FRAMEWORKS

ISO/IEC 27001 Information Security Management

ISO/IEC 27001 is the international standard for establishing, implementing, maintaining, and continually improving an information security management system (ISMS) within the context of an organisation's business risks.

Section 01 · The standard

What is ISO 27001?

ISO 27001 is the international standard for information security management systems. Rather than prescribing technologies, it defines how an organisation decides what to protect and how to prove that the protection works.

It is risk-based by design. Controls follow from a risk assessment rather than being applied wholesale, and the Statement of Applicability records which ones apply and why — keeping the system proportionate to the business it serves.

Certification comes from an accredited body after a two-stage audit: a review of the ISMS documentation, then verification that it runs in practice. The certificate lasts three years, with annual surveillance audits in between.

In Europe it is the recognised baseline for NIS 2 risk-management measures and supports GDPR Article 32 obligations — and it increasingly arrives as a precondition in enterprise procurement.

2022
Current edition
93
Annex A controls
4
Control themes
Scope-led
Implementation planning
3 years
Certification cycle
Annex A · 2022 Control Catalogue

The 93 Annex A controls are grouped into four themes. Each cell represents one control; point at a theme to see the controls organisations most often ask about.

Organizational controls (A.5)

37 of 93
  • A.5.1 Policies for information security
  • A.5.9 Inventory of information and other associated assets
  • A.5.15 Access control
  • A.5.19 Information security in supplier relationships
  • A.5.23 Information security for use of cloud services
  • A.5.24 Incident management planning and preparation
  • A.5.30 ICT readiness for business continuity
Section 02 · Business drivers

Why organisations certify

Organizations rarely pursue ISO 27001 because the security team asked for it. The decision is usually forced by something external: a customer contract that names the certificate as a precondition, a procurement questionnaire that cannot be answered credibly without it, a regulator that has started to treat certification as evidence of adequate technical and organisational measures, or an insurance underwriter adjusting premiums against documented risk management.

  1. 01 Customer procurement Enterprise buyers demand the certificate during vendor review. Strength 5 of 5
  2. 02 Regulatory alignment NIS 2, GDPR, DORA and sector supervisors map onto Annex A. Strength 4 of 5
  3. 03 Supply-chain trust Prime contractors flow down certification as a contractual clause. Strength 4 of 5
  4. 04 Insurance & premium Underwriters price documented risk management differently. Strength 3 of 5
  5. 05 Internal posture The risk register gives management a single control view. Strength 2 of 5
Indicative strength on a 1–5 scale, based on Up Secure engagement patterns.
SaaS vendors

Enterprise buyers condition renewals and new logos on ISO 27001 alongside SOC 2. The certificate short-circuits the review.

Software houses

Client contracts with financial-services, healthcare and public-sector buyers increasingly flow down ISO 27001 as a prime-contractor obligation.

Regulated sectors

Under DORA, NIS 2 and national frameworks, certification provides a defensible, externally audited baseline for inspections.

Section 03 · The journey

Illustrative implementation paths

These sequences are illustrative planning models, not time estimates or certification promises. They show how phases may overlap as scope and coordination grow; an organisation-specific plan must follow gap analysis, resourcing, evidence needs, and certification-body scheduling.

Scope pattern One defined boundary Illustrative planning sequence 6 planning steps
  1. 01 Gap analysis & scoping Narrow scope, one site, few systems
    Step 1
  2. 02 Risk assessment & treatment plan Risks, owners, and selected controls
  3. 03 ISMS documentation Policies, SoA, and mandatory records
  4. 04 Control implementation Mostly cloud-native tooling
  5. 05 ISMS operation & evidence Running the system, collecting records
  6. 06 Internal audit & management review Clause 9 before the auditors arrive
  7. 07 Stage 1 & Stage 2 certification audit Accredited certification body
Assess Design & build Operate & verify Certify
Scope pattern Several teams and systems Illustrative planning sequence 12 planning steps
  1. 01 Gap analysis & scoping Where you stand against the standard
    Step 1
  2. 02 Risk assessment & treatment plan Risks, owners, and selected controls
  3. 03 ISMS documentation Policies, SoA, and mandatory records
  4. 04 Control implementation Annex A controls per the treatment plan
  5. 05 Awareness & training People controls in practice
  6. 06 ISMS operation & evidence Running the system, collecting records
  7. 07 Internal audit & management review Clause 9 before the auditors arrive
  8. 08 Stage 1 & Stage 2 certification audit Accredited certification body
Assess Design & build Operate & verify Certify
Scope pattern Multiple units or locations Illustrative planning sequence 18 planning steps
  1. 01 Gap analysis & scoping Multiple sites, units, and legal entities
    Step 1
  2. 02 Risk assessment & treatment plan Per-unit risks rolled into one register
  3. 03 ISMS documentation Policies aligned across the organisation
  4. 04 Control implementation Coordinated across teams and vendors
  5. 05 Awareness & training Rolled out per department and region
  6. 06 ISMS operation & evidence Running the system, collecting records
  7. 07 Internal audit & management review Clause 9 across the full scope
  8. 08 Stage 1 & Stage 2 certification audit Multi-site sampling by the audit team
Assess Design & build Operate & verify Certify
Section 04 · How Up Secure helps

Where you'll get supported

The areas we work in, and where each one falls across the certification lifecycle. The services that deliver them are listed further down.

Areas of support across the certification lifecycle
ISO 27001 support by certification stage
Area of support PrepareImplementCertifyMaintain
Advisory & leadership
Consulting & ISMS design Covered during Prepare Covered during Implement Covered during Certify Covered during Maintain
Security leadership (vCISO) Covered during Prepare Covered during Implement Covered during Certify Covered during Maintain
Management reviews Not covered during Prepare Not covered during Implement Covered during Certify Covered during Maintain
Assessment & assurance
Gap analysis & maturity audit Covered during Prepare Not covered during Implement Not covered during Certify Not covered during Maintain
Risk assessment Covered during Prepare Covered during Implement Not covered during Certify Not covered during Maintain
Internal audit Not covered during Prepare Covered during Implement Covered during Certify Covered during Maintain
Vendor assessment Not covered during Prepare Covered during Implement Covered during Certify Covered during Maintain
Enablement & tooling
Training & awareness Not covered during Prepare Covered during Implement Covered during Certify Covered during Maintain
Software solutions — audit Covered during Prepare Covered during Implement Covered during Certify Not covered during Maintain
Software solutions — risk Covered during Prepare Covered during Implement Covered during Certify Not covered during Maintain
Section 05 · Services

What we deliver

Engage a single phase or the full path to certification — each service below stands on its own.

Audits and Assessments

Systematic compliance audits, security assessments, and maturity evaluations across GDPR, ISO 27001, NIS 2, SOC 2, and AI Act frameworks for organizations in regulated industries.

Secure Source Code Review

SAST and manual code review for Python/Django apps. Findings mapped to OWASP Top 10 and CWE with fix guidance.

NIS 2 DirectiveISO 27001
Read more

Consultancy and Advisory

Strategic consultancy and implementation advisory across GDPR, AI Act, ISO 27001, NIS 2, and cybersecurity for organizations building compliance programs or making security architecture decisions.

Security and Privacy Architecture Review

Security and privacy architecture review for SaaS applications — threat modeling, data flow analysis, and design recommendations.

NIS 2 DirectiveGDPRISO 27001
Read more

Cybersecurity and Data Protection Risk Assessment

Combined cybersecurity and data protection risk assessment with risk register, treatment plan, and DPIA support.

NIS 2 DirectiveGDPRISO 27001SOC 2
Read more

ISO 27001 Consulting

ISO 27001 consulting — gap analysis, ISMS design, risk assessment, and certification readiness for SaaS companies.

NIS 2 DirectiveISO 27001
Read more

Secure SDLC Consulting

Secure SDLC consulting — embedding security gates, threat modeling, and DevSecOps practices into your development pipeline.

NIS 2 DirectiveGDPRISO 27001
Read more

Role Outsourcing

Dedicated specialist roles including DPO, Privacy Engineer, Security Engineer, vCISO, and AI Compliance Officer available on a fractional or full-time outsourced basis.

Virtual CISO (vCISO) Services

Fractional vCISO providing security strategy, risk management, and compliance oversight for growing SaaS teams.

NIS 2 DirectiveISO 27001SOC 2
Read more

Process Outsourcing and Managed Services

Ongoing risk assessments, vendor due diligence programs, and compliance monitoring delivered as managed services with defined service levels and regular reporting cadences.

Vendor Risk Assessment

Third-party vendor risk assessment for cybersecurity, data protection, and supply chain security compliance.

NIS 2 DirectiveGDPRISO 27001SOC 2
Read more
Start the conversation

Scope an ISO 27001 engagement with engineers who have read the standard and shipped the software.

The first conversation defines realistic scope, clarifies applicable clauses and controls, and produces an honest view of what certification requires. No templates, no boilerplate — the proposal is written against the specific systems and risks identified.

Why Up Secure
Engineering + legal under one roof Consultants who have operated production systems and certified DPOs on the same engagement team.
Practical, not paper-only Controls that survive contact with the SDLC, not documentation parallel to engineering practice.
Framework portability Evidence produced once serves NIS 2, GDPR and SOC 2 assessments — not rebuilt per audit.
Section 06 · Frequently asked

Questions decision-makers ask before committing

Frequently asked questions

How long does ISO 27001 certification take?
There is no universal timetable. Scope, current security maturity, resource availability, evidence needs, and certification-body scheduling determine the plan. A gap assessment should be used to build an organisation-specific roadmap rather than relying on a generic duration.
Is ISO 27001 certification mandatory?
The standard itself is voluntary, but it is increasingly demanded by enterprise customers in procurement and is the recognised way to demonstrate the cybersecurity risk-management measures required by the NIS 2 Directive. Many organisations certify because a key contract or regulator expects it.
Is there a new revision of ISO 27001?
The current certifiable edition remains ISO 27001:2022, updated by Amendment 1 in 2024, which brought climate-related considerations into the organisational context and interested-party analysis. Certificates against the 2013 edition expired in October 2025, so certification audits now run exclusively against the 2022 edition. The most recent publication in the family is ISO/IEC 27000:2026, released in July 2026 — a refreshed overview of the ISMS standards family that clarifies how the documents fit together, without changing certification requirements.
What does the certification audit involve?
An accredited certification body audits in two stages. Stage 1 reviews the ISMS documentation and readiness; Stage 2 verifies the system operates in practice by sampling records, interviewing staff, and testing controls. The certificate is valid for three years, maintained through annual surveillance audits.
What does implementation cost depend on?
The scope of the ISMS, the number of locations and systems, existing security maturity, and how much is delivered internally versus with external support. Certification body fees scale with organisation size; implementation effort is usually the larger share.
How does ISO 27001 relate to NIS 2 and GDPR?
ISO 27001 provides the management-system backbone both regulations assume: NIS 2 Article 21 risk-management measures map closely onto Annex A controls, and GDPR Article 32 expects appropriate technical and organisational measures that a certified ISMS demonstrates. One implementation serves all three obligations.