Free tool · ISO 27001

Do I need ISO 27001?

ISO 27001 is voluntary, but it is the certificate buyers in Europe, the UK and India usually ask for, and many enterprise and public-sector tenders list it. Answer five questions to see whether you need the certificate now, or whether working to the standard is enough for the moment.

Short answer

Usually no law requires ISO 27001; buyers and tenders do. You need the certificate if you are a B2B company handling customer data that sells to enterprises or the public sector in Europe, the UK or India, or a SEBI-regulated MII or Qualified RE. If US buyers dominate, SOC 2 usually comes first. Certification takes a Stage 1 and Stage 2 audit and lasts three years.

Answer for your organisation

ISO 27001 certifies a management system for information security, not a product.
ISO 27001 is international. In the US, buyers more often ask for SOC 2.
SEBI's CSCRF sorts regulated entities into five categories; MIIs and Qualified REs are the top two. See the CSCRF guide if you are unsure of yours.
Worked example: a European B2B SaaS company selling to enterprises

Result

An indication from your answers, not legal advice. Applicability turns on facts a form cannot see; confirm it with counsel or your auditor before you rely on it.
Likely required: expect to be asked as deals grow

Outside the US, ISO 27001 is the certificate enterprise buyers recognise. Security questionnaires are usually the first sign; a certificate lets you answer most of them with one document. Start before a large deal depends on it, because the first certification takes months, not weeks.

ISMS requirementsISO/IEC 27001:2022 cl. 4–10
Statement of Applicability against Annex Acl. 6.1.3, Annex A
  • Scope: decide what the ISMS covers: usually the product, the teams that build and run it, and the offices or cloud accounts they use. A narrow, honest scope certifies faster than a vague one.
  • Risk and the SoA: run a risk assessment, choose treatments, and write the Statement of Applicability: which of the 93 Annex A controls apply, which do not, and why.
  • Run it, then audit: operate the ISMS for long enough to have records (an internal audit and a management review at minimum), then book Stage 1 and Stage 2 with an accredited certification body.
01

What ISO 27001 is

ISO/IEC 27001:2022 sets the requirements for an information security management system (ISMS): the way an organisation decides which information risks matter, treats them, and checks that the treatment works. Clauses 4 to 10 are the management system. Annex A lists 93 reference controls in four themes (organisational, people, physical and technological), which you apply where your risk assessment calls for them. ISO/IEC 27002 gives guidance on each control; it cannot be certified to. The 2022 edition replaced the 2013 edition, which ISO has withdrawn, and Amendment 1 of 2024 added climate action changes.

02

Certification or alignment

ISO itself says certification is a choice: some organisations implement the standard for its practice, others also certify to reassure customers. Alignment means you run your security to the standard but no auditor has checked it, so a buyer has only your word. Certification means a certification body audited your ISMS and issued a certificate naming its scope. A certificate from an accredited body carries more weight, because an accreditation body has checked the certifier. Ask buyers which they need; tenders that list ISO 27001 almost always mean a certificate.

03

How certification works

Stage 1 reviews your ISMS documentation and readiness: scope, risk assessment, Statement of Applicability, policies. Stage 2 tests whether the ISMS and controls operate as documented, by interview, sampling and evidence. Nonconformities found must be corrected before the certificate is issued. The certificate runs for three years, with a surveillance audit in each of the two years after certification and a recertification audit before the third year ends. An internal audit and a management review must happen before Stage 2 and every year after.

04

Sources

Questions

The things people ask us

Is ISO 27001 mandatory?

Not as a general rule. It becomes a requirement when a buyer's procurement policy, a contract or a tender demands it, which is common in Europe, the UK and India. A few sector rules mandate it, such as SEBI's CSCRF for its largest regulated entities.

Is ISO 27001 mandatory in India?

For most companies, no. SEBI's CSCRF does make it mandatory for market infrastructure institutions and Qualified REs. For everyone else it is usually a condition of the deal, not of the law: many enterprise buyers and public-sector tenders ask suppliers for it.

How long does ISO 27001 certification take?

Often three to six months from a standing start, depending on scope and how many controls already exist. The audits themselves take days; most of the time goes on running the ISMS long enough to have records, including an internal audit and a management review.

How long is an ISO 27001 certificate valid?

Three years, provided you pass a surveillance audit in each of the two years after certification. A recertification audit before the end of the third year starts a new cycle.

How many controls are in ISO 27001:2022?

Annex A lists 93 controls in four themes: organisational, people, physical and technological. You do not have to implement all of them; the Statement of Applicability records which apply and why the others do not.

What is the difference between ISO 27001 and SOC 2?

ISO 27001 certifies a management system and produces a certificate; SOC 2 is a CPA's attestation report on controls. ISO 27001 is expected in Europe and much of Asia, SOC 2 in the United States. Most controls overlap, so the second costs much less.

Do I need Cyber Essentials if I have ISO 27001?

For UK central government contracts that call for Cyber Essentials, yes, unless the buyer accepts your ISO certificate as evidence of equivalent controls. The two schemes check different things, and the procurement note asks for Cyber Essentials or equivalent controls.

Book a walkthrough

See what applies to you, and track it.

TryTrustable maps your controls to every framework you need and keeps the evidence current.