Skip to content
Compliance Framework

ISO/IEC 27001

ISO/IEC 27001 is the international standard for an information security management system. It produces a certificate from an accredited body, and what it certifies is the management system itself, not a list of controls.

Compliance Guide
7 min read

What ISO/IEC 27001 is

ISO/IEC 27001 is the international standard for an information security management system, or ISMS. Unlike SOC 2, it produces an actual certificate, issued by an accredited certification body after a two-stage audit.

The distinction that matters is what is being certified. ISO 27001 certifies a management system: the governing structure by which you decide what to protect, how much, and on what basis. The individual controls follow from that system rather than being the point of it.

Who asks for it

ISO 27001 tends to come up where SOC 2 does not, and increasingly companies are asked for both.

  • European and Asian enterprise buyers, who often treat it as the default rather than SOC 2
  • Procurement and vendor-risk teams at multinational customers
  • Tenders and RFPs that name certification as a qualifying condition
  • Partners who need a recognised certificate rather than a report they have to read and interpret

The management system

The clauses of the standard describe the machinery of the ISMS, and this is where certification is won or lost. An organization with strong technical controls and no functioning management system will not pass.

  • Context and scope: what the ISMS covers, and which interested parties it has to satisfy
  • Leadership: a security policy, assigned responsibilities, and demonstrable management commitment
  • Planning: a defined risk assessment methodology, a risk treatment plan, and measurable objectives
  • Support and operation: competence, awareness, documented information, and the operating record
  • Performance evaluation: monitoring, internal audit, and management review at planned intervals
  • Improvement: nonconformities logged, corrected, and driven to root cause

Annex A and the Statement of Applicability

Annex A lists reference controls, organized in the current version into organizational, people, physical, and technological themes. You do not have to implement all of them, but you do have to account for all of them.

That accounting is the Statement of Applicability: a document naming every Annex A control, whether it applies, why, and where its implementation lives. It is the single most scrutinized artifact in the certification audit, because it is where a claim about scope meets a justification an auditor can test.

Certification and the three-year cycle

Certification runs in stages and then continues. A Stage 1 audit reviews whether the ISMS documentation is ready; a Stage 2 audit tests whether it operates as described. A certificate issued on that basis runs for three years.

It is not left alone in the meantime. Surveillance audits happen annually, and the full cycle repeats with a recertification audit at the end. Internal audits and management reviews have to have genuinely taken place between them, with records to show it.

How Verdict helps

Verdict builds and runs the ISMS: scope and context, the risk methodology and risk register, the policy set, the Statement of Applicability, and the internal audit and management review cycle that certification depends on.

We carry it through Stage 1 and Stage 2, hold the corrective action record for anything raised, and keep the system live through surveillance and recertification. You review the whole of it in a client portal rather than assembling it before each audit.

ISO/IEC 27001 is part of commercial assurance, the work that covers what a customer, partner, or procurement team asks you to produce before they will do business with you. The same lane also covers SOC 2 Type I and Type II, and HIPAA. For the mechanics of an engagement, see how we work.

Whether you are pursuing a first certificate or maintaining one through surveillance, we can run the ISMS and keep the record audit-ready.

Talk to a Consultant