Sometimes yes. Often, not yet. ISO/IEC 27001 certification is a formal, audited commitment that runs continuously once you start it. Before committing, it is worth establishing what your customer has actually written down — because a meaningful share of requests that arrive as "are you ISO 27001 certified?" are satisfied by evidence that does not require certification at all.
What ISO 27001 is, and what it is not
ISO/IEC 27001:2022 is the international standard for an information security management system — an ISMS. The 2022 revision is the current edition, superseding 2013. It is published jointly by the International Organization for Standardization and the International Electrotechnical Commission, and it is a purchased standard rather than freely available guidance.
Two distinctions matter more than anything else in this article.
A management system is not a control checklist. The standard's central requirement is that you run a system — identifying risks, deciding treatments, assigning ownership, auditing yourself, and reviewing all of it at management level on an ongoing basis. Controls sit inside that system; they are not the point of it.
ISO does not certify anyone. Certification is issued by an independent certification body, ideally one accredited for the purpose. When a customer asks whether you are "ISO certified," they are asking whether an accredited third party has audited you and issued a certificate with a defined scope.
What your customer usually means
"Are you ISO 27001 certified?" arrives from several very different places, and the right response differs in each.
- A procurement checkbox. Someone assembling a supplier questionnaire included a standard field. Nobody has decided it is mandatory. This is the most common case, and often the most easily resolved.
- A contractual requirement. The customer's own obligations — regulatory, or flowed down from their customers — genuinely require certified suppliers. Here the answer is binding and alternatives will not help.
- A proxy for "can we trust you with our data?" The customer wants assurance and reached for the most recognisable name. Other evidence frequently satisfies them.
- A risk-team escalation. Your engagement crossed a threshold — data volume, system access, criticality — and triggered a formal supplier review. Certification is one route through; it is rarely the only one.
The way to tell them apart costs nothing: ask for the requirement in writing. "Could you point me to the clause or policy that sets this out?" is a normal procurement question. The answer usually reveals which of the four you are dealing with within a day.
What often satisfies the requirement instead
Where certification is not contractually mandated, these are commonly accepted — individually or in combination. None is a substitute for certification where certification is genuinely required.
| Alternative | What it demonstrates | Typical effort |
|---|---|---|
| Completed security questionnaire | Direct answers to what the customer actually asked | Days |
| Independent security assessment or penetration test report | Third-party evidence about real systems, not documentation | Weeks |
| Documented control evidence | That named safeguards exist and are operating | Days to weeks |
| Contractual security schedule | Binding commitments, with remedies if breached | Days, with legal input |
| Alignment statement | That you follow a recognised framework without certifying against it | Weeks |
| SOC 2 report | Audited controls under a different regime, common with North American buyers | Months |
An honest alignment statement is worth more than it sounds, provided it is accurate. Saying "we follow the Canadian Centre for Cyber Security baseline and can evidence each control" is a real answer. Saying "we are ISO 27001 aligned" without being able to show what that means is not, and experienced reviewers will test it.
What certification actually commits you to
Certification is frequently costed as a project. It behaves like an operating commitment.
- A management system you run continuously. Risk assessments, documented decisions, internal audits and management reviews, on a recurring cycle — not once for the auditor.
- An initial audit in two stages. A review of your documented system, then an audit of whether you actually operate it.
- Ongoing surveillance. Certificates run on a multi-year cycle with periodic surveillance audits and a recertification at the end. Lapse, and you are answering a harder question than before you started.
- A defined scope. You certify a scope — particular services, locations or systems — not automatically the whole organization. A certificate whose scope excludes the service your customer buys can raise more questions than it settles.
- Real internal effort. Audit fees are frequently the smaller cost. The larger one is people writing, operating and evidencing the system.
For a smaller organization starting without an ISMS, a first certification is commonly a programme of several months to a year rather than a quarter. That is not an argument against it. It is an argument against starting it in response to one customer email without checking what that email required.
A way to decide
Four questions, in this order:
- What has the customer written down? Get the requirement in its actual wording before responding to a summary of it.
- Is certified the only acceptable answer? Ask directly whether alternative evidence would satisfy the review. Many buyers say yes.
- What closes this deal? Identify the smallest honest evidence that resolves the immediate requirement.
- What serves the next five deals? If ISO 27001 keeps appearing in your pipeline, the calculation changes — you are no longer buying a certificate for one customer, you are removing a recurring obstacle.
Questions three and four often have different answers, and that is the useful tension. Meet the immediate requirement with proportionate evidence, then decide about certification against your pipeline rather than against one conversation.
When certification is the right answer
There are clear cases where the analysis is short:
- A contract or regulator genuinely requires a certified supplier.
- ISO 27001 appears in most of your qualified opportunities, and its absence is costing you deals you would otherwise win.
- You sell into sectors or regions where it functions as an entry requirement rather than a differentiator.
- You already operate most of a management system informally, and certification would formalise something real rather than construct something new.
That last case is more common than organizations expect, and it materially changes the cost. Certification is far cheaper when it documents how you already work than when it invents a system for an audit.
Where to start this week
Ask for the requirement in writing, and ask whether alternative evidence is acceptable. Both are ordinary procurement questions, neither signals weakness, and together they usually tell you within a few days whether you are facing a checkbox or a commitment.
Then decide about certification with your pipeline in view — not with one customer email in front of you.
Primary sources
- International Organization for Standardization and International Electrotechnical Commission, ISO/IEC 27001:2022 Information security management systems. A purchased standard; its text is not reproduced here.
- Canadian Centre for Cyber Security, Baseline cyber security controls for small and medium organizations, V1.2 — a freely published alternative for organizations establishing a control baseline.
Source status last checked 20 August 2026. ISO/IEC 27001:2022 is the current edition, superseding 2013; there has never been a 2002 edition. This article is educational, does not reproduce licensed standard text, and does not provide legal, regulatory, compliance or certification advice.