ISO 27001 Compliance: What Auditors Require and When You Need the Certificate
ISO 27001 compliance means running your information security the way ISO/IEC 27001 sets out. Most teams meet the standard when a customer sends over a security questionnaire. It lands as one more line on a cybersecurity compliance checklist.
That framing hides the decision underneath it. You can follow the standard without ever being certified against it. The two routes cost very different amounts.
In this blog, you will:
Tell compliance apart from certification.
See which buyers and regulators accept a self-declared ISMS.
Read what Clauses 4 to 10 require of you.
Follow the audit stages and the real cost drivers.
You will finish able to decide whether you need the certificate, and what it takes.
What Is ISO 27001 Compliance?
ISO 27001 compliance means your information security management system meets the requirements of ISO/IEC 27001:2022. The standard treats information security as a managed system, with a defined scope and named owners.
That system has a name and a boundary. An information security management system (ISMS) covers your policies, roles, processes, and records. You use it to manage information risk inside a scope you define.
The standard comes in two halves. Clauses 4 to 10 carry the mandatory requirements every organization has to meet. Annex A holds 93 security controls, and your risk assessment decides which ones you select.
Compliance holds only while the system keeps running. You are compliant on the day you can show it works as documented.
Compliant vs Certified: What the Certificate Actually Buys
Compliance and certification differ by who says so. You decide you are compliant. A certification body decides you are certified, and it audits you first.
Both routes start from the same requirements. The work of building an ISMS does not change if nobody audits it.
The table below compares the two on what decides your budget and your timeline.
Compliant (self-declared) | Certified | |
Who confirms it | Your own team | An accredited certification body |
How it is tested | Internal audit and management review | A Stage 1 and Stage 2 audit by an external assessor |
What you can hand a buyer | Your own documents and answers | A certificate naming your scope |
Renewal | Whatever cadence you set | Annual surveillance, full recertification every three years |
Cost | Internal time only | Internal time plus audit fees |
What happens when it slips | Nothing, until something breaks | A surveillance audit finds it |
Self-declared compliance is honest work while nobody is asking for a certificate. The moment somebody asks, it stops being enough. The word compliant carries no weight without a name attached to it.
Certification also adds a forcing function that alignment lacks. An external assessor opens by checking whether last year's corrective actions closed. Internal programs quietly skip that check when the quarter gets busy.
Who Accepts a Self-Declared ISMS, and Who Does Not
Whether a self-declared ISMS is enough depends entirely on who is asking for it. The answer splits along one line. Does the party on the other side carry their own liability for your security?
The table below sets out the six requesters that come up most often. Each row says what they usually do with a self-declaration.
Who is asking | Accepts self-declared? | Why |
Enterprise procurement | Rarely | The certificate replaces a bespoke security review, and that saving is the reason they asked |
A prime contractor flowing down a clause | No | Their own contract names an accredited certificate, so they cannot accept less |
A cyber insurer at renewal | Sometimes | Underwriters score the controls themselves, and some accept evidence without accreditation |
A financial or healthcare regulator | Depends | Most name their own framework and treat ISO 27001 as supporting evidence |
Your own board or audit committee | Usually | Internal assurance has no accreditation requirement behind it |
A mid-market customer with a questionnaire | Often | They want the questionnaire answered, and the answers are the deliverable |
Two patterns run through that table. Anyone who inherits your risk wants a third party to have checked. Anyone assuring themselves can accept your word.
Healthcare shows the regulator case clearly. The HIPAA technical safeguards set the actual obligation there. An ISO 27001 certificate supports that obligation without replacing it.
We get asked which of these matters most. The honest answer is whichever one is holding up a contract right now.
Is ISO 27001 a Legal Requirement?
ISO 27001 is not written into law anywhere. No statute requires the certificate, and no regulator will fine you for lacking one.
The standard reaches you through contracts instead. A customer agreement, a supplier clause, or a tender requirement names it. From that point it binds you as firmly as a regulation would.
Data protection law works the other way around. GDPR compliance asks for appropriate technical and organizational measures without naming a standard. A certified ISMS becomes one way to show you chose those measures on purpose.
So run the question in one direction. Find out who is actually asking, and let their answer set your scope.

What Do Clauses 4 to 10 Require?
Clauses 4 to 10 are the mandatory half of ISO 27001. You cannot exclude any of them. They tell you to build a management system, run it, check it, and fix it, in that order.
The numbering confuses people, so it helps to say where the requirements begin. The standard runs from Clause 1 to Clause 10. The first three cover scope, references, and definitions. The part you certify against starts at Clause 4.
Each clause produces something an auditor will ask to see. The table below names what that is.
Clause | Title | What it asks you to produce |
4 | Context of the Organization | A defined ISMS scope, plus a list of interested parties and what they require |
5 | Leadership | A signed information security policy and named roles that carry real authority |
6 | Planning | A risk assessment process, a risk treatment plan, a Statement of Applicability, and measurable objectives |
7 | Support | Evidence of competence, awareness activity, and version control over your documents |
8 | Operation | Records showing the risk assessment and the treatment plan actually ran |
9 | Performance Evaluation | Measurement results, an internal audit program, and management review minutes |
10 | Improvement | A record of every nonconformity, the action taken, and whether the action worked |
Clause 6 carries the most weight of the seven. Everything you implement later traces back to the risk assessment it asks for. The rest of the standard stands on your IT risk management practice.
We build every ISO 27001 conversation around Clause 6 for that reason. Get it wrong and the Statement of Applicability has nothing solid underneath it.
One recent change sits inside Clause 4. ISO/IEC 27001:2022/Amd 1:2024 added climate change to the context you have to consider. Your context review now has to say whether it applies to you.

Why Clause 9.1 Catches Teams With the Best Monitoring
Clause 9.1 asks you to measure the ISMS. Your monitoring watches infrastructure, which is a different object entirely. Teams with excellent dashboards still fail it. Those dashboards answer a question the clause never asked.
The clause names six things you have to determine before you start collecting anything.
What gets monitored and measured, including the security processes and the controls themselves
The methods used, which have to give comparable and reproducible results
When the measuring happens
Who performs it
When the results get analyzed and evaluated
Who does that evaluation
What Clause 9.1 Measures Is the Control
Infrastructure monitoring tells you a server stayed up and a firewall stayed reachable. Control measurement tells you whether the access review happened on schedule. It counts how many accounts came off, and it shows which way that number is moving.
Both draw on the same underlying data. Only one of them answers Clause 9.1.
Why a Dashboard Screenshot Fails the Method Test
The method requirement is the part that quietly fails. Comparable means two measurements taken six months apart used the same definition. Reproducible means somebody else running your method arrives at your number.
A dashboard screenshot fails both tests. It shows a value at one moment, with no method stated behind it. An assessor can neither repeat that nor compare it.
The fix is smaller than it sounds. Pick three or four measures you really run. Write the method down before you start collecting. Keep the definition stable across periods.
Log compliance reporting turns retention and coverage into a repeatable number. Clause 9.1 is looking for exactly that shape.
We keep seeing programs over-invest in the control list and under-invest here. It shows up at the internal audit long before a certification body arrives.
What Documents Does ISO 27001 Compliance Require?
ISO 27001 requires a specific set of documented information. An auditor will ask for all of it. The list is shorter than most teams expect. It leaves very little room for interpretation.
It splits cleanly into two groups, and the difference between them drives your timeline.
Documents You Write Once and Maintain
These are authored deliverables, and a focused team can finish them in weeks.
The ISMS scope statement
The information security policy
Your risk assessment process and your risk treatment process
The Statement of Applicability
Measurable information security objectives
The operating procedures your own scope makes necessary
Records the System Generates by Running
These cannot be written in advance, because each one is evidence that something happened.
Risk assessment results and risk treatment results
Evidence of competence for the people holding ISMS roles
Monitoring and measurement results
The internal audit program and its findings
Management review outputs
Nonconformities, the actions taken, and the results of those actions
The split matters for planning more than for filing. The first group is a writing project with an end date. The second group only exists if the system actually ran. Starting late costs a lot no matter how fast you write.
Where Annex A Fits
Annex A is the control reference you select from once the risk assessment is finished. It lists 93 security controls across four themes covering organizational, people, physical, and technological measures.
Clause 6 is what sends you there. You treat each risk first, then compare your chosen controls against Annex A. The comparison confirms nothing necessary was left out.
Applicability stays your decision. You can exclude a control that addresses no risk you identified. Write the reason into your Statement of Applicability.
Ownership splits unevenly once you get into the detail. Roughly a third of the ISO 27001 Annex A controls depend on systems IT operations runs every day. Policies and risk records sit with the compliance function instead.
How Do You Become ISO 27001 Compliant?
Becoming ISO 27001 compliant runs through seven steps. The order matters more than the speed. Each step produces the input the next one needs.
Define the scope: Name the services, sites, and information the ISMS covers. A narrow scope certifies faster and a wide one sells better. Make this call with sales in the room.
Get leadership signed on: Clause 5 requires named accountability and a signed policy. Both need someone who controls budget.
Run the risk assessment: Identify risks to confidentiality, integrity, and availability inside the scope. Choose a treatment for each one.
Select controls and write the Statement of Applicability: Compare your treatments against Annex A. Record a decision for every control, exclusions included.
Implement and start collecting records: Operational controls need history behind them. These go first, and the procedure documents go last.
Run an internal audit and a management review: Both are mandatory. Both have to happen before a certification body will proceed.
Book the external audit: Stage 1 reviews your documentation and readiness. Stage 2 tests whether the system operates the way your documents claim.
Steps 1 to 6 are identical whether or not you certify. Only the last one is optional. The compliant-versus-certified debate usually skips that part.
Most of the calendar disappears into step 5. A control implemented three months before the audit has three months of evidence. That pool is what an assessor samples from.
Six months is the number teams plan against. Most of the first certifications we have watched landed closer to nine.
What Compliance Automation Covers, and What It Does Not
Compliance automation platforms collect and organize evidence against a framework, and they do that job well. They do not perform the measurement and evaluation Clause 9 asks for. They also do not run your infrastructure.
It helps to separate the two halves before you start shortlisting. The list below covers what these platforms genuinely handle.
Mapping your controls to the standard and tracking the status of each
Pulling evidence automatically from cloud and identity systems through integrations
Holding policy documents with acknowledgment tracking against each employee
Flagging a control whose evidence has gone stale
The work below stays with you regardless of what you buy.
Deciding the scope, running the risk assessment, and writing the Statement of Applicability, because nobody automates a judgment
Defining what you measure and why, which is the Clause 9.1 method question
The internal audit and the management review, both of which need people
The operational records themselves, which come from the systems that do the work
The integration list is the thing to check before you buy. These platforms read well from cloud providers and identity providers. They read less well from on-premises infrastructure, network devices, and the service desk.
Patch evidence is the clearest example. An assessor asks which vulnerabilities were found, what got deployed against them, and when. That trail sits in your patch compliance record. A collector can only report what that record already holds.
We have watched plenty of teams buy a platform before settling their scope. Buying before scoping runs the sequence backwards. The platform organizes decisions, and it does not make them.
What the 2022 Revision Changed, and What the 2025 Deadline Means Now
ISO/IEC 27001:2022 replaced the 2013 edition, and the transition window has already closed. Every valid certificate today runs against the 2022 revision.
We are still asked about the 2013 edition regularly, months after it stopped meaning anything.
Two changes carried the weight. Annex A came down from 114 controls to 93 through consolidation. The fourteen old domains became the four themes in use now.
The deadline is the part still causing confusion. According to IAF MD 26, certificates issued against the 2013 edition expired or were withdrawn on 31 October 2025.
That carries a practical consequence for anyone who let the date pass. The transition audit no longer exists as a route. Those companies start over with a full Stage 1 and Stage 2 assessment.
The same check applies to certificates you receive. A supplier certificate naming the 2013 edition proves nothing now. The printed expiry date makes no difference.
How Long Does ISO 27001 Compliance Take, and What Does It Cost?
A first ISO 27001 certification usually takes six to twelve months from a standing start. The cost splits into two parts. Only one of them is inside your control.
The table below gives typical durations for each stage. The last column names what actually moves each one.
Stage | Typical duration | What drives it |
Scoping and gap analysis | 2 to 6 weeks | How clearly your services and data are already documented |
Risk assessment and treatment planning | 4 to 8 weeks | Scope size and the number of systems inside it |
Implementation | 3 to 6 months | How many controls you are building from scratch |
Evidence accumulation | 3 months minimum | Fixed, because records need elapsed time to exist |
Internal audit and management review | 2 to 4 weeks | Whether your team has run one before |
Stage 1 and Stage 2 | 4 to 10 weeks apart | The certification body's calendar |
Audit fees are not really a negotiation. Certification bodies calculate audit days from a published table in ISO/IEC 27006-1. The table scales with the effective number of people inside your scope. Documented modifiers adjust the figure from there.
The 2024 revision widened who counts. Effective number of persons now covers everyone working inside your scope. Payroll status no longer matters, so contractors and freelancers add audit days.
Internal time is the larger number and the one nobody budgets. Someone has to run the risk assessment, chase evidence, and sit through the audit. On a first certification that usually takes most of one person's year.
Scope is the lever you really control. Certifying one product line cuts audit days, implementation work, and elapsed time together. You can widen the scope at the next recertification.
Does the Certification Body You Pick Matter?
It matters more than the price difference between quotes. A certificate carries weight because an accreditation body has assessed the certification body that issued it.
In the United States that accreditation body is ANAB. It holds recognition for ISO/IEC 27001 under the International Accreditation Forum arrangement. That arrangement lets a certificate issued in one country be accepted in another.
Unaccredited certificates exist and cost less. Enterprise procurement teams check for the accreditation mark. The saving then shows up as a problem at the worst possible moment.
ISO 27001 vs SOC 2, NIST, and GDPR
ISO 27001 overlaps heavily with SOC 2, NIST, and GDPR. The overlap sits in the evidence you produce, one level below the frameworks.
The table below compares what each one is and who tends to ask for it.
Framework | What it is | What you end up holding | Who usually asks |
ISO 27001 | A certifiable management system standard | A certificate naming your scope | International and enterprise procurement |
SOC 2 | An attestation against the trust services criteria | An auditor's report with the test detail | North American SaaS buyers |
NIST CSF | Voluntary guidance, with no certificate to earn | An assessed program and a maturity view | US federal work and internal planning |
GDPR | Law, naming no standard at all | Your own records of the measures you chose | Regulators and EU customers |
ISO 27001 vs SOC 2
SOC 2 and ISO 27001 both examine security controls, and buyers split along geography more than logic. Plenty of companies end up holding both.
SOC 2 compliance covers the trust services criteria and the two report types in detail.
ISO 27001 vs NIST
Nobody issues a NIST certificate, so the two are not really alternatives. Teams use NIST CSF to organize and assess the security program. They then certify the management system around it against ISO 27001.
NIST compliance is also the route into US federal work, where an ISO 27001 certificate carries less weight.
ISO 27001 and GDPR
GDPR and ISO 27001 pull in the same direction without lining up cleanly. A certified ISMS answers a good share of the security obligation. It says nothing about lawful basis, consent records, data subject requests, or retention tied to purpose.
So treat the certificate as evidence for one part of the question. Your privacy program still needs its own records alongside it.
The saving becomes real once your evidence is organized by artifact type instead of by framework. A change record carrying a risk assessment, an approval, and a back-out plan answers a question in all four.
What IT Operations Has to Supply
IT operations supplies the operational records behind a large share of ISO 27001 evidence. It supplies almost none of the governance. Knowing which half lands on your desk is what keeps the project moving.
Four record types carry most of that load.
Asset records: A current inventory with an owner and a classification against every entry
Change records: The request, the risk assessment, the approval, the implementation, and the back-out plan
Incident and problem records: The event, what was decided afterwards, and the change that came out of it
Logging and monitoring records: What is collected, how long it is kept, what alerted, and who reviewed each alert
Completeness decides whether any of them counts. An approval in a chat thread never reaches the record an assessor reads. The control gets judged on the record.
That gap is the one we see most often. The change happened, the approval was real, and nothing durable recorded either.
The links between records matter as much as the records themselves. IT change management can carry an incident through to the change that fixed it. That single trace answers the improvement clause, where three separate exports would not.
Where those records live decides how long evidence gathering takes. Keeping service management and infrastructure monitoring on one unified observability and ITSM platform turns assembly into a query. The asset, change, incident, and log records already reference each other.
One concession is worth making plainly. No platform certifies you. Scope, risk assessment, internal audit, and management review stay with whoever owns the ISMS. So does the Statement of Applicability.
Decide Who Is Asking Before You Decide What to Build
The decision that sets your whole ISO 27001 budget is who needs the answer. A customer contract points at a certificate and a fixed date. An internal risk goal points at the same management system without the audit fees.
Neither route is quick. A control has to run for months before an assessor has anything to sample. No platform budget compresses that.
What the work leaves behind outlasts the certificate itself. You keep a scope you can describe, a risk assessment people use, and records that link to each other. Those three answer the next regulatory compliance request without a second project.
FAQs
How long is an ISO 27001 certificate valid?
An ISO 27001 certificate runs for three years. A surveillance audit happens in each of the two intervening years. A full recertification audit happens before the three years end. Missing a surveillance audit can get the certificate suspended.
Can a small company get ISO 27001 certified?
Yes, small companies certify all the time. Audit days scale with the effective number of people inside your scope. A twenty-person company pays far less than a thousand-person one. Small teams usually certify a narrow scope first.
What happens if the auditor finds a nonconformity?
A minor nonconformity needs a corrective action plan with a documented root cause. The certificate still issues once the plan is accepted. A major one blocks certification until you fix it and the assessor verifies the fix.
Does our cloud provider's ISO 27001 certificate cover us?
No, their certificate covers their scope and not yours. You still assess them as a supplier and document what they are responsible for. Evidencing the controls on your side is where asset and change records in ServiceOps get used.
Author
Ramya Shah
Technical Writer
Ramya Shah is a technical content writer with a computer engineering background and roots in automotive journalism. He covers IT Service Management, observability, IT operations, and AI-driven automation. An early adopter of AI-assisted writing workflows, he turns complex IT processes into clear, engaging content optimized for search and answer engines (AEO), lifting content output and organic visibility.


