Practical, auditor-led ISO 27001 consultancy to build, certify and maintain an information security management system (ISMS). From gap analysis to certification readiness — and ongoing maintenance afterwards — led by an IRCA Registered Principal Auditor.
ISO 27001 is the international standard for information security management. Increasingly, it is the price of entry — customers, public-sector buyers and regulated partners expect certified suppliers to demonstrate that information is genuinely protected.
Done well, an ISMS is far more than a certificate on the wall. It gives you a structured, risk-based way to protect customer data, win tenders, and respond confidently to security questionnaires. Done badly, it is a paperwork exercise that fails at the first incident. Our job is to make sure yours is the former.
A clear path from where you are now to a certified, maintainable ISMS.
We assess your current information security posture against ISO 27001:2022 and produce a clear, prioritised picture of what stands between you and certification.
We define the scope of your information security management system and help you build the policies, processes and controls it needs — proportionate to your business.
We help you establish a repeatable information security risk assessment and treatment methodology that your certification body will recognise and accept.
We support you in justifying the inclusion or exclusion of each Annex A control and producing a defensible Statement of Applicability (SoA).
Internal audits and a pre-certification review by an IRCA Registered Principal Auditor mean you walk into Stage 1 and Stage 2 with confidence.
Certification is the start, not the finish. We help you keep the ISMS living through surveillance audits, management reviews and continual improvement.
An ISMS generates a constant stream of evidence — risk assessments, corrective actions, audit findings, asset registers, supplier reviews and management reviews. Keeping all of that current is where many organisations slip between surveillance audits.
After implementation, many of our clients use PICMS to maintain that evidence, track audit actions and stay continually compliant. PICMS is a separate UK-built ISO compliance platform, designed by an IRCA Registered Principal Auditor — it is the software, while TAC provides the consultancy.
Speak to an IRCA Registered Principal Auditor about your information security goals, timeline and certification target. We typically respond within 24 hours.
Book a consultation