What it actually means when a company says it is ISO 27001 certified
ISO 27001 certified means an independent, accredited certification body has audited your information security management system and issued a certificate that is valid for three years, subject to annual surveillance audits.
The short answer
Being ISO 27001 certified means a third party has checked your work, not that you have written a policy binder and called it done. An accredited certification body (think BSI, DNV, Schellman, or similar) runs a two-stage audit against the ISO/IEC 27001 standard, examines your Statement of Applicability and the controls in Annex A, and if you pass, issues a certificate with a scope statement, an issue date, and an expiry date three years out. In between, you sit through annual surveillance audits. Miss one badly enough and the certificate gets suspended.
This distinction matters because a lot of vendors say they are "ISO 27001 compliant" when what they mean is "we read the standard and built some controls." Compliant and certified are not the same claim. Certified means there is a certificate number you can verify with the issuing body and a public register entry in most cases. Compliant, self-attested, or aligned means take their word for it.
What actually gets audited
The audit is not a checklist tick. Stage 1 is a documentation review: does your Information Security Management System (ISMS) exist on paper, does it cover risk assessment, does your Statement of Applicability map to the 93 controls in Annex A (or the older 114 if you are still on the 2013 revision), and is there evidence of management review. Stage 2 is the real test: the auditor samples evidence, interviews staff, checks that access reviews actually happened, that incident tickets exist, that your change management process was followed on a real deployment, not a hypothetical one.
For teams running production workloads on AWS, this is where things get concrete fast. Auditors want to see IAM access reviews with timestamps, CloudTrail retention that matches your policy, encryption at rest evidence, a documented and tested backup/restore, and a risk register that references your actual architecture rather than a generic template downloaded from a compliance SaaS tool. If your infrastructure is provisioned by hand and nobody can explain why a security group is open, that is a finding.
How long it takes and what it costs
Realistic timelines run six to nine months from a standing start for a company with existing AWS infrastructure and no formal ISMS: gap assessment, risk assessment, control implementation, internal audit, then Stage 1 and Stage 2 with the certification body. Faster is possible if you already run SOC 2 and can reuse evidence, since the two frameworks overlap heavily on access control, change management, and vendor risk. I will not quote you a number for audit fees or consulting costs here because they vary by scope, headcount, and which certification body you use; get quotes from at least two accredited bodies before you commit, because pricing is not standardised across the market.
Certified vs compliant vs aligned
| Claim | What it actually means | Can you verify it |
|---|---|---|
| ISO 27001 certified | Accredited body audited the ISMS and issued a certificate with scope and expiry | Yes, certificate number and register lookup |
| ISO 27001 compliant | Self-declared, no independent audit, no certificate | No, take their word for it |
| ISO 27001 aligned | Controls loosely mapped to the standard, often marketing language | No |
| In progress / pursuing | Gap assessment or implementation underway, no audit booked yet | Ask for a target Stage 2 date |
If a vendor's security page says "aligned with ISO 27001" and does not name the certification body, assume there is no certificate. Ask for the certificate PDF and the scope statement directly; a real one names the ISMS scope, the standard version, the issuing body, and the certificate number.
Why the scope statement matters more than the badge
The certificate itself is almost useless without the scope statement attached to it. A company can be genuinely ISO 27001 certified for its HR system and completely uncertified for the production AWS environment that holds your data. I have seen vendors wave a certificate at a customer during due diligence when the scope explicitly excludes the product they are selling. Always ask for the Statement of Applicability scope, not just the certificate cover page, and check the expiry date and last surveillance audit result while you are at it.
Getting there without drowning in paperwork
The mistake most engineering-led teams make is treating ISO 27001 as a documentation exercise that runs parallel to the actual infrastructure. It should not be parallel. Your Statement of Applicability should reference your real Terraform modules, your real IAM boundary policies, your real backup schedule in AWS Backup. When the audit evidence is the infrastructure itself rather than a separate compliance wiki nobody updates, surveillance audits stop being a fire drill every year. This is also the fastest route if you are simultaneously chasing SOC 2, since the underlying technical controls (access review, encryption, logging, change management) are close to identical between the two frameworks and can be evidenced once.
What to do next
If you are being asked by a customer or a sales team whether you are ISO 27001 certified, the honest answer is either yes with a certificate number and scope you can hand over, or not yet with a realistic date. Anything vaguer than that is a sign the underlying ISMS is not built yet. Start with a gap assessment against your current AWS environment, not against a generic template, and decide early whether certification or a SOC 2 report better matches what your customers are actually asking for, because the audit evidence and the sales conversation are different for each.
Related: ISO 27001 certification support, fractional CISO, and DevOps and compliance consulting.
Common questions
How do I verify a company's ISO 27001 certificate is real?
Ask for the certificate PDF and the Statement of Applicability scope, then check the certification body's public register (most accredited bodies maintain one) using the certificate number. Confirm the expiry date and that the scope actually covers the product or service you are buying, not just the company's back office.
Is ISO 27001 certification the same across every certification body?
The standard is identical, but certification bodies differ in accreditation, audit rigour, and price. Only use bodies accredited by a recognised national accreditation body (UKAS in the UK, ANAB in the US, and equivalents elsewhere). A certificate from an unaccredited body is not worth much in due diligence.
Can a startup with a small team get ISO 27001 certified?
Yes, team size is not the blocker. The standard scales to the size of the organisation; a five-person startup can be certified if the ISMS, risk assessment, and Annex A controls are genuinely implemented and evidenced. The main constraint is usually founder time and whether infrastructure is documented well enough to produce audit evidence.
Do we need ISO 27001 certification if we already have SOC 2?
It depends on your customers. US buyers often accept SOC 2 Type II alone; European and APAC buyers, plus government and enterprise procurement, frequently require ISO 27001 specifically. Many companies end up holding both because the underlying controls overlap substantially and the incremental audit effort is manageable.
What happens if we fail a surveillance audit after certification?
A minor nonconformity gets a corrective action plan and a follow-up review, usually within 90 days, without losing the certificate. A major nonconformity can lead to certificate suspension until it is remediated and re-verified. Certification bodies publish their nonconformity grading criteria; ask yours for it before Stage 2.
How long does ISO 27001 certification last before we need to redo it all?
The certificate is valid for three years, but it is not a set-and-forget arrangement. You go through annual surveillance audits in years one and two, then a full recertification audit at the end of year three that is nearly as thorough as the original Stage 2.
How this article was made: drafted with AI assistance from my own engagement notes and lab work, then fact-checked and edited by me (Sahil Dubey) before publishing. Corrections: hi@sahildubey.us.