ISO 27001
The international information security standard most often named in enterprise procurement and European contracts.
What it is
ISO/IEC 27001 specifies the requirements for an information security management system — a documented, risk-driven program with defined scope, leadership accountability, control selection, and internal audit. Certification is issued by an accredited certification body after a two-stage audit, and is maintained through annual surveillance audits on a three-year cycle. The standard is control-agnostic: Annex A gives you 93 controls to consider, and the Statement of Applicability records which ones you applied and why.
Who typically needs it
- SaaS companies whose enterprise or European buyers name ISO 27001 in the security addendum
- Companies already carrying SOC 2 who keep losing deals to competitors with an ISO certificate
- Organizations with a European entity, European customers, or a data-processing footprint in the EU
- Firms preparing for TISAX, where an ISO 27001 program does most of the underlying work
- Anyone who wants one management system to hang subsequent frameworks off, rather than a stack of one-off projects
What the engagement looks like
Baseline. We assess your current state against the ISO 27001 clauses and the Annex A controls you are likely to apply, and score every control red, yellow, or green. You get a prioritized remediation roadmap and a defensible read on scope — which entities, which systems, which locations — before anyone commits budget to a certification date.
Build. We author the management system: scope statement, information security policy, risk methodology and risk register, Statement of Applicability, and the supporting policy suite. We run the risk assessment with your team rather than for them, because the internal audit and the certification body will both ask who owns each decision.
Build, continued. Evidence is where most programs stall. We stand up the evidence library, define what each control produces on what cadence, and work through remediation with your engineering and IT owners until the controls actually operate rather than merely exist on paper.
Audit Sprint. We run the internal audit and management review the standard requires, mock the Stage 1 documentation review, and close findings before the certification body sees them. During the formal audit we sit with you, manage the evidence requests, and handle the assessor relationship.
Steady State. Certification is a three-year commitment with annual surveillance. We keep the risk register current, refresh policies on schedule, run the annual internal audit and management review, and prepare the surveillance evidence so each year is a review rather than a rebuild.
Common failure modes
- Scope drawn too wide in the first cycle, which turns a nine-month program into an eighteen-month one
- A Statement of Applicability that excludes controls without a recorded justification the auditor will accept
- Risk registers written once for the audit and never revisited, which surveillance audits find immediately
- No internal audit or management review evidence, which is a clause-level nonconformity regardless of control maturity
Price range
Programs typically run between $35,000 and $85,000 for the Build phase, depending on scope, entity count, and how much of the control set already operates.
Talk to us about your ISO 27001.
Thirty minutes on the calendar, an honest read on where you stand, and a plain answer on what your next framework actually takes.
Book a consultation