Skip to content
Information Security Management › ISO27001

ISO 27001 compliance and certification: what the standard requires and what the certificate proves

ISO 27001 compliance means meeting the requirements of the standard. ISO 27001 certification is an accredited body confirming that you do. Here is the difference, the requirements in clauses 4 to 10 and Annex A, what a certificate really covers, and what the three-year cycle costs.

ISO 27001 as four steps from the standard to compliance, certification and accreditation, beside a three-year cycle

Table of Contents

    A customer writes ISO 27001 into a tender. The board asks whether you are "ISO 27001 compliant". A supplier sends over a certificate and nobody is quite sure what it proves. Three situations, one standard, three different questions.

    This article answers all three. It explains what ISO/IEC 27001:2022 requires, the difference between complying with the standard and being certified against it, what a certificate actually covers, and what the three years of a certification cycle cost. The step-by-step route is in our practical guide to ISO 27001 certification, and the full list of requirements is in our ISO 27001 checklist. This page is about understanding what you are signing up for before you start.

    The figures come from ISO, the ISO Survey 2024, the accreditation rules in ISO/IEC 27006-1, the NIS2 Directive, the GDPR, UK and European certification bodies and the UK Parliament, and we say which.

    The short answer: what is ISO 27001 compliance, and what is ISO 27001 certification?

    ISO 27001 compliance means your organisation meets the requirements of ISO/IEC 27001:2022. You run an information security management system (ISMS) that satisfies clauses 4 to 10, and you have taken a documented position on all 93 Annex A controls in a Statement of Applicability. You can do that without ever meeting an auditor.

    ISO 27001 certification means a certification body, accredited by a national accreditation body such as UKAS in the United Kingdom or DANAK in Denmark, has carried out a two-stage audit and issued a certificate confirming that your ISMS conforms to the standard within a defined scope. The certificate is valid for three years with a surveillance audit each year.

    The difference is the evidence. Compliance is something you assert and can document. Certification is something an independent third party confirms. Customers, tenders and supplier assessments almost always ask for the second, because it is the only one of the two they can check without auditing you themselves. Neither makes you GDPR or NIS2 compliant on its own, but both cover a large share of the security work those laws require.

    Three things that get mixed up

    Search queries around ISO 27001 treat the standard, compliance with it and the certificate as one thing. They are three things built on top of each other, and a fourth, accreditation, decides whether the certificate is worth showing anyone.

    Term What it is Who is behind it Can you prove it to others?
    The standard, ISO/IEC 27001 A document setting requirements for an ISMS. The current edition is 2022, adopted in Europe as EN ISO/IEC 27001:2023 ISO and IEC. Bought from ISO or your national standards body, it is not free No, it is a text, not a status
    ISO 27001 compliance Your ISMS meets clauses 4 to 10 and you have taken a position on Annex A You Only by showing documentation or being audited
    ISO 27001 certification A certificate issued after a two-stage audit, valid three years within a defined scope A certification body Yes, the certificate and scope statement can be sent to customers
    Accreditation Confirmation that the certification body itself meets ISO/IEC 17021-1 and ISO/IEC 27006-1 UKAS in the UK, DAkkS in Germany, DANAK in Denmark, and their peers Yes, the accreditation mark is on the certificate and the certificate can be looked up in IAF CertSearch

    The last row is the one most people skip. Any company may legally issue an "ISO 27001 certificate". The National Cyber Security Centre makes exactly this point: only bodies accredited by UKAS are covered by the international peer review that makes their assessments independent and recognised across borders. When you assess a supplier's certificate, look for the accreditation mark and look the certificate up.

    Four stacked layers, from the ISO/IEC 27001 standard up through compliance and certification to accreditation, with who decides each

    What is ISO 27001?

    ISO/IEC 27001 is the international standard for an information security management system. It is published jointly by ISO and IEC. The third edition, ISO/IEC 27001:2022, was published in October 2022, and Amendment 1 from 2024 added climate change as a factor the organisation must consider under clauses 4.1 and 4.2. Annex A was not changed.

    The transition from the 2013 edition closed on 31 October 2025. Every 2013 certificate has expired, and any valid certificate today is issued against the 2022 edition. The vocabulary standard ISO/IEC 27000 was republished on 3 July 2026, but it does not change the requirements in 27001 and does not affect the validity of existing certificates.

    The standard is built around three properties of information: confidentiality, integrity and availability. It is not a list of technical requirements. It describes a management system that forces the organisation to know its risks, decide how to treat them and prove that the decisions are followed through. That is why ISO 27001 is equally relevant to a manufacturer, a local authority and a SaaS provider, even though their controls look very different.

    It is also widely used. The ISO Survey 2024, the most recent published edition, counts 96,709 valid certificates covering 179,877 sites worldwide. The United Kingdom has 4,445 certificates, the fourth highest number of any country after China, India and Japan. Germany has 2,444 and the Netherlands 1,568. In the UK the standard is what larger customers, public procurement and international partners ask for by name, and it is the natural backbone for organisations covered by NIS2 in the EU.

    ISO 27001 compliance requirements: clauses 4 to 10

    The requirements for the management system itself sit in clauses 4 to 10. All of them are mandatory. You cannot exclude a clause the way you can exclude an Annex A control. The table shows what each clause requires and what an auditor typically asks to see.

    Clause What it requires Typical audit evidence
    4 Context of the organisation Understand internal and external issues (4.1), interested parties' requirements including legislation (4.2), define the scope of the ISMS (4.3) and establish the system (4.4) Scope statement, stakeholder analysis, register of legal requirements
    5 Leadership Top management commitment (5.1), information security policy (5.2), roles, responsibilities and authorities (5.3) Signed policy, meeting minutes, security organisation chart
    6 Planning Risk assessment (6.1.2), risk treatment with a Statement of Applicability (6.1.3), measurable security objectives (6.2), planning of changes (6.3, new in 2022) Risk methodology, risk register, risk treatment plan, SoA, objectives
    7 Support Resources (7.1), competence (7.2), awareness (7.3), communication (7.4), control of documented information (7.5) Training log, competence matrix, document control with versions
    8 Operation Carry out what was planned (8.1), risk assessment at planned intervals (8.2), implement the risk treatment plan (8.3) Completed risk assessments, status of treatment actions, supplier management
    9 Performance evaluation Monitoring and measurement (9.1), internal audit (9.2), management review (9.3) Audit programme, audit reports, management review minutes
    10 Improvement Continual improvement (10.1), nonconformity and corrective action (10.2) Nonconformity log with root cause analysis and closed actions

    Read the table as a cycle, not a list. Clauses 4 to 6 plan, 7 and 8 do, 9 measures and 10 corrects. That cycle is what separates a management system from a folder of policies, and it is what the auditor looks for evidence of. An organisation that has written every document but has never held an internal audit or a management review is not ISO 27001 compliant, however good the documents are.

    The risk assessment in clause 6.1.2 is the engine. Everything else, from the choice of controls to the order in which budget is spent, has to trace back to it. Our article on information security risk management shows how one method can serve ISO 27001, the GDPR, NIS2 and DORA at the same time.

    Plan-do-check-act loop around the ISMS: plan is clauses 4 to 6, do is 7 and 8, check is clause 9 and act is clause 10

    Annex A: 93 controls and the Statement of Applicability

    Annex A is the standard's catalogue of reference controls. The 2022 edition consolidated the previous 114 controls in 14 domains into 93 controls in four themes. Eleven controls are new, including threat intelligence (5.7), information security for use of cloud services (5.23), ICT readiness for business continuity (5.30), configuration management (8.9), information deletion (8.10), data masking (8.11), data leakage prevention (8.12), monitoring activities (8.16), web filtering (8.23) and secure coding (8.28).

    Theme Number of controls Examples
    5 Organisational 37 Policies (5.1), access control (5.15 to 5.18), supplier relationships (5.19 to 5.23), incident management (5.24 to 5.28), business continuity (5.29 to 5.30), legal and contractual requirements (5.31 to 5.34)
    6 People 8 Screening (6.1), terms of employment (6.2), awareness and training (6.3), remote working (6.7)
    7 Physical 14 Physical perimeters (7.1), physical security monitoring (7.4), clear desk and clear screen (7.7), secure disposal (7.14)
    8 Technological 34 Secure authentication (8.5), vulnerability management (8.8), logging (8.15), cryptography (8.24), secure development (8.25 to 8.31)

    The controls are references, not requirements in themselves. Clause 6.1.3 requires you to compare the controls your risk assessment points to with Annex A and, in a Statement of Applicability (SoA), to take a position on each of the 93 with a justification for inclusion or exclusion and an implementation status. A control can be excluded. What cannot be excluded is the justification. The SoA is also the first document a certification body reads, and it is referenced on the certificate next to the scope statement.

    Guidance on how to implement the controls sits in ISO/IEC 27002:2022. It is not certifiable and it cannot buy you out of the risk assessment, but it is where your IT team will look things up.

    Four columns for the Annex A themes with 37, 8, 14 and 34 controls, standing on the Statement of Applicability as a shared base

    What an ISO 27001 certificate proves, and what it does not

    A certificate is a precise document. It confirms that an accredited body found, at a given point in time, that the ISMS within the stated scope conforms to ISO/IEC 27001:2022. Three things follow from that wording, and they are worth reading aloud both when you pursue a certificate and when you assess someone else's.

    Scope decides everything. A certificate covering "the operation of the customer portal at the Manchester site" says nothing about the HR system, the finance function or the subsidiary in Dublin. The scope statement is printed on the certificate and it is the first thing an experienced buyer reads. A narrow scope is not cheating, it is often sensible, but it has to match what the customer is actually buying.

    The certificate proves the system works, not that nothing can go wrong. An auditor samples. A certified organisation can suffer a breach, and that does not invalidate the certificate as long as the incident is handled through the system. The standard promises a managed level of risk, not zero risk.

    The certificate is not a legal approval. ISO 27001 certification does not in itself satisfy the GDPR, NIS2 or DORA. We come back to this below, because it is the claim we most often see made wrongly in the market.

    The certification cycle: three years, four audits

    Certification is not an exam you pass once. It is a three-year cycle governed by ISO/IEC 17021-1 and ISO/IEC 27006-1:2024, the standards certification bodies themselves must follow. The step-by-step preparation is covered in our guide to the ISO 27001 certification process. Here is the cycle itself.

    When Audit What the auditor does Effort
    Year 0 Stage 1 Reviews the documentation: scope, policy, risk assessment, SoA, internal audit and management review. Decides whether you are ready for Stage 2 Typically 1 to 2 days, often partly remote
    Year 0 Stage 2 Checks that the system works in practice: interviews, sampling of controls, logs and evidence. Nonconformities must be closed before the certificate is issued The bulk of the audit days
    Years 1 and 2 Surveillance audit Checks selected areas, always including internal audit, management review, nonconformities, complaints and changes. The first surveillance falls within 12 months of the certification decision Around one third of the initial audit time per year
    Year 3 Recertification Full review of the whole ISMS before the certificate expires. New certificate for three years Around two thirds of the initial audit time

    The number of audit days is set by the number of people working within the scope. ISO/IEC 27006-1:2024 clarified that this includes everyone working for the organisation within scope, whether employees or not, so contractors and freelancers count, and that the number of sites is no longer a separate factor. The same revision removed the earlier 30 per cent ceiling on remote auditing, so a larger share of an audit can now take place over video.

    If the certificate is not renewed before it expires, it lapses. There is no extension, and in a tender an expired certificate is the same as no certificate.

    Timeline: Stage 1 and Stage 2 in year 0, surveillance audits in years 1 and 2, and recertification in year 3 before expiry

    What does ISO 27001 certification cost?

    Cost is the part most articles skip or quote in a single headline number. Here are the figures we can stand behind, split into the four items that actually make up the bill. Certification has no fixed price list, so these are UK and European market figures, and we say where each one comes from.

    Item Initial certification Ongoing (years 1 to 3) Source and date
    Certification body GBP 3,500 to 26,000 for Stage 1 and Stage 2 combined depending on headcount. Around EUR 5,250 to 10,500 for organisations up to 25 people Surveillance around one third and recertification around two thirds of the initial audit time Tempo Audits, UK (July 2026). instant27001, Netherlands (2026)
    External consultancy The largest variable. Total first-time programmes in the UK are quoted at GBP 5,000 to 50,000 all in, of which consultancy is the main driver Optional. Many organisations only buy an externally run internal audit High Table, UK (2026)
    Internal time 0.5 to 1 full-time equivalent for 6 to 18 months Typically 0.2 to 0.5 full-time equivalent to run the system .legal, experience figures 2026
    Standard and tooling The standard is bought from ISO or a national body. A compliance platform is usually a subscription Subscription per year ISO store. Vendor pricing

    The single factor that moves the audit fee most is the number of people in scope. ISO/IEC 27006-1 contains an indicative audit time table that certification bodies use as a starting point and may adjust up or down for complexity. As one UK accredited body reproduces it in 2026: 1 to 10 people gives 5 audit days, 26 to 45 gives 8.5, 46 to 65 gives 10, 86 to 125 gives 12, 176 to 275 gives 14 and 426 to 625 gives 16.5. The same body publishes a day rate of GBP 1,250. Halve the number of people in scope and the audit days fall noticeably, and the saving repeats in every year of the cycle.

    Two notes on the table. The certification body is rarely the largest item, internal time and consultancy are. And the ongoing cost is real: the certificate has to be maintained with an internal audit, a management review and a risk assessment every year, or it falls at the next surveillance.

    Stacked bars of the worked example: certification body and consultancy per year, about GBP 37,500 in year 0, plus internal time and tooling

    A worked example: scope, audit days and three years of cost

    Harbourline Analytics Ltd and Priya Nair are fictional. We invented them for this article, and they are neither customers nor a case study.

    Harbourline Analytics is a UK software company with 120 staff, headquartered in Leeds, that runs an analytics platform for energy utilities in the UK, the Netherlands and Germany. Two of its largest customers are essential entities under NIS2 and have written ISO 27001 into their supplier requirements, with a deadline at contract renewal in 2027. Priya Nair is head of engineering and has been handed the task.

    Her first decision is scope. If she certifies the whole company, all 120 people are in scope and the indicative table gives 12 audit days for the initial certification. If she limits the scope to "the development, hosting and support of the Harbourline analytics platform and the IT infrastructure that underpins it", the 55 people in engineering, support, IT and leadership who work within that scope give 10 days. Sales, marketing and finance stay outside, because they do not touch customer data in the platform.

    She chooses the narrow scope and checks it against what the customers require. Both buy the platform and the support around it, not Harbourline's payroll system, so the scope matches what they are actually worried about. She writes that into the scope statement so it appears on the certificate.

    Her three-year budget looks like this. Certification body at the published day rate of GBP 1,250: 10 days for Stage 1 and Stage 2, so GBP 12,500, then around 3.5 days for each surveillance audit, roughly GBP 4,400 each, and around 7 days for recertification, roughly GBP 8,750, in total about GBP 30,000 over three years. External consultancy for the gap analysis and the internal audit: GBP 25,000 in year one, which sits inside the GBP 5,000 to 50,000 band quoted above, then GBP 5,000 a year for an externally run internal audit. Internal time: half a full-time role for 12 months, then a fifth. A platform for the ISMS on an annual subscription. Year one lands at around GBP 37,500 plus internal time, and each of the following two years at around GBP 9,500 plus subscription and internal time.

    Had Priya chosen the whole company as scope, audit days would have risen by 20 per cent, but the larger bill would have been awareness training, access management and physical controls for 65 people who contribute nothing to what the customers are asking for. The point of the example is that scope is the most important financial decision in the whole programme, and it should be made on the basis of who is asking for the evidence and what they are buying.

    ISO 27001 and the law: GDPR, NIS2, DORA and the UK

    No European or UK law requires private companies to hold ISO 27001 certification. Even so, the standard is the most common way to structure the security work those laws demand, and it pays to be precise about where the line runs.

    Framework What it requires What ISO 27001 covers What the certificate does not do
    GDPR Article 32 and UK GDPR Appropriate technical and organisational measures based on risk, with pseudonymisation, encryption, confidentiality, integrity, availability, resilience, restoration and regular testing given as examples A risk-based method and controls for access, cryptography, backup, logging and testing. Article 32(3) names approved certification mechanisms as one element for demonstrating compliance Not an Article 42 scheme. Does not cover lawful basis, data subject rights, the record of processing (Article 30) or processor contracts (Article 28)
    NIS2 Directive, Article 21(2) Ten minimum measures for essential and important entities: risk analysis policies, incident handling, business continuity, supply chain security, secure acquisition and development, effectiveness assessment, cyber hygiene and training, cryptography, HR security and access control, MFA and secure communications All ten areas have matching Annex A controls and clause 6, 7 and 9 requirements. Article 25 explicitly encourages the use of European and international standards Not registration with the competent authority, not the 24-hour, 72-hour and one-month incident reporting in Article 23, not management approval and training duties in Article 20
    DORA, Articles 5 to 16 ICT risk management framework for financial entities, applicable since 17 January 2025 Management system, risk assessment, continuity and third-party management Not DORA's incident reporting, resilience testing or register of ICT third-party providers
    UK NIS Regulations 2018 and the Cyber Security and Resilience Bill Security duties and incident reporting for operators of essential services and digital service providers. The Bill, which extends scope to managed service providers and tightens reporting, was at report stage in the House of Lords on 16 September 2026 and had not yet received Royal Assent The NCSC Cyber Assessment Framework maps closely to an ISO 27001 ISMS, and regulators accept it as supporting evidence Not a substitute for registration, CAF self-assessment where a regulator requires it, or statutory incident reporting

    The pattern is the same throughout. The laws require you to manage risk and have controls in place, and ISO 27001 is the most proven way to do that. The laws also require regulator contact, deadlines, registers and individual rights, and the standard does not cover those. Our comparison of NIS2 and ISO 27001 goes through the NIS2 requirements one by one, and our guide to GDPR compliance covers that side.

    ISO 27001 or something else? ISAE 3000, ISAE 3402, SOC 2, Cyber Essentials and ISO 27701

    Customers do not always ask for ISO 27001. Some ask for an assurance report, some for a badge, and the difference is not cosmetic.

    Evidence Type Issued by Validity Typically used when
    ISO 27001 Certification of a management system Accredited certification body 3 years with annual surveillance International tenders, supplier requirements, NIS2 backbone
    ISAE 3000 and ISAE 3402 Auditor's assurance report on controls over a period (type 2) or at a point in time (type 1) Registered auditor Usually covers 12 months, renewed annually Processors reporting to controllers (3000), outsourced financial processes (3402)
    SOC 2 US assurance report against the AICPA Trust Services Criteria CPA firm Report period, usually 12 months US customers and SaaS sales into the US
    Cyber Essentials and Cyber Essentials Plus UK government-backed scheme covering five technical control areas, run by the NCSC through IASME IASME certification bodies 12 months UK public sector contracts, small suppliers, a baseline rather than a management system
    ISO/IEC 27701:2025 Privacy information management system (PIMS). Since 14 October 2025 a standalone standard, no longer only an extension of 27001 Certification body, transition rules still being set by accreditation bodies 3 years Organisations that want to evidence GDPR work on top of security work

    The most important distinction is between certification and assurance. ISO 27001 certifies the system going forward, while an ISAE 3000 report or ISAE 3402 report documents that specific controls operated over a specific period. Many European processors hold both, because customers ask for ISO 27001 in the tender and for ISAE 3000 in the annual audit. The controls can largely be reused if they are documented in one place. For Danish readers, our comparison of the D-seal and ISO 27001 covers the Danish national label as well.

    Who needs ISO 27001 certification, and who can settle for compliance?

    Go for certification when someone outside the organisation needs to trust your security without auditing you themselves. That is the case when customers or tenders name the standard, when you supply NIS2-covered entities that must manage their supply chain under Article 21(2)(d), when you sell software or hosting across borders, or when you want an external discipline that keeps the ISMS alive year after year.

    Settle for compliance, meaning conformity without a certificate, when the evidence is only needed internally, when a regulator expects you to follow the standard but does not require certification, or when you are building the ISMS as your NIS2 framework and intend to certify only when customers ask. The work is the same. What you save is the audit fee and the external discipline. What you lose is the proof.

    A middle path many organisations take is to build to the standard from day one and have an external party run the clause 9.2 internal audit. You are then ready for Stage 1 the day a tender demands it, without having paid for the certificate in the years before.

    How .legal supports your ISO 27001 compliance

    The hard part of ISO 27001 is not writing the documents once. It is keeping the cycle running every year so that the risk assessment, the SoA, the internal audit and the management review are current when the auditor arrives. That is what .legal is built for.

    In our information security management module you work directly in the ISO/IEC 27001:2022 structure: you document scope, policies and roles, run risk assessments with one shared method, and take a position on all 93 Annex A controls in a Statement of Applicability with justifications and implementation status. Policy management handles versioning and staff sign-off for clause 7.5, and the Frameworks module maps the same controls to NIS2 Article 21, GDPR Article 32 and ISAE 3000, so one documented control counts in every framework it satisfies. Compliance task management keeps internal audits, management reviews and risk reviews on the calendar with owners and deadlines, and the full history is ready as an audit trail for Stage 1, Stage 2 and surveillance audits.

    The platform does not perform the audit and it does not make you certified. It makes sure the work you put into the ISMS is documented, reusable and easy to find when it has to be shown. Book a demo and see the ISO 27001 framework in the platform.

    FAQs: ISO 27001 Compliance & Certification

    What is the difference between ISO 27001 compliance and ISO 27001 certification?

    Compliance means your ISMS meets the requirements of ISO/IEC 27001:2022 and you have taken a position on Annex A in a Statement of Applicability. You can document that yourself. Certification means an accredited certification body has confirmed it through a two-stage audit and issued a certificate valid for three years within a defined scope. The work is the same. The difference is whether an independent party has checked it.

    What are the ISO 27001 compliance requirements in brief?

    Clauses 4 to 10 of ISO/IEC 27001:2022 are all mandatory: context and scope, leadership and policy, risk assessment and treatment with a Statement of Applicability, resources and awareness, operation, internal audit and management review, and corrective action. Annex A lists 93 reference controls in four themes that you must take a documented position on. Meeting the clauses and justifying your Annex A choices is what ISO 27001 compliance means.

    Are the Annex A controls mandatory?

    No, but taking a position on them is. Clause 6.1.3 requires you to compare the controls your risk assessment points to with the 93 controls in Annex A and, in a Statement of Applicability, justify which are included, which are excluded and why. A control can be excluded with a sound justification. Clauses 4 to 10, on the other hand, cannot be excluded.

    Who can issue an ISO 27001 certificate in the UK?

    Any company may legally issue a certificate, but only certificates from a certification body accredited against ISO/IEC 17021-1 and ISO/IEC 27006-1 are recognised internationally. In the UK the accreditation body is UKAS, and the NCSC advises checking for UKAS accreditation for exactly this reason. The accreditation mark appears on the certificate, and certificates from accredited bodies can be looked up in the IAF CertSearch database.

    What does an ISO 27001 certificate say, and what does scope mean?

    The certificate names the organisation, the standard (ISO/IEC 27001:2022), the certification body with its accreditation mark, the validity period and a scope statement describing exactly which activities, locations and systems the ISMS covers. Scope decides what the certificate proves. A certificate for the operation of a customer portal says nothing about the rest of the company, so read the scope statement before accepting the certificate as evidence.

    How long does it take to get ISO 27001 certification?

    For most mid-sized organisations starting from scratch, 6 to 18 months from decision to certificate is realistic, covering gap analysis, implementation, at least one internal audit and management review, and the two-stage external audit. Organisations with existing documentation and a mature security culture can be faster. The certificate is then valid for three years with a surveillance audit each year and recertification before it expires.

    Can you reduce the cost of ISO 27001 certification by choosing a smaller scope?

    Yes. Audit days are set by the number of people working within the scope, using the indicative table in ISO/IEC 27006-1. Fewer people in scope means fewer audit days in the initial certification, the surveillance audits and the recertification. The scope must still match what your customers are actually buying. A scope that leaves out the very service a customer is worried about produces a certificate that customer cannot use.

    Does ISO 27001 certification make us GDPR or NIS2 compliant?

    No. GDPR Article 32 requires appropriate measures based on risk, and NIS2 Article 21(2) requires ten minimum measures. ISO 27001 covers both with controls and a risk method, but neither law requires certification, and the certificate does not cover lawful basis, data subject rights, the record of processing, registration with the competent authority or incident reporting within 24 and 72 hours. The standard is the framework for the security work, not the proof of legal compliance.

    What is the difference between ISO 27001 and ISO 27002?

    ISO/IEC 27001 contains the requirements for the management system and the list of the 93 reference controls in Annex A. It is the standard you can be certified against. ISO/IEC 27002:2022 is the guidance document that describes purpose, implementation and attributes for each of the 93 controls. It is not certifiable. Put simply, 27001 says what and 27002 says how.

    What happens to the certificate if we suffer a security breach?

    A breach does not cancel the certificate by itself. The standard promises managed risk, not zero risk. At the next surveillance audit, or in a special audit, the certification body will check that the incident was handled through your incident process, that the root cause was analysed and that corrective actions were completed under clause 10.2. If that has not happened, the certificate can be suspended or withdrawn.

    Still unsure?

    Ask Johannes directly, he runs most demos personally

    Book him here
    Processing activities

    .legal compliance platform

    Achieve ISO 27001 with .legal

    Streamline your ISO 27001 certification journey with the .legal compliance platform. Manage controls, track documentation, and prepare for audits systematically.
    • Map and track all Annex A controls
    • Manage risk assessments and treatment plans
    • Document policies and procedures
    • Prepare for certification audits
    • Monitor continuous compliance
    +400 companies use .legal
    Region Sjælland
    Aarhus Universitet
    aj_vaccines_logo
    Realdania
    Right People
    IO Gates
    PLO
    Finans Danmark
    geia-food
    Evida
    Klasselotteriet
    NRGI1
    BLUE WATER SHIPPING
    Karnov
    Ingvard Christensen
    VP Securities
    AH Industries
    Lægeforeningen
    InMobile
    AK Nygart
    DEIF
    DMJX
    Axel logo
    qUINT Logo
    KAUFMANN (1)
    SMILfonden-logo
    kurhotel_skodsborg
    nemlig.com
    Molecule Consultancy
    Novicell