ISO 27001
The international information security standard most often named in enterprise procurement and European contracts.
What it is
ISO/IEC 27001 specifies the requirements for an information security management system — a documented, risk-driven program with defined scope, leadership accountability, control selection, and internal audit. Certification is issued by an accredited certification body after a two-stage audit, and is maintained through annual surveillance audits on a three-year cycle. The standard is control-agnostic: Annex A gives you 93 controls to consider, and the Statement of Applicability records which ones you applied and why.
Who typically needs it
- SaaS companies whose enterprise or European buyers name ISO 27001 in the security addendum
- Companies already carrying SOC 2 who keep losing deals to competitors with an ISO certificate
- Organizations with a European entity, European customers, or a data-processing footprint in the EU
- Firms preparing for TISAX, where an ISO 27001 program does most of the underlying work
- Anyone who wants one management system to hang subsequent frameworks off, rather than a stack of one-off projects
What the engagement looks like
Common failure modes
- Scope drawn too wide in the first cycle, which turns a nine-month program into an eighteen-month one
- A Statement of Applicability that excludes controls without a recorded justification the auditor will accept
- Risk registers written once for the audit and never revisited, which surveillance audits find immediately
- No internal audit or management review evidence, which is a clause-level nonconformity regardless of control maturity
Price range
Programs typically run between $35,000 and $85,000 for the Build phase, depending on scope, entity count, and how much of the control set already operates.
Talk to us about your ISO 27001.
Thirty minutes on the calendar, an honest read on where you stand, and a plain answer on what your next framework actually takes.