What is ISO 27001?
ISO 27001 is the international standard for Information Security Management Systems (ISMS). It defines the requirements for building, operating, and continually improving a structured system to protect your organisation's information from threats such as cyberattacks, data breaches, insider threats, and accidental loss.
The current version is ISO/IEC 27001:2022. It is published by ISO and IEC and is recognised globally across all industries and sectors.
Who needs ISO 27001 certification?
Any organisation that handles sensitive information can benefit, but it is most commonly required by IT and SaaS companies selling to enterprise clients, financial services and fintech firms, healthcare organisations, government contractors, managed IT service providers, and legal and professional services firms.
In practice, certification is increasingly treated as a commercial necessity rather than a voluntary choice — enterprise clients and government bodies routinely require it before signing contracts.
How long does ISO 27001 certification take?
For small and medium organisations, certification typically takes 6 to 9 months. Mid-sized organisations usually need 9 to 14 months. Large enterprises with multiple locations and complex infrastructures generally require 12 to 24 months. The biggest factors affecting speed are current security maturity, leadership decisiveness, scope size, and whether you use a GRC platform to automate evidence collection.
How much does ISO 27001 certification cost?
Costs vary significantly by organisation size and scope. In the first year, expect costs for a consultant or implementation partner, certification body audit fees (Stage 1 and Stage 2), a GRC or ISMS platform, penetration testing, internal staff time, and security awareness training tools. Years 2 and 3 involve annual surveillance audits, platform subscriptions, and ongoing staff time.
Internal staff time is the biggest hidden cost — a typical first implementation consumes 200 to 500 hours across IT, HR, legal, and management.
What is the difference between ISO 27001 and SOC 2?
ISO 27001 is an international standard that results in a certificate valid for three years. SOC 2 is a US-originated attestation report covering a specific period (typically 6 to 12 months). ISO 27001 is recognised globally, especially in Europe, government, and regulated industries.
SOC 2 is primarily recognised by US technology and SaaS companies. There is approximately 60 to 70 percent control overlap between the two. Many technology companies pursue both, with ISO 27001 first as the recommended sequence because it provides the management system foundation that makes SOC 2 faster to complete.
What are ISO 27001 Annex A controls?
Annex A provides a library of 93 information security controls grouped into four themes: Organisational (37 controls), People (8 controls), Physical (14 controls), and Technological (34 controls). These are reference controls — you do not implement all of them automatically. You select the controls relevant to your identified risks, document how they are implemented, and justify the exclusion of any controls that do not apply. Your selections are captured in the Statement of Applicability.
Do small companies need ISO 27001?
ISO 27001 is fully scalable to smaller organisations. A 20-person company can achieve certification — the scope is simply tighter and the documentation lighter. For small companies, the most common driver is a customer requirement: an enterprise client or government body requires it before signing a contract.
The investment is proportionately smaller than for large organisations, and the commercial payoff — unlocking contracts that were previously inaccessible — is immediate and measurable.
How often is ISO 27001 surveillance audit required?
Surveillance audits are conducted annually — once in Year 1 and once in Year 2 after initial certification. These are shorter, partial-scope audits where the auditor covers different areas each time and checks that your ISMS is still operational, relevant, and improving. At the end of Year 3, a full recertification audit is required to renew the certificate for another three-year cycle.
What is an ISMS?
An Information Security Management System (ISMS) is a structured combination of policies, processes, people, and technical controls designed to protect an organisation's information. It is not a piece of software — it is a management framework that covers how you identify risks, implement protections, monitor effectiveness, and continually improve. ISO 27001 defines the requirements an ISMS must meet to achieve certification.
Can ISO 27001 be self-certified?
No. ISO 27001 certification must be issued by an independent, accredited Certification Body (CB). Self-declaration or self-assessment does not constitute certification and will not be accepted by customers, regulators, or partners. Only use CBs accredited by a recognised national accreditation body — UKAS in the UK, DAkkS in Germany, ANAB in the USA, or NAB in India.
What documents are required for ISO 27001?
The standard requires several mandatory documents including: ISMS scope statement, information security policy, risk assessment methodology and results, risk treatment plan, Statement of Applicability, information security objectives, evidence of competence, operational planning and control records, internal audit results, management review minutes, and records of corrective actions. Document control — version management, approval processes, and retention — is itself a requirement under Clause 7.5.
What is a Statement of Applicability?
The Statement of Applicability (SoA) lists all 93 Annex A controls and states — for each one — whether it applies to your organisation, whether it is implemented, and for excluded controls, why it is not applicable. It is one of the most important documents an auditor reviews during certification. Enterprise customers also frequently request it during procurement to understand your security posture.
How do I prepare for an ISO 27001 audit?
Ensure your ISMS documentation is complete and current — scope statement, risk register, Statement of Applicability, policies, internal audit results, and management review records. Run at least one full internal audit cycle before the external audit. Close any gaps identified in the internal audit. Ensure staff across all departments can articulate their security responsibilities — auditors interview employees beyond the IT team. Verify that controls are operating with documented evidence, not just described in policies.
What happens if you fail an ISO 27001 audit?
You do not pass or fail in a binary sense. The auditor issues findings categorised as major nonconformities, minor nonconformities, observations, or positive findings. Major nonconformities must be resolved before the certificate can be issued. Minor nonconformities must be addressed within a defined timeframe. If nonconformities are not resolved, the certification body may suspend or withdraw the certificate. Most well-prepared organisations receive some minor findings — this is normal and expected.
How long is ISO 27001 certification valid?
The certificate is valid for three years from the date of the Stage 2 audit. During this period, annual surveillance audits in Year 1 and Year 2 verify that the ISMS is still operating and improving. At the end of Year 3, a full recertification audit renews the certificate for another three-year cycle. Organisations that maintain their ISMS throughout the cycle find recertification significantly easier than the initial certification.
What is ISO 27001 accreditation?
ISO 27001 accreditation refers to the recognition of certification bodies that are qualified to audit and certify organizations against the ISO/IEC 27001 standard. Organizations typically become ISO 27001 certified, while certification bodies receive accreditation from authorized accreditation bodies.
How to get ISO 27001 certified?
To get ISO 27001 certified, an organization must establish an Information Security Management System (ISMS), define its scope, conduct a risk assessment, implement required controls, complete internal audits and management reviews, and pass an external certification audit conducted by an accredited certification body.
How to define ISO 27001 scope?
ISO 27001 scope defines the boundaries of your ISMS, including the products, services, locations, processes, systems and departments covered by certification. A well-defined scope should align with business objectives, information assets, security risks and customer requirements.
Why ISO 27001?
ISO 27001 helps organizations manage information security risks through a structured ISMS framework. It improves security governance, strengthens customer trust, supports compliance efforts and helps businesses meet security expectations from partners and global clients.
How fast can I get ISO 27001 certified?
The time required to achieve ISO 27001 certification depends on the organization's size, complexity and existing security maturity. Most mid-sized organizations typically take around 6–12 months, while smaller organizations with mature controls may complete the process faster.
How many controls are in ISO 27001?
ISO/IEC 27001:2022 includes 93 Annex A controls grouped into four categories: Organizational, People, Physical and Technological controls. Organizations select applicable controls based on their information security risks and document them in their Statement of Applicability (SoA).