Get Your ISO/IEC 27001 Quote
The security certificate buyers ask for by name before they share their data
ISO/IEC 27001 certifies that an organisation runs an information security management system: risks assessed against real assets, controls chosen and justified, access and encryption managed, suppliers held to security terms, and incidents handled. It is the certificate procurement teams, regulators and insurers ask for before customer data moves.
You need ISO/IEC 27001 if…
- !An enterprise customer will not move to contract until you hold an accredited ISO/IEC 27001 certificate.
- !A security questionnaire arrived with two hundred questions and no single source of evidence to answer them.
- !You had an incident, and the review afterwards showed nobody owned the risk or the response.
- !A tender requires certification covering the specific site and service being bid, not a group certificate.
- !Customer data sits in cloud services that were adopted without any security review.
- !Your cyber insurance renewal now asks for evidence of certified controls and tested backups.
A management system standard for protecting information: its confidentiality, integrity and availability. You assess what could go wrong, select controls from a defined set, justify anything you leave out, and run the whole thing as routine business.
Certified by an accredited certification body against ISO/IEC 27001, not against ISO/IEC 27002, which is guidance. SOC 2, by contrast, is an attestation report signed by a CPA firm.
Three-year certificate with annual surveillance audits. The 2013 edition is withdrawn, so current certificates are issued against ISO/IEC 27001:2022.
Software and service firms, outsourcers, data centres, banks, hospitals, telecom operators and any supplier storing or processing a customer’s data.
Where this certification is demanded
ISO/IEC 27001 is applicable across 9 of the 25 industries SIS covers. The pages below set out the specific reason it comes up in each one.
What ISO/IEC 27001 Actually Requires
The backbone an implementer has to build, in the order it usually gets built.
Define which services, sites, systems and people the system covers, and record what customers, regulators and contracts require of information security.
Top management approves the information security policy, appoints risk and asset owners, and funds the controls it has signed off.
Identify risks to real assets and services, decide treatment, and produce a Statement of Applicability justifying every Annex A control applied or excluded.
Screening, security terms in employment contracts, defined responsibilities, training matched to the role, and a disciplinary process for deliberate breaches.
Access control, cryptography, logging and monitoring, secure development and change control, backup and restore, physical security, and supplier security clauses.
Measure control performance, run internal audits, handle and learn from incidents, test continuity, and take the whole picture to management review.
How ISO/IEC 27001 Certification Works
No black box. A defined, time-bound route from first call to certificate in hand.
Application & Proposal
Scoping turns on services and sites in scope, headcount with system access, cloud and outsourced components, development activity, and whether the scope must name a specific customer contract.
1–2 daysGap Review & Readiness
Two things sink readiness more than any control gap: a risk register that stops at the IT boundary, and a restore nobody has actually run since the backup tool changed.
1–2 weeksStage 1 + Stage 2 Audit
Stage 1 reviews scope, risk method, Statement of Applicability and internal audit records. Stage 2 tests controls in operation: access reviews, logs, joiner and leaver records, restores and incident tickets.
Scheduled around operationsCertificate Issued
The certificate carries a precise scope statement, and that is the part a customer’s vendor portal reads. Annual surveillance goes after access reviews and restore evidence, because those decay fastest.
Valid 3 yearsIndustries That Need ISO/IEC 27001
Commonly taken alongside
Not Sure Which Certification You Need?
Three questions. The selector reads the same industry-to-standard mapping this whole site is built on, then shortlists what applies to you.
Which sector best describes your organisation?
Scope wording decides what the audit costs
We will not quote ISO/IEC 27001 from a web form. The scope sentence changes the audit days more than headcount does, and it takes a call to get that sentence right.
Get My Free Quote →What ISO/IEC 27001 Changes for Your Business
Certification is not a certificate on the wall. It is a working system that pays for itself.
Clears vendor onboarding
Enterprise security reviews accept an accredited certificate and scope statement, which removes weeks of questionnaire exchange before a contract can be signed.
Right-to-audit stays unused
One audited system answers many customers. Right-to-audit clauses get exercised far less often when the certificate and Statement of Applicability cover the service in question.
Access finally gets reviewed
Joiner, mover and leaver control plus periodic access review removes the dormant accounts and standing admin rights that most breaches actually use.
Restores are tested, not assumed
Backup verification turns an assumption into a record. The incident that finds out whether you can restore should not be the first test of it.
Supplier risk gets contractual
Security terms, subcontractor approval and monitoring are written into supplier agreements instead of discovered during an incident involving one of them.
Recognised in every market
IAF-member accreditation means the certificate is accepted by corporate buyers and tender authorities in other countries without commissioning a duplicate assessment of their own.
Knowledge Base - Downloads
Practical documents prepared by our auditors. Fill the short form once and every download on the page unlocks.
ISO/IEC 27001:2022 implementation guide for lean teams
Clause and Annex A walkthrough with the evidence each control generates, written for teams doing this without a full-time security function.
Risk register and Statement of Applicability
Linked templates so every risk treatment traces to a control decision and every exclusion carries a written justification.
Stage 2 evidence pack checklist
The records auditors request most often, grouped by control theme, so nothing is being searched for during the audit.
ISO/IEC 27001 compared with SOC 2
Certification against attestation: what each one proves, which buyers accept which, and when running both is worth the additional cost.
Frequently Asked Questions
Straight answers to what buyers ask before they commit to ISO/IEC 27001.
What is the difference between ISO/IEC 27001 and SOC 2?
Do we have to apply all 93 Annex A controls?
Does the scope have to cover the whole company?
We use cloud providers for everything. What is left for us to control?
How long does certification take from a standing start?
What happens if the auditor raises a major non-conformity?
Start ISO/IEC 27001 certification with an accredited body
Our auditors test controls rather than read policies. What you end up with is a scope statement precise enough to survive a customer’s vendor review without a follow-up call.
Get My Free Quote → WhatsApp Us