Certification & assurance

Turn security requirements into a practical certification plan.

39Security helps small and growing businesses prepare for recognised cyber-security and management-system certifications without turning the project into a paperwork exercise. We define scope, identify gaps, implement controls, build evidence and prepare your team for independent assessment.

Choose the right route

Certification support matched to your business goal.

We provide readiness and implementation support. Independent certification is carried out by the relevant certification or assessment body.

Cyber Essentials

UK Government-backed technical controls covering firewalls, secure configuration, security updates, user access control and malware protection. Suitable for organisations that want a clear baseline and evidence for customers, tenders or insurance.

View Cyber Essentials packages

ISO/IEC 27001

Build an information security management system around risk, governance, evidence and continual improvement. Appropriate where customers, contracts or growth plans require a formal information-security framework.

Explore ISO 27001 readiness →

ISO/IEC 20000-1

Structure IT service management around service planning, delivery, control and continual improvement. Useful for IT providers and internal IT functions that need demonstrable service-management discipline.

Explore ISO 20000-1 readiness →

ISO/IEC 42001

Establish governance for the responsible management of artificial-intelligence systems, including policy, risk, impact, accountability and continual improvement.

Explore ISO 42001 readiness →

1. Scope and gap review

Define the certification boundary, business objectives, existing controls and the evidence already available.

2. Implementation

Close priority gaps with proportionate policies, technical controls, ownership, records and operating routines.

3. Assessment readiness

Check evidence, prepare internal stakeholders and resolve findings before independent assessment.

Not sure which standard fits?

Start with a scoped readiness conversation.

We will help you separate customer requirements, contractual needs and useful assurance from certification work that would add little value.

Talk to 39Security