ISO 27001
ISO/IEC 27001: Information Security Management Systems
ISO/IEC 27001 is the international standard for information security management. An accredited certification body audits your ISMS and issues a certificate.
Last verified Jul 17, 2026
Q&A
What is ISO 27001?
ISO/IEC 27001 is the international standard for information security management. An accredited certification body audits your ISMS and issues a certificate.
Who needs ISO 27001?
Organizations that want an internationally recognized information-security certification, particularly those selling into European, UK, and APAC markets where ISO 27001 is commonly expected in procurement. It suits companies that want a certificate they can display, not just a report shared under NDA.
How long does ISO 27001 take?
Building and operating the ISMS before a first certification audit typically takes six to twelve months. Certification then runs on a three-year cycle: Stage 1 and Stage 2 audits up front, surveillance audits in years one and two, and recertification in year three.
How much does a ISO 27001 audit cost?
Certification-body audit fees vary with organization size, number of sites, and scope, and are separate from the internal effort or consulting to build the ISMS. Larger, multi-site scopes cost materially more than a single-entity ISMS.
What does a ISO 27001 audit cover?
An accredited certification body audits your ISMS against ISO/IEC 27001:2022 in two stages, then conducts annual surveillance. The output is a certificate of conformity, not an opinion report.
What it is
ISO/IEC 27001 is the world's most widely recognized standard for an Information Security Management System (ISMS). Unlike SOC 2, it is a true certification: an accredited certification body audits your ISMS and, if it conforms, issues a certificate valid for three years.
Certification follows a two-stage audit. Stage 1 reviews your ISMS documentation and readiness; Stage 2 tests that the system is implemented and effective. After certification, surveillance audits in years one and two confirm the ISMS is maintained, with full recertification in year three. The current version is ISO/IEC 27001:2022.
Because it is internationally recognized, ISO 27001 is frequently the preferred or required framework for buyers in Europe, the UK, the Middle East, and Asia-Pacific, where it often carries more weight than a US-centric SOC 2 report.
Organizations that want an internationally recognized information-security certification, particularly those selling into European, UK, and APAC markets where ISO 27001 is commonly expected in procurement. It suits companies that want a certificate they can display, not just a report shared under NDA.
An accredited certification body audits your ISMS against ISO/IEC 27001:2022 in two stages, then conducts annual surveillance. The output is a certificate of conformity, not an opinion report.
Building and operating the ISMS before a first certification audit typically takes six to twelve months. Certification then runs on a three-year cycle: Stage 1 and Stage 2 audits up front, surveillance audits in years one and two, and recertification in year three.
Certification-body audit fees vary with organization size, number of sites, and scope, and are separate from the internal effort or consulting to build the ISMS. Larger, multi-site scopes cost materially more than a single-entity ISMS.
Only a certification body accredited by a recognized national accreditation body (for example UKAS, RvA, or an IAF member) can issue a valid ISO 27001 certificate. Consultants can help you prepare but cannot certify. Verify the accreditation and check for the accreditation mark on the certificate.
Service pathways
Not every service under this framework is fully available today. Hover a pathway for context.
- AvailableAnnual surveillance audit
- AvailableReadiness / gap assessment
- AvailableStage 1 + Stage 2 certification audit
Find ISO 27001 auditors by region
Browse independent ISO 27001 auditors serving each region.