Skip to content

Certification & Readiness

ISO 27001 Information Security Management

ISO 27001 is the international standard for information security management systems. It covers how an organisation assesses information security risk, selects controls, and demonstrates that those controls are operating.

Certification is issued by an accredited certification body after an audit. StandardsDesk does not audit or certify — we introduce your enquiry to suitable independent consultants and certification bodies who quote you directly.

Independent referral service: StandardsDesk does not perform ISO audits and does not issue certificates. We refer suitable enquiries to independent consultants and certification bodies, and we may receive a referral fee. Submitting a request does not guarantee certification, a particular price, or acceptance by any provider. Read the affiliate disclosure.

Who it's for

Organisations that commonly pursue ISO 27001

  • SaaS and technology companies asked for security assurance in sales cycles
  • Businesses handling customer or employee personal data at scale
  • Suppliers to enterprise, financial services or public-sector buyers
  • Organisations replacing repeated bespoke security questionnaires

Typical scope

What the work usually involves

  • Scope definition and information asset inventory
  • Risk assessment, risk treatment plan and Statement of Applicability
  • Policies, access control, supplier and incident management processes
  • Internal audit and management review before certification
  • Stage 1 and Stage 2 audits, then surveillance audits across the cycle

FAQ

ISO 27001 questions we're asked most

How is ISO 27001 different from SOC 2?

ISO 27001 is a certifiable international standard for a management system; SOC 2 is an attestation report produced by an auditor against trust services criteria. Buyers in different markets ask for different things — some organisations pursue both.

Do we need penetration testing?

Testing is not automatically mandated by the standard, but many organisations use it as evidence that technical controls work. Providers will tell you what they expect for your scope.

What drives the cost?

Typically headcount, number of sites, the complexity of your systems and how mature your existing controls are. Pricing comes from the independent provider, not from StandardsDesk.

Is StandardsDesk a certification body?

No. We are an independent referral service. We do not perform audits or issue certificates, and we may receive a referral fee when an introduction leads to business.

Ready to compare ISO 27001 quotes?

Describe your scope once and we'll introduce it to suitable independent providers.