Information Security Management System ISO 27001 certification — deploy your ISMS and achieve certification

We support your organisation from the initial analysis through to certification audit preparation: ISMS scope, risk analysis, risk treatment, statement of applicability, security policies, control implementation, internal audit and corrective actions.

The final certification is issued by an independent certification body. ISO itself states that it does not perform certifications and does not issue certificates.

Can be articulated with your NIS2 and GDPR programmes.

ISO 27001 Lead Auditor certified experts
Risk analysis adapted to your context
Helps structure your security governance and evidence of control

What you get

At the end of the certification process

An ISO 27001 certified ISMS, your IT security under control, risks documented and managed — international recognition of your security level.

Risks Analysed
93 controls Applicability assessed
ISMS Auditable

A compliant ISMS is not about ticking 93 boxes: controls must be justified by your risks, your context and your requirements.

What is the ISO/IEC 27001 standard?

ISO/IEC 27001 is the international reference standard defining the requirements for an information security management system, or ISMS. It enables an organisation to structure the management of its security risks and protect the confidentiality, integrity and availability of information.

Confidentiality

Information is accessible only to authorised people or systems.

Integrity

Information remains reliable and protected against uncontrolled changes.

Availability

Information and services remain accessible when they are needed.

Risk management

Security measures are defined according to risks and context.

Who is involved in your ISO 27001 certification?

Your organisation

Builds, applies and keeps the ISMS alive.

Complianz System

Supports, structures, audits internally and prepares the organisation.

Certification body

Performs the third-party assessment and issues the certification, where applicable.

ISO / IEC

Develop and publish the standard but do not certify organisations.

Information security risk analysis and treatment Can be articulated with your NIS2 and GDPR programmes 95% first-attempt success rate

+40 ISO 27001 certifications

4.9/5 client satisfaction

95% certification rate

Are you ready for ISO 27001?

ISO 27001 preparation

Maturity 38 / 100
Level ISMS needs structuring
Priorities 4 workstreams
  • Scope60 %
  • Risks40 %
  • SOA20 %
  • Controls50 %
  • Audit20 %

Recommended priorities

  • carry out the risk analysis
  • build the Statement of Applicability
  • formalise the priority controls
  • prepare the internal audit programme

Recommended support

ISO 27001 SME support

Assess my ISO 27001 project

Indicative diagnostic. Actual maturity requires analysis of practices, evidence, risks and requirements applicable to your organisation.

The ISMS: the heart of your ISO 27001 approach

The information security management system organises how the organisation identifies its risks, defines responsibilities, selects security controls, monitors their effectiveness and continually improves its level of control. ISO/IEC 27001 applies to organisations of all sizes, and the ISMS must be adapted to the organisation’s context and needs.

Governance

Scope, security policy, roles and leadership involvement.

Risks

Identification, assessment and treatment of information security risks.

Controls

Selection, justification and deployment of controls, formalised in the SOA.

Monitoring

Indicators, reviews, internal audits and security incident follow-up.

Continual improvement

Handling of deviations and progressive strengthening of control.

What is the ISO 27001 Statement of Applicability?

The Statement of Applicability, often called SoA, formalises the security controls retained in the ISMS and justifies their inclusion or exclusion in light of risk treatment and applicable requirements. Annex A serves as the comparison baseline.

Simplified example of an ISO 27001 Statement of Applicability
Control Applicable? Justification Status
Control A Yes Identified risk Deployed
Control B No Not relevant to the scope Justified
Control C Yes Client requirement In progress

The 93 Annex A controls: how to use them?

Organizational

Governance, responsibilities, suppliers, incidents, continuity…

People

Awareness, people-related responsibilities…

Physical

Protection of premises and equipment…

Technological

Access, systems, technical security, development, logging…

ISO 27001 starts from risk, not from a security checklist

  1. Asset / information
  2. Threat
  3. Vulnerability
  4. Risk
  5. Treatment
  6. Security control
  7. Residual risk

What our ISO 27001 support includes

An ISMS built in the order of a real project: from scope definition through to certification audit preparation.

ISMS scope definition

Framing of the processes, sites, systems and information covered by the ISMS — and of what is excluded.

ISO/IEC 27001 gap analysis

Assessment of the gaps between your current organisation and the standard’s requirements, to prioritise the work plan. See the ISO 27001 gap analysis.

Risk analysis & treatment

Identification, assessment and treatment of security risks using a methodology adapted to your context. ISO/IEC 27005 can serve as a framework; EBIOS Risk Manager can be used when relevant.

Statement of Applicability

Formalisation of retained controls, with justified inclusions and exclusions — what is the ISO 27001 Statement of Applicability?

Governance & information security policy

Roles, responsibilities, security policy and ISMS documentary framework — beyond the ISSP alone.

Control implementation

Deployment of retained controls, proportionate to risks, context and applicable requirements.

Incident management

Detection, notification, response and lessons-learned procedures for security incidents.

Business continuity & IT resilience

Analysis of continuity needs, preparation of the necessary measures, and formalisation of a BCP or continuity procedures when the context justifies it.

Awareness & training

Helping teams understand security rules and their responsibilities within the ISMS.

Internal audit & certification preparation

Internal audit (ISO 27001 mock audit), non-conformity remediation and support during the certification body’s audit.

The first step: measure your gap with ISO 27001

Compliant

Requirement under control, with evidence.

Partially compliant

Existing practice, but incomplete.

Needs structuring

Method insufficiently formalised.

Missing

Requirement not covered.

Internal audit: test the ISMS before the certification audit

The ISO 27001 mock audit checks that the ISMS is actually applied, evidenced and corrected before the certification body intervenes.

Verify

Are the ISMS requirements and processes actually applied?

Look for evidence

Can the described practices be demonstrated?

Identify gaps

Nonconformities, weaknesses and opportunities for improvement.

Correct

Action plan before the certification body steps in.

At the audit, your ISMS must live in practice

  • up-to-date risk analysis
  • treatment decisions
  • SoA
  • responsibilities
  • tracked incidents
  • training completed
  • controls applied
  • internal audits
  • corrective actions
  • reviews
  • metrics and indicators
  • operational evidence

A policy that describes a practice that does not exist is not enough: the ISMS must live in practice.

ISO 27001 is not limited to technical cybersecurity

ISO 27001

  • governance
  • risks
  • responsibilities
  • processes
  • controls
  • documentation
  • continual improvement

ISO 27001 and NIS2: complementary approaches

ISO/IEC 27001 provides a structured system for managing security risks. This can help an organisation organise and demonstrate certain practices useful in a NIS2 programme, but ISO 27001 certification is not, on its own, sufficient to establish NIS2 compliance.

What costs should you plan for ISO 27001 certification?

Support

Diagnostic, ISMS, risks, documentation, internal audit.

Maintenance

Audits, ISMS improvement and ongoing follow-up.

The €7,900 excl. VAT figure is not the price of ISO 27001 certification: it is the entry point for support. Certification body fees, any technical controls and maintenance are additional.

How much does ISO 27001 certification support cost?

Cost depends on your IT size, certification scope and initial security maturity. Tailored quote provided within 48 hours.

ISO 27001 SME support

€7,900 – 14,000 excl. VAT

SME up to 100 employees

  • ISO 27001 gap analysis
  • Information security risk analysis and treatment
  • ISSP and ISMS documentation
  • Statement of Applicability (SOA)
  • Internal audit + certification support
Request a quote

ISMS maintenance & improvement

€2,400 – 4,800 excl. VAT / year

Maintaining ISO 27001 certification

  • Annual risk review
  • Internal audit programme
  • Surveillance audit preparation
  • ISMS documentation updates
  • Regulatory monitoring (NIS2, GDPR)
Request a quote

Fees charged by the certification body are distinct from Complianz System support fees, unless explicitly stated otherwise. Indicative pricing excl. VAT. Tailored quote within 48 hours.

Your questions about ISO 27001 certification

Our ISO 27001 Lead Auditor certified experts respond within 24 hours to any question about your ISMS project.

Contact us
What is ISO 27001?

ISO/IEC 27001 is the international reference standard defining the requirements for an information security management system (ISMS). It helps structure security risk management and protect the confidentiality, integrity and availability of information. See the definition.

What is the current version of ISO 27001?

The currently published version is ISO/IEC 27001:2022, supplemented by Amendment 1:2024 (ISO/IEC 27001:2022/Amd 1:2024). See the current framework.

What is an ISMS?

The ISMS organises how the organisation identifies its risks, defines responsibilities, selects security controls, monitors their effectiveness and continually improves its level of control. It must be adapted to the context. See the ISMS.

What is the ISO 27001 Statement of Applicability?

The Statement of Applicability (SoA) formalises the security controls retained in the ISMS and justifies their inclusion or exclusion in light of risk treatment and applicable requirements. Annex A is a comparison baseline: the SoA is not a copied checklist. See the dedicated section.

Are all 93 controls mandatory?

No: they serve as a reference. Their applicability must be evaluated and justified in the risk treatment process and in the SoA. See the 93 Annex A controls.

Is EBIOS mandatory for ISO 27001?

No. The standard requires risk management but does not make EBIOS RM mandatory. EBIOS RM is one possible methodology, among other approaches suited to the organisation’s context. See the risk-based approach.

What is the difference between ISO 27001 and ISO 27005?

ISO/IEC 27001 contains the ISMS requirements, which certification is based on. ISO/IEC 27005 provides guidelines dedicated to information security risk management. It is not a certification standard.

What is the difference between ISO 27001 and ISO 27002?

ISO/IEC 27001 defines the ISMS requirements. ISO/IEC 27002 provides detailed recommendations on security controls. You certify an ISMS against 27001; 27002 is guidance, not a certification framework. See Annex A.

Does ISO 27001 make you NIS2 compliant?

No, not on its own. ANSSI states that an ISO 27001 certification does not in itself create NIS2 compliance, even though it is a useful tool for structuring the security approach. See ISO 27001 and NIS2.

Does ISO 27001 make you GDPR compliant?

No, not on its own. The CNIL cites ISO/IEC 27001 as a relevant element when assessing the security level, but this remains distinct from overall GDPR compliance. An ISO 27001 certification is not a GDPR certificate.

Who issues ISO 27001 certification?

An independent external certification body. ISO and IEC develop and publish the standard but do not certify organisations. Complianz System supports, structures and prepares the organisation, without issuing the certificate. See who does what.

How long does it take to get certified?

It depends on the scope, initial maturity and the ability to actually deploy the ISMS. As a guide, a project often lasts between 9 and 24 months. A gap analysis gives a more precise timeline.

How much does ISO 27001 cost?

The budget is not a single price. Plan for support, possible technical implementation, certification body fees and ISMS maintenance. Complianz support fees, from €7,900 excl. VAT, are not the price of certification. See what costs to plan for.

Can you certify only part of the organisation?

The ISMS covers a defined scope: processes, sites, systems and information included, plus justified exclusions. It is therefore possible to certify part of the organisation, provided the scope is coherent, documented and defensible at audit. It is not a way to artificially exclude exposed activities. See the support scope.

Do you need another pentest for ISO 27001?

Not systematically. A pentest may be relevant depending on the risks, selected controls and context. ISO 27001 does not require a pentest as such: the decision belongs in risk treatment and evidence of control. See ISO 27001 and technical audit.

Ready to certify your IT security with ISO 27001?

Our ISO 27001 Lead Auditor experts support you from A to Z. Security maturity diagnostic offered at kick-off. First conversation free, no commitment.

Start my ISO 27001 certification
Diagnostic offered Lead Auditor experts Helps structure your security governance and evidence of control
Innovation hub