● UK · EU — Regulated fintech & energy Certifications delivered: ISO 27001 · PCI DSS v4 · DORA
Written for: CISO Head of Audit COO Board director

Delivered ISO 27001 certification end-to-end in 26 weeks; zero major non-conformities at Stage 2

Headline outcome

a UK energy market operator · Energy market operations · 2018

ISO 27001 for a UK energy market operator

Context

A UK energy market operator was facing a regulatory expectation that the ISMS supporting its market-clearing platform would be ISO 27001 certified within the calendar year. The platform processed high-value settlement flows under a regulator-mandated operational uptime expectation; an unplanned outage during the certification window was not an acceptable trade-off.

The internal team had drafted policies; what was missing was the control evidence, the internal audit, and the operating model that would keep the certification renewable in subsequent years.

Risk

  • Schedule risk — the auditor was booked; slipping meant a 6-month delay and a public statement.
  • Operational risk — controls implemented sloppily would burden the platform team for years.
  • Audit risk — major non-conformities at Stage 2 would force a re-audit and a regulator conversation no one wanted to have.

Engagement

We took the ISMS lead role for 26 weeks:

  • Weeks 1-4: scoping — the boundary of the ISMS, the risk register, the Statement of Applicability. We deliberately scoped in the market-clearing platform and out of corporate IT (which had its own programme already in train).
  • Weeks 5-16: control design and implementation — every control built with the team that operates it, not for them. We set up the evidence collection so the auditors could see it themselves rather than ask for it.
  • Weeks 17-22: internal audit — full dry-run with structured findings and remediation plan. 23 minor findings, all closed before Stage 1.
  • Weeks 23-25: Stage 1 + Stage 2 — we attended every meeting with the auditor, held the relationships, wrote the management responses.
  • Week 26: certification — issued on time, zero major non-conformities, three minor observations.

Outcome

  • Certification delivered on date. No public-statement slippage.
  • Zero major non-conformities at Stage 2. Three minor observations closed in week 1 of the surveillance cycle.
  • Recertification cycle running cleanly two years on. The team is still using the same operating model.
  • Operating overhead for compliance reporting fell ~40% in the first year because evidence was generated by the platform itself, not by humans assembling it for audit.

The pillar article on DORA readiness for fintech draws on the operating-model patterns from this engagement.

Related case studies

Next step

Working on something similar?

We'll diagnose the shape of your problem in a 30-minute call. No proposals, no pitching.