ISO/IEC 27001 Certification
Information security management systems
ISO/IEC 27001 is the international reference standard for information security. Certification demonstrates to customers, partners and authorities that the organisation systematically manages risks to the confidentiality, integrity and availability of information.
- Current edition
- ISO/IEC 27001:2022
- Intended for
- IT and software companies, cloud and outsourcing providers, financial services, healthcare, telecommunications and any organisation processing sensitive information
- Certificate validity
- 3 years, with annual surveillance audits
- Integrates with
- ISO 9001
What is ISO 27001
ISO/IEC 27001:2022 specifies the requirements for establishing, implementing, maintaining and continually improving an information security management system (ISMS). The core of the standard is the information security risk assessment and treatment process, on the basis of which the organisation selects the necessary controls and documents them in the Statement of Applicability.
Annex A of the 2022 edition contains 93 reference controls grouped into four themes: organisational controls, people controls, physical controls and technological controls. Controls introduced in 2022 include threat intelligence, information security for use of cloud services, ICT readiness for business continuity, monitoring activities, web filtering and secure coding.
ISO/IEC 27001 certification is increasingly a contractual condition in relationships with enterprise and public sector customers, and a means of demonstrating the technical and organisational measures required by the GDPR and by network and information systems security legislation (NIS2).
- Software development companies, SaaS and managed IT service providers
- Outsourcing providers (BPO, contact centres, data processing)
- Financial institutions, fintech, insurance and their suppliers
- Organisations in healthcare, telecommunications, energy and other sectors covered by NIS2
- Any organisation that wants to demonstrate a verifiable level of information security to its customers
Benefits of ISO 27001 certification
Contractual requirement met
A credible response to security questionnaires and to the requirements of enterprise and public sector customers.
Risks managed systematically
Risk assessment and treatment become a repeatable process with owners and deadlines.
Support for GDPR and NIS2
Demonstrating the appropriate technical and organisational measures required by data protection and cybersecurity legislation.
Operational resilience
Business continuity, incident management and ICT readiness reduce the impact of security events.
Customer trust
An internationally recognised certificate, verifiable online, rather than self-declarations.
Supplier control
Security requirements in supplier relationships and in the use of cloud services.
Main requirements of the standard
The standard follows the high level structure (Annex SL) common to ISO management system standards, with its requirements set out in clauses 4 to 10.
-
Clause 4
Context of the organisation
Internal and external issues, interested parties and their requirements, the scope of the ISMS, including interfaces and dependencies with other organisations.
-
Clause 5
Leadership
Management commitment, the information security policy, roles, responsibilities and authorities.
-
Clause 6
Planning
Information security risk assessment and treatment, the Statement of Applicability, security objectives and planning of changes.
-
Clause 7
Support
Resources, competence, awareness, communication and documented information.
-
Clause 8
Operation
Operational planning and control, performing risk assessments at planned intervals and implementing the risk treatment plan.
-
Clause 9
Performance evaluation
Monitoring, measurement, analysis and evaluation, internal audit and management review.
-
Clause 10
Improvement
Continual improvement, nonconformity and corrective action.
The 2022 edition and the end of the transition
ISO/IEC 27001:2022 replaced the 2013 edition. The transition period ended on 31 October 2025; all valid certificates must be issued to the 2022 edition, with Annex A restructured into 4 themes and 93 controls.
Amendment 1:2024 on climate change
Clauses 4.1 and 4.2 require determining the relevance of climate change for the ISMS, for example regarding infrastructure availability and business continuity.
The Certification Process
A clear and transparent process, from application to certificate issuance.
-
01
Application and quotation
Send us your organisation's details and the standard you are aiming for. We review your application and prepare a tailored quotation, including the audit duration and plan.
-
02
Stage 1 audit
We review your management system documentation and assess how ready your organisation is for the certification audit.
-
03
Stage 2 audit
The on-site audit checks that the system is implemented and effective against the requirements of the standard.
-
04
Decision and certificate
The certification committee reviews the audit report and issues the certificate, valid for 3 years.
Annual surveillance audits and a recertification audit at the end of the three-year cycle keep your certificate valid without interruption.
Certification RegulationsFrequently asked questions about ISO 27001
Can't find the answer you are looking for?
Contact usWhat is the Statement of Applicability (SoA)?
Does ISO/IEC 27001 cover GDPR requirements?
Is the organisation or the software product certified?
What documents and evidence are needed for the audit?
How does it relate to NIS2?
Integrated certification
Standards that share the same structure can be implemented as one integrated system and audited together in a single combined audit, reducing total audit time.
Request a quote for ISO 27001 certification
Tell us a little about your organisation and the standard you are aiming for. We will come back to you with a quotation and a proposed audit schedule as soon as possible.
- [email protected]
- Phone
- +40 750 419 503
- Working Hours
- L-V: 09:00 - 18:00