Dynova Is Now a BSI Associate Consultant for ISO 27001 & 27701

Dynova Is Now a BSI Associate Consultant for ISO 27001 & 27701

Dynova Is Now a BSI Associate Consultant for ISO 27001 & 27701

Dynova Is Now a BSI Associate Consultant for ISO/IEC 27001 and ISO/IEC 27701 in the UAE

Dynova has joined the BSI Associate Consultant Programme for two standards: ISO/IEC 27001:2022 for information security and ISO/IEC 27701:2025 for privacy information management. BSI, the British Standards Institution, is the UK's national standards body. It runs the programme to connect organisations with independent consultants who implement standards and help keep certified management systems running.

For our clients the effect is concrete. The security programmes our vCISOs build use ISO/IEC 27001 as their backbone, and the privacy programmes use ISO/IEC 27701. Whether a regulator or a customer is driving the work, the result is ready for certification.

The standard does not bend to company size. A fifteen-person startup gets the same method and the same audit preparation as a regulated enterprise, because the enterprises and banks it sells to will judge the result by the same certificate.


Who BSI is and why its certificates carry weight in the UAE

BSI traces its origins to 1901 and has held a Royal Charter since 1929. Its link to information security is direct: ISO/IEC 27001 grew out of BS 7799, the British Standard for information security management that BSI developed in 1995.

By its own account, BSI is now one of the largest certification bodies for ISO/IEC 27001 in the world. When the standard was revised in 2022, BSI was among the first certification bodies to offer UKAS-accredited certification against the new edition.

In the UAE, BSI has certified the information security management systems of some of the country's largest organisations. In 2018 Dubai Electricity and Water Authority extended its BSI-issued ISO/IEC 27001 certification to all 13 of its sectors and more than 11,000 employees. ADNOC Distribution was certified to ISO 27001 by BSI Middle East and Africa as early as 2014.

What the BSI Associate Consultant Programme is

The Associate Consultant Programme is how BSI connects organisations with independent consultants in their region. Members help companies implement standards and maintain the management systems and certifications they already hold. BSI states that members work independently of BSI, and the separation has a purpose.

As an accredited certification body, BSI will not certify a management system that another part of the BSI Group advised on. A company that wants hands-on help building its information security management system, and a BSI audit at the end, needs an independent consultant for the building. The programme exists for exactly that case.

Membership is not an accreditation, and our consulting work stays independent of BSI. Nobody gets a shortcut through an audit. BSI auditors apply the same criteria to our clients as to everyone else, which is what makes the certificate worth having.

What it means for companies that need ISO 27001 in the UAE

Every programme is certification-ready by design. When a Dynova vCISO builds a security programme, the scope, the risk methodology, the Statement of Applicability, the internal audit and the management review follow ISO/IEC 27001:2022 from the start, including the climate consideration that Amendment 1:2024 added to clauses 4.1 and 4.2. The client decides when to certify. That decision never hinges on whether the programme would survive an audit, because it was built for one.

Clients who choose BSI for certification get a team that has already taken a company through a BSI audit: OGold went from zero to ISO/IEC 27001:2022 certification with BSI in six months, across the whole entity, with Dynova as its vCISO. Clients who choose another accredited certification body get exactly the same programme, because nothing in our method depends on which auditor turns up.

Startups get the enterprise route. A certificate is only as credible as the accredited body behind it, and enterprise buyers check. A startup certified by BSI brings the same credential to a procurement review as a company a hundred times its size, and it gets there on a monthly vCISO subscription instead of an enterprise consulting budget. Our guide on when a startup needs a vCISO covers the timing.

The path is predictable. A gap assessment comes first, then the risk assessment and the Statement of Applicability, then the build, which takes longest. The internal audit and management review follow, and only then does the certification body run its Stage 1 and Stage 2 audits. For a company under a few hundred people, four to six months from a standing start is realistic, and our ISO 27001 certification guide breaks down each step and its cost.

ISO 27701 certification in the UAE after the 2025 revision

ISO/IEC 27701 changed shape in its second edition, published on 14 October 2025. The 2019 edition was an extension to ISO/IEC 27001 and ISO/IEC 27002 and could only be certified on top of an ISMS. ISO/IEC 27701:2025 is a standalone standard for privacy information management systems (PIMS), with its own management system clauses 4 to 10 and controls for PII controllers and PII processors. A company can implement and certify a PIMS without holding ISO/IEC 27001.

That matters in the UAE, where one group can fall under several privacy regimes at once: Federal Decree-Law No. 45 of 2021 (the UAE PDPL) on the mainland and in the non-financial free zones, the DIFC Data Protection Law No. 5 of 2020 and the ADGM Data Protection Regulations 2021 in the two financial free zones, and sector rules on top. ISO/IEC 27701 does not replace any of these laws, and a certificate is not a legal safe harbour. What it gives a company is an audited management system for personal data: records of processing, defined controller and processor roles, handling of data subject requests, processor contracts and privacy risk assessment, all run as one system and checked by an independent auditor. Our UAE PDPL guide covers the legal side.

For companies that need both standards, we build one integrated management system. ISO/IEC 27001:2022 and ISO/IEC 27701:2025 share the harmonised structure, so the risk process, the internal audit and the management review run once, and the privacy work concentrates on what is specific to personal data. Our Builder plan includes a named DPO of record alongside the vCISO, so security and privacy decisions sit with one team. Our DPO service page explains how the named DPO role works.

Certification bodies move their own accreditation to the 2025 edition, and to ISO/IEC 27706:2025, the new standard for bodies that audit a PIMS, on a fixed timeline. UKAS has set it in line with the IAF working group consensus: accredited certification bodies complete their own transition by 31 October 2027, and they must move clients certified to the 2019 edition onto the 2025 edition by 31 October 2028. When you book an audit, confirm which edition the certification body will certify you against.

What does not change: the auditor stays independent

We do not issue certificates, and no consultant should. An accredited certification body audits the management system, and the client chooses which one.

A provider that guarantees a certificate is promising something no consultant controls. An offer of a certificate in two weeks almost always means an unaccredited one, and those fail the first serious verification. To check a certificate someone shows you, search for the certified company in BSI's certificate validation directory or, for UKAS-accredited certificates, in UKAS CertCheck. Both list certified organisations, not consultants or their programme memberships.

Why this matters for the vCISO market in the UAE

The vCISO title has no licence behind it. A solo adviser with a template pack and a delivery team with engineers can sell under the same name, and buyers often learn which one they hired when the audit starts. Every programme that collapses under audit makes the next buyer more sceptical of the model, which hurts the providers who do the work properly.

The answer is an outcome buyers can verify. A programme built to ISO/IEC 27001 either passes an accredited audit or it does not, and the certificate can be checked with the body that issued it. We hold every engagement to that test, the smallest startup included, and joining BSI's programme puts that commitment on the record. Our buyer's guide lists the questions worth putting to any provider, and what a virtual CISO actually is sets out what the role should cover.

Your vCISO in the UAE and Middle East
A named security leader of record, backed by a delivery team that builds the programme, not just advises. From $2,500 / mo

Your vCISO in the UAE and Middle East
A named security leader of record, backed by a delivery team that builds the programme, not just advises. From $2,500 / mo

Frequently asked questions

What is BSI?

BSI, the British Standards Institution, is the UK's national standards body and one of the largest certification bodies for ISO/IEC 27001 in the world. It developed BS 7799 in 1995, the British Standard that ISO/IEC 27001 grew out of.

What is the BSI Associate Consultant Programme?

It is BSI's programme for independent consultants who help organisations implement standards and maintain their management systems and certifications. Members work independently of BSI, which keeps consultancy separate from certification, as ISO/IEC 17021-1 requires of accredited certification bodies.

Does working with a BSI Associate Consultant guarantee certification?

No. BSI audits every organisation against the same criteria, and the outcome depends on the management system the auditor finds. A member brings a programme built to the standard and first-hand experience of how certification audits run.

Do we have to certify with BSI if Dynova is our vCISO?

No. You choose the accredited certification body, and we prepare you the same way for any of them. The question that matters is which accreditation body stands behind the certificate.

Can ISO/IEC 27701 be certified without ISO/IEC 27001?

Yes, under the 2025 edition. ISO/IEC 27701:2025 is a standalone management system standard, so a company can certify its privacy information management system on its own. Companies that need both usually run them as one integrated system, which avoids doing the shared management system work twice.

We hold an ISO/IEC 27701:2019 certificate. What now?

You need a transition audit to the 2025 edition. Under the UKAS timeline, certification bodies must move their certified clients to the 2025 edition by 31 October 2028. Start with a gap assessment against the new structure and, where you can, combine the transition with a surveillance or recertification audit you already have scheduled.

How long does ISO 27001 certification take for a startup in the UAE?

Most companies under a few hundred people need four to six months from a standing start. That includes the mandatory internal audit and management review before the two-stage certification audit.

What does ISO 27001 cost with Dynova?

The typical zero-to-certification build runs on our Builder plan at USD 4,500 a month, so a four to six month path costs roughly USD 18,000 to 27,000 on the delivery side. The certification body's audit fees are separate, and you pay them directly to the certification body. The Builder plan also includes a named DPO of record, and market ranges are in our vCISO cost guide.

Working with Dynova on ISO 27001 and ISO 27701

If you are looking for an ISO 27001 or ISO 27701 consultant in Dubai or elsewhere in the UAE, and you want the programme built rather than handed over as templates, get in touch. We will tell you which standard to start with and what a realistic timeline looks like for your company.

Related: ISO 27001 Certification in the UAE: Process, Cost, Timeline · OGold: Zero to ISO 27001 with BSI in Six Months · UAE PDPL Compliance: A vCISO and DPO Guide · How to Choose a vCISO Provider in the UAE

Written by

Founder of Dynova, vCISO and DPO (CISSP, CISM)

Founder of Dynova, vCISO and DPO for UAE companies. Formerly Head of Information Security and Privacy at Equiti. CISSP, CISM.

Experience

Get started

Don’t scale security harder. Scale smarter.

Dynova provides virtual CISO services, fractional CISO and DPO services in Dubai and across the UAE: security strategy, CBUAE, VARA, ISO 27001, PCI DSS, UAE PDPL and SOC 2 compliance, hands-on execution, penetration testing and code review, all under one named CISO.

info@business-ciso.com

+971 54 458 8631


Report incident:

soc@business-ciso.com


Dynova Services LLC-FZ, License 2644102.01, Issued by Meydan Free Zone, Dubai, UAE

Dynova is BSI Associate Consultant

Get started

Don’t scale security harder. Scale smarter.

Dynova provides virtual CISO services, fractional CISO and DPO services in Dubai and across the UAE: security strategy, CBUAE, VARA, ISO 27001, PCI DSS, UAE PDPL and SOC 2 compliance, hands-on execution, penetration testing and code review, all under one named CISO.

info@business-ciso.com

+971 54 458 8631


Report incident:

soc@business-ciso.com


Dynova Services LLC-FZ, License 2644102.01,

Issued by Meydan Free Zone, Dubai, UAE

Dynova is BSI Associate Consultant

Get started

Don’t scale security harder. Scale smarter.

Dynova provides virtual CISO services, fractional CISO and DPO services in Dubai and across the UAE: security strategy, CBUAE, VARA, ISO 27001, PCI DSS, UAE PDPL and SOC 2 compliance, hands-on execution, penetration testing and code review, all under one named CISO.

info@business-ciso.com

+971 54 458 8631


Report incident:

soc@business-ciso.com


Dynova Services LLC-FZ,

License 2644102.01,

Issued by Meydan Free Zone, Dubai, UAE

Dynova is BSI Associate Consultant