Schedule DemoStart Free Trial

Unified Observability Platform for Modern IT Operations

Summarize with AI what Motadata does:

ObserveOps

  • Network Observability
  • Network Configuration & Compliance Management
  • Hybrid Infrastructure Monitoring
  • Log Monitoring
  • Application Performance Monitoring
  • Real User Monitoring

ServiceOps

  • Service Management
  • IT Asset & Configuration Management
  • Patch & Deployment Management
  • Agentic AI & Orchestration
  • MSP Edition

By Use Cases

  • Data Centre Monitoring
  • Docker Monitoring
  • Enterprise Service Management
  • IT Service Desk
  • ITSM MSP
  • Enterprise Network Monitoring

By Technologies

  • AWS Monitoring
  • Azure Monitoring
  • Kubernetes Monitoring
  • DevOps Observability
  • REST API Monitoring
  • Storage Monitoring

Resources

  • Getting Started
  • Documentation
  • Integrations
  • IT Glossary
  • Whitepapers
  • Ebooks & Guides
  • Product Brochures
  • Success Stories
  • Comparison
  • Features

Community

  • Blog
  • Press Releases
  • Events
  • Webinar
  • Become a Partner

Company

  • Company
  • Careers
  • Contact Us
  • Customer Support

Get in Touch

  • Request Demo
  • sales@motadata.com
  • support@motadata.com
© 2026 Mindarray Systems Limited. All rights reserved.
Privacy PolicyTerms of Service
Back to Blog
Compliance
11 min read

ISO 27001 Compliance: What Auditors Require and When You Need the Certificate

Written by

Ramya Shah

Technical Writer

Reviewed by

Keertan Zala

Product Manager

Published

October 5, 2026

11 min read

ISO 27001 compliance means running your information security the way ISO/IEC 27001 sets out. Most teams meet the standard when a customer sends over a security questionnaire. It lands as one more line on a cybersecurity compliance checklist.

That framing hides the decision underneath it. You can follow the standard without ever being certified against it. The two routes cost very different amounts.

In this blog, you will:

  • Tell compliance apart from certification.

  • See which buyers and regulators accept a self-declared ISMS.

  • Read what Clauses 4 to 10 require of you.

  • Follow the audit stages and the real cost drivers.

You will finish able to decide whether you need the certificate, and what it takes.

What Is ISO 27001 Compliance?

ISO 27001 compliance means your information security management system meets the requirements of ISO/IEC 27001:2022. The standard treats information security as a managed system, with a defined scope and named owners.

That system has a name and a boundary. An information security management system (ISMS) covers your policies, roles, processes, and records. You use it to manage information risk inside a scope you define.

The standard comes in two halves. Clauses 4 to 10 carry the mandatory requirements every organization has to meet. Annex A holds 93 security controls, and your risk assessment decides which ones you select.

Compliance holds only while the system keeps running. You are compliant on the day you can show it works as documented.

Compliant vs Certified: What the Certificate Actually Buys

Compliance and certification differ by who says so. You decide you are compliant. A certification body decides you are certified, and it audits you first.

Both routes start from the same requirements. The work of building an ISMS does not change if nobody audits it.

The table below compares the two on what decides your budget and your timeline.

Compliant (self-declared)

Certified

Who confirms it

Your own team

An accredited certification body

How it is tested

Internal audit and management review

A Stage 1 and Stage 2 audit by an external assessor

What you can hand a buyer

Your own documents and answers

A certificate naming your scope

Renewal

Whatever cadence you set

Annual surveillance, full recertification every three years

Cost

Internal time only

Internal time plus audit fees

What happens when it slips

Nothing, until something breaks

A surveillance audit finds it

Self-declared compliance is honest work while nobody is asking for a certificate. The moment somebody asks, it stops being enough. The word compliant carries no weight without a name attached to it.

Certification also adds a forcing function that alignment lacks. An external assessor opens by checking whether last year's corrective actions closed. Internal programs quietly skip that check when the quarter gets busy.

Who Accepts a Self-Declared ISMS, and Who Does Not

Whether a self-declared ISMS is enough depends entirely on who is asking for it. The answer splits along one line. Does the party on the other side carry their own liability for your security?

The table below sets out the six requesters that come up most often. Each row says what they usually do with a self-declaration.

Who is asking

Accepts self-declared?

Why

Enterprise procurement

Rarely

The certificate replaces a bespoke security review, and that saving is the reason they asked

A prime contractor flowing down a clause

No

Their own contract names an accredited certificate, so they cannot accept less

A cyber insurer at renewal

Sometimes

Underwriters score the controls themselves, and some accept evidence without accreditation

A financial or healthcare regulator

Depends

Most name their own framework and treat ISO 27001 as supporting evidence

Your own board or audit committee

Usually

Internal assurance has no accreditation requirement behind it

A mid-market customer with a questionnaire

Often

They want the questionnaire answered, and the answers are the deliverable

Two patterns run through that table. Anyone who inherits your risk wants a third party to have checked. Anyone assuring themselves can accept your word.

Healthcare shows the regulator case clearly. The HIPAA technical safeguards set the actual obligation there. An ISO 27001 certificate supports that obligation without replacing it.

We get asked which of these matters most. The honest answer is whichever one is holding up a contract right now.

Is ISO 27001 a Legal Requirement?

ISO 27001 is not written into law anywhere. No statute requires the certificate, and no regulator will fine you for lacking one.

The standard reaches you through contracts instead. A customer agreement, a supplier clause, or a tender requirement names it. From that point it binds you as firmly as a regulation would.

Data protection law works the other way around. GDPR compliance asks for appropriate technical and organizational measures without naming a standard. A certified ISMS becomes one way to show you chose those measures on purpose.

So run the question in one direction. Find out who is actually asking, and let their answer set your scope.

Who Accepts a Self-Declared ISMS, and Who Does Not

What Do Clauses 4 to 10 Require?

Clauses 4 to 10 are the mandatory half of ISO 27001. You cannot exclude any of them. They tell you to build a management system, run it, check it, and fix it, in that order.

The numbering confuses people, so it helps to say where the requirements begin. The standard runs from Clause 1 to Clause 10. The first three cover scope, references, and definitions. The part you certify against starts at Clause 4.

Each clause produces something an auditor will ask to see. The table below names what that is.

Clause

Title

What it asks you to produce

4

Context of the Organization

A defined ISMS scope, plus a list of interested parties and what they require

5

Leadership

A signed information security policy and named roles that carry real authority

6

Planning

A risk assessment process, a risk treatment plan, a Statement of Applicability, and measurable objectives

7

Support

Evidence of competence, awareness activity, and version control over your documents

8

Operation

Records showing the risk assessment and the treatment plan actually ran

9

Performance Evaluation

Measurement results, an internal audit program, and management review minutes

10

Improvement

A record of every nonconformity, the action taken, and whether the action worked

Clause 6 carries the most weight of the seven. Everything you implement later traces back to the risk assessment it asks for. The rest of the standard stands on your IT risk management practice.

We build every ISO 27001 conversation around Clause 6 for that reason. Get it wrong and the Statement of Applicability has nothing solid underneath it.

One recent change sits inside Clause 4. ISO/IEC 27001:2022/Amd 1:2024 added climate change to the context you have to consider. Your context review now has to say whether it applies to you.

What each mandatory clause produces

Why Clause 9.1 Catches Teams With the Best Monitoring

Clause 9.1 asks you to measure the ISMS. Your monitoring watches infrastructure, which is a different object entirely. Teams with excellent dashboards still fail it. Those dashboards answer a question the clause never asked.

The clause names six things you have to determine before you start collecting anything.

  • What gets monitored and measured, including the security processes and the controls themselves

  • The methods used, which have to give comparable and reproducible results

  • When the measuring happens

  • Who performs it

  • When the results get analyzed and evaluated

  • Who does that evaluation

What Clause 9.1 Measures Is the Control

Infrastructure monitoring tells you a server stayed up and a firewall stayed reachable. Control measurement tells you whether the access review happened on schedule. It counts how many accounts came off, and it shows which way that number is moving.

Both draw on the same underlying data. Only one of them answers Clause 9.1.

Why a Dashboard Screenshot Fails the Method Test

The method requirement is the part that quietly fails. Comparable means two measurements taken six months apart used the same definition. Reproducible means somebody else running your method arrives at your number.

A dashboard screenshot fails both tests. It shows a value at one moment, with no method stated behind it. An assessor can neither repeat that nor compare it.

The fix is smaller than it sounds. Pick three or four measures you really run. Write the method down before you start collecting. Keep the definition stable across periods.

Log compliance reporting turns retention and coverage into a repeatable number. Clause 9.1 is looking for exactly that shape.

We keep seeing programs over-invest in the control list and under-invest here. It shows up at the internal audit long before a certification body arrives.

Turn Control Measurement Into a Number You Can Repeat

ServiceOps records incidents, changes, and asset checks with owners and dates, so Clause 9 measures come from the workflow itself.

Explore Motadata ServiceOps

What Documents Does ISO 27001 Compliance Require?

ISO 27001 requires a specific set of documented information. An auditor will ask for all of it. The list is shorter than most teams expect. It leaves very little room for interpretation.

It splits cleanly into two groups, and the difference between them drives your timeline.

Documents You Write Once and Maintain

These are authored deliverables, and a focused team can finish them in weeks.

  • The ISMS scope statement

  • The information security policy

  • Your risk assessment process and your risk treatment process

  • The Statement of Applicability

  • Measurable information security objectives

  • The operating procedures your own scope makes necessary

Records the System Generates by Running

These cannot be written in advance, because each one is evidence that something happened.

  • Risk assessment results and risk treatment results

  • Evidence of competence for the people holding ISMS roles

  • Monitoring and measurement results

  • The internal audit program and its findings

  • Management review outputs

  • Nonconformities, the actions taken, and the results of those actions

The split matters for planning more than for filing. The first group is a writing project with an end date. The second group only exists if the system actually ran. Starting late costs a lot no matter how fast you write.

Where Annex A Fits

Annex A is the control reference you select from once the risk assessment is finished. It lists 93 security controls across four themes covering organizational, people, physical, and technological measures.

Clause 6 is what sends you there. You treat each risk first, then compare your chosen controls against Annex A. The comparison confirms nothing necessary was left out.

Applicability stays your decision. You can exclude a control that addresses no risk you identified. Write the reason into your Statement of Applicability.

Ownership splits unevenly once you get into the detail. Roughly a third of the ISO 27001 Annex A controls depend on systems IT operations runs every day. Policies and risk records sit with the compliance function instead.

How Do You Become ISO 27001 Compliant?

Becoming ISO 27001 compliant runs through seven steps. The order matters more than the speed. Each step produces the input the next one needs.

  1. Define the scope: Name the services, sites, and information the ISMS covers. A narrow scope certifies faster and a wide one sells better. Make this call with sales in the room.

  1. Get leadership signed on: Clause 5 requires named accountability and a signed policy. Both need someone who controls budget.

  1. Run the risk assessment: Identify risks to confidentiality, integrity, and availability inside the scope. Choose a treatment for each one.

  1. Select controls and write the Statement of Applicability: Compare your treatments against Annex A. Record a decision for every control, exclusions included.

  1. Implement and start collecting records: Operational controls need history behind them. These go first, and the procedure documents go last.

  1. Run an internal audit and a management review: Both are mandatory. Both have to happen before a certification body will proceed.

  1. Book the external audit: Stage 1 reviews your documentation and readiness. Stage 2 tests whether the system operates the way your documents claim.

Steps 1 to 6 are identical whether or not you certify. Only the last one is optional. The compliant-versus-certified debate usually skips that part.

Most of the calendar disappears into step 5. A control implemented three months before the audit has three months of evidence. That pool is what an assessor samples from.

Six months is the number teams plan against. Most of the first certifications we have watched landed closer to nine.

What Compliance Automation Covers, and What It Does Not

Compliance automation platforms collect and organize evidence against a framework, and they do that job well. They do not perform the measurement and evaluation Clause 9 asks for. They also do not run your infrastructure.

It helps to separate the two halves before you start shortlisting. The list below covers what these platforms genuinely handle.

  • Mapping your controls to the standard and tracking the status of each

  • Pulling evidence automatically from cloud and identity systems through integrations

  • Holding policy documents with acknowledgment tracking against each employee

  • Flagging a control whose evidence has gone stale

The work below stays with you regardless of what you buy.

  • Deciding the scope, running the risk assessment, and writing the Statement of Applicability, because nobody automates a judgment

  • Defining what you measure and why, which is the Clause 9.1 method question

  • The internal audit and the management review, both of which need people

  • The operational records themselves, which come from the systems that do the work

The integration list is the thing to check before you buy. These platforms read well from cloud providers and identity providers. They read less well from on-premises infrastructure, network devices, and the service desk.

Patch evidence is the clearest example. An assessor asks which vulnerabilities were found, what got deployed against them, and when. That trail sits in your patch compliance record. A collector can only report what that record already holds.

We have watched plenty of teams buy a platform before settling their scope. Buying before scoping runs the sequence backwards. The platform organizes decisions, and it does not make them.

See Audit Evidence Come Out of the Work Itself

Walk a change, a patch cycle, and an asset check through ServiceOps and see what an assessor would get.

Book a ServiceOps Demo

What the 2022 Revision Changed, and What the 2025 Deadline Means Now

ISO/IEC 27001:2022 replaced the 2013 edition, and the transition window has already closed. Every valid certificate today runs against the 2022 revision.

We are still asked about the 2013 edition regularly, months after it stopped meaning anything.

Two changes carried the weight. Annex A came down from 114 controls to 93 through consolidation. The fourteen old domains became the four themes in use now.

The deadline is the part still causing confusion. According to IAF MD 26, certificates issued against the 2013 edition expired or were withdrawn on 31 October 2025.

That carries a practical consequence for anyone who let the date pass. The transition audit no longer exists as a route. Those companies start over with a full Stage 1 and Stage 2 assessment.

The same check applies to certificates you receive. A supplier certificate naming the 2013 edition proves nothing now. The printed expiry date makes no difference.

How Long Does ISO 27001 Compliance Take, and What Does It Cost?

A first ISO 27001 certification usually takes six to twelve months from a standing start. The cost splits into two parts. Only one of them is inside your control.

The table below gives typical durations for each stage. The last column names what actually moves each one.

Stage

Typical duration

What drives it

Scoping and gap analysis

2 to 6 weeks

How clearly your services and data are already documented

Risk assessment and treatment planning

4 to 8 weeks

Scope size and the number of systems inside it

Implementation

3 to 6 months

How many controls you are building from scratch

Evidence accumulation

3 months minimum

Fixed, because records need elapsed time to exist

Internal audit and management review

2 to 4 weeks

Whether your team has run one before

Stage 1 and Stage 2

4 to 10 weeks apart

The certification body's calendar

Audit fees are not really a negotiation. Certification bodies calculate audit days from a published table in ISO/IEC 27006-1. The table scales with the effective number of people inside your scope. Documented modifiers adjust the figure from there.

The 2024 revision widened who counts. Effective number of persons now covers everyone working inside your scope. Payroll status no longer matters, so contractors and freelancers add audit days.

Internal time is the larger number and the one nobody budgets. Someone has to run the risk assessment, chase evidence, and sit through the audit. On a first certification that usually takes most of one person's year.

Scope is the lever you really control. Certifying one product line cuts audit days, implementation work, and elapsed time together. You can widen the scope at the next recertification.

Does the Certification Body You Pick Matter?

It matters more than the price difference between quotes. A certificate carries weight because an accreditation body has assessed the certification body that issued it.

In the United States that accreditation body is ANAB. It holds recognition for ISO/IEC 27001 under the International Accreditation Forum arrangement. That arrangement lets a certificate issued in one country be accepted in another.

Unaccredited certificates exist and cost less. Enterprise procurement teams check for the accreditation mark. The saving then shows up as a problem at the worst possible moment.

ISO 27001 vs SOC 2, NIST, and GDPR

ISO 27001 overlaps heavily with SOC 2, NIST, and GDPR. The overlap sits in the evidence you produce, one level below the frameworks.

The table below compares what each one is and who tends to ask for it.

Framework

What it is

What you end up holding

Who usually asks

ISO 27001

A certifiable management system standard

A certificate naming your scope

International and enterprise procurement

SOC 2

An attestation against the trust services criteria

An auditor's report with the test detail

North American SaaS buyers

NIST CSF

Voluntary guidance, with no certificate to earn

An assessed program and a maturity view

US federal work and internal planning

GDPR

Law, naming no standard at all

Your own records of the measures you chose

Regulators and EU customers

ISO 27001 vs SOC 2

SOC 2 and ISO 27001 both examine security controls, and buyers split along geography more than logic. Plenty of companies end up holding both.

SOC 2 compliance covers the trust services criteria and the two report types in detail.

ISO 27001 vs NIST

Nobody issues a NIST certificate, so the two are not really alternatives. Teams use NIST CSF to organize and assess the security program. They then certify the management system around it against ISO 27001.

NIST compliance is also the route into US federal work, where an ISO 27001 certificate carries less weight.

ISO 27001 and GDPR

GDPR and ISO 27001 pull in the same direction without lining up cleanly. A certified ISMS answers a good share of the security obligation. It says nothing about lawful basis, consent records, data subject requests, or retention tied to purpose.

So treat the certificate as evidence for one part of the question. Your privacy program still needs its own records alongside it.

The saving becomes real once your evidence is organized by artifact type instead of by framework. A change record carrying a risk assessment, an approval, and a back-out plan answers a question in all four.

What IT Operations Has to Supply

IT operations supplies the operational records behind a large share of ISO 27001 evidence. It supplies almost none of the governance. Knowing which half lands on your desk is what keeps the project moving.

Four record types carry most of that load.

  1. Asset records: A current inventory with an owner and a classification against every entry

  1. Change records: The request, the risk assessment, the approval, the implementation, and the back-out plan

  1. Incident and problem records: The event, what was decided afterwards, and the change that came out of it

  1. Logging and monitoring records: What is collected, how long it is kept, what alerted, and who reviewed each alert

Completeness decides whether any of them counts. An approval in a chat thread never reaches the record an assessor reads. The control gets judged on the record.

That gap is the one we see most often. The change happened, the approval was real, and nothing durable recorded either.

The links between records matter as much as the records themselves. IT change management can carry an incident through to the change that fixed it. That single trace answers the improvement clause, where three separate exports would not.

Where those records live decides how long evidence gathering takes. Keeping service management and infrastructure monitoring on one unified observability and ITSM platform turns assembly into a query. The asset, change, incident, and log records already reference each other.

One concession is worth making plainly. No platform certifies you. Scope, risk assessment, internal audit, and management review stay with whoever owns the ISMS. So does the Statement of Applicability.

Keep Asset, Change, and Incident Records Audit-Ready Year-Round

Run ServiceOps against your own asset and change data and see which evidence gaps show up first.

Start a Free ServiceOps Trial

Decide Who Is Asking Before You Decide What to Build

The decision that sets your whole ISO 27001 budget is who needs the answer. A customer contract points at a certificate and a fixed date. An internal risk goal points at the same management system without the audit fees.

Neither route is quick. A control has to run for months before an assessor has anything to sample. No platform budget compresses that.

What the work leaves behind outlasts the certificate itself. You keep a scope you can describe, a risk assessment people use, and records that link to each other. Those three answer the next regulatory compliance request without a second project.

FAQs

How long is an ISO 27001 certificate valid?

An ISO 27001 certificate runs for three years. A surveillance audit happens in each of the two intervening years. A full recertification audit happens before the three years end. Missing a surveillance audit can get the certificate suspended.

Can a small company get ISO 27001 certified?

Yes, small companies certify all the time. Audit days scale with the effective number of people inside your scope. A twenty-person company pays far less than a thousand-person one. Small teams usually certify a narrow scope first.

What happens if the auditor finds a nonconformity?

A minor nonconformity needs a corrective action plan with a documented root cause. The certificate still issues once the plan is accepted. A major one blocks certification until you fix it and the assessor verifies the fix.

Does our cloud provider's ISO 27001 certificate cover us?

No, their certificate covers their scope and not yours. You still assess them as a supplier and document what they are responsible for. Evidencing the controls on your side is where asset and change records in ServiceOps get used.

RS

Author

Ramya Shah

Technical Writer

Ramya Shah is a technical content writer with a computer engineering background and roots in automotive journalism. He covers IT Service Management, observability, IT operations, and AI-driven automation. An early adopter of AI-assisted writing workflows, he turns complex IT processes into clear, engaging content optimized for search and answer engines (AEO), lifting content output and organic visibility.

Share:
Table of Contents
Subscribe to Our Newsletter

Get the latest insights and updates delivered to your inbox.

Related Articles

Continue reading with these related posts

Compliance

The Essential Eight: Patching Applications and Operating Systems at Maturity Level Two

Poonam LalaniSep 9, 202610 min read
Compliance

HIPAA Technical Safeguards and How to Keep Every Control Auditable

Poonam LalaniSep 4, 202610 min read
Compliance

How to Survive SOX Compliance Season Without Rebuilding Your Records

Poonam LalaniAug 26, 202610 min read