ISO 27001
International information security certification
What it is
ISO 27001 is an international certification for how you manage information security. Instead of auditing individual controls the way SOC 2 does, it certifies a management system: how you assess risk, choose controls and keep improving them. An accredited certification body issues it on a three-year cycle, with a smaller surveillance audit each year.
It is the certification buyers in Europe and much of Asia expect. Many global enterprises accept either ISO 27001 or SOC 2, and some insist on ISO.
What it takes
About 8–14 engineer-weeks to build in-house, or 4–8 using Vanta, Drata or Secureframe.
Typically four to nine months to certification, depending on how much already exists.
Answer these first
- Sales: Do our buyers require ISO specifically, or would SOC 2 do?
- Engineering: What is the scope: the product, or the whole company?
- Security: Do we have a documented risk assessment and treatment plan?
- Security: Who is the named owner of the management system?
- Finance: Can SOC 2 and ISO evidence run through one platform?
- Legal: Which accredited certification body will we use?
This page works best with JavaScript on. Every answer also has its own address, like /what/scim.