ISO/IEC 27001
The international standard for information security management systems. Certifiable, audited by a third party, and usually the first one you are asked for.
What ISO 27001 is
ISO/IEC 27001 sets out the requirements for an information security management system. It is not a list of technical measures: it is a management framework that requires you to identify your risks, decide what you do about each one, document it and review it continuously.
The current version is ISO/IEC 27001:2022. Its Annex A holds 93 controls grouped into four themes: organisational, people, physical and technological. None is mandatory by default. The standard requires you to justify which ones you apply and which you do not, and that document is the Statement of Applicability.
That flexibility is deliberate. ISO 27001 does not tell you what your security should look like, it tells you that you have to know why it looks the way it does.
Who ISO 27001 applies to
Nobody, as a legal obligation. ISO 27001 is adopted voluntarily, and in practice it is adopted because the market asks for it:
- Enterprise customers who require it during procurement
- Public tenders that score it or require it
- Funding rounds with security due diligence
- Supply chains where your customer answers to their own auditor
There is no size or sector threshold. An eight-person company can certify if its management system is real.
What ISO 27001 requires
The standard has two halves and both are audited.
Clauses 4 to 10, the management system. Organisational context and interested parties. A defined, defensible scope. Leadership and policy. Risk assessment and treatment. Objectives. Competence and awareness. Documentation. Internal audit. Management review. Nonconformities and continual improvement.
Annex A, the 93 controls. They are selected from your risk assessment, not from a template. The Statement of Applicability justifies every inclusion and every exclusion.
The most expensive mistake in a first certification is not a badly implemented control: it is a badly defined scope. Too broad multiplies the work, and too narrow leaves you with a certificate that does not do what you wanted it for.
How ISO 27001 is demonstrated
With a certificate issued by an accredited certification body, independent of the organisation being audited. The cycle runs three years: an initial audit in two stages, annual surveillance audits, and recertification in the third year.
The certification body sets the date. No software vendor can issue or accelerate a certificate, only prepare you so the audit goes well.
With Zerod
ISO 27001 is built to fit your organisation, and so is Zerod.
Activate the standard and Zerod gives you its control register, uses AI to generate the policies and documentation the management system requires, and organises evidence collection against each control. The risk assessment, the Statement of Applicability and the internal audit live in the platform, not in a folder of screenshots.
Zerod is certified to ISO/IEC 27001:2022. We know what an audit asks for because we went through one.
Frequently asked questions
How long does ISO 27001 certification take?
It depends on the scope, on whether documented processes already exist, and on the certification body's availability. What you do control is the work before that: risk assessment, policies, controls and evidence.
Does ISO 27001 replace SOC 2?
No. They are different frameworks with different logic. ISO 27001 certifies a management system; SOC 2 produces an audit report against a set of criteria. Many companies end up with both because different markets ask for them.