Do I need ISO 27001?
ISO 27001 is voluntary, but it is the certificate buyers in Europe, the UK and India usually ask for, and many enterprise and public-sector tenders list it. Answer five questions to see whether you need the certificate now, or whether working to the standard is enough for the moment.
Usually no law requires ISO 27001; buyers and tenders do. You need the certificate if you are a B2B company handling customer data that sells to enterprises or the public sector in Europe, the UK or India, or a SEBI-regulated MII or Qualified RE. If US buyers dominate, SOC 2 usually comes first. Certification takes a Stage 1 and Stage 2 audit and lasts three years.
Result
Outside the US, ISO 27001 is the certificate enterprise buyers recognise. Security questionnaires are usually the first sign; a certificate lets you answer most of them with one document. Start before a large deal depends on it, because the first certification takes months, not weeks.
- Scope: decide what the ISMS covers: usually the product, the teams that build and run it, and the offices or cloud accounts they use. A narrow, honest scope certifies faster than a vague one.
- Risk and the SoA: run a risk assessment, choose treatments, and write the Statement of Applicability: which of the 93 Annex A controls apply, which do not, and why.
- Run it, then audit: operate the ISMS for long enough to have records (an internal audit and a management review at minimum), then book Stage 1 and Stage 2 with an accredited certification body.
What ISO 27001 is
ISO/IEC 27001:2022 sets the requirements for an information security management system (ISMS): the way an organisation decides which information risks matter, treats them, and checks that the treatment works. Clauses 4 to 10 are the management system. Annex A lists 93 reference controls in four themes (organisational, people, physical and technological), which you apply where your risk assessment calls for them. ISO/IEC 27002 gives guidance on each control; it cannot be certified to. The 2022 edition replaced the 2013 edition, which ISO has withdrawn, and Amendment 1 of 2024 added climate action changes.
Certification or alignment
ISO itself says certification is a choice: some organisations implement the standard for its practice, others also certify to reassure customers. Alignment means you run your security to the standard but no auditor has checked it, so a buyer has only your word. Certification means a certification body audited your ISMS and issued a certificate naming its scope. A certificate from an accredited body carries more weight, because an accreditation body has checked the certifier. Ask buyers which they need; tenders that list ISO 27001 almost always mean a certificate.
How certification works
Stage 1 reviews your ISMS documentation and readiness: scope, risk assessment, Statement of Applicability, policies. Stage 2 tests whether the ISMS and controls operate as documented, by interview, sampling and evidence. Nonconformities found must be corrected before the certificate is issued. The certificate runs for three years, with a surveillance audit in each of the two years after certification and a recertification audit before the third year ends. An internal audit and a management review must happen before Stage 2 and every year after.
Sources
- ISO: ISO/IEC 27001:2022 Information security management systems: Requirements
- ISO: ISO/IEC 27002:2022 Information security controls
- SEBI: Cybersecurity and Cyber Resilience Framework (CSCRF), circular of 20 August 2024
Facts checked against these sources in October 2026. Laws, thresholds and guidance change: check the source before you rely on a figure.
The things people ask us
Is ISO 27001 mandatory?
Not as a general rule. It becomes a requirement when a buyer's procurement policy, a contract or a tender demands it, which is common in Europe, the UK and India. A few sector rules mandate it, such as SEBI's CSCRF for its largest regulated entities.
Is ISO 27001 mandatory in India?
For most companies, no. SEBI's CSCRF does make it mandatory for market infrastructure institutions and Qualified REs. For everyone else it is usually a condition of the deal, not of the law: many enterprise buyers and public-sector tenders ask suppliers for it.
How long does ISO 27001 certification take?
Often three to six months from a standing start, depending on scope and how many controls already exist. The audits themselves take days; most of the time goes on running the ISMS long enough to have records, including an internal audit and a management review.
How long is an ISO 27001 certificate valid?
Three years, provided you pass a surveillance audit in each of the two years after certification. A recertification audit before the end of the third year starts a new cycle.
How many controls are in ISO 27001:2022?
Annex A lists 93 controls in four themes: organisational, people, physical and technological. You do not have to implement all of them; the Statement of Applicability records which apply and why the others do not.
What is the difference between ISO 27001 and SOC 2?
ISO 27001 certifies a management system and produces a certificate; SOC 2 is a CPA's attestation report on controls. ISO 27001 is expected in Europe and much of Asia, SOC 2 in the United States. Most controls overlap, so the second costs much less.
Do I need Cyber Essentials if I have ISO 27001?
For UK central government contracts that call for Cyber Essentials, yes, unless the buyer accepts your ISO certificate as evidence of equivalent controls. The two schemes check different things, and the procurement note asks for Cyber Essentials or equivalent controls.
See what applies to you, and track it.
TryTrustable maps your controls to every framework you need and keeps the evidence current.