What ISO 27001 actually is and why it exists
ISO 27001 is the international standard that defines how an organisation should build, run and improve a management system for protecting information. It is a framework for managing risk, not a checklist of technical controls.
The short answer
ISO 27001 is a standard published by the International Organization for Standardization that specifies requirements for an Information Security Management System, usually shortened to ISMS. An ISMS is the set of policies, processes, risk assessments and controls an organisation uses to keep information confidential, available and intact. The standard does not tell you which firewall to buy or which encryption algorithm to use. It tells you how to run a system that decides those things for yourself, based on your own risks, and then proves you are actually following it.
Certification against ISO 27001 means an accredited auditor has reviewed your ISMS and confirmed it meets the standard's requirements and that you can produce evidence of it operating for a period of time, typically several months before the audit.
Where it came from and who owns it
ISO 27001 sits in the ISO 27000 family, jointly published by ISO and the International Electrotechnical Commission (IEC), hence the full reference ISO/IEC 27001. It descends from the British Standard BS 7799 from the 1990s. The current widely adopted version is ISO/IEC 27001:2022, which replaced the 2013 edition and reorganised the control set. If someone hands you a certificate dated against the 2013 version now, ask when they are transitioning, since the formal migration deadline for existing certificates has passed in most accreditation schemes.
The standard itself is a paid document, not free public text, which is one reason so much confusion exists online about what it actually contains.
The two halves of the standard
ISO 27001 has two parts that get conflated constantly. Clauses 4 to 10 are the mandatory management system requirements: context of the organisation, leadership commitment, risk assessment methodology, objectives, resourcing, competence, documented information, operational planning, performance evaluation, internal audit, management review, and continual improvement. You cannot skip any of these and still get certified.
Annex A is a reference set of 93 controls grouped into four themes: organisational, people, physical and technological. You don't have to implement every Annex A control. You run a risk assessment, decide which controls are relevant to your actual risks, and document any exclusions with justification in a Statement of Applicability. That document, the SoA, is arguably the single most important artefact in an ISO 27001 project because it is the bridge between your risk assessment and your control implementation.
What an auditor is actually checking
An external auditor is not grading your technical architecture in isolation. They are checking three things: that you identified your risks properly, that you chose controls that address those risks, and that you can show evidence the controls have been operating, not just designed on paper. A Stage 1 audit reviews documentation readiness. A Stage 2 audit, usually weeks later, tests whether the system is actually operating, through interviews, sampled evidence and walkthroughs. Surveillance audits happen annually after that, with full recertification every three years.
This is why organisations that treat ISO 27001 as a one-off document exercise often fail Stage 2, or pass it and then struggle at the first surveillance audit. The evidence has to be continuous, not retrofitted.
How it compares to other frameworks people confuse it with
ISO 27001 gets mixed up with SOC 2, PCI DSS and generic security questionnaires constantly, partly because vendors use them interchangeably in sales conversations. They are not interchangeable.
| Framework | What it actually is | Who typically asks for it |
|---|---|---|
| ISO 27001 | Certifiable management system standard, international | Enterprise buyers, government tenders, EU and APAC customers |
| SOC 2 | Attestation report against Trust Services Criteria, US-originated | North American SaaS buyers, US enterprise procurement |
| PCI DSS | Mandatory control set for anyone handling card data | Payment processors, acquiring banks |
| Cyber Essentials | UK baseline self-assessment or light audit | UK public sector contracts, SME-scale suppliers |
If you already hold SOC 2 and a prospect asks for ISO 27001, that is usually a signal they operate internationally or sell into regulated or public sector buyers who specifically require a certificate rather than an attestation report.
Who actually needs it and when
Nobody needs ISO 27001 by law in most jurisdictions. It becomes necessary when a customer, a tender, or a regulator requires it as a condition of doing business, or when you are scaling past the point where ad hoc security practices create real risk to the business. The most common trigger I see is a single large enterprise or government contract whose procurement team has ISO 27001 as a non-negotiable line item. The second most common is a board or investor pushing for formal risk governance after a near-miss or an incident.
Cost and timeline depend heavily on scope, existing maturity and whether you already run AWS infrastructure with some controls in place. A greenfield ISMS built from nothing typically takes longer than one layered onto existing cloud security practices, because so much of Annex A maps directly onto things like access control, logging, encryption and change management that a reasonably mature AWS environment already does in some form.
What it is not
ISO 27001 is not a guarantee you won't be breached. It is not a technical penetration test. It is not a substitute for PCI DSS if you handle card data, or for HIPAA if you handle US health data, both of which have their own mandatory requirements regardless of your ISO status. And it is not a static document you file away after certification; the standard requires ongoing internal audits, management review and continual improvement as a condition of keeping the certificate.
Related: if you are scoping an ISMS against existing AWS infrastructure, start with ISO 27001 implementation support, or if you need the groundwork of a compliant environment first, look at a secure cloud landing zone or a fractional cloud compliance architect engagement.
Common questions
Is ISO 27001 a legal requirement?
No. There is no general law mandating ISO 27001 certification. It becomes a practical requirement when a customer contract, government tender, or specific industry scheme requires it. Some regulated sectors reference it indirectly as evidence of adequate security governance, but the standard itself is voluntary.
How long does ISO 27001 certification take?
Most organisations take between six and twelve months from starting the ISMS to passing Stage 2 audit, depending on existing security maturity, scope, and how much evidence already exists from day-to-day operations. Organisations with mature AWS environments and existing logging and access controls tend to move faster.
Do I need ISO 27001 if I already have SOC 2?
Not automatically. They serve different buyer expectations. If your customers are mostly US enterprise and SaaS buyers, SOC 2 often suffices. If you sell into Europe, APAC, government, or large multinational procurement, ISO 27001 is frequently a hard requirement that SOC 2 does not satisfy.
What is the Statement of Applicability?
It is the document that lists all 93 Annex A controls, states whether each applies to your organisation, and justifies any exclusions based on your risk assessment. Auditors treat it as the central reference point connecting your risk analysis to the controls you actually implemented.
Can a small company get ISO 27001 certified?
Yes, there is no minimum size requirement. The standard scales to the size and complexity of the organisation. Small companies sometimes find it faster to certify precisely because there is less infrastructure and fewer processes to document and evidence.
What happens after you get certified?
Certification is valid for three years but requires annual surveillance audits to confirm the ISMS is still operating. You must keep running internal audits, management reviews, and risk assessments throughout, since the certificate can be suspended or withdrawn if the system lapses.
How this article was made: drafted with AI assistance from my own engagement notes and lab work, then fact-checked and edited by me (Sahil Dubey) before publishing. Corrections: hi@sahildubey.us.