ISO 27001 is the international standard for an information security management system, and certification means an accredited auditor checked your program against it and signed the certificate. Enterprise buyers in Europe and Asia ask for it the way US buyers ask for SOC 2.
The standard itself is not the confusing part. What trips people up is the machinery around it: two audit stages, an accredited certification body that cannot double as your consultant, and a three year cycle with annual check-ins.
Below is what the requirements actually cover, how the audit runs, and what drives the price.
The Short Answer
ISO 27001 certification requires an accredited auditor to examine your information security management system (ISMS) and confirm it meets the standard, which includes a defined scope, risk assessment, treatment plan, policies, internal audits, and management reviews. The process involves two audit stages, with Stage 1 focusing on documentation review and Stage 2 testing live controls, typically taking four to eight weeks apart. Certification bodies cannot also act as consultants, necessitating separate engagement for preparation and certification.
What ISO 27001 certification actually proves
ISO 27001 certification means an accredited auditor examined your information security management system, or ISMS, and confirmed it meets the standard. That is a narrower claim than most buyers assume. Your certificate says the security program has structure, ownership, and evidence behind it. It does not promise you will never suffer a breach.
An ISMS is the management system wrapped around your controls: a defined scope, a risk assessment, a treatment plan, policies, an internal audit, and a management review on a fixed schedule. Clauses 4 through 10 of the standard spell out those mandatory pieces. Annex A then lists the controls you choose from, based on what your risk assessment surfaced.
Two things carry equal weight in the audit. First, the management system paperwork. Second, live proof that the controls you claimed are running every day.
Annex A after the 2022 revision: 93 controls in 4 themes
The 2022 revision reorganized Annex A from 114 controls across 14 domains into 93 controls across 4 themes. Eleven controls are new, dozens merged, and the numbering changed entirely. If a consultant hands you a gap assessment built on the old 14 domains, they are working from a stale template.
| Theme | Controls | What it covers |
|---|---|---|
| Organizational | 37 | Policies, roles, supplier relationships, threat intelligence, cloud service use, incident planning, continuity |
| People | 8 | Screening, employment terms, awareness training, remote work, reporting security events |
| Physical | 14 | Secure areas, equipment siting, media handling, clear desk, physical monitoring |
| Technological | 34 | Access control, cryptography, logging, secure development, data leakage prevention, web filtering, backup |
New entries cover threat intelligence, security for cloud services, data leakage prevention, secure coding, and physical monitoring. Most of them describe work your team already does in some form. Proving it is the hard part, and our clause by clause breakdown of the ISO 27001 requirements goes deeper on each one.
Nobody applies all 93 controls. You do have to justify every exclusion in a document called the Statement of Applicability, and auditors read that one first. Treat it as the spine of your program rather than a form you fill in at the end.
Inside the certification process: Stage 1 and Stage 2 audits
Certification happens in two audit stages, usually four to eight weeks apart. The first one checks your documents. Whether the system actually runs is what the second one tests.
Stage 1: documentation review
The auditor reads your scope statement, risk assessment, Statement of Applicability, policy set, internal audit results, and management review minutes. Their question is simple: does an ISMS exist on paper, and are you ready for a closer look? Findings at this stage are almost always document gaps, so you get a window to close them before the next visit.
Stage 2: the certification audit
Now the auditor samples evidence. Access reviews, joiner and leaver tickets, supplier assessments, incident records, backup restore tests, and training records all come out. Interviews with staff outside the security team are normal, because the standard cares whether people follow the process you wrote. Issues land as minor or major nonconformities. A major one blocks your certificate until you close it with a corrective action plan that names a root cause.
Most companies need three to nine months of runway before Stage 1 even starts. Auditors want evidence over a period, not a screenshot from last Tuesday, so run your internal audit and your management review early enough that both have real output by the time the auditor arrives.
Certification body versus consultant: the trap
Here is the rule that catches first timers. The firm helping you prepare cannot also be the firm that certifies you. ISO/IEC 17021-1 bars a certification body from certifying a management system it consulted on until at least two years after that work ends, and the bar covers entities it controls.
So you are buying two separate things from two separate companies.
| Consultant or virtual CISO | Certification body (registrar) | |
|---|---|---|
| Job | Gap assessment, risk methodology, policies, internal audit, evidence coaching | Stage 1, Stage 2, surveillance and recertification audits |
| Who vets them | Nobody. You check references and auditor experience yourself | An accreditation body such as ANAB in North America or UKAS in the UK |
| How they bill | Project fee or monthly retainer through the readiness period | Auditor days, priced per stage, plus travel |
| Can they issue your certificate? | No | Yes, and only if an accreditation body backs them |
Verify that accreditation before you sign anything. A certificate from an unaccredited body is a PDF, and enterprise procurement will spot it during a security review. Ask the question in writing, early.
We hold agreements with 54 providers that run security risk assessments, and a real chunk of our matching work is keeping those two roles apart. If one shop pitches you readiness work and certification in the same contract, walk. A good ISO 27001 consulting engagement stops at the prep: gap assessment, risk methodology, policy build, internal audit, and evidence coaching before the auditor shows up.
Surveillance audits and the three year cycle
Your certificate lasts three years, and the audit work never stops. Year one covers initial certification. A surveillance audit follows within 12 months of the certification decision, and another a year after that. Each one samples a shorter slice of your ISMS. In the third year a recertification audit repeats something close to the full Stage 2 before the certificate expires, and no separate surveillance audit runs that year.
Surveillance is where programs quietly fall apart. The person who owned access reviews quits, the risk register goes stale, and the auditor catches it in month eighteen. Budget for the running cost, not just the sprint to the first certificate: annual internal audits, a management review, evidence collection, and one person who owns all of it.
That last part explains why most teams end up on a platform. Pulling evidence automatically from your cloud and identity providers beats chasing screenshots every quarter, and the better compliance management platforms map a single piece of evidence to both ISO 27001 and SOC 2 at once.
What ISO 27001 certification costs, and what moves the number
No honest quote arrives before a scoping conversation. Price comes from auditor days, and auditor days come from headcount, site count, and how much of the business sits inside your scope statement. Anyone quoting a flat fee off a web form is guessing.
Three buckets make up the spend. Your certification body bills Stage 1, Stage 2, and the surveillance years. A consultant or virtual CISO bills the readiness work. Tooling and testing fill the rest, including a penetration test if your risk assessment calls for one, which for a small business runs $5,000 to $20,000 per project.
| Cost driver | What it does to the quote |
|---|---|
| Headcount | Audit days scale with employee numbers. Growing from 30 people to 150 can roughly double the audit fee |
| Scope | One product line and its cloud footprint costs far less than the whole company, every office, and every legacy system |
| Number of locations | Each in scope site adds audit time and travel. Remote auditing softens this, so ask what your body allows |
| Existing SOC 2 | A good share of your evidence carries over, often around half in our experience, which cuts readiness cost sharply and audit cost a little |
| Cloud versus on premise | Server rooms and factory floors pull in physical controls, asset management, and more sampling |
| Internal ownership | No internal owner means paying a virtual CISO to be one, monthly, across the full three year cycle |
For a reference point, a SOC 2 program at a small company starts around $20,000 and climbs from there. ISO 27001 sits in similar territory once you add readiness work and audit fees together, and it lands lower when a SOC 2 program already did half the lifting. A fair quote spells out auditor days, states travel separately, prices the surveillance years up front, and draws a clean line between what the certification body charges and what your consultant charges.
How to choose an ISO 27001 certification partner
We do not care which vendor you pick. Our economics are simple: vendors pay us, you never do, so the only bad outcome here is a match that falls apart in month four. These questions separate a real partner from a template shop.
Questions to ask before you sign
- Which accreditation body backs you, and can you send me the certificate?
- How many auditor days are in this quote, and what headcount and site count did you assume?
- Who is the lead auditor, and which industries have they worked in?
- Do you also sell readiness consulting? If yes, you cannot certify us, so pick a lane.
- Do years two and three appear in this proposal, or do they arrive as a surprise later?
- Will you accept our SOC 2 evidence where the controls overlap?
- If we take a major nonconformity, what does the follow up visit cost?
Traps that cost real money
The biggest one is scope. Certifying the whole company when your customer only cares about one platform can triple the bill and win you zero extra deals. Write the scope statement to match the contracts you are chasing, then widen it later if a buyer demands more.
Second trap: treating the certificate as the finish line. Auditors sample evidence over time, so a program built in six weeks of heroics shows cracks at the first surveillance audit. Third: assuming ISO 27001 replaces SOC 2. Plenty of companies carry both, because their European buyers ask for one and their US buyers ask for the other. Our guide to SOC 2 compliance covers that second path, and what a penetration test costs explains the Annex A 8.8 line item.
When the cheap option is fine
Under about 25 people, running one cloud product, with no offices full of servers? A lean consultant plus a compliance platform plus a mid sized certification body will get you there without drama. Save the heavyweight advisory engagement for regulated industries, multi site manufacturers, and anyone carrying a serious on premise footprint.
Frequently Asked Questions
How long does ISO 27001 certification take?
Most companies reach certification in six to twelve months from a standing start. Evidence sets the floor: auditors want your ISMS operating for a period, usually three months at minimum, plus one completed internal audit and one management review. Teams with SOC 2 already running often finish in four to six months, because the risk assessment and much of the control evidence carry straight over.
What is the difference between ISO 27001 and SOC 2?
ISO 27001 certifies a management system against an international standard, and an accredited body issues a pass or fail certificate. SOC 2 produces an auditor’s report describing your controls and any exceptions, with no certificate at the end. Buyers in Europe and Asia usually ask for ISO 27001, while US enterprise buyers usually ask for SOC 2. Controls overlap heavily, so running both costs far less than double.
How many controls does ISO 27001 have?
The 2022 version lists 93 Annex A controls across four themes: 37 organizational, 8 people, 14 physical, and 34 technological. You apply the ones your risk assessment justifies, then document why you left the others out. Older material citing 114 controls in 14 domains describes the 2013 edition, which no longer applies.
Can our consultant also certify us?
No. Accreditation rules impose a two-year cooling-off period on a firm that helped build your ISMS, so in practice your consultant and your certification body are separate companies. Some large firms offer both through different divisions, and accreditation bodies still treat that as a conflict for the same client. Pick your prep partner and your registrar independently, then ask each one directly about the other role.
Does ISO 27001 certification expire?
Yes. Certificates run on a three year cycle, with two surveillance audits and then a full recertification audit in year three. Skip a surveillance audit and your certification body can suspend or withdraw the certificate. Plan the recurring cost from day one: internal audit, management review, evidence collection, and the audit fees themselves.
Do we need a penetration test for ISO 27001?
The standard never names a penetration test outright, though Annex A control 8.8 on technical vulnerability management makes one the practical way to satisfy an auditor. Most certified companies run at least an annual test against in scope systems. Expect $5,000 to $20,000 per project for a small business, depending on the number of applications and whether the quote includes retesting.
Written by Russ Herman, founder of Defend My Business. We are a technology broker, like a mortgage broker but for business security, internet, and voice. We hold agreements with 400+ vetted providers. Vendors pay us, you never do. See exactly how we make money. Questions: 1-877-453-8759 or [email protected].
Get a Tailored ISO 27001 Shortlist
3 vetted vendors matched to your size, industry, and budget. Free, vendor-neutral, 24-hour turnaround.
Get a Quote →Want help getting your compliance program right?
Defend My Business helps SMBs cut through the marketing and get their compliance program right for their environment, budget, and compliance needs — then deploy and manage it. Through our 400+ vendor network we can often secure better pricing and terms than buying direct, and we stay vendor-neutral, so the recommendation fits you, not a sales quota. Want a second opinion? Pair this with our compliance services or talk it through with an advisor.
Book a free call with a DMB advisor →