[email protected]
Accredited Certification Body · IAS & IAF Member · Certificates Verifiable Online
HomeStandardsISO/IEC 27001

Get Your ISO/IEC 27001 Quote

Takes 30 seconds · a specialist responds within 2 business hours
Step 1 of 2
CertificationTrainingCompliance Audits
Not sure - guide me
ISO/IEC 27001
No spam. No obligation. A clear quote.
15,000+Certified Clients
30+Countries Served
IAS · IAFAccredited
ISO/IEC 27001:2022 · Information Security Management

The security certificate buyers ask for by name before they share their data

ISO/IEC 27001 certifies that an organisation runs an information security management system: risks assessed against real assets, controls chosen and justified, access and encryption managed, suppliers held to security terms, and incidents handled. It is the certificate procurement teams, regulators and insurers ask for before customer data moves.

You need ISO/IEC 27001 if…

  • !An enterprise customer will not move to contract until you hold an accredited ISO/IEC 27001 certificate.
  • !A security questionnaire arrived with two hundred questions and no single source of evidence to answer them.
  • !You had an incident, and the review afterwards showed nobody owned the risk or the response.
  • !A tender requires certification covering the specific site and service being bid, not a group certificate.
  • !Customer data sits in cloud services that were adopted without any security review.
  • !Your cyber insurance renewal now asks for evidence of certified controls and tested backups.
What it is

A management system standard for protecting information: its confidentiality, integrity and availability. You assess what could go wrong, select controls from a defined set, justify anything you leave out, and run the whole thing as routine business.

Who issues it

Certified by an accredited certification body against ISO/IEC 27001, not against ISO/IEC 27002, which is guidance. SOC 2, by contrast, is an attestation report signed by a CPA firm.

Validity

Three-year certificate with annual surveillance audits. The 2013 edition is withdrawn, so current certificates are issued against ISO/IEC 27001:2022.

Who gets asked for it

Software and service firms, outsourcers, data centres, banks, hospitals, telecom operators and any supplier storing or processing a customer’s data.

9of 25 industries

Where this certification is demanded

ISO/IEC 27001 is applicable across 9 of the 25 industries SIS covers. The pages below set out the specific reason it comes up in each one.

Defence IndustryTransport and LogisticsMedical DevicesPublic SectorTelecommunication IndustryEducation Industry+3 more

What ISO/IEC 27001 Actually Requires

The backbone an implementer has to build, in the order it usually gets built.

1
Scope & interested parties

Define which services, sites, systems and people the system covers, and record what customers, regulators and contracts require of information security.

2
Policy & leadership

Top management approves the information security policy, appoints risk and asset owners, and funds the controls it has signed off.

3
Risk assessment & treatment

Identify risks to real assets and services, decide treatment, and produce a Statement of Applicability justifying every Annex A control applied or excluded.

4
People & awareness

Screening, security terms in employment contracts, defined responsibilities, training matched to the role, and a disciplinary process for deliberate breaches.

5
Operational controls

Access control, cryptography, logging and monitoring, secure development and change control, backup and restore, physical security, and supplier security clauses.

6
Audit, incidents, improvement

Measure control performance, run internal audits, handle and learn from incidents, test continuity, and take the whole picture to management review.

How ISO/IEC 27001 Certification Works

No black box. A defined, time-bound route from first call to certificate in hand.

Application & Proposal

Scoping turns on services and sites in scope, headcount with system access, cloud and outsourced components, development activity, and whether the scope must name a specific customer contract.

1–2 days

Gap Review & Readiness

Two things sink readiness more than any control gap: a risk register that stops at the IT boundary, and a restore nobody has actually run since the backup tool changed.

1–2 weeks

Stage 1 + Stage 2 Audit

Stage 1 reviews scope, risk method, Statement of Applicability and internal audit records. Stage 2 tests controls in operation: access reviews, logs, joiner and leaver records, restores and incident tickets.

Scheduled around operations

Certificate Issued

The certificate carries a precise scope statement, and that is the part a customer’s vendor portal reads. Annual surveillance goes after access reviews and restore evidence, because those decay fastest.

Valid 3 years
A focused single-site scope is commonly certified in six to ten weeks and multi-site or heavily outsourced scopes take longer, so name the contract date at application and the audit gets scheduled against that rather than against the queue.

Industries That Need ISO/IEC 27001

🛡️
Defence Industry
Open full page →
Why it applies hereDefence work means classified drawings, weapon system code and personnel data sitting on contractor networks. ISO/IEC 27001 provides the access control, cryptography, supplier security and incident response framework required before facility security clearance is granted. Domestically it aligns with national industrial security expectations; for exporters it is the common language buyers use to judge whether a vendor can hold controlled information.Typical trigger: Facility security clearance; export contracts
🚚
Transport and Logistics
Open full page →
Why it applies hereTransport management systems, EDI links, customs filings and customer shipment data make logistics providers an attractive target and a route into customer networks. ISO/IEC 27001 provides access control, supplier security and incident response, and is now standard in the security questionnaires shippers send before integrating systems.Typical trigger: System integration; shipper questionnaires
🩺
Medical Devices
Open full page →
Why it applies hereConnected devices, patient data, clinical trial records and proprietary designs put device companies squarely inside information security expectations. ISO/IEC 27001 provides the control framework hospitals and health systems now demand before procurement, and supports the cybersecurity documentation regulators require for software-enabled devices.Typical trigger: Hospital procurement; device cybersecurity
🏛️
Public Sector
Open full page →
Why it applies hereGovernment systems hold citizen identity, revenue, health and law enforcement data and are a standing target for state and criminal actors. ISO/IEC 27001 provides the certified control framework for access, cryptography, supplier security and incident response, and is increasingly written into e-governance programme requirements and empanelment criteria for departments and their vendors.Typical trigger: E-governance requirements; empanelment
📡
Telecommunication Industry
Open full page →
Why it applies hereOperators sit on subscriber identity, call records, location data and interception infrastructure, making them critical national infrastructure and a priority target. ISO/IEC 27001 provides the certified control framework regulators and enterprise customers require, covering access, network security, supplier risk and incident response.Typical trigger: Regulatory obligation; enterprise customers
🎓
Education Industry
Open full page →
Why it applies hereInstitutions hold student records, assessment data, health information and research output, and are increasingly targeted by ransomware. ISO/IEC 27001 provides access control, backup, supplier security and incident response, and is often required for research collaborations and government-funded programmes.Typical trigger: Ransomware exposure; research collaborations
💻
Information Technology Industry
Open full page →
Why it applies hereInformation security is the single most requested certification in technology procurement. ISO/IEC 27001 provides the certified framework for access control, secure development, supplier risk, cryptography and incident response, and is typically the minimum required to enter enterprise vendor lists or handle customer data under contract.Typical trigger: Enterprise vendor onboarding
🏦
Banking and Finance
Open full page →
Why it applies hereFinancial institutions are the most targeted sector for cyber attack and operate under explicit regulatory security expectations. ISO/IEC 27001 provides the certified framework for access control, cryptography, third-party risk and incident response, and is commonly required of both institutions and their technology vendors during onboarding.Typical trigger: Regulatory expectation; vendor onboarding
🍽️
Hotel, Restaurant and Leisure Service
Open full page →
Why it applies hereBooking systems, point of sale, loyalty databases and WiFi networks hold guest and payment data across distributed sites with limited local IT support. ISO/IEC 27001 provides access control, supplier security and incident response, and is increasingly requested by corporate clients and franchisors.Typical trigger: Distributed site security; franchisor requirements

Commonly taken alongside

Security, privacy, continuity and service management draw on the same asset register, supplier list and incident process, so certifying them together lets SIS run one set of interviews across the common clauses and typically removes two to three audit days from the total.

Not Sure Which Certification You Need?

Three questions. The selector reads the same industry-to-standard mapping this whole site is built on, then shortlists what applies to you.

Question 1 of 3

Which sector best describes your organisation?

Scope wording decides what the audit costs

We will not quote ISO/IEC 27001 from a web form. The scope sentence changes the audit days more than headcount does, and it takes a call to get that sentence right.

Get My Free Quote →

What ISO/IEC 27001 Changes for Your Business

Certification is not a certificate on the wall. It is a working system that pays for itself.

Clears vendor onboarding

Enterprise security reviews accept an accredited certificate and scope statement, which removes weeks of questionnaire exchange before a contract can be signed.

📉

Right-to-audit stays unused

One audited system answers many customers. Right-to-audit clauses get exercised far less often when the certificate and Statement of Applicability cover the service in question.

🔑

Access finally gets reviewed

Joiner, mover and leaver control plus periodic access review removes the dormant accounts and standing admin rights that most breaches actually use.

💾

Restores are tested, not assumed

Backup verification turns an assumption into a record. The incident that finds out whether you can restore should not be the first test of it.

🔗

Supplier risk gets contractual

Security terms, subcontractor approval and monitoring are written into supplier agreements instead of discovered during an incident involving one of them.

🌐

Recognised in every market

IAF-member accreditation means the certificate is accepted by corporate buyers and tender authorities in other countries without commissioning a duplicate assessment of their own.

Knowledge Base - Downloads

Practical documents prepared by our auditors. Fill the short form once and every download on the page unlocks.

PDF GUIDE

ISO/IEC 27001:2022 implementation guide for lean teams

Clause and Annex A walkthrough with the evidence each control generates, written for teams doing this without a full-time security function.

TEMPLATE

Risk register and Statement of Applicability

Linked templates so every risk treatment traces to a control decision and every exclusion carries a written justification.

CHECKLIST

Stage 2 evidence pack checklist

The records auditors request most often, grouped by control theme, so nothing is being searched for during the audit.

WHITEPAPER

ISO/IEC 27001 compared with SOC 2

Certification against attestation: what each one proves, which buyers accept which, and when running both is worth the additional cost.

🔒 Documents are locked. Fill the form once to unlock every download.

Frequently Asked Questions

Straight answers to what buyers ask before they commit to ISO/IEC 27001.

What is the difference between ISO/IEC 27001 and SOC 2?
ISO/IEC 27001 is a certification issued by an accredited certification body against a published standard, valid three years with annual surveillance. SOC 2 is an attestation report issued by a CPA firm against trust services criteria, covering a point in time for Type 1 or a period for Type 2, and it is reissued annually. Many US buyers ask for SOC 2; most other markets ask for 27001.
Do we have to apply all 93 Annex A controls?
No. You apply the controls that treat your identified risks, and record in the Statement of Applicability which ones apply, which do not, and why. Exclusions must be justified against the risk assessment, not convenience. An auditor will challenge an exclusion such as secure development if you write software, however it is worded.
Does the scope have to cover the whole company?
No, but the scope statement must be honest and precise, because customers read it. Certifying one service line or one site is legitimate and common. What causes problems is a narrow certified scope presented to buyers as if it covered the whole organisation, which is exactly what a careful vendor review checks.
We use cloud providers for everything. What is left for us to control?
Plenty. The provider secures its infrastructure; you remain responsible for configuration, identity and access, key management, logging, data classification, backup arrangements, and the contract terms you accepted. Auditors look closely at cloud administrative access, tenancy configuration and whether anyone reviews the provider’s own assurance reports rather than filing them.
How long does certification take from a standing start?
For a defined single-site scope with reasonable IT hygiene already in place, six to ten weeks is realistic, including gap review, implementation and both audit stages. The internal audit and one management review must have happened before Stage 2, and that sequencing, not the audit itself, is what usually sets the earliest possible date.
What happens if the auditor raises a major non-conformity?
The certificate is not issued until it is closed. You submit a root cause analysis, a correction and a corrective action, with evidence. Depending on severity, SIS verifies this remotely or with a short follow-up visit. A major finding is normally something systemic, such as no risk treatment plan or an internal audit programme that has never run.
Email Us
✉ EmailGet Quote