We use essential cookies to run this site. Analytics & marketing cookies load only with your consent — see our Cookie Policy and Privacy Policy.

Frequently asked questions

ISO 27001 certification confirms that an organisation has a structured system to manage and protect sensitive information from security risks.
Customers ask for ISO 27001 certification to confirm their data is protected through defined security controls and risk management practices.
ISO 27001 is not legally mandatory, but customers, partners and enterprise contracts often require it.
Organisations handling customer data, employee data or digital services commonly need ISO 27001 certification.
Yes. ISO 27001 scales to startups, small businesses and large enterprises.
ISO 27001 certification typically takes three to six months, depending on scope and readiness.
An ISO 27001 audit verifies whether your policies, controls and processes meet ISO requirements.
Stage 1 reviews documentation and readiness. Stage 2 checks actual implementation and the effectiveness of controls.
An ISMS is a framework of policies, processes and controls used to manage information security risks.
Key documents include the risk assessment, Statement of Applicability, ISMS policies, procedures and audit records.
Annex A lists the security controls used to address identified information security risks.
It sets out which Annex A controls apply to the organisation and how they are implemented or justified.
Defining the ISMS scope and running an accurate risk assessment are the most common challenges.
Tools can help, but ISO 27001 focuses more on governance, processes and risk management.
Cost varies with organisation size, scope and certification body audit fees.
ISO 27001 audits are conducted by accredited independent certification bodies.
Yes. Employee awareness and role-based training are mandatory requirements.
Yes. ISO 27001 applies to cloud, SaaS, on-premise and hybrid environments.
Yes. ISO 27001 certification is recognised internationally.
Certification is valid for three years, with annual surveillance audits.
Yes. It supports GDPR by strengthening data protection and security controls.
Yes. Structured risk management and continuous monitoring reduce incidents.
No. Auditors verify actual control implementation, not just documentation.
Yes. Internal audits are mandatory before external certification audits.
Yes. Many enterprise customers prefer or require ISO 27001 certified vendors.
IT, SaaS, fintech, healthcare, cloud providers, MSPs and professional services.
Audit duration depends on scope and organisation size, usually a few audit days.
Yes. It integrates well with ISO 9001, ISO 14001, SOC and PCI DSS.
Defining the ISMS scope and running a risk assessment is the first step.
It means auditors identified nonconformities that must be corrected before certification or continuation.
Poor risk assessment, unclear scope, missing evidence, weak controls and lack of management involvement.
Yes. Organisations can fix nonconformities and submit corrective actions within the allowed timelines.
A serious ISMS failure, such as missing risk treatment or ineffective security controls.
A partial gap that does not break the ISMS but still requires correction.
Usually 30 to 90 days, depending on severity and certification body rules.
No. It means readiness gaps must be fixed before Stage 2.
Yes. Missing or inconsistent documents often lead to nonconformities.
Yes. Auditors often find gaps when staff are unaware of ISMS policies.
Yes. Unresolved issues during surveillance audits can lead to suspension or withdrawal.
By running internal audits, training employees and making sure controls operate in practice.
No. ISO 27001 focuses on governance and processes, not just tools.
Yes. Leadership commitment and reviews are verified during audits.
Yes. An unclear or incorrect ISMS scope is a common audit issue.
Yes. Experienced guidance helps align ISMS implementation with audit expectations.
ISO 27001 is a security management standard, SOC is an assurance report and PCI DSS focuses on payment card security.
ISO 27001 is a certification, SOC produces reports and PCI DSS is a compliance requirement.
Enterprise customers require SOC reports for vendor risk assurance.
Any organisation handling payment card data must comply with PCI DSS.
No. ISO 27001 is voluntary, while PCI DSS is mandatory for card data.
No. They serve different purposes and are often used together.
ISO 27001 for governance and SOC 2 for customer assurance are commonly combined.
PCI DSS focuses only on protecting cardholder data.
ISO 27001 focuses on management controls, not penetration testing by default.
Yes. SOC audits test control effectiveness over time.
Both ISO 27001 certification and SOC reports support enterprise trust.
Yes. ISO 27001 requires continuous governance and improvement.
Yes. SOC reports are designed mainly for customer assurance.
No. PCI DSS applies only to payment card environments.
ISO 27001 scales well and suits startups.
Yes. A strong ISMS simplifies SOC and PCI DSS compliance.