FYconsulting - Main Banner

ISO 27001 / ISO 20000-1

Get ISO 27001 and ISO 20000-1 with a system that works for your business

100% of our clients have successfully obtained ISO 27001 / ISO 20000-1 certification since 2010

We build We build

a tailored information security and IT service management system designed specifically for your company.

Focus on Focus on

measurable improvements: our processes reduce risks, increase information systems security, service reliability and simplify your team’s work.

Guide Guide

you not only to successful certification but also to efficient operations under the new processes.

ISO/IEC 27001 is the globally recognized standard for establishing, implementing, maintaining an Information Security Management System (ISMS). It provides companies with a structured, risk-based framework to protect sensitive information.

ISO/IEC 20000-1 is the global standard for establishing and implementing an IT Service Management System (SMS). It provides a structured framework that helps organizations of any size demonstrate consistent, dependable, and high-quality IT service delivery.

We help
Companies getting certified for the first time

We help in the following cases:

  • You do not have established IT security or IT service management processes in place;
  • Your team is overloaded and unable to keep up with documentation;
  • Your clients require ISO 27001 / ISO 20000-1 certification as a condition for signing a contract.

We will build a system from the ground up that continues to operate effectively for many years after the audit.

Large companies tired of inefficient processes

We work with companies where:

  • There are numerous policies in place, but they are ineffective;
  • Auditors identify nonconformities that consume significant team resources;
  • Processes are not aligned across teams;
  • There is a lack of transparency and control over incidents, risks, or access in the area of cybersecurity.

We remove everything unnecessary and build a system your team will actually use — one that will not raise concerns from auditors.

We take on 95% of the work

We know that team resources are limited. Our task is to reduce stress and overload during the certification process, so we:

  • Prepare documents tailored to your team and business, and streamline existing documentation to what is practically needed.
  • Conduct meetings and training sessions with your teams, explaining standards in plain language.
  • Help implement new processes so everyone on the team understands how to apply them and actually uses the documents in daily work.
  • Engage auditors who are aligned with us and recommended by clients, ensuring certification goes smoothly. In any case, we prepare you even for the strictest auditors and answer all their questions if they arise.
We involve you in the process, asking for document approvals and participating in trainings with us. However, we don’t get stuck waiting for approvals and continue working on parallel tasks to accelerate the process.
You’ll see progress in real time

All work is managed in Microsoft Teams or another system that is convenient for your team. You will be able to track the plan, monitor tasks with status updates, and review document drafts with comments in real time.

Set up a system that will work for years
We understand which procedures are actually needed for your business

ISO 27001 is a complex standard, as you not only need to meet the basic requirements but also address 90 different controls. Each control must be assessed, supported with evidence, or officially justified if it does not apply.

We prepare the key document, the Statement of Applicability, which specifies which controls are relevant to your business, what evidence is required, and which controls are excluded — and why.

Implementation and maintenance requirements may vary depending on the state. We take local regulations into account and implement only what is practically necessary.
Oksana Goncharov
Oksana Goncharov

Management Systems - Quality Assurance

Oksana Goncharov
Create practical and working documentation
Create practical and working documentation

We conduct risk assessments and implement new processes tailored to your business:

  • Develop a secure environment for on-premises servers if the company does not use cloud solutions;
  • Ensure backup power is available in case of electricity outages;
  • Establish an approach for vulnerability assessment and incident response, including breaches and cyberattacks;
  • Refine onboarding and offboarding processes in the context of data security requirements;
  • Define measures to respond to risks of data loss due to power outages, phishing, unauthorized server access, and personal data leaks.
Train your team and explain the standard in simple terms
Train your team and explain the standard in simple terms

After our training sessions, your specialists will have a solid understanding of:

  • Information security rules;
  • How to recognize phishing, handle confidential data, and manage employee onboarding/offboarding with data security in mind;
  • Each person’s responsibilities within the ISMS;
  • Key actions to take during incidents and security breaches.
Fast-track your certification preparation

Clients often turn to us when certification is urgently needed, as it affects critical contracts and partnerships. We understand this and accelerate the entire process. We will be your reliable partner, persevering and driving the project to successful completion.

12 to 18 weeks

The average timeframe for preparing a company of up to 20 employees

We receive 25% of our fee only after successful certification. The final payment is made only once you have your certificate in hand.
We help when your business needs multiple certifications at once
We help when your business needs multiple certifications at once

If your company needs to obtain several certifications simultaneously, we integrate them into a single management system, helping streamline processes and optimize costs.

  • Instead of managing multiple parallel processes, you get one coherent system with unified logic, where all standards are interconnected and non-duplicative.
  • This significantly reduces the burden on your staff — your team completes all necessary training within a single system — and speeds up certification achievement.
  • The integrated system is stable and scalable, making it easy to add new standards in the future.
What clients say
"In 2020, we needed to bid on a major government contract which required both ISO 27001 and ISO 20000-1 certifications."

We’ve worked with FY Consulting for several years, and each engagement we’ve had an enjoyable experience. What we enjoy most about working with FY Consulting is their knowledge of the various appraisals and certifications. They make sure that we are kept informed of new updates or changes that might affect us. I would recommend FY Consulting to other companies and have done so. They are competitively priced and a great partner to work with.

CMMC/NIST ISO 20000-1 ISO 27001 ISO 9001
Hannibal S. Jackson
— President and CEO, Y-Tech
8 years in Business with FYC
US Government
Hannibal S. Jackson

Very prepared, very put together, had all the documentation in order, really coached us through the whole process, telling us each step by step what to expect, what we needed to do, what we had to do, what we didn't need to do.
Really professionals, really knowing exactly what it takes to get from zero to 60 and getting us into a position where we were able to actually get certified the first time around.
I really can't say enough good things about FY Consulting.

ISO 27001
Eli Wainhaus
— IT Infrastructure Manager, Steel Warehouse
1 years in Business with FYC
Aerospace Automotive
Eli Wainhaus
95% of our clients continue to work with us
95% of our clients continue to work with us
  • We see solutions, not problems, never give up, and guide your team to results in a way that even auditors highly value the systems we build.
  • We help you achieve certification quickly and without unnecessary bureaucracy, so you can secure important contracts and improve your KPIs.
  • We translate complex requirements into clear, understandable language and provide practical guidance for your team, ensuring everyone knows why it matters and what actions to take.
Video testimonials
ISO 27001
Eli Wainhaus
IT Infrastructure Manager, Steel Warehouse
1 years in Business with FYC
Aerospace Automotive
We’ll share our clients’ contacts so you can confirm the effectiveness of our work yourself.
Start your certification with us

We’ll help you build a quality management system that delivers stability, efficiency, and a competitive advantage.

Or just call us at ‭+1 (908) 875-7466‬