ISO/IEC 27001 Certification

ISO/IEC 27001 is the international standard for information security management. Certification gives customers, partners and regulators independent evidence that you manage information security risks systematically.

What Is ISO/IEC 27001?

ISO/IEC 27001 specifies requirements for an information security management system (ISMS). It requires you to assess information security risks and treat them with appropriate controls. Annex A lists 93 reference controls in organizational, people, physical and technological themes. The current edition is ISO/IEC 27001:2022, amended in 2024.

Key Requirements

Clause / element Topic In practice
4 Context and scope Interested parties, interfaces, ISMS scope
5 Leadership Information security policy, roles
6.1 Risk assessment and treatment Method, risk owners, treatment plan, Statement of Applicability
7 Support Competence, awareness, documented information
8 Operation Operating the treatment plan; reassessing risk
9 Performance evaluation Monitoring, internal audit, management review
10 Improvement Corrective action, continual improvement
Annex A Reference controls 93 controls in 4 themes

Who Needs It?

Software and SaaS providers, IT service and cloud providers, data centers, fintech, healthcare, outsourcing providers, government contractors and any supplier asked to evidence information security.

The Certification Process

  1. Application: share your scope, sites and headcount; we confirm the route and audit time.
  2. Proposal and agreement: written proposal and certification agreement.
  3. Stage 1 audit: documentation and readiness review.
  4. Stage 2 audit: on-site evaluation of implementation and effectiveness.
  5. Certification decision: made by a competent reviewer who was not on the audit.
  6. Surveillance and recertification: annual surveillance, recertification every three years.

Stage 1 reviews the scope, risk methodology, treatment plan and Statement of Applicability. Auditors review evidence of controls in operation; they do not perform penetration testing.

What ISO 27001 Auditors Focus On

  • A clear, defensible scope.
  • A repeatable, owned risk assessment.
  • Statement of Applicability justifications that match reality.
  • Controls operating in practice: access, change, backups, logging, vulnerabilities, suppliers, incidents.
  • Awareness training and management review.

Certification vs SOC 2

ISO/IEC 27001 certifies a management system. SOC 2 is an attestation report issued by a CPA firm. Some customers accept either; others specify one.

FAQs

How many controls are in Annex A?

93 controls, grouped into organizational, people, physical and technological themes.

Do we have to implement every Annex A control?

No. You decide based on your risk assessment and justify each inclusion or exclusion in the Statement of Applicability.

Do you carry out penetration testing?

No. Auditors review evidence of your security testing and how you act on findings.

Quick quote

Get a free quote

Reply in writing with route and audit days.