Skip to content

ISO 27001

ISO/IEC 27001 is the international standard for an information security management system: the policies, controls and processes an organisation runs to manage security risk, audited by an accredited certification body. Certification says a system is in place and operating; it does not by itself say how secure any particular product is.

First published in 2005 and revised in 2022, the standard certifies a management system, not a piece of software.

Why it matters when the plan changes

Procurement teams ask for the certificate because it is the shortest available answer to a long question. It is a reasonable proxy and it is a proxy: an organisation can be certified and still ship a product with a specific weakness, and an uncertified organisation can run tight security. The standard has evolved since it was first published in 2005 and revised in 2022, so a certificate's age says something about which version was audited. Reading the statement of applicability tells you what was actually in scope.

The tension for a young supplier is timing. Certification takes months and costs money that early companies spend on the product. An independent security review with published findings is a different kind of evidence, point-in-time rather than continuous, and honest suppliers say which of the two they have rather than letting one be mistaken for the other. Under GDPR Article 32, the underlying obligation is measures appropriate to the risk, and certification helps demonstrate that without being compliance itself.

In practice

A security questionnaire asks for ISO 27001 certification. A supplier answers with a penetration test report and an independent code review that closed with no open findings. The procurement lead marks the answer as non-compliant, because the form has a box for a certificate and none for evidence. A conversation about what each document actually shows resolves it, but only because someone asked.

Evidence

What it cannot tell you

Certification confirms that an information security management system operates according to the standard's requirements, within the scope named on the certificate. It does not test any product for specific vulnerabilities and it says nothing about controls outside that scope. Two certified organisations can hold materially different statements of applicability behind the same certificate.

Questions

An accredited body audited the organisation's information security management system and found it conformed to the standard, first published in 2005 and revised in 2022, for the scope stated on the certificate. It proves the system exists and operates; it does not test any specific product for vulnerabilities.

The document listing which of the standard's controls the organisation applies, and why any are excluded. It is where the real content of a certification sits, and it is the thing to ask for, because two certified organisations can have very different statements behind the same certificate.

No, and neither is a substitute for the other. A test finds specific weaknesses in a specific system at a point in time. Certification shows a management system operating over time. A supplier with one and not the other should say which it has, and a buyer should ask for both descriptions.

Article 32 of the General Data Protection Regulation requires controllers and processors to implement technical and organisational measures appropriate to the risk, without mandating any specific standard. Certification is widely accepted as evidence that such measures are in place, so it helps demonstrate compliance without being compliance itself; the processing agreement still has to specify the measures.

What independent evidence exists instead: penetration tests and their findings, code review, logging and monitoring, access control, incident history, and what is planned. A supplier that answers those directly and states the limits of each is giving more information than a certificate alone would.