ISO 27001 certification.
The international standard for information security management. Heavier than SOC 2 up front, more durable afterwards, and the one European and Asian enterprise buyers recognise immediately.
At a glance
- Timeline
- 6 to 9 months typical
- Standard
- ISO/IEC 27001:2022 with Annex A controls
- Certification
- Three-year cycle with annual surveillance audits
- Our role
- ISMS design, implementation and internal audit
- Certification body
- Independent, we prepare you for them
What this actually is.
ISO 27001 certifies a management system, not a snapshot. That distinction is why it takes longer and why it holds up better: you are building a risk assessment process, a treatment plan and a review cycle that must demonstrably operate, year after year.
What we cover.
Who needs this.
- Companies selling into Europe, the UK, the Middle East or Asia
- Organisations already holding SOC 2 and needing international recognition
- Businesses where a tender or framework agreement requires certification
- Teams wanting a durable programme rather than an annual scramble
Frequently asked.
ISO 27001 or SOC 2?
Geography and buyer. North American enterprise buyers ask for SOC 2. European, UK, Middle Eastern and Asian buyers ask for ISO 27001. If you sell to both, do them together: the control overlap is substantial and the incremental cost of the second is far lower than the first.
What changed in the 2022 revision?
Annex A was restructured from 114 controls into 93 across four themes, with eleven new controls covering threat intelligence, cloud services, secure development and data leakage prevention. Existing certifications had a transition period, and new implementations should target 2022 directly.
Do we need a full-time security person?
Not necessarily, but you need a named owner with real authority. The most common cause of failure is an ISMS assigned to someone with no mandate to change how engineering or HR operate.
How much does certification cost?
Two costs: our readiness fee and the certification body's audit fee, which is driven by headcount and scope. We give you a realistic combined figure at the end of the gap assessment.
Related services.
The certification your enterprise customers ask for by name, and the one most likely to be blocking a deal right now. We take you from gap assessment to a clean Type I or Type II report.
CMP 05ISO 42001 AI GovernanceThe first international standard for artificial intelligence management systems. If you build or deploy AI, enterprise procurement will start asking for this, and today almost nobody can answer.
SVC 06Secure Code ReviewA penetration test finds what is exploitable from outside. A code review finds what is latent inside, including the flaw that is currently unreachable and will become reachable in the next release.
Find out what stands between you and certification.
Start with a gap assessment. You get a specific list of what is missing and a realistic timeline, whether or not you continue with us.