ISO/IEC 27001 is the international standard that sets requirements for an information security management system (ISMS): the policies, processes, people and controls an organization uses to manage security risk and keep improving. It is published jointly by two international standards bodies, ISO and the IEC. Organizations can be audited and certified against it by an independent certification body, which makes it one of the most widely recognized ways to show customers that security is run as a managed program.
At a glance
- ISO/IEC 27001 specifies how to run an ISMS: leadership, risk assessment, risk treatment, monitoring, internal audit and continual improvement.
- It includes a reference set of security controls; the organization decides which apply and records the reasons in a Statement of Applicability.
- Certification is issued by an independent certification body after an external audit and covers a defined scope.
- A certificate typically runs on a multi-year cycle with periodic surveillance audits.
- The scope on the certificate may cover only part of an organization, so check that it includes the service you buy.
What problem it solves
Customers want to know that a supplier handles their information safely, and they want a shortcut that doesn’t involve auditing every supplier themselves. A one-off security project or a list of tools doesn’t answer that, because security degrades without someone managing it.
ISO/IEC 27001 addresses this by focusing on the management system. It requires leadership commitment, a repeatable way to assess and treat risks, defined responsibilities, measurement and regular review. A certificate gives customers, partners and regulators a recognized signal that this system exists and has been independently checked. It is especially common in Europe, Asia and in international supply chains.
How it works
Scope. The organization defines what the ISMS covers: which business units, locations, systems and services. A narrow scope is easier to certify but tells customers less.
Risk assessment and treatment. The organization runs a structured risk assessment, then decides how to treat each risk. Controls are chosen from the standard’s reference annex (detailed guidance on them is in the companion standard ISO/IEC 27002) or from elsewhere where needed.
Statement of Applicability. This document lists each reference control, whether it applies, whether it is in place, and why any are excluded. Auditors and informed customers read it closely.
Operation and improvement. The organization runs its controls, monitors them, conducts internal audits and management reviews, and fixes nonconformities. This cycle is what keeps the system alive between audits.
Certification. An accredited certification body audits the ISMS, typically in stages: a documentation review, then a full audit of how it operates. A certificate follows if the audit is passed, with surveillance audits during the cycle and a recertification audit at the end.
When it matters for buyers
- When selling to international or enterprise customers. Certification is frequently a requirement in procurement or supplier onboarding.
- When evaluating a provider. A current certificate with a relevant scope is a strong starting point for vendor due diligence, and can answer parts of a security questionnaire.
- When building a security program from scratch. The standard provides a structure that other frameworks, such as the NIST Cybersecurity Framework (NIST CSF), can map onto.
- When expanding abroad. It is widely recognized across regions, which helps when local requirements differ.
Our governance, risk and compliance overview covers advisors and platforms that help with readiness and audits.
Questions to ask vendors
- Can you share your current certificate, and which certification body issued it?
- Is the certification body accredited, and by which accreditation body?
- What is the scope on the certificate, and does it include the service, systems and locations we will use?
- Can we see your Statement of Applicability, or at least a summary of excluded controls?
- When was your last surveillance audit, and were any major nonconformities raised?
- Which of your own suppliers, such as cloud hosts, fall outside your scope?
- Do you also hold related certifications or reports, such as SOC 2 or cloud-specific extensions?
How it differs from SOC 2
SOC 2 is an attestation report from a CPA firm, built on AICPA criteria and most common in North America. It gives an opinion on specific controls and, in a Type II report, detailed test results over a period. ISO/IEC 27001 is a certifiable international standard for the management system as a whole; the output is a certificate with a scope rather than a detailed report. The controls overlap heavily, and many providers hold both. Both feed into the broader data security compliance and governance, risk and compliance (GRC) work that maps one set of controls to many requirements.
