Key takeaways
- The current version is ISO/IEC 27001:2022. Every certificate issued against the 2013 version lost its validity on 31 October 2025.
- Annex A contains 93 controls in four themes: 37 organizational, 8 people, 14 physical, and 34 technological. Most start-ups and scale-ups implement between 60 and 80 of them.
- Clauses 4 to 10 are mandatory and cannot be deselected. Annex A is a menu; the clauses are not.
- A certificate is valid for three years, with surveillance audits in years one and two and a recertification audit in year three.
- Audit effort scales with the number of people in scope, not with how ambitious the project is. That is why quotes from different certification bodies diverge so widely.
What is ISO 27001?
ISO 27001 is the internationally recognized standard for building and running an information security management system, or ISMS. It is published jointly by the International Organization for Standardization and the International Electrotechnical Commission through committee ISO/IEC JTC 1/SC 27, and the standard itself is listed on ISO.org.
The key word is system. ISO 27001 does not hand you a checklist of firewalls to install, and it prescribes neither technologies nor vendors. It asks you to demonstrate that you run a living process for protecting information: you assess risks, decide on controls, implement them, and keep checking whether they work. That process orientation is what gives a certificate its weight. It signals to a customer that security is built into how you work rather than assembled in the week before the audit.
Everything the standard asks for ultimately serves three properties of information, known as the CIA triad. Confidentiality means sensitive data stays accessible only to authorized people. Integrity means information remains accurate and complete and has not been altered without detection. Availability means authorized users can reach information when they need it. Every single control in your ISMS serves at least one of those three, and a control that serves none of them is probably unnecessary.
A common misconception: teams often talk about "ISMS certification" as though it were something separate. It is not. You are always certified against ISO 27001, and the ISMS is the thing the auditor examines. Anyone searching for ISMS certification is looking for exactly this process.
The current version is ISO/IEC 27001:2022, published in October 2022. Companies holding the older 2013 certificate had until 31 October 2025 to transition. That deadline has passed, so every certificate issued against the 2013 version is now invalid.
ISO 27001 at a glance
Who needs ISO 27001 certification?
Anyone handling other people's data who wants to sell to companies that take security seriously. That now covers a very large share of the European tech market, and increasingly it is regulation rather than sales pressure forcing the question.
Certification is voluntary in the narrow legal sense, but several frameworks make an ISMS effectively unavoidable. The EU's NIS2 directive extends cybersecurity obligations to thousands of mid-sized companies in critical and important sectors, and the management practices it requires overlap closely with ISO 27001. In Germany it has applied since 6 December 2025 with no transition period. The European Commission's official guidance is worth reading if you are unsure whether your sector is in scope.
Automotive suppliers additionally go through a TISAX assessment, and many enterprise buyers simply will not onboard a vendor without a recognized security certificate. Security questionnaires from large buyers increasingly list ISO 27001 as a yes-or-no criterion rather than a preference.
The market pressure is structural. According to the 2025 compliance benchmark report, 81 percent of companies worldwide either already hold an ISO 27001 certificate or plan to pursue one, up from 67 percent the year before. For a company without one, the gap to certified competitors widens every quarter it waits.
A second effect is routinely underestimated. Roughly 70 percent of ISO 27001 requirements overlap with other frameworks including SOC 2, NIS2, GDPR, and TISAX. Policies, controls, and evidence built once for ISO 27001 can be reused across further audit programs. Building a multi-framework program around an ISO 27001 ISMS cuts total cost substantially, because you are not starting from zero each time. Where NIS2 and ISO 27001 overlap is covered in our piece on the overlap between NIS2 and ISO 27001.
One important difference: NIS2 adds mandatory incident reporting deadlines, an early warning to the competent authority within 24 hours and a full report within 72 hours, plus liability rules for management. Both go beyond the scope of ISO 27001. The two regimes complement each other; they do not substitute for each other.
How ISO 27001 is structured
The standard splits into two parts: the mandatory clauses that define the management system, and Annex A, which lists the selectable security controls. Understanding that split is the most useful thing you can do before you start, because only one of the two parts is negotiable.
Clauses 4 to 10 are mandatory
These seven clauses form the non-negotiable core. An auditor examines every one of them.
- Clause 4 requires you to understand the context of the organization, including the expectations of relevant interested parties.
- Clause 5 places responsibility explicitly on leadership. Management must demonstrate active commitment to the ISMS and assign clear responsibilities.
- Clause 6 covers planning: your risk assessment methodology, the risk treatment plan, and your security objectives.
- Clause 7 addresses support: resources, competence, awareness, communication, and documented information.
- Clause 8 governs operational planning and control, including execution of the risk treatment plan.
- Clause 9 requires performance evaluation through monitoring, measurement, internal audits, and management reviews.
- Clause 10 deals with continual improvement and the handling of nonconformities.
Together they are the Plan-Do-Check-Act cycle in standard form. That is the difference between a management system and a one-off security project.
Annex A is a menu
Annex A is the part the 2022 revision changed. The control catalogue was condensed from 114 to 93 and reorganized from 14 domains into four clear themes. Eleven entirely new controls were added, among them A.5.7 on threat intelligence, A.5.23 on information security for cloud services, and A.5.30 on ICT readiness for business continuity.
You do not implement all 93. You select the controls your risk assessment justifies and document every inclusion and exclusion in a Statement of Applicability. Most start-ups and scale-ups land between 60 and 80 controls, concentrating on what genuinely matters for their product infrastructure and data environment. Which control demands what is covered in detail in our guide to the 93 Annex A controls.
What an ISMS actually consists of
An information security management system is not software. It is the combination of policies, processes, procedures, and controls your company uses to manage information security systematically and demonstrably. Five components carry it.
Policies are the foundation. They set the rules by which your company handles security. What matters is that they describe how you actually work. If your acceptable use policy forbids something your team does daily, it is worthless, and in an audit it is a finding.
The risk assessment tailors the ISMS to your situation. You build an inventory of your information assets, identify realistic threat scenarios for your tech stack and industry, assess likelihood and impact, and decide per risk how to treat it: reduce, transfer, avoid, or knowingly accept. The result belongs in a risk register maintained as a living document rather than a one-off spreadsheet.
Controls are the concrete mechanisms that reduce risk. Technical ones like encryption and multi-factor authentication, physical ones like entry restrictions and equipment protection, and administrative ones like policies, training, and defined processes. The administrative ones are the most frequently underestimated.
Incident management decides what happens when something goes wrong anyway. For a start-up that does not mean a round-the-clock security operations center. It means documented procedures, clearly named roles, tested communication paths, and a commitment to learn from every incident. When your first serious incident arrives, a written playbook is the difference between a coordinated response and improvisation.
Continual improvement keeps the system alive. Internal audits check whether controls work as intended, management reviews assess overall health, and corrective actions close the gaps you find. ISO 27001 requires this cycle explicitly.
The practical difference shows up at onboarding. Without an ISMS, someone verbally explains access practices to a new developer, maybe demonstrates the security tooling, and hopes for the best. With one, there is a documented access control policy, a defined provisioning process, a mandatory training module, and evidence that every step was completed. When an auditor or a customer asks how you manage access, you have a demonstrable answer rather than an assurance.
ISO 27001 for start-ups and scale-ups
For younger companies, scope is the single most important lever. A 25-person company that puts only its product and the supporting infrastructure in scope is running a far smaller project than one covering the whole group. Scope also drives audit effort, because audit days follow the number of people in scope rather than the ambition of the project.
For most start-ups, a sensible scope covers the production environment, customer data processing, development practices, and the corporate systems that directly support them. Areas that process no sensitive information do not need to be included. A tightly drawn, defensible scope makes certification reachable faster without diminishing what the certificate is worth.
The most common mistake at this size runs the other way. Teams cut scope so tight that the certificate no longer answers the buyer's question. If your largest customer wants to know whether the customer portal is covered and your certificate covers only internal IT, you have passed an audit and gained nothing. Cut scope to match what sales is actually asked about, and widen it in the next certification cycle.
A concrete example: a 45-person SaaS company puts product, infrastructure, and customer support in scope, assigns one internal owner at roughly half their working time, and builds the ISMS on a platform rather than in spreadsheets. At that headcount, the initial certification audit runs to around eight and a half audit days.
The second reason small companies stall is not scope but interpretation. The standard tells you what must be achieved, not what to do on Monday morning.
How to shape an ISMS so it grows with you instead of crushing you on day one is covered in our guide to building an ISMS for startups.
The road to certification: the four phases
Certification follows a predictable sequence: preparation, implementation, internal audit, and the external certification audit. Three to six months is the normal case. Teams running everything in spreadsheets regularly take nine to twelve months.
Two points deserve particular attention, because they produce a disproportionate share of audit findings.
The Statement of Applicability is the most closely scrutinized document in the entire process. It must be fully consistent with the results of your risk assessment. A control excluded without a defensible reason suggests to the auditor that the risk assessment was rushed, and they will look harder.
The evidence period is routinely underestimated. The Stage 2 audit requires proof that controls have been operating for a period of typically three to six months. Start collecting too late and you either move the audit date or accept formal findings.
If your question is simply how long ISO 27001 certification takes, our short answer covers it.
Tooling shortens the evidence work, not the building work. If you can demonstrate controls automatically, you save the weeks that would otherwise go into hunting down screenshots and log exports. The processes themselves still have to exist, and there is no shortcut for that.
What drives the cost
The bill has three parts: gap analysis and preparation, implementation of the ISMS, and the certification body's audit fees. Only the audit fees are fixed. The other two depend on how much manual work goes into documentation and evidence collection, and that is where a project becomes expensive or does not.
A common planning error: managing directors budget the audit invoice and miss the larger line item. For most mid-sized companies the months of person-time spent on documentation and evidence collection exceed the certification body's fees considerably, yet they appear in no quote. It is also the only part you control, because no software reduces what the certification body charges.
Specific figures by company size, broken down across the three blocks and including the surveillance audit, are in our overview of what ISO 27001 certification costs. How different approaches change that calculation is compared in our review of the best ISO 27001 compliance tools.
The route you choose determines both controllable blocks at once. Which route reaches the certificate fastest, and how to recognize a provider that can actually hold that pace, is covered in our piece on getting ISO 27001 certified quickly.
Choosing a certification body
Certificates are not issued by ISO. They come from an accredited certification body, and accreditation is granted by a national accreditation body: UKAS in the United Kingdom, DAkkS in Germany, and equivalents elsewhere. Bodies operating across Europe include TÜV Nord, TÜV SÜD, BSI Group, Bureau Veritas, and DNV.
Recognition matters as much as competence. A certificate from a body your buyer has never heard of will get read differently in a procurement process, even if the audit behind it was rigorous. The most practical route to a decision runs through your own customers: ask the two or three most important ones which bodies they recognize before you sign anything.
Not every seal that looks like ISO 27001 comes from an accredited body. The IAF maintains a global database of accredited certificates where a certificate can be validated, which is also how your customers will check yours. A non-accredited certificate surfaces at the latest during a vendor review, and at that point you have spent money and months on a document that fails at its only job. How to spot dubious providers and worthless certificates is covered separately.
Where teams stumble: common mistakes and audit findings
Most first-time failures are not exotic. They are the same few patterns auditors see over and over.
Scope is too broad from the start. The most common reason certification takes longer than planned is trying to pull every internal system and process into the first scope. Begin with the production environment and customer data, then widen in the next cycle.
Documentation is treated as the goal. Auditors check whether controls operate, not whether they are well written. A comprehensive access control policy is worthless if your actual process does not match it. Build the real process first, then document what you actually do. The single most frequent finding of all is a policy specifying quarterly reviews with no record of the last three.
The evidence effort is underestimated. As above: three to six months of operation has to be demonstrable. Continuous, automated collection solves that structurally. A scramble shortly before the audit does not.
Supplier security gets forgotten. Controls A.5.19 to A.5.22 cover supplier relationships and supply chain security. For a SaaS company, your cloud provider, your payment processor, and your main SaaS tools are in scope. Incomplete supplier assessments are one of the most reliable finding categories there is.
The internal audit is treated as a formality. A genuine internal audit before the Stage 2 date finds the problems that would otherwise become formal findings, and it shows the external auditor that your review cycle works. Tick it off and you will be surprised at Stage 2.
One cause sits before the project even starts. Hang certification on the wrong role and you generate findings before the first policy is written.
The pattern behind all five points is the same: ISO 27001 rewards living systems and punishes paper theatre.
Certification is the start, not the finish
The certificate is not the goal. It is the beginning of a three-year relationship with your certification body. Surveillance audits in years one and two confirm the ISMS is still alive and improving; a full recertification audit follows in year three.
This is exactly where spreadsheet-based compliance quietly falls apart. The project team disperses after the celebration, evidence collection goes dormant, and the next surveillance audit becomes a fire drill. Continuous compliance solves it by turning evidence collection into an ongoing background process rather than an annual event. The teams that stay calm at renewal are the ones that never stopped collecting.
The same mechanism works outward. A maintained ISMS turns security reviews in your sales process from negotiations into short confirmations. You move from "we take security seriously" to "here is our certificate, here is our Statement of Applicability, and this is how we manage those risks."
How Kertos supports certification
ISO 27001 does not have to consume a year of your team's time. Kertos combines an agentic compliance platform with certified experts who work alongside you. The platform ships policy templates aligned to ISO 27001:2022, maps each task to the clause it satisfies, and collects evidence automatically through integrations with the systems you already run. Instead of assembling screenshots and log exports, evidence accumulates in the background from the day you connect your systems. Against a spreadsheet-based approach, that cuts manual effort by around 80 percent.
Kertos customer AskUI was certified in around ten weeks, without external consultants and without blocking their engineering team. Emidat completed full certification in two and a half months, also without outside consultants. Across the customer base the audit success rate is 100 percent, which mostly reflects the difference between arriving at a Stage 2 audit with months of continuously collected evidence and arriving with documentation assembled under time pressure.
Because Kertos is built in Europe and hosted on European infrastructure, it also meets the data residency expectations that NIS2 and GDPR place on you.
If ISO 27001 is on your roadmap, the next step is a demo where we map out your specific route to certification.
Frequently asked questions
How long does ISO 27001 certification take?
Three to six months is the normal case. Maturity and automation are the deciding factors: teams running everything in spreadsheets regularly take nine to twelve months, while teams with a dedicated platform and expert support take considerably less.
Is ISO 27001 mandatory?
Not by law. Frameworks such as NIS2 and TISAX, together with enterprise procurement requirements, make it effectively necessary for many European tech companies.
Can a 15-person start-up get ISO 27001 certified?
Yes. ISO 27001 is designed to scale to any company size. A small company usually has a simpler system landscape, fewer processes, and less coordination overhead, which means a tighter scope and a more manageable audit. What matters is not team size but that one person owns the program and drives evidence collection.
Do we need external consultants?
Not necessarily. Many companies reach certification with a compliance platform and their certification body's resources. Consultants add the most value where regulatory complexity is high or internal capacity is very thin. Either way, what matters is whether the ISMS is lived afterward or existed only for the audit.
What is the difference between ISO 27001 and ISO 27002?
ISO 27001 is the certifiable standard defining the management system requirements. ISO 27002 is a companion guideline explaining how the Annex A controls are implemented in practice. You are certified against 27001 and consult 27002 for detail.
How many controls does ISO 27001:2022 contain?
Annex A contains 93 controls across four themes: 37 organizational, 8 people, 14 physical, and 34 technological. Most start-ups and scale-ups implement 60 to 80 of them and justify both inclusions and exclusions in the Statement of Applicability.
What happens if we fail the Stage 2 audit?
An outright failure is rare. More often the auditor raises nonconformities. Minor ones require a corrective action plan within a set deadline; major ones require a follow-up audit of the affected areas. The most common cause of surprises is evidence gaps, meaning controls that are documented but not demonstrably in operation.
How often is recertification required?
The certificate is valid for three years, with annual surveillance audits in years one and two and a full recertification audit at the end of the cycle. For an overview of every supported framework and where ISO 27001 sits alongside SOC 2, GDPR, and NIS2, see our ISO 27001 certification page.






