Blog
•
Compliance
What Is ISO 27001 Certification? A Complete 2026 Guide

ISO 27001 certification is the process of proving that an organization's information security management system (ISMS) conforms to ISO/IEC 27001:2022. During an ISO 27001 audit, an accredited certification body conducts a two-stage assessment of the ISMS and issues an ISO 27001 certificate, valid for three years. ISO and IEC publish the standard, but they do not issue certificates.
Even though no general statute requires ISO 27001 certification, many enterprise deals demand it. A certified vendor can offer buyers independently verified assurance that it manages information security systematically. Uncertified vendors, by comparison, add diligence work and potential exposure to a supply chain that boards and regulators already scrutinize.
Yet, despite the risk, some teams still treat ISO 27001 like a simple control checklist.
This guide explains what ISO 27001 certification is, why it's important, how long it takes, and how much it costs. It also gives step-by-step instructions for individuals and organizations to get certified, without security theater.
What Is ISO 27001?
ISO/IEC 27001 is the international standard for an information security management system. The most current version is ISO/IEC 27001:2022, published jointly by the International Organization for Standardization (ISO) and the International Electrotechnical Commission (IEC) on October 25, 2022.
ISO 27001:2022 sets requirements for an ISMS. It has three parts:
Scope: Information, systems, and business units to protect, and the boundary that decision draws.
Ownership: People accountable for each risk decision and for each control that follows from it.
Verification: Internal audits and management reviews that confirm controls operate as intended, and the system stays current, even as the organization changes.
Because those requirements are generic, they apply to every organization regardless of type, size, or nature, including small cloud-native companies with no on-premises infrastructure to secure.
ISO 27001 is the international standard for running an information security management system, or ISMS. ISO 27001 certification means that an accredited certification body has audited an organization's ISMS against its security requirements. ISO writes the standard, but only certification bodies issue certificates. |
Before it became an international standard, ISO 27001 was a British Standard. Edward Humphreys, who managed the development of its predecessors, BS 7799-1 and BS 7799-2, calls them the forerunners of ISO/IEC 27002 and ISO/IEC 27001. Eventually, the code of practice became Annex A, and the auditable requirements became ISO 27001 itself.
ISO/IEC 27001 was first published in 2005, revised in 2013, and reissued in its current third edition in 2022.
Year | ISO 27001 milestone |
1995 | BS 7799-1 was published as a code of practice, with BS 7799-2 setting the requirements for organizations to be audited against |
2000 | BS 7799-1 was published internationally as ISO/IEC 17799 (later renumbered ISO/IEC 27002), the control set behind Annex A |
2005 | BS 7799-2 was published internationally as ISO/IEC 27001 |
2013 | The second edition of ISO/IEC 27001 was published |
2022 | The third and most current edition, ISO/IEC 27001:2022, was published on October 25, 2022 |
2025 | The transition from the 2013 edition to the 2022 edition officially closed on October 31, 2025 |
In 2026, ISO/IEC 27001:2022 is the only edition a live certificate can name, and every valid certification must reference it specifically.
What Is ISO 27001 Certification, and Who Issues It?
ISO 27001 certification means an accredited certification body has audited an organization's ISMS and issued a certificate confirming it conforms to the standard. ISO publishes the standard, but a certification body conducts the audit and issues the certificate.
Several distinct roles stand behind that certificate, each working to a published standard. A certification body performs the audit and issues the certificate, and an accreditation body certifies the certification body's competence to do so.
Role | Description | Standard |
Certification body | Audits organizations against ISO 27001 and issues certificates | |
Accreditation body | Assesses a certification body's competence and impartiality, a role United Kingdom Accreditation Service (UKAS) describes as “checking the checkers” | |
Mutual recognition arrangement | An agreement between accreditation bodies to recognize each other's accredited certificates as equivalent | The accreditation bodies' peer arrangements |
Here, the term ‘accredited’ describes the certification body, not the organizations it audits. Once issued, an ISO 27001 certificate from an accredited body is considered ‘accredited certification.’ Impartiality rules also apply within each body to keep the roles separate. For example, ISO/IEC 17021-1 requires the people who make certification decisions to be different from the people who run the audit.
After a positive certification decision, the certificate is issued as a hard and/or soft copy and stays valid for three years. In the interim, accredited certificates are maintained by surveillance audits and searchable via IAF CertSearch.
Most importantly, an ISO 27001 certificate should always come from an independent certification body. Compliance vendors that claim they can issue ISO 27001 certificates are more likely to sell security theater, where compliance checkboxes replace real protection.
Is ISO 27001 Certification Worth It?
ISO 27001 certification is worth the investment for most organizations, especially when buyers ask for it. Because no general statute requires ISO 27001 certification, customer procurement typically drives adoption. Today, it is among the most widely recognized information security standards in the world.
In 2023, the annual ISO Survey reported 47,291 valid ISO 27001 certificates worldwide. One year later, that figure nearly doubled to 96,709. However, that jump likely reflects the ISO Survey's switch to IAF CertSearch data. Because it counted certificates earlier surveys missed, demand was higher than previously measured.
Of those 2024 ISO 27001 certifications, 4,671 went to the information technology sector, while the United States held 4,260. A 2024 CIS survey of mostly Austrian organizations found that 93% of ISO 27001-certified respondents said the benefits outweighed the cost and effort, and a majority reported that ISO 27001-based measures reduced residual risk.
Meanwhile, vendors without ISO 27001 certification are more likely to be disqualified before commercial discussions even begin. For uncertified organizations, the common alternative is a security questionnaire, a process that tends to be “expensive, slow, and inconsistent,” per ISO 27001 auditor Erin Casteel.
An accredited audit gives procurement a single external assurance document. That way, when enterprise prospects inevitably ask about ISO 27001 certification, organizations can answer with confidence.
What Are the ISO 27001 Requirements?
The auditable requirements of ISO/IEC 27001:2022 are Clauses 4 to 10, with no exceptions. According to the standard itself, "Excluding any of the requirements specified in Clauses 4 to 10 is not acceptable when an organization claims conformity to this document.”
Annex A is less prescriptive and permits exclusions for its 93 controls. But first, organizations must meet the ISO 27001 requirements in Clauses 4 through 10. They include:
Context and scope: Which external and internal issues matter, with decision-making boundaries drawn around the ISMS.
Leadership: Someone with real authority to own the policy, roles, and resourcing.
Risk assessment and treatment: A risk assessment that informs treatment decisions and determines which controls are necessary.
The Statement of Applicability: A record of the necessary Annex A controls, why each one is included, whether each one is implemented, and the justification for exclusion.
Support and operation: Competence, awareness, documented information, and the operating processes that produce evidence from an ISMS.
Internal audit and management review: An internal assessment of the ISMS against ISO 27001, with results reviewed before a certification body shows up.
Corrective action: A fix for every finding goes on the record.
Meeting these requirements is often more challenging than expected. According to National Quality Assurance (NQA) research, almost half of Clause 4 nonconformities involve an ISMS that never adequately defined its external and internal issues. The next most common nonconformity is scope, either incomplete or missing from the ISMS entirely.
The 93 Annex A Controls (2022 Edition)
Annex A of ISO/IEC 27001:2022 contains 93 controls organized across organizational, people, physical, and technological themes. The 2022 edition introduced 11 new controls and merged another 24, bringing the total down from 114.
Annex A theme | Control count | Description |
Organizational | 37 | The largest group, and the one closest to the management system itself |
People | 8 | Controls that attach to individuals |
Physical | 14 | Controls over facilities, equipment, and physical access |
Technological | 34 | Controls implemented in and by your systems |
Total | 93 | Down from 114 in the previous edition |
Because Annex A is a reference set, most organizations implement only the controls required by their risk treatment. Unlike Clauses 4 through 10, these requirements include exceptions. Examples of acceptable reasons for leaving an Annex A control unimplemented include:
A lack of related risk
An acceptable risk given related controls and impact
Another control that replaces it
As such, treating all 93 controls as a checklist is perhaps one of the standard's most expensive misreadings. The result is what we call ‘security theater,’ where programs exist to pass audits, and risk decisions never get made.
The problem is so widespread today that the ISO/IEC 27001 Auditing Practices Group even publishes a note on the improper uses of Annex A. Top offenders include treating it as a “comprehensive list of controls” and a “requirement list.” To reinforce this point, the 2022 edition renamed Annex A the “Information security controls reference.”
The ISO 27001 Certification Process: Stage 1 and Stage 2
The initial ISO 27001 certification audit runs in two stages, testing different things. ISO/IEC 17021-1 requirements define that two-stage structure. It includes:
Stage 1: A readiness audit of the documented ISMS.
Stage 2: An on-site test of whether the ISMS actually runs the way the documents describe.
But passing Stage 2 doesn't by itself produce an ISO 27001 certificate. Instead, the certificate follows a formal certification decision, a separate step the certification body takes after the audit.
Surveillance Audits and the Three-Year Cycle
ISO 27001 certificates run on a three-year cycle so organizations can plan and budget for audits in advance. Here, ISO/IEC 17021-1 sets the audit program. It covers:
An initial two-stage audit and the certification decision.
Surveillance in the first and second years.
Recertification in the third year, before the certificate expires.
Because surveillance audits only sample part of the ISMS, they typically take less time than initial audits, which evaluate the whole.
Audit cycle | Audit type | Timing rule |
Initial | Two-stage audit | Two stages, then a formal certification decision |
Year One | Surveillance | No more than 12 months from the certification decision |
Year Two | Surveillance | At least once per calendar year, except in recertification years |
Year Three | Recertification | Before the certificate expires |
How Long Does ISO 27001 Certification Take?
ISO 27001 certification for a small, tightly scoped SaaS company commonly takes about two to three quarters, faster if security processes already exist. The certificate then runs on a three-year cycle, with surveillance in years one and two and recertification before year three. Based on headcount, Advisera estimates:
3 to 5 months at 20–50
5 to 8 months at 50–200
8 to 20 months at 200+
Still, such estimates often account only for time spent building the system. Accredited certification bodies generally want the ISMS to have been operating long enough to sample (commonly about three months of records) plus a completed internal audit and management review.
How Much ISO 27001 Certification Costs
ISO 27001 certification typically runs ~$25K–$70K all-in in year one for a small SaaS company. Perhaps surprisingly, the audit invoice is only part of that sum. In fact, a certification body's audit invoice and the all-in cost of getting audit-ready are two vastly different numbers.
The audit invoice equals auditor-days times a day rate. Accredited certification bodies set auditor-days from ISO/IEC 27006-1, which sets 5 auditor-days at 1–10 people in scope, 7 at 16–25, and 10 at 46–65. Day rates are separate, and US rates commonly run ~$1,500–$2,500.
Cost component | What scales | Typical figure |
Certification body auditor-days | People inside your scope | 1–10 employees = 5 auditor-days; 16–25 = 7; 46–65 = 10; 86–125 = 12; 176–275 = 14 |
Auditor day rate | Where the auditor bills | ~$1,500–$2,500 USD |
The audit invoice | Auditor-days times rate | 7 auditor-days at a 20-person company = ~$10K–$21K, or ~$13K–$25K once admin and certificate fees are included |
First-year all-in, 10–50 people | Tooling, consulting, and internal time on top of the audit | ~$25K–$70K for the platform or consultant, extra tooling, training, and internal time, of which certification body fees are ~$13K–$25K |
First-year all-in, 50–200 people | The same components at more scope | Scales with scope; quoted per engagement |
Consultant, optional | Complexity of your environment | Part of the ~$25K–$70K all-in range |
Note: The auditor-day bands come from ISO/IEC 27006-1. Every dollar figure is an estimate from Oneleet's experience, and a certification body's actual quote replaces it.
Here, scope is the one cost most organizations can control. Because audit days scale with size, an overscoped initial audit raises the cost for all three years.
ISO 27001 Certification for Individuals vs Organizations
Organizations get ISO 27001 certified, and individuals get personnel credentials. The Professional Evaluation and Certification Board (PECB) is one example of a body that issues them under ISO/IEC 17024. Its Lead Implementer credential asks for five years of professional experience, including two in information security management, plus 300 hours of project activity.
Organizations | Individuals | |
What’s issued | An ISO 27001 certificate for the ISMS | A personnel credential, such as PECB's ISO/IEC 27001 Lead Implementer or Lead Auditor |
Who issues it | An accredited certification body under ISO/IEC 17021-1 | A personnel certification body under ISO/IEC 17024 |
Validity | Three years, maintained by surveillance audits | Three years, with an annual maintenance fee |
What it proves | The ISMS conforms to ISO 27001 within its defined scope | The holder's experience and competence, never the employer's conformity |
SOC 2 vs ISO 27001
ISO 27001 produces a certificate, and SOC 2 produces an attestation report. More specifically:
SOC 2 is an attestation against the American Institute of Certified Public Accountants (AICPA) Trust Services Criteria.
ISO 27001 is a certificate for an information security management system.
SOC 2 | ISO 27001 | |
Who governs it | The AICPA, through its Assurance Services Executive Committee | ISO and IEC write the standard; certification bodies audit under ISO/IEC 17021-1 |
What you receive | An attestation report on your controls | A certificate covering the scope you defined |
Who performs the work | A practitioner running an AICPA attestation engagement | An accredited certification body you choose |
Criteria basis | The 2017 Trust Services Criteria, with Revised Points of Focus 2022 | Clauses 4 to 10, plus the controls in your Statement of Applicability |
A mapping suggests correspondence only, as shown by the AICPA’s "Mapping: 2017 Trust Services Criteria to ISO 27001". Generally speaking, neither SOC 2 nor ISO 27001 converts into the other.
Which one to pursue depends on the target. ISO 27001 is a globally recognized standard, often indispensable for international organizations. But SOC 2 can serve the same purpose in certain markets. In fact, a completed SOC 2 program often already covers about 70% of the operational controls ISO 27001 will look at: access, change, incidents, vendors, logging. You are not starting over!
How Software Speeds Up ISO 27001 Certification
ISO 27001 software speeds up the certification process by running the entire program in one platform. Oneleet gives you everything you need for ISO 27001 certification. With its compliance platform, teams can:
Map each security control across frameworks, so a control defined once for SOC 2 counts toward ISO 27001 and HIPAA. With Oneleet, a finished SOC 2 program covers about 70% of the ISO 27001 work.
Build a risk register in minutes from a pre-built library of common threats, score each risk with a formula, and link it to the control that treats it, the same links a Stage 2 auditor tests under Clause 6.
Manage policies, controls, evidence, and remediation in one place, with hundreds of automated monitors that identify compliance gaps before an auditor does.
Offload evidence review to a former auditor. A dedicated security program manager checks every piece of evidence against its control before the auditor sees it and stays on as vCISO for the full term.
Choose an independent, accredited certification body to conduct and sign off on the audit. Oneleet manages every type of ISO 27001 audit required, across internal, external, and surveillance.
Prove the system resists attack with a manual gray box pentest by OSCE-certified testers, and retesting at no additional cost once the fixes land.
With Oneleet, the pentest engagement produces a full report, updated after remediation, and a Letter of Attestation that omits vulnerability details. Both serve as audit evidence when controls 8.8 and 8.29 sit in the Statement of Applicability.
One annual fee covers the platform, service, audit, and pentest, with total client time running around 20–30 hours. Plus, the first 30 days are risk-free, with cancellation available before the pentest begins or an auditor is engaged.
Get ISO 27001 certified to close deals faster and more securely with Oneleet →
ISO 27001 Certification FAQ
Is ISO 27001 a certification or a standard?
ISO/IEC 27001:2022 is the standard, and certification is the outcome of an accredited audit against that standard. ISO and IEC write the requirements, but only an accredited certification body issues the certificate.
How long does ISO 27001 certification take?
Typically, ISO 27001 certification takes two to three quarters. Risk assessment and control implementation take about 3 to 5 months for 20 to 50 employees and 5 to 8 months for 50 to 200. Accredited certification bodies generally want the ISMS to have been operating long enough to sample (commonly about three months of records) plus a completed internal audit and management review.
How much does ISO 27001 certification cost?
The cost of ISO 27001 certification depends on scope. The certification body's fee is auditor-days times a day rate, starting at 5 auditor-days for 1 to 10 people at US rates of ~$1,500 to $2,500 a day. All-in, a small SaaS company can expect ~$25K to $70K in year one, once the platform or consultant, extra tooling, training, and internal time are counted.
How many controls are in ISO 27001?
ISO 27001 includes 93 controls, all listed in Annex A of the 2022 edition across four themes: 37 organizational, 8 people, 14 physical, and 34 technological. An organization implements only the controls its risk treatment requires.
Is ISO 27001 certification worth it?
Yes, ISO 27001 certification is usually worth it, especially when buyers ask for it. No general statute requires ISO 27001, so customer procurement drives adoption. In the 2024 CIS Certification Status Report, 93% of respondents at certified companies said the benefits outweighed the cost and effort.
Can individuals get ISO 27001 certified?
No, individuals cannot get ISO 27001 certified. Organizations get certified, and individuals earn personnel credentials instead, such as PECB's ISO/IEC 27001 Lead Implementer and Lead Auditor schemes under ISO/IEC 17024. None of those credentials certify the holder's employer.
SOC 2 vs ISO 27001: which one do I need?
Whether SOC 2 or ISO 27001 is the best choice depends on the buyer. SOC 2 is an AICPA attestation report on an organization's controls against the Trust Services Criteria, and ISO 27001 is a certificate for its information security management system. The AICPA publishes a mapping between the two, but neither one converts into the other.
Does ISO 27001 require a penetration test?
No ISO 27001 clause requires a penetration test, and certification audits do not include one. Instead, the Statement of Applicability creates the obligation to test. Pentest practitioners point to Annex A 8.8 and 8.29, and an organization that declares those controls applicable owes the auditor evidence that it conducts security testing. The same logic applies to SOC 2, where a missing penetration test is the most common reason reports fail a buyer’s security review.
Mariah Brooks is a governance, risk, and compliance (GRC) SME with more than six years of experience writing for enterprise security, risk, and regulatory teams, covering compliance frameworks, AI governance, and information security risk management.
Check all other articles




