What is ISO 27001 certification and who actually needs it?
7 min read · Certifyi research team · Updated July 2026
ISO 27001 is an international standard for an Information Security Management System. Unlike SOC 2, it produces a genuine certificate issued by an accredited certification body after a two-stage audit, valid for three years with annual surveillance audits. It is the expected standard across Europe, the UK and much of APAC.
What an ISMS actually is
The certificate is not awarded for having good security tools. It is awarded for running a management system: a documented, repeating cycle of scoping, risk assessment, control selection, implementation, internal audit, management review and improvement.
This is why ISO 27001 feels heavier than SOC 2 to first-time teams. You are being assessed on governance discipline, not only on technical controls.
How certification works
Certification is a two-stage external audit performed by an accredited certification body.
- Stage 1: the auditor reviews your documentation and readiness. Gaps surface here, which is the point.
- Stage 2: the auditor tests whether your ISMS operates as documented, sampling evidence and interviewing staff.
- Certificate issued, valid for three years.
- Surveillance audits in years one and two, then full recertification in year three.
The Statement of Applicability
The SoA is the document auditors scrutinise most. It lists every Annex A control, states whether it applies, and justifies exclusions.
A SoA that lists controls without justifying exclusions is one of the most common Stage 1 findings. "Not applicable" is an acceptable answer only when you explain why.
ISO 27001 versus SOC 2
They overlap heavily on controls and diverge on structure and geography.
| ISO 27001 | SOC 2 | |
|---|---|---|
| Output | Certificate | Auditor attestation report |
| Issued by | Accredited certification body | Licensed CPA firm |
| Validity | 3 years plus surveillance | Period covered, refreshed annually |
| Strongest in | Europe, UK, APAC, India | United States |
| Emphasis | Management system and governance | Control operation against criteria |
When to do both
If you sell in both the US and Europe, you will eventually need both. The efficient path is a single unified control library where one control satisfies requirements in both frameworks, so evidence collected once counts twice.
Doing them as two separate projects, often on two separate tools, is how companies end up paying twice for the same work.
Key takeaways
- ISO 27001 certifies a management system, not just controls.
- Certification is a two-stage audit, valid three years with annual surveillance.
- The Statement of Applicability must justify exclusions, not just list controls.
- Run ISO 27001 and SOC 2 off one control library to avoid duplicate work.
Frequently asked questions
How long does ISO 27001 take?
A first ISMS typically takes three to six months to reach Stage 1, then four to eight weeks to Stage 2, depending on how much documentation and evidence already exists.
Is ISO 27001 harder than SOC 2?
It is more prescriptive about governance: internal audits and management reviews are mandatory clauses. The technical control overlap with SOC 2 is substantial.
Do we need a consultant?
Not necessarily, but you do need someone accountable who understands the clause structure. Certifyi provides a named compliance lead in place of hiring for it.
What happens if we fail Stage 2?
Findings are usually raised as minor or major nonconformities with a window to remediate rather than an outright failure. Major nonconformities delay certification.
Related reading
Get audit-ready in 8 to 12 weeks
Certifyi pairs the platform with a named compliance lead, at published pricing from $8,000/year.
Book a 20-min deal readiness call