What is ISO 27001?
ISO/IEC 27001 is an international standard published jointly by the International Organization for Standardization (ISO) and the International Electrotechnical Commission (IEC). It specifies the requirements for establishing, implementing, maintaining and continually improving an Information Security Management System. The goal of the system is to protect the confidentiality, integrity and availability of information through risk management.
The current edition is ISO/IEC 27001:2022. In addition to the management system requirements themselves (clauses 4-10: organisational context, leadership, planning, support, operation, performance evaluation and improvement), the standard includes Annex A with 93 security controls grouped into four themes: organisational, people, physical and technological. In Poland the standard has been adopted by the Polish Committee for Standardization as PN-EN ISO/IEC 27001.
Who is it for?
ISO 27001 certification is voluntary. The standard is not a law, and any organisation can implement it regardless of size or industry. In practice, however, the certificate has become a market standard: corporate customers increasingly require it in contracts and security questionnaires, as do buyers in public tenders.
The most common adopters are technology and SaaS companies, IT and cloud service providers, financial institutions, healthcare companies, and any organisation processing data entrusted by its customers. An implemented ISMS also makes it easier to demonstrate compliance with other requirements, such as NIS 2, DORA, GDPR or TISAX, because a large share of controls overlaps between these frameworks.
What does certification look like?
The certificate is issued by an independent, accredited certification body (for example TÜV, BSI, DNV, Bureau Veritas). The certification audit takes place in two stages. Stage 1 is a documentation and readiness review: the auditor checks the ISMS scope, policy, risk assessment and Statement of Applicability, and highlights areas to fix before the main audit. Stage 2 is the implementation audit: the auditor verifies through sampling and interviews that the system genuinely works in practice.
The certificate is valid for 3 years. During that period the certification body conducts annual surveillance audits (usually two, after the first and the second year) to confirm the system is being maintained. Before the end of the third year a full recertification audit takes place, renewing the certificate for another three-year cycle. Any nonconformities must be resolved through corrective actions within agreed deadlines. Major nonconformities can block the issuance or continuation of the certificate.
How long does it take and what does it cost?
Implementing an ISMS typically takes 3 to 9 months, depending on the size of the organisation, the maturity of existing processes and team availability. A small technology company with well-organised IT can be audit-ready sooner; a multi-site organisation or one starting from scratch needs more time. It is best to schedule the audit only once the system has been running for at least several weeks and has produced its first evidence (training records, access reviews, an internal audit, a management review).
The cost of certification depends primarily on the size of the organisation and the scope of the system. The number of audit days is determined by headcount and the complexity of operations, following the accreditation rules that certification bodies must apply. The total budget includes the certification audit (Stage 1 + Stage 2), annual surveillance audits, optional consultant support and the cost of your own team’s time. For small and medium companies the biggest cost is usually the team’s time rather than the audit fee itself, which is why automating the implementation genuinely lowers the total cost.
How does Guardiso help?
Guardiso guides you through the entire ISO 27001 implementation, from the first self-assessment to the auditor portal, and keeps the system alive after certification.
- All 93 Annex A controls seeded automatically when you enable the standard, with descriptions, implementation statuses and assigned owners.
- Security policies generated from ready-made templates and tailored to your organisation, with versioning and management approval.
- Compliance evidence collected in one place: attachments, recurring tasks and automated evidence from integrations.
- A Statement of Applicability (SoA) built from the control register, with inclusion and exclusion justifications, ready to hand to the auditor.
- A risk register linked to controls, with assessment, treatment plans and residual risk tracking.
- An auditor portal: the auditor gets controlled access to documentation and evidence without files being emailed around.
- Cross-mapping to other standards (NIS 2, DORA, SOC 2, TISAX), so work done for ISO 27001 counts towards the requirements of related frameworks.
