The short version
ISO 27001 is the international standard for running an information security management system, or ISMS. An accredited body certifies you after a two-stage audit. The certificate lasts three years. A check-in audit runs each year.
Most first-time projects run six phases: scope, risk, design, rollout, internal audit, then the external audit. The work that decides the outcome happens in phases 2 and 4, not in the audit itself.
Buyers ask for it by name now. Big buyers, government departments, and banks, hospitals, and insurers treat it as the price of entry. If you sell software or handle other people’s data, you will meet it in a security questionnaire sooner or later.
Here is what the standard asks for, what the process looks like from scoping to certificate, and where audits go wrong. Want the clause-level detail? Our guide on how to design and implement an ISO 27001 ISMS goes deeper.
Sources: ISO Survey 2024 · ISO/IEC 27001:2022 · DNV audit data
What ISO 27001 is
ISO/IEC 27001 sets the rules for building and running an ISMS. The ISO and the IEC publish it. The current version is ISO/IEC 27001:2022.
An ISMS is not a tool you buy. It is the set of policies, processes, and controls you use to protect information. It also covers the routine that keeps them working. The standard cares as much about the routine as the controls.
Four ideas hold the whole thing up
- Risk drives everything. ISO 27001 hands you no checklist. You find your own risks and pick controls that match them.
- Annex A is a reference, not a shopping list. It holds 93 controls in four themes: Organizational 37, People 8, Physical 14, Technological 34.
- You write down what you do. Scope, policy, risk method, Statement of Applicability, treatment plan, and the records that prove the controls run.
- It never finishes. The standard runs on Plan-Do-Check-Act. Certification starts the cycle. It does not close it.
How it differs from SOC 2
Both cover information security. They work in different ways.
ISO 27001 gives you a certificate from an accredited body. Buyers worldwide accept it. SOC 2 gives you an audit report from a CPA firm. It is mainly a North American ask. ISO 27001 audits your management system. SOC 2 tests your controls against the Trust Services Criteria over a window of time.
Plenty of Canadian firms end up doing both. The controls overlap by a wide margin, so the second one costs far less than the first. Start with what SOC 2 is and SOC 2 Type 1 vs Type 2 if that is your path.
The 2022 version, and why the old one is gone
ISO 27001:2022 replaced the 2013 version. The transition window closed on 31 October 2025. Certificates against the 2013 version are no longer valid.
Check your certificate
If you hold a certificate and it names ISO/IEC 27001:2013, it expired with the transition window. A buyer who checks the register will see that. Talk to your certification body about a fresh audit.
The 2022 version cut the control count from 114 to 93 and regrouped them into four themes. It added eleven controls that did not exist in 2013, covering threat intelligence, cloud services, data leakage prevention, secure coding, and monitoring.
One more change landed later. Amendment 1:2024, published in February 2024, added climate change to Clauses 4.1 and 4.2. You have to consider whether it is a relevant issue for your ISMS. Your answer can be no, but silence is a finding. Our breakdown of ISO 27001 vs ISO 27002 explains where the control guidance sits.
Why teams get certified
Six reasons come up again and again.
- Buyers demand it. Enterprise buyers, government tenders, and banks, hospitals, and insurers name the certificate as a condition of the contract.
- It supports the law you live under. The controls map onto PIPEDA, PHIPA, Quebec Law 25, GDPR, HIPAA, NIS2, and DORA. The certificate proves none of them on its own, but it gives you the evidence base.
- It finds risk you did not know about. The risk assessment forces a full sweep of assets, threats, and third parties.
- It shortens sales cycles. One certificate answers a hundred questionnaire lines. Security review stops being the thing that stalls the deal.
- It tidies the operation. Building an ISMS surfaces unclear ownership, undocumented processes, and duplicated tools.
- Insurers notice. Cyber insurers price certified firms on better terms. Some ask for evidence of a management system before they quote.
There is a harder driver behind all of this. The average breach cost US$4.99 million in 2026, up 12% in a year. In Canada it hit CA$7.11 million, a record (IBM).
“AI has dramatically lowered the barrier for cybercriminals. Attackers can now execute attacks in minutes rather than days with advanced frontier models.”
Mark HughesGlobal Managing Partner, Cybersecurity Services, IBM
Phases 1 to 3: scope it, assess it, design it
Most first-time projects run six phases. The first three build the system on paper.
Scoping and gap analysis
Goal: draw the boundary, then find out where you stand.
Decide which business units, sites, systems, and data sit inside the ISMS. Scope too wide and the project stalls. Scope too narrow and buyers dismiss the certificate. Most SaaS teams scope to the product, the platform that runs it, and the teams that touch it.
Then run a gap analysis against Clauses 4 to 10 and the Annex A controls. You want a ranked list of what is missing, not a score.
Name your interested parties too. Customers, regulators, staff, and partners all have security expectations, and Clause 4.2 asks you to record them.
Risk assessment and treatment
Goal: find your risks, score them, and decide what to do about each one.
Write the method first. How you spot risks, how you score likelihood and impact, and where your acceptance line sits. Then work through your assets, threats, and weak points.
For each risk above the line, pick a treatment: reduce it, share it, avoid it, or accept it. That becomes your Risk Treatment Plan.
Then build the Statement of Applicability. It lists all 93 Annex A controls and says which you use, which you drop, and why. Every control you keep points back to a risk.
This is where audits are won and lost
DNV looked at more than 1,700 certified firms. 27% failed to meet Clause 6.1.2, the risk assessment clause. It is the single most common serious finding. The usual causes are a method nobody wrote down and scales with no definitions behind them.
Our guide to the ISO 27001 risk assessment walks the four steps in detail.
ISMS design and documents
Goal: write the system down, in a form your team will use.
The standard names some documents you must have. The scope. The information security policy. The risk method. The SoA. The treatment plan. Your objectives. And proof that the people running controls know what they are doing.
Others support them. Acceptable use, access control, supplier security, incident response, business continuity, secure development.
Then assign owners. An ISMS owner, a risk owner per risk, a control owner per control, and someone independent to run internal audit.
What good looks like
Short policies that match how you work. Auditors compare the document to reality and write up the gap. A ten-page access control policy you ignore is worse than a one-page policy you follow.
Phases 4 to 6: run it, check it, prove it
The last three phases turn the paper system into something an auditor can test.
Implementation
Goal: put the controls into daily use and start keeping records.
Technical controls come first for most teams. Access management, encryption, logging, endpoint protection, backup and restore, network segmentation, vulnerability management.
People and process controls run alongside. Security training, supplier reviews, onboarding and offboarding, incident drills.
Then collect evidence from day one. Access review records, training completions, scan results, change tickets, incident logs. Auditors do not ask whether a control exists. They ask you to show it running over months.
The gap that surprises people
You need a track record before Stage 2, not just a working control. Most certification bodies want to see at least two to three months of evidence. Start collecting the day a control goes live.
Internal audit and management review
Goal: find your own problems before the external auditor does.
Internal audit checks the ISMS against the standard and against your own documents. The auditor has to be independent of the work under review. A small firm can use a trained employee from another team or bring someone in.
Findings need root cause analysis and corrective action, not a patch. An auditor who sees the same finding twice will ask why the first fix did not hold.
Management review is a separate Clause 9.3 requirement. Leadership reviews audit results, risk changes, objectives, and performance, then records decisions. Skipping it is an easy finding to write.
The certification audit
Goal: get the certificate from an accredited certification body.
Stage 1: readiness
The auditor reads your documents and decides whether you are ready for Stage 2. Gaps get raised here so you can close them. Treat it as a rehearsal, not a formality.
Stage 2: the real audit
The auditor tests whether the ISMS runs. Interviews, walkthroughs, and evidence sampling. Findings come back as major or minor nonconformities, plus observations.
After
Clear the majors and the body issues your certificate. It runs three years. A surveillance audit checks a slice of the system each year. A full recertification audit comes at the end of year three.
Getting certified in Canada
The standard is the same everywhere. Who signs your certificate is not.
Pick an accredited body
In Canada, the Standards Council of Canada accredits the bodies that issue ISO 27001 certificates. To qualify, a certification body has to meet ISO/IEC 17021-1 first. The SCC signs the IAF Multilateral Recognition Arrangement. That is what makes a Canadian certificate count abroad.
“Certification to ISO/IEC 27001 by SCC-accredited certification bodies is widely accepted internationally.”
Standards Council of CanadaInformation Security Management Systems accreditation program
Check the accreditation before you sign. An unaccredited certificate costs less and buys you nothing. The buyer who asked for it will check the register.
Canadian data residency compliance
Your scope and risk work have to name the law that applies to you. PIPEDA at the federal level. PHIPA for Ontario health data. Quebec Law 25. PIPA in Alberta and B.C. Financial services add OSFI B-13 and B-10, which push third-party and technology risk straight into the register.
Where the data sits is a risk line, not a footnote. Buyers in health, government, and finance ask about residency before they ask about the certificate. Treat it as a named risk with a named treatment, and show it again in the SoA under the transfer and supplier controls.
Nank.ai runs SOC 2 and ISO 27001 in Toronto, Ontario, and across Canada, and holds client data in the client’s own country.
What separates a pass from a stall
Eight things decide it.
- Leadership means it. Clause 5 asks for management commitment, and an auditor can tell within an hour whether it exists. A project handed to IT alone shows up in the interviews.
- The scope is honest. Wide enough to cover what buyers care about. Narrow enough to finish.
- The risk assessment holds up. Real assets, real threats, defined scales, named owners. This is the 27% clause.
- Documents match reality. Write what you do. Then do what you wrote.
- Evidence collects itself. Manual screenshot hunts do not survive year two. Pull records from the systems that already produce them.
- Staff are part of it. Training that lands, and a reporting path people use without fear.
- You plan past the certificate. Surveillance audits come every year. A system that decays after the badge arrives fails the first one.
- Your partners build your capability. A consultant who keeps the knowledge is a renewal you cannot escape.
Where a compliance service helps
Most of the effort in a first certification is not judgment. It is collection, mapping, and chasing. That part responds well to automation.
| The problem | What handles it |
|---|---|
| You do not know where to start | Gap analysis against ISO 27001:2022, returned as a ranked roadmap rather than a score |
| The risk assessment stalls | A written method, defined scales, and control mapping you can defend in an audit |
| Documents pile up | Policy templates tailored to your scope, not generic boilerplate |
| Evidence is scattered | Automated collection from your cloud, identity, and ticketing systems |
| Nobody can run internal audit | An independent auditor, or training for someone on your team |
| Stage 2 is coming | A readiness review that runs the audit before the auditor does |
| Year two arrives | Continuous control monitoring and drift alerts between audits |
Nank.ai delivers this as compliance as a service. A compliance manager runs the project with you. Our agentic AI compliance platform handles evidence collection, control monitoring, and drift alerts. Most clients reach audit-ready in about three months.
Frequently asked questions
How long does ISO 27001 certification take?
Three to twelve months for most first-timers, depending on scope and starting point. The floor is set by evidence, not effort. Certification bodies want to see controls running for two to three months before Stage 2. You cannot compress past that.
How much does ISO 27001 certification cost?
Three separate costs. The certification body charges audit-day fees, which scale with headcount and scope. Then there is the tooling and remediation work to close gaps. Then internal time, which is the largest and the one teams forget. Ask certification bodies for the three-year cost, not the Stage 2 quote, because surveillance audits recur.
Is ISO 27001 certification required?
No law requires it. Contracts do. Big buyers, government tenders, and banks, hospitals, and insurers name it as a condition, so for many firms it is required in practice.
What is the difference between ISO 27001 and ISO 27002?
ISO 27001 holds the requirements you certify against, and Annex A lists the 93 controls by name. ISO 27002 explains how to implement those controls. You certify to 27001. You read 27002 for the detail. See our full comparison.
How long is an ISO 27001 certificate valid?
Three years. A surveillance audit checks part of the system in each of the next two years. A full recertification audit runs at the end of the cycle. Miss a surveillance audit and the body can suspend or withdraw the certificate.
Do you need ISO 27001 if you already have SOC 2?
It depends on who is asking. SOC 2 satisfies most North American buyers. ISO 27001 travels better in Europe, the UK, and Asia, and it is a certificate rather than a report. The control overlap is large, so adding the second framework costs far less than the first.
Can a small firm get ISO 27001 certified?
Yes. The standard scales with the risk, not the headcount. A ten-person SaaS firm can certify with a tight scope and proportionate documents. Audit-day fees track your size, so a small scope means a smaller bill.
Key takeaways
- ISO 27001 certifies a management system, not a product. Risk drives the control selection.
- ISO 27001:2013 certificates expired with the transition window on 31 October 2025. Check which version yours names.
- The 2022 version holds 93 controls in four themes. Amendment 1:2024 added climate change to Clauses 4.1 and 4.2.
- Six phases: scope, risk, design, rollout, internal audit, certification audit. Phase 2 decides most outcomes.
- 27% of certified firms fail Clause 6.1.2, the risk assessment clause. It is the most common serious finding.
- Use an SCC-accredited certification body so buyers outside Canada accept the certificate.
- The certificate runs three years, with a surveillance audit each year.
Ready to start on ISO 27001?
Talk to us about SOC 2 and ISO 27001 in Toronto and across Canada. Audit-ready in about three months, with your data held in your own country.
Hunter Zhu Founder of Nank.ai, a Toronto firm that takes Canadian firms to ISO 27001, SOC 2, and ISO 42001. Connect on LinkedIn