ISO/IEC 27001

Vendor-neutral guidance for founders, CTOs, CISOs, and compliance owners on ISO/IEC 27001:2022 — what the standard is, who typically seeks certification, how the accredited audit cycle works, and how it differs from a SOC 2 report. Not legal advice. Does not determine your obligations. Does not start a clock. Does not issue a certificate.

What is ISO/IEC 27001?

ISO/IEC 27001:2022 is a voluntary ISMS standard. Clauses 4–10 are certifiable; Annex A lists 93 selectable controls across four themes. Not legal advice.

Who needs ISO 27001?

ISO 27001 is rarely a legal mandate. Buyer RFPs, EU markets, and sector pressure usually drive demand; SOC 2 may suffice for some US buyers. Not legal advice.

How do you get ISO 27001 certified?

A numbered path to ISO/IEC 27001:2022: scope the ISMS, assess risk, write the SoA, operate controls, then accredited Stage 1 and Stage 2. Not legal advice.

What is the ISO 27001 certification process?

Stage 1 reviews documentation and readiness; Stage 2 tests implementation and effectiveness. Only an IAF-MLA accredited body issues the certificate. Not legal advice.

What is an ISO 27001 readiness assessment?

An ISO 27001 readiness (gap) assessment is industry best practice, not a mandatory clause. It is not Stage 1 and not an accredited certificate. Not legal advice.

What are the ISO 27001 Annex A controls?

ISO/IEC 27001:2022 Annex A has 93 controls in four themes (37 / 8 / 14 / 34). They are selected in the SoA — not all mandatory. 27002 is guidance. Not legal advice.

What evidence does an ISO 27001 auditor request?

ISO 27001 auditors sample mandatory documented information (scope, policy, risk, SoA, audits, reviews, corrective actions) plus supporting operating records. Not legal advice.

How long does ISO 27001 certification take?

Typical ISO 27001 elapsed time is often several months to more than a year, driven by scope, maturity, and the Stage 1 to Stage 2 gap. Illustrative, not a guarantee.

How much does ISO 27001 cost?

ISO 27001 cost is certification-body fees plus internal time, tooling, consultants, and remediation. Figures here are typical and illustrative, not quotes. Not legal advice.

What is an ISO 27001 surveillance audit?

ISO 27001 surveillance audits usually sample the ISMS in years 1 and 2 of a three-year cycle. They are partial, not recertification. Not legal advice.

What is ISO 27001 recertification?

ISO 27001 recertification is the full reassessment before a typical three-year expiry. It is not surveillance and not a first-time Stage 1/2. Not legal advice.

How do you choose an ISO certification body?

Choose an IAF-MLA accredited ISO/IEC 27001 certification body and verify it in IAF CertSearch. This page ranks no one. Unaccredited certificates are a red flag.

SOC 2 vs ISO 27001: which do you need?

SOC 2 is a CPA attestation report against the AICPA TSC. ISO 27001 is an accredited ISMS certificate. Neither is a law. This page does not pick a winner.

Do you need both SOC 2 and ISO 27001?

Running SOC 2 and ISO 27001 together is a business decision driven by mixed buyers. Controls overlap; the report and the certificate do not. Not a requirement.

How does ShipReady Metrics support ISO 27001 evidence?

ShipReady Metrics maps ISO 27001 to about 72 canonical controls, records evidence, and shows coverage density — not a pass. It does not issue certificates. Not legal advice.