Your customer wants an independent assessment.
An external risk assessment of your security, carried out by an independent assessor and mapped control by control to ISO/IEC 27001, so your customer's compliance team can read it straight across their own requirements.
- A free 45 minute diagnostic, not a sales call
- Two written reports, the gap analysis and the post-remediation reassessment
- Findings mapped control by control to ISO/IEC 27001
- Run by a senior practitioner, not a coordinator
Loading the calendar
Open the booking pageCalendar not loading? Open Calendly directly
CISSP, ISO/IEC 27001 Senior Lead Implementer and Lead Auditor, ISO/IEC 42001 Lead Implementer and Lead Auditor, PMP.
When this is what you need
A customer's security questionnaire has one outstanding item, an external assessment.
A prime or a framework asks for evidence of a documented risk assessment programme.
An investor or lender wants an independent view before a deal.
A contract names SOC 2 or a local equivalent and you need the equivalent.
Two reports
Report one
The gap analysis
Your position against ISO/IEC 27001 clauses 4 to 10 and all 93 Annex A controls. Every finding is tied to the clause or control it relates to, the evidence it rests on, a required action, an owner and a target date.
Report two
The post-remediation report
A reassessment against the same register once the actions are closed, recording what closed and what remains open.
Both reports are written to your customer's own headings, with the ISO references underneath, plus a findings register you keep.
How it works
Free 45 minute diagnostic
We agree the boundary of the assessment.
Documents and evidence
You share what you already hold. No access to your systems is needed.
Interviews and walkthroughs
Short interviews and screen-share walkthroughs.
Report one
Delivered within three weeks of the start date.
Report two
Delivered within two weeks of the remediation evidence.
Fixing what it finds
Remediation is scoped separately from the assessment.
Where Goldline carries out the remediation, the independent verification is done by someone else. An assessor who marks their own work is what the standard exists to prevent.
Route one
You close the actions and Goldline reassesses.
Route two
Goldline helps you close them, and an independent party verifies.
From £1,950 plus VAT, fixed
Both reports are included. The fee is set at the diagnostic, by scope, and does not move afterwards. It credits in full against an ISO 27001 programme started within twelve months.
Outside the fee: certification, which only an accredited certification body can issue, and remediation.
What it is not
- This is not certification.
- This is not a SOC 2 attestation, which only a licensed CPA firm can issue.
- This is not a penetration test.
Looking at the standard itself? Read the ISO 27001 overview.
