All frameworks
    CertificationISO/IEC; certified by accredited certification bodies

    ISO 27001

    ISO/IEC 27001: Information Security Management Systems

    ISO/IEC 27001 is the international standard for information security management. An accredited certification body audits your ISMS and issues a certificate.

    Last verified Jul 17, 2026

    Q&A

    What is ISO 27001?

    ISO/IEC 27001 is the international standard for information security management. An accredited certification body audits your ISMS and issues a certificate.

    Who needs ISO 27001?

    Organizations that want an internationally recognized information-security certification, particularly those selling into European, UK, and APAC markets where ISO 27001 is commonly expected in procurement. It suits companies that want a certificate they can display, not just a report shared under NDA.

    How long does ISO 27001 take?

    Building and operating the ISMS before a first certification audit typically takes six to twelve months. Certification then runs on a three-year cycle: Stage 1 and Stage 2 audits up front, surveillance audits in years one and two, and recertification in year three.

    How much does a ISO 27001 audit cost?

    Certification-body audit fees vary with organization size, number of sites, and scope, and are separate from the internal effort or consulting to build the ISMS. Larger, multi-site scopes cost materially more than a single-entity ISMS.

    What does a ISO 27001 audit cover?

    An accredited certification body audits your ISMS against ISO/IEC 27001:2022 in two stages, then conducts annual surveillance. The output is a certificate of conformity, not an opinion report.

    What it is

    ISO/IEC 27001 is the world's most widely recognized standard for an Information Security Management System (ISMS). Unlike SOC 2, it is a true certification: an accredited certification body audits your ISMS and, if it conforms, issues a certificate valid for three years.

    Certification follows a two-stage audit. Stage 1 reviews your ISMS documentation and readiness; Stage 2 tests that the system is implemented and effective. After certification, surveillance audits in years one and two confirm the ISMS is maintained, with full recertification in year three. The current version is ISO/IEC 27001:2022.

    Because it is internationally recognized, ISO 27001 is frequently the preferred or required framework for buyers in Europe, the UK, the Middle East, and Asia-Pacific, where it often carries more weight than a US-centric SOC 2 report.

    Who needs it

    Organizations that want an internationally recognized information-security certification, particularly those selling into European, UK, and APAC markets where ISO 27001 is commonly expected in procurement. It suits companies that want a certificate they can display, not just a report shared under NDA.

    What's audited

    An accredited certification body audits your ISMS against ISO/IEC 27001:2022 in two stages, then conducts annual surveillance. The output is a certificate of conformity, not an opinion report.

    Typical timeline

    Building and operating the ISMS before a first certification audit typically takes six to twelve months. Certification then runs on a three-year cycle: Stage 1 and Stage 2 audits up front, surveillance audits in years one and two, and recertification in year three.

    Typical cost

    Certification-body audit fees vary with organization size, number of sites, and scope, and are separate from the internal effort or consulting to build the ISMS. Larger, multi-site scopes cost materially more than a single-entity ISMS.

    What to verify on an auditor

    Only a certification body accredited by a recognized national accreditation body (for example UKAS, RvA, or an IAF member) can issue a valid ISO 27001 certificate. Consultants can help you prepare but cannot certify. Verify the accreditation and check for the accreditation mark on the certificate.

    Service pathways

    Not every service under this framework is fully available today. Hover a pathway for context.

    • Annual surveillance audit
      Available
    • Readiness / gap assessment
      Available
    • Stage 1 + Stage 2 certification audit
      Available

    Find ISO 27001 auditors by region

    Browse independent ISO 27001 auditors serving each region.