Skip to main content

Your customer wants an independent assessment.

An external risk assessment of your security, carried out by an independent assessor and mapped control by control to ISO/IEC 27001, so your customer's compliance team can read it straight across their own requirements.

  • A free 45 minute diagnostic, not a sales call
  • Two written reports, the gap analysis and the post-remediation reassessment
  • Findings mapped control by control to ISO/IEC 27001
  • Run by a senior practitioner, not a coordinator
Book the free 45 minute diagnosticPick a time that suits you. Bring the questionnaire, the contract clause or the customer email.Same-week availability

Loading the calendar

Open the booking page

Calendar not loading? Open Calendly directly

CISSP, ISO/IEC 27001 Senior Lead Implementer and Lead Auditor, ISO/IEC 42001 Lead Implementer and Lead Auditor, PMP.

When this is what you need

A customer's security questionnaire has one outstanding item, an external assessment.

A prime or a framework asks for evidence of a documented risk assessment programme.

An investor or lender wants an independent view before a deal.

A contract names SOC 2 or a local equivalent and you need the equivalent.

WHAT YOU GET

Two reports

Report one

The gap analysis

Your position against ISO/IEC 27001 clauses 4 to 10 and all 93 Annex A controls. Every finding is tied to the clause or control it relates to, the evidence it rests on, a required action, an owner and a target date.

Report two

The post-remediation report

A reassessment against the same register once the actions are closed, recording what closed and what remains open.

Both reports are written to your customer's own headings, with the ISO references underneath, plus a findings register you keep.

How it works

01

Free 45 minute diagnostic

We agree the boundary of the assessment.

02

Documents and evidence

You share what you already hold. No access to your systems is needed.

03

Interviews and walkthroughs

Short interviews and screen-share walkthroughs.

04

Report one

Delivered within three weeks of the start date.

05

Report two

Delivered within two weeks of the remediation evidence.

Fixing what it finds

Remediation is scoped separately from the assessment.

Where Goldline carries out the remediation, the independent verification is done by someone else. An assessor who marks their own work is what the standard exists to prevent.

Route one

You close the actions and Goldline reassesses.

Route two

Goldline helps you close them, and an independent party verifies.

THE FEE

From £1,950 plus VAT, fixed

Both reports are included. The fee is set at the diagnostic, by scope, and does not move afterwards. It credits in full against an ISO 27001 programme started within twelve months.

Outside the fee: certification, which only an accredited certification body can issue, and remediation.

What it is not

  • This is not certification.
  • This is not a SOC 2 attestation, which only a licensed CPA firm can issue.
  • This is not a penetration test.

Looking at the standard itself? Read the ISO 27001 overview.

We use cookies and similar technologies to measure how this site is used, to see which organisations visit, and to measure our advertising. If you accept, we load Plausible, Google Analytics and Google Ads, Microsoft Clarity, which records session replays, and Apollo. Nothing loads until you accept. Read our Cookies policy.