Risk & Leadership

Do You Actually Need ISO 27001 Certification?

A customer asks whether you are certified. It is a reasonable question, and it is often not the question they mean. Working out what they actually require can be the difference between a three-week response and a nine-month programme.

Part of the seriesSecurity Guidance, Applied

Sometimes yes. Often, not yet. ISO/IEC 27001 certification is a formal, audited commitment that runs continuously once you start it. Before committing, it is worth establishing what your customer has actually written down — because a meaningful share of requests that arrive as "are you ISO 27001 certified?" are satisfied by evidence that does not require certification at all.

What ISO 27001 is, and what it is not

ISO/IEC 27001:2022 is the international standard for an information security management system — an ISMS. The 2022 revision is the current edition, superseding 2013. It is published jointly by the International Organization for Standardization and the International Electrotechnical Commission, and it is a purchased standard rather than freely available guidance.

Two distinctions matter more than anything else in this article.

A management system is not a control checklist. The standard's central requirement is that you run a system — identifying risks, deciding treatments, assigning ownership, auditing yourself, and reviewing all of it at management level on an ongoing basis. Controls sit inside that system; they are not the point of it.

ISO does not certify anyone. Certification is issued by an independent certification body, ideally one accredited for the purpose. When a customer asks whether you are "ISO certified," they are asking whether an accredited third party has audited you and issued a certificate with a defined scope.

What your customer usually means

"Are you ISO 27001 certified?" arrives from several very different places, and the right response differs in each.

  • A procurement checkbox. Someone assembling a supplier questionnaire included a standard field. Nobody has decided it is mandatory. This is the most common case, and often the most easily resolved.
  • A contractual requirement. The customer's own obligations — regulatory, or flowed down from their customers — genuinely require certified suppliers. Here the answer is binding and alternatives will not help.
  • A proxy for "can we trust you with our data?" The customer wants assurance and reached for the most recognisable name. Other evidence frequently satisfies them.
  • A risk-team escalation. Your engagement crossed a threshold — data volume, system access, criticality — and triggered a formal supplier review. Certification is one route through; it is rarely the only one.

The way to tell them apart costs nothing: ask for the requirement in writing. "Could you point me to the clause or policy that sets this out?" is a normal procurement question. The answer usually reveals which of the four you are dealing with within a day.

What often satisfies the requirement instead

Where certification is not contractually mandated, these are commonly accepted — individually or in combination. None is a substitute for certification where certification is genuinely required.

AlternativeWhat it demonstratesTypical effort
Completed security questionnaireDirect answers to what the customer actually askedDays
Independent security assessment or penetration test reportThird-party evidence about real systems, not documentationWeeks
Documented control evidenceThat named safeguards exist and are operatingDays to weeks
Contractual security scheduleBinding commitments, with remedies if breachedDays, with legal input
Alignment statementThat you follow a recognised framework without certifying against itWeeks
SOC 2 reportAudited controls under a different regime, common with North American buyersMonths

An honest alignment statement is worth more than it sounds, provided it is accurate. Saying "we follow the Canadian Centre for Cyber Security baseline and can evidence each control" is a real answer. Saying "we are ISO 27001 aligned" without being able to show what that means is not, and experienced reviewers will test it.

What certification actually commits you to

Certification is frequently costed as a project. It behaves like an operating commitment.

  • A management system you run continuously. Risk assessments, documented decisions, internal audits and management reviews, on a recurring cycle — not once for the auditor.
  • An initial audit in two stages. A review of your documented system, then an audit of whether you actually operate it.
  • Ongoing surveillance. Certificates run on a multi-year cycle with periodic surveillance audits and a recertification at the end. Lapse, and you are answering a harder question than before you started.
  • A defined scope. You certify a scope — particular services, locations or systems — not automatically the whole organization. A certificate whose scope excludes the service your customer buys can raise more questions than it settles.
  • Real internal effort. Audit fees are frequently the smaller cost. The larger one is people writing, operating and evidencing the system.

For a smaller organization starting without an ISMS, a first certification is commonly a programme of several months to a year rather than a quarter. That is not an argument against it. It is an argument against starting it in response to one customer email without checking what that email required.

A way to decide

Four questions, in this order:

  1. What has the customer written down? Get the requirement in its actual wording before responding to a summary of it.
  2. Is certified the only acceptable answer? Ask directly whether alternative evidence would satisfy the review. Many buyers say yes.
  3. What closes this deal? Identify the smallest honest evidence that resolves the immediate requirement.
  4. What serves the next five deals? If ISO 27001 keeps appearing in your pipeline, the calculation changes — you are no longer buying a certificate for one customer, you are removing a recurring obstacle.

Questions three and four often have different answers, and that is the useful tension. Meet the immediate requirement with proportionate evidence, then decide about certification against your pipeline rather than against one conversation.

When certification is the right answer

There are clear cases where the analysis is short:

  • A contract or regulator genuinely requires a certified supplier.
  • ISO 27001 appears in most of your qualified opportunities, and its absence is costing you deals you would otherwise win.
  • You sell into sectors or regions where it functions as an entry requirement rather than a differentiator.
  • You already operate most of a management system informally, and certification would formalise something real rather than construct something new.

That last case is more common than organizations expect, and it materially changes the cost. Certification is far cheaper when it documents how you already work than when it invents a system for an audit.

Where to start this week

Ask for the requirement in writing, and ask whether alternative evidence is acceptable. Both are ordinary procurement questions, neither signals weakness, and together they usually tell you within a few days whether you are facing a checkbox or a commitment.

Then decide about certification with your pipeline in view — not with one customer email in front of you.

Primary sources

  1. International Organization for Standardization and International Electrotechnical Commission, ISO/IEC 27001:2022 Information security management systems. A purchased standard; its text is not reproduced here.
  2. Canadian Centre for Cyber Security, Baseline cyber security controls for small and medium organizations, V1.2 — a freely published alternative for organizations establishing a control baseline.

Source status last checked 20 August 2026. ISO/IEC 27001:2022 is the current edition, superseding 2013; there has never been a 2002 edition. This article is educational, does not reproduce licensed standard text, and does not provide legal, regulatory, compliance or certification advice.

Not sure what your customer actually requires?

A ByteDefender risk assessment establishes what evidence you can honestly provide today, what a customer review would find, and whether certification is proportionate to your pipeline.

Explore risk assessment