Your IT Department

Compliance

Achieve ISO 27001. Prove it. Keep it.

Certification as a business enabler, not a box-ticking exercise.

An expert-led route to ISO 27001 certification, with a dedicated compliance consultant, the Adoptech platform and independent internal audit. We guide your team through certification and help keep your information security management system active and audit-ready, year after year.

When winning the work depends on proving your security

A client, tender or procurement team asks for ISO 27001, and suddenly a certificate becomes a condition of doing business. Without an internal compliance function, it can be difficult to know where to start, what evidence is needed and how to keep the programme moving alongside everyday work.

Certification is a business enabler, not a box-ticking exercise.

A structured, consultant-led route to certification that builds ownership in your team and keeps your information security management system active beyond the first audit.

Is this you?

Certification is blocking a deal

A client, tender or procurement team has asked for ISO 27001. You need a clear route to certification so information security requirements do not hold up the contracts you want to win.

You have no compliance function

You are a growing SME without a dedicated compliance manager or prior experience of certification. You need specialist guidance without recruiting a new internal team.

You want to get it right first time

You want a well-prepared programme, clear guidance and an independent internal audit before certification, rather than discovering gaps when the external auditor arrives.

You need to keep it, not just pass it

ISO 27001 runs on a three-year certification cycle. You need ongoing ownership, reviews and evidence so your management system stays active and ready for surveillance and recertification audits.

What managed compliance means for your business

Turn certification into a practical business asset, with expert guidance, clearer evidence and an information security management system your team can own and maintain.

Open doors to new contracts

Achieve the ISO 27001 certification required by your target clients, tenders or procurement teams, giving you a recognised way to demonstrate your information security management.

A well-prepared first audit

Expert implementation guidance and an independent internal audit help you identify gaps and prepare for external certification, rather than approaching the audit without a clear view of readiness.

Expertise without new headcount

Get a dedicated fractional compliance consultant and project-managed support, without recruiting an in-house compliance manager to guide the programme.

Ownership that stays with your team

Your consultant guides and advises while your team carries out its assigned actions and decisions. You build understanding of your management system, rather than relying on someone else to own it.

Less friction in procurement

Your branded TrustHub page brings compliance information together for prospects and customers, helping reduce the back-and-forth of security questionnaires and evidence requests.

Readiness beyond the first certificate

Quarterly security meetings, ongoing monitoring and annual internal audits keep your information security management system active through surveillance and recertification.

Independent certification credibility

We source quotes from UKAS-accredited certification bodies and support you through the external audit, keeping certification independent from compliance guidance and implementation support.

One accountable partner

Your platform, consultant, internal audit and auditor liaison are coordinated as one programme, with Microsoft security controls brought into the evidence process where relevant.

A managed route to ISO 27001, built around your team

Your Compliance combines the Adoptech platform, a dedicated compliance consultant and structured project management. Your consultant guides and advises; your team owns the decisions and completes its assigned actions, building a management system that reflects how your business works.

Managed Compliance as a Service

One programme, from standing start to audit-ready

Policies, controls, evidence and registers sit in one connected platform, supported by a consultant who keeps the programme moving. Independent internal audit checks readiness, while external certification remains with a separate accredited certification body.

  • Full Adoptech GRC platform and branded TrustHub
  • Dedicated fractional consultant and project management
  • Independent internal audit and certification auditor liaison
  • Quarterly security meetings and ongoing assurance

The support behind your certification

Scope and set up

Agree the scope and objectives of your information security management system. We set up the platform and connect Microsoft 365, Entra and Intune integrations for automated evidence collection.

Build policies and registers

A guided implementation workflow and document builder support more than 70 policies. Risk, vendor, legal and asset registers help bring the programme together, with your team reviewing and approving what applies.

Connect controls and evidence

Automated monitoring collects evidence, supported by technical control configuration and evidence across your Microsoft environment. Your team completes assigned actions, with guidance on requirements and decisions.

Check readiness independently

An independent certified Adoptech auditor carries out the internal audit within the platform. Your consultant supports you in reviewing findings and closing gaps before external certification.

Coordinate external certification

We source quotes from UKAS-accredited certification bodies, liaise with the auditor and support you through Stage 1 and Stage 2. Your team attends the external audit; the certification body makes the certification decision.

Maintain and improve

Quarterly security meetings, continuous monitoring and annual internal audits keep the programme active through surveillance and recertification. Your branded TrustHub helps share compliance evidence with prospects and customers.

External certification is independent and separately charged. The external audit is a third-party cost paid to the accredited certification body. We source quotes and coordinate the process; Adoptech does not perform the external certification audit. One-off onboarding and scoping are also charged separately from the monthly managed service.

Ready to build your route to ISO 27001?

Talk to us about your certification requirements, your current position and the support your team needs.

Talk to a compliance expert

From first steps to certification, and beyond

A structured six-stage journey takes your team from scoping to external certification, then into ongoing maintenance. Your consultant guides each stage while your team agrees the scope, approves policies, completes actions and participates in audits and reviews.

Onboard and scope

A kick-off session establishes ISMS scope and objectives. Platform setup and Microsoft integrations prepare evidence collection. Your team agrees the scope and objectives.

Build the ISMS

Guided implementation, the document builder and risk, vendor and legal registers shape your information security management system. Your team takes part in check-ins and approves policies.

Evidence and controls

Automated monitoring collects evidence while technical controls are configured and evidenced across your Microsoft environment. Your team completes assigned actions.

Internal audit

An independent certified Adoptech auditor carries out your internal audit within the platform. Your team reviews findings and closes gaps.

Certification audit

We source quotes from UKAS-accredited certification bodies, liaise with the auditor and support the process. Your team attends the external audit, which is separately charged.

Maintain and improve

Quarterly security meetings, continuous monitoring and annual internal audits keep the programme active through surveillance and recertification. Your team participates in quarterly reviews.

Keeping your management system alive

Quarterly security meetings review the programme between audits, keeping risks, evidence and improvement priorities current through the three-year certification cycle.

Risk register

Are risks being identified, owned and treated appropriately?

Vendor register

Are suppliers and their security obligations up to date?

Legal register

Are legal, regulatory and contractual requirements being met?

Business context

Have political, economic, social, technological, environmental or legal factors changed the context of your management system?

Control health

Are controls operating effectively and evidence being collected?

Audit readiness

Are you prepared for the next surveillance or recertification audit?

Continual improvement

What should be strengthened before the next review cycle?

Compliance connected to how your technology is managed

Your Compliance brings the platform, consultant, internal audit and certification auditor liaison into one programme. Where you also take our managed IT and security services, those teams can help configure and evidence the technical controls behind your information security management system.

Included in your compliance programme

  • Adoptech platform and branded TrustHub
  • Dedicated compliance consultant and project management
  • Guided policies, registers and evidence collection
  • Annual independent internal audit
  • UKAS-accredited auditor sourcing and liaison
  • Quarterly security meetings and ongoing review

The managed services behind your technical evidence

Available as a standalone service. You do not need to move your IT support to us to take Your Compliance. Related managed IT and security services are separately selected, not automatically included. YourFortify can provide vulnerability management and remediation evidence. The external certification audit is independent and separately charged; we source quotes and coordinate the process.

Expert guidance. Practical security knowledge. Clear ownership.

A dedicated compliance consultant guides your ISO 27001 programme, supported by the platform and independent audit. Our security and compliance team helps connect that programme with the practical technology and evidence behind it.

Human-led compliance support

Your dedicated fractional compliance consultant provides guidance and project management, with regular check-ins and in-hours access through Microsoft Teams. Your team retains ownership of decisions and assigned actions.

Independent audit and certification

An independent Adoptech auditor checks internal readiness. External certification is carried out by a separate UKAS-accredited certification body, with quotes sourced and the audit process coordinated on your behalf.

Connected technical expertise

Where you take our managed IT and security services, the teams supporting your Microsoft environment can help configure and evidence controls. Compliance is also available on its own, without moving your IT support.

Meet our security and compliance team lead

Fern Ritchie, Team Leader and Senior Security and Compliance Engineer at Your IT Department

Fern Ritchie

Team Leader, Senior Security & Compliance Engineer

Fern Ritchie leads our security and compliance team. She joined Your IT as an apprentice in 2019, completed her Level 3 Infrastructure Technician Apprenticeship in 2022 and went on to specialise in cyber security.

She holds CompTIA Security+, a first-class Applied Cyber Security degree, the Cyber Essentials Assessors Certificate and Microsoft 365 Certified: Endpoint Administrator Associate (MD-102). Her background combines practical IT support experience with security and compliance knowledge.

  • CompTIA Security+
  • Applied Cyber Security degree, First Class
  • Microsoft 365 Endpoint Administrator Associate (MD-102)

Ready to become ISO 27001 certified?

Talk to us about the requirements driving your certification, where you stand today and how a managed programme could support your team.

  • Dedicated compliance consultant
  • Adoptech platform and TrustHub
  • Independent internal audit
  • External auditor sourcing and liaison
  • Quarterly security meetings
Talk to a compliance expert

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Ut elit tellus, luctus nec ullamcorper mattis, pulvinar dapibus leo.

Frequently Asked Questions

Your questions about ISO 27001 certification, managed compliance and keeping your business audit-ready.

The service combines a dedicated compliance consultant, the Adoptech platform, guided implementation, an independent internal audit and external auditor sourcing and liaison. After certification, quarterly security meetings, ongoing monitoring and annual internal audits help keep your information security management system active and audit-ready.

Your consultant guides the programme and keeps it moving, but your team retains ownership. You agree the scope, approve policies, complete assigned actions and participate in audits and reviews. The aim is to build a management system your business understands and can maintain, rather than a set of documents nobody uses.

No. Your Compliance is available as a standalone service. If you also use our managed IT and security services, those teams can help configure and evidence relevant technical controls. Those services are separately selected, not automatically included in the compliance programme.

The service includes escalation, containment guidance and coordination of response activity. Automated containment is used where supported by policy. Major incident remediation or recovery projects may require a separate scope of work, rather than being included automatically in the monthly service.

An independent certified Adoptech auditor carries out the internal audit. External certification is performed by a separate UKAS-accredited certification body. Adoptech does not perform the external certification audit, preserving independence between compliance support and certification.

The programme continues through the three-year certification cycle. Quarterly security meetings, ongoing monitoring and annual internal audits help maintain your risks, policies, controls and evidence, supporting preparation for surveillance and recertification audits.

Certification can help satisfy security requirements specified by clients, tenders and procurement teams. Your included branded TrustHub page brings compliance information together in one place, helping reduce repeated evidence requests and the back-and-forth of security questionnaires. It does not guarantee a contract award.