 2 covers organisational, people and physical controls in a format that maps directly to ISO. Doing CE + CA first typically cuts ISO 27001 internal effort by 30–40%.
Common pitfalls
- Trying to write every policy at once instead of pulling them as risks arise
- Treating SoA as a paper exercise instead of an honest control inventory
- Skipping internal audit cycle – Stage 1 will fail without it
- Forgetting to evidence management review with proper minutes and actions
