ISO 27001

Certification

ISO 27001 certification, sized for your business.

ISO 27001 implementation, internal audit leadership, and certification preparation. Led by PECB-accredited Lead Auditors.

Overview

A management system standard, not a technical checklist.

ISO/IEC 27001 is the world's most widely respected information security certification — and the only ISO standard that organisations can be certified against. It specifies the requirements for establishing, implementing, and maintaining an Information Security Management System (ISMS), regardless of company size or sector.

The standard has two components. The management framework — 10 mandatory clauses covering how your organisation plans, implements, monitors, and improves its ISMS. Annex A — a reference set of 93 security controls across 4 domains (organisational, people, physical, technological) that you select, implement, and document based on your risk assessment. ISO 27001 does not prescribe a fixed set of controls; it requires you to identify your specific risks and justify your control choices in a Statement of Applicability.

Who ISO 27001 is for

Voluntary — but for a growing number of SMBs, commercially essential rather than merely advisable.

  • Technology & SaaS companies

    Enterprise procurement processes increasingly mandate ISO 27001 as a minimum vendor qualification. Without it, you may be disqualified from tenders before technical evaluation.

  • Suppliers to financial services

    Banks, insurers, and investment firms subject to DORA must extend security requirements down their supply chain. ISO 27001 is the most widely recognised way to meet that bar.

  • Healthcare & life sciences

    Health data triggers GDPR, NIS2, and sector-specific obligations. ISO 27001 provides the governance framework that satisfies all three simultaneously.

  • Professional services firms

    Law firms, accountants, consultancies handling confidential client data are increasingly expected to demonstrate certification to retain enterprise and regulated-sector clients.

  • Public-sector suppliers

    EU and national procurement frameworks list ISO 27001 as a required qualification for IT and data-processing contracts — particularly those involving personal or sensitive public data.

  • Any business seeking cyber insurance

    Insurers apply lower premiums and broader coverage to certified organisations. ISO 27001 is the single most recognised signal of mature security governance in underwriting.

The 10 management clauses

What every ISMS must demonstrate.

  1. 01Clause 4

    Context of the organisation

    Understanding your business environment, interested parties, and the ISMS scope.

  2. 02Clause 5

    Leadership

    Management commitment, the security policy, and assignment of roles and responsibilities.

  3. 03Clause 6

    Planning

    Risk assessment, risk treatment plan, and information security objectives.

  4. 04Clause 7

    Support

    Resources, competence, awareness training, communication, and documented information.

  5. 05Clause 8

    Operation

    Implementing the risk treatment plan, managing operational security processes and changes.

  6. 06Clause 9

    Performance evaluation

    Monitoring, measurement, internal audit (mandatory), and management review.

  7. 07Clause 10

    Improvement

    Addressing non-conformities, corrective actions, and continual improvement of the ISMS.

  8. 08Annex A

    93 controls across 4 domains

    Organisational (37), people (8), physical (14), technological (34). Selected and justified in your Statement of Applicability.

Consequences (non-fines)

No statutory penalties — but commercial cost compounds.

ISO 27001 is voluntary, so there are no statutory fines for non-certification. The cost of lacking certification, however, compounds: disqualification from procurement tenders, inability to meet client security requirements, loss of enterprise clients in regulated sectors, higher cyber-insurance premiums and reduced coverage, and inability to supply regulated financial institutions or public sector buyers.

Certified organisations also use ISO 27001 to meet 60–70% of NIS2, 40–55% of GDPR Article 32, 45–60% of DORA, and 40–50% of PCI DSS obligations — making it the most cost-effective single foundation for a multi-framework compliance program.

  • NIS2 coverage

    60–70%

    of NIS2 Article 21 obligations met by a well-scoped ISMS.

  • GDPR Art. 32

    40–55%

    of the technical and organisational security measures GDPR requires.

  • DORA coverage

    45–60%

    of DORA ICT risk management obligations.

Our approach

Certification, designed for SMB scale.

What we deliver

  • Gap analysis against the 10 management clauses and Annex A — costed roadmap to certification
  • ISMS design and scope definition — sized for your organisation, not enterprise-bloated
  • Risk assessment, risk treatment plan, and Statement of Applicability
  • Policy library written in language people will read and apply — not 200 pages of compliance text
  • Mandatory awareness training (Clause 7.2/7.3) with audit-grade completion records
  • Internal audit (mandatory before Stage 2) — led by PECB ISO 27001 Lead Auditors
  • Pre-certification readiness review and corrective-action support
  • Certification body selection guidance — body-independent across the EU (AFNOR in France, TÜV in Germany, TrustCB in the Netherlands, AENOR in Spain, CISQ in Italy, SGS in Switzerland, plus EU-operating bodies like Bureau Veritas, BSI, LRQA, DNV, SQS)
  • Stage 1 / Stage 2 audit support and ongoing surveillance audit retainer

Typical timeline

6–12 months for most SMBs starting from a low baseline. Existing controls or prior compliance work make this faster.

  1. Weeks 1–4

    Gap analysis

    Current state vs ISO 27001 requirements, ISMS scope definition, prioritised costed action plan.

  2. Months 2–5

    ISMS build

    Risk assessment, treatment, policies, controls, Statement of Applicability, training program rollout.

  3. Month 6

    Internal audit

    Independent internal audit against all clauses and selected Annex A controls. Corrective actions resolved.

  4. Months 7–9

    Certification audit

    Stage 1 (document review) then Stage 2 (on-site assessment) with your chosen accredited certification body.

FAQ

Common questions.

What's the difference between ISO 27001 and ISO 27002?
ISO 27001 is the certification standard — it defines the requirements an organisation's ISMS must meet, and is the basis for third-party certification audits. ISO 27002 is the implementation guidance standard — detailed advice on how to implement each of the 93 Annex A controls. ISO 27001 is the *what*; ISO 27002 is the *how*. You certify against ISO 27001, not 27002.
Does ISO 27001 certification need to cover the whole organisation?
No — the scope of your ISMS is something you define during planning. Many organisations begin with a focused scope covering a specific department, service line, or data-processing environment, then expand over time. For SMBs, a whole-organisation scope is often the most practical because operations are less complex. The scope must be clearly documented and justified in your ISMS documentation.
Can a small business (under 20 employees) realistically achieve certification?
Yes — and small businesses frequently certify faster than large organisations precisely because their scope is simpler and decision-making is faster. The ISMS documentation is proportionate to organisation size and complexity: a 15-person SaaS company does not need the same volume of policies as a 500-person manufacturer.
Which certification body should we use?
ISO 27001 certification must be issued by an accredited certification body — accredited by a national accreditation body that is a member of the IAF. Well-recognised bodies operating across the EU include AFNOR Certification (France), TÜV SÜD and DEKRA (Germany), TrustCB (Netherlands), AENOR (Spain), CISQ (Italy), SQS (Switzerland), plus EU-wide players like Bureau Veritas, BSI, LRQA, SGS, Intertek, and DNV. We are certification-body independent and help you select the right body for your jurisdiction and sector.
What happens if we fail the Stage 2 audit?
An outright fail is rare when properly prepared. More commonly, Stage 2 identifies major non-conformities that must be resolved within a defined window (typically 90 days) before certification is issued. Minor non-conformities are noted in the audit report but do not prevent certification — they are addressed at the first surveillance audit. Our pre-certification internal audit is designed to surface and resolve issues before the external auditor sees them.
Does ISO 27001 help with GDPR compliance?
Yes — ISO 27001 directly addresses GDPR Article 32's requirement for appropriate technical and organisational security measures. A certified ISMS demonstrates to supervisory authorities (the CNIL in France) that your organisation has implemented and maintains a structured approach to protecting personal data. ISO 27001 does not cover all GDPR obligations — lawful basis, data subject rights, DPIAs, and DPO requirements need separate GDPR-specific work.