IT Glossary
What is ISO 27001?
ISO 27001 is the international standard defining the requirements for an information security management system, certifiable through independent audit.
The moment a company starts selling to larger organisations, a security questionnaire arrives — forty pages, often more, asking about access control, supplier management, incident response and business continuity. ISO 27001 exists partly so that conversation can be replaced by a certificate. The standard specifies how an organisation builds and runs an information security management system: define the scope, identify the risks to your information, decide what to do about each, implement controls chosen from a defined catalogue, document the decisions, train the people, measure whether it works, and improve it on a cycle. An accredited external auditor then examines the evidence and issues a certificate valid for three years with annual surveillance. Note what it certifies. Not that you cannot be breached, and not that any specific technology is in place, but that security is managed deliberately, with named owners and evidence, rather than resting on the diligence of one competent administrator. For companies selling software, hosting or nearshore services into Europe, that distinction has become a commercial qualification rather than a badge.
Let’s talk about your project
Message us on WhatsApp or send an email — you talk directly to a developer.
office@northdan.com · +40 752 070 247
Why it matters for your business
An open door to enterprise contracts
Certification answers the supplier security assessment in one document, removing weeks of questionnaires from every large deal.
Security that is organised, not heroic
Risks, owners and reviews are defined, so protection stops depending on one experienced person remembering to check things.
Incidents that are rarer and cheaper
Documented response and continuity procedures shorten outages and reduce the losses that follow from improvising under pressure.
Frequently asked questions
How long does ISO 27001 certification take and what does it cost?
For a small or mid-sized company, six to twelve months from a standing start, and the audit itself is the smaller expense. Budget for consultancy if you have no internal expertise, the two-stage certification audit priced by headcount and scope, annual surveillance visits, and — the real cost — internal time to write, implement and evidence the controls. Narrow the scope and both figures fall sharply.
Is ISO 27001 required by law?
Not in itself; it is a voluntary standard. It becomes effectively compulsory through contracts, since large customers, public tenders and some regulated sectors demand it from suppliers. It also aligns closely with what regulations such as GDPR and the NIS2 directive expect in terms of organisational measures, which is why certified companies find those obligations considerably easier to demonstrate.
How does ISO 27001 differ from an ordinary security audit?
A security audit or penetration test is a snapshot: here are the weaknesses found this week. ISO 27001 assesses the system that keeps finding and fixing weaknesses continuously. One tells you the state of your defences today, the other tells a customer that management, risk assessment and improvement exist as a process. Serious organisations run both, for different reasons.
Let’s talk about your project
Message us on WhatsApp or send an email — you talk directly to a developer.
office@northdan.com · +40 752 070 247