Operational guidance, not legal advice. This page distills named public sources (regulator guidance and industry practice). It is not a legal determination, not a notification decision, and not a substitute for your counsel, insurer, or a retained DFIR firm. Verify applicability and current deadlines for your facts and jurisdiction.
Who needs ISO 27001?
Last verifiedYou need ISO/IEC 27001 when a buyer or tender asks for an accredited certificate — not because it is a law. Clauses 4–10 apply only if you certify. This page is not legal advice, does not determine YOUR obligations, does not start a clock, and does not file.
Applicability guide, last verified 10 September 2026. ISO 27001 is a voluntary standard, not a law. No sentence here says you must get certified. Distinguish a contractual or market request from a legal requirement, from guidance, from industry best practice, and from a ShipReady Metrics recommendation.
What this page is, and what it is not
Audience: a CTO or founder weighing whether ISO/IEC 27001 is worth pursuing this year, versus a SOC 2 report, versus waiting.
This page is not legal advice. It does not determine YOUR obligations, does not decide that ISO 27001 or any adjacent regime applies to you, does not start a clock, and does not file anything with a certification body or a regulator. Last verified 10 September 2026.
ISO/IEC 27001 is a voluntary standard, not a law. Clauses 4–10 are certifiable ISMS requirements only if you seek accredited certification. Annex A remains a selectable catalogue via the Statement of Applicability. Only an IAF-MLA accredited certification body issues a recognised certificate, under ISO/IEC 17021-1 and ISO/IEC 27006.
Do I need ISO 27001 now?
Walk the situations below as a decision tree, not as a mandate. A “yes” in the first column is a planning signal, not a legal finding. Last verified 10 September 2026. Not legal advice.
| Situation | What usually drives demand | Kind of text | What this page does not do |
|---|---|---|---|
| Named enterprise buyer or RFP requires an ISO/IEC 27001 certificate | Contractual / market access. The certificate is a bid or onboarding condition. | Contractual requirement if the contract is signed — not a statute. | Does not interpret your RFP or decide you must bid. |
| EU or other international buyers treat ISO 27001 as the default assurance artefact | Market expectation outside many US-only sales motions. | Industry best practice / market convention. | Does not determine YOUR obligations in any Member State. |
| Regulated-sector customer (financial, health, public sector) asks for an ISMS certificate | Sector procurement practice. Adjacent regimes such as DORA or NIS2 may raise ICT-risk pressure without naming this certificate. | Mix of contractual demand and, where those regimes apply, legal requirements that are not “get ISO 27001 certified.” | Does not apply DORA or NIS2 to you, and does not start a clock. |
| US-only buyers ask for SOC 2 Type II and never mention ISO 27001 | A SOC 2 attestation report against the AICPA Trust Services Criteria may be the artefact that unblocks the deal. | Attestation criteria / market convention — not a law. | Does not say SOC 2 is “enough” as a legal conclusion. |
| You already run Clauses 4–10 style governance and want one internationally recognised certificate | Internal programme choice. Certification is still voluntary. | Industry best practice if you choose it. | Does not issue a certificate or file with a certification body. |
| No buyer, no tender, no board request | Usually wait. Building an ISMS “in case” is cost without a requester. | ShipReady Metrics recommendation is to confirm demand first. | Does not start a clock and does not file. |
Legal requirement, regulatory guidance, best practice, or our recommendation
The failure mode is treating every “customers expect ISO” slide as a legal mandate. Label the authority. Last verified 10 September 2026. Not legal advice.
| Statement | Which kind of authority | What it does not mean |
|---|---|---|
| ISO/IEC 27001:2022 is a voluntary certification standard. | Certification standard — not a law. | Does not say you must get certified. |
| A signed customer contract that requires a current accredited certificate. | Legal requirement in the contractual sense. | Does not apply to organisations that have not signed that contract. |
| DORA and NIS2 information-and-communication-technology risk duties. | Legal requirement only where the regime applies. They are not a substitute for ISO 27001 and they do not, by themselves, order this certificate. | Does not determine YOUR obligations under those regimes. |
| Prefer ISO 27001 when the buyer set is international; prefer SOC 2 when the buyer set is US enterprise SaaS. | Industry best practice / market convention. Not a ranking of which artefact is better. | Does not make either artefact a statute. |
| Confirm a named requester before scoping Clauses 4–10 and an Annex A SoA. | ShipReady Metrics recommendation. | Does not start a clock and is not an auditor's opinion. |
When SOC 2 may suffice instead
SOC 2 is a CPA attestation report, not a certificate. ISO 27001 is accredited certification against Clauses 4–10 with Annex A selected via the SoA. If every active buyer asks only for SOC 2, ISO 27001 is optional. If a European tender names ISO 27001, a SOC 2 report usually does not substitute. Last verified 10 September 2026. Not legal advice.
Doing both is a business decision, covered on the both-artefacts page in this cluster. It is not a requirement of either framework.
Checklist
Work this as the checklist artifact before you hire a certification body. Last verified 10 September 2026. Not legal advice.
- Can we name the organisation that asked, in writing, for an ISO/IEC 27001 certificate?
- Is the ask a certificate, a SOC 2 report, or “security certification” used loosely?
- Is the driver a contract, a tender, a sector questionnaire, or an internal goal?
- Have we checked whether DORA, NIS2, or another regime is being confused with a certification mandate?
- If we proceed, do we accept that only an IAF-MLA accredited certification body (ISO/IEC 17021-1 / ISO/IEC 27006; audit days influenced by IAF MD 5) issues a recognised certificate?
- Have we recorded that this page does not determine YOUR obligations and does not start a clock?
What to do now
None of these steps files anything or starts a statutory clock.
- Collect the actual wording of the last three security asks from buyers.
- Sort them into ISO 27001 certificate, SOC 2 report, questionnaire only, or unclear.
- If ISO 27001 is named, read how to get certified and how to choose a certification body in this cluster.
- If only SOC 2 is named, read the SOC 2 vs ISO 27001 page and the SOC 2 framework guide — not an unpublished /docs/soc-2 path.
- Re-verify the sources below; last verified 10 September 2026.
Where this shows up in ShipReady Metrics
Only shipped behaviour is described here. ShipReady Metrics does not issue certificates, does not produce an auditor's opinion, and is not a downloadable evidence binder.
If you already have a session: signed-in app → Compliance holds the obligation map. You mark frameworks in-scope; that mark is not a legal opinion that ISO 27001 applies. ISO 27001 sits in the 24-framework library with an Annex A crosswalk to about 72 canonical controls and a crosswalk-density honesty layer — coverage, not a pass.
Evidence collection and evidence review (met-verdict overlay) record artefacts against those controls. The policies library and cyber risk register store YOUR material. Human judgment plus an accredited certification body remain required.
Primary sources (last verified 10 September 2026)
ISO/IEC 27001:2022 remains a voluntary standard. IAF describes how accredited certification is recognised. AICPA describes SOC 2 as an attestation report. Adjacent EU regimes are cited only as examples of pressure that is not the same thing as “you must get certified.” Not legal advice.