Your organisation
Builds, applies and keeps the ISMS alive.
We support your organisation from the initial analysis through to certification audit preparation: ISMS scope, risk analysis, risk treatment, statement of applicability, security policies, control implementation, internal audit and corrective actions.
The final certification is issued by an independent certification body. ISO itself states that it does not perform certifications and does not issue certificates.
Can be articulated with your NIS2 and GDPR programmes.
What you get
At the end of the certification process
An ISO 27001 certified ISMS, your IT security under control, risks documented and managed — international recognition of your security level.
A compliant ISMS is not about ticking 93 boxes: controls must be justified by your risks, your context and your requirements.
What is ISO 27001?
ISO/IEC 27001 is the international reference standard defining the requirements for an information security management system, or ISMS. It enables an organisation to structure the management of its security risks and protect the confidentiality, integrity and availability of information.
Information is accessible only to authorised people or systems.
Information remains reliable and protected against uncontrolled changes.
Information and services remain accessible when they are needed.
Security measures are defined according to risks and context.
Who does what?
Builds, applies and keeps the ISMS alive.
Supports, structures, audits internally and prepares the organisation.
Performs the third-party assessment and issues the certification, where applicable.
Develop and publish the standard but do not certify organisations.
Quick diagnostic
ISO 27001 preparation
ISO 27001 SME support
Indicative diagnostic. Actual maturity requires analysis of practices, evidence, risks and requirements applicable to your organisation.
Information security management system
The information security management system organises how the organisation identifies its risks, defines responsibilities, selects security controls, monitors their effectiveness and continually improves its level of control. ISO/IEC 27001 applies to organisations of all sizes, and the ISMS must be adapted to the organisation’s context and needs.
Scope, security policy, roles and leadership involvement.
Identification, assessment and treatment of information security risks.
Selection, justification and deployment of controls, formalised in the SOA.
Indicators, reviews, internal audits and security incident follow-up.
Handling of deviations and progressive strengthening of control.
Statement of Applicability (SoA)
The Statement of Applicability, often called SoA, formalises the security controls retained in the ISMS and justifies their inclusion or exclusion in light of risk treatment and applicable requirements. Annex A serves as the comparison baseline.
| Control | Applicable? | Justification | Status |
|---|---|---|---|
| Control A | Yes | Identified risk | Deployed |
| Control B | No | Not relevant to the scope | Justified |
| Control C | Yes | Client requirement | In progress |
Annex A
Governance, responsibilities, suppliers, incidents, continuity…
Awareness, people-related responsibilities…
Protection of premises and equipment…
Access, systems, technical security, development, logging…
From risk to control
Scope of engagement
An ISMS built in the order of a real project: from scope definition through to certification audit preparation.
Framing of the processes, sites, systems and information covered by the ISMS — and of what is excluded.
Assessment of the gaps between your current organisation and the standard’s requirements, to prioritise the work plan. See the ISO 27001 gap analysis.
Identification, assessment and treatment of security risks using a methodology adapted to your context. ISO/IEC 27005 can serve as a framework; EBIOS Risk Manager can be used when relevant.
Formalisation of retained controls, with justified inclusions and exclusions — what is the ISO 27001 Statement of Applicability?
Roles, responsibilities, security policy and ISMS documentary framework — beyond the ISSP alone.
Deployment of retained controls, proportionate to risks, context and applicable requirements.
Detection, notification, response and lessons-learned procedures for security incidents.
Analysis of continuity needs, preparation of the necessary measures, and formalisation of a BCP or continuity procedures when the context justifies it.
Helping teams understand security rules and their responsibilities within the ISMS.
Internal audit (ISO 27001 mock audit), non-conformity remediation and support during the certification body’s audit.
ISO 27001 gap analysis
Requirement under control, with evidence.
Existing practice, but incomplete.
Method insufficiently formalised.
Requirement not covered.
Internal audit
The ISO 27001 mock audit checks that the ISMS is actually applied, evidenced and corrected before the certification body intervenes.
Are the ISMS requirements and processes actually applied?
Can the described practices be demonstrated?
Nonconformities, weaknesses and opportunities for improvement.
Action plan before the certification body steps in.
Expected evidence
A policy that describes a practice that does not exist is not enough: the ISMS must live in practice.
ISO 27001 vs technical cybersecurity
ISO 27001 and NIS2
ISO/IEC 27001 provides a structured system for managing security risks. This can help an organisation organise and demonstrate certain practices useful in a NIS2 programme, but ISO 27001 certification is not, on its own, sufficient to establish NIS2 compliance.
What does ISO 27001 really cost?
Diagnostic, ISMS, risks, documentation, internal audit.
Any tools or technical controls that may be required.
Fees of the external certification body.
Audits, ISMS improvement and ongoing follow-up.
The €7,900 excl. VAT figure is not the price of ISO 27001 certification: it is the entry point for support. Certification body fees, any technical controls and maintenance are additional.
Our pricing
Cost depends on your IT size, certification scope and initial security maturity. Tailored quote provided within 48 hours.
ISO 27001 SME support
€7,900 – 14,000 excl. VAT
SME up to 100 employees
Advanced ISO 27001 support
€14,000 – 28,000 excl. VAT
Mid-market, complex or multi-site IT
ISMS maintenance & improvement
€2,400 – 4,800 excl. VAT / year
Maintaining ISO 27001 certification
Fees charged by the certification body are distinct from Complianz System support fees, unless explicitly stated otherwise. Indicative pricing excl. VAT. Tailored quote within 48 hours.
ISO/IEC 27001 is the international reference standard defining the requirements for an information security management system (ISMS). It helps structure security risk management and protect the confidentiality, integrity and availability of information. See the definition.
The currently published version is ISO/IEC 27001:2022, supplemented by Amendment 1:2024 (ISO/IEC 27001:2022/Amd 1:2024). See the current framework.
The ISMS organises how the organisation identifies its risks, defines responsibilities, selects security controls, monitors their effectiveness and continually improves its level of control. It must be adapted to the context. See the ISMS.
The Statement of Applicability (SoA) formalises the security controls retained in the ISMS and justifies their inclusion or exclusion in light of risk treatment and applicable requirements. Annex A is a comparison baseline: the SoA is not a copied checklist. See the dedicated section.
No: they serve as a reference. Their applicability must be evaluated and justified in the risk treatment process and in the SoA. See the 93 Annex A controls.
No. The standard requires risk management but does not make EBIOS RM mandatory. EBIOS RM is one possible methodology, among other approaches suited to the organisation’s context. See the risk-based approach.
ISO/IEC 27001 contains the ISMS requirements, which certification is based on. ISO/IEC 27005 provides guidelines dedicated to information security risk management. It is not a certification standard.
ISO/IEC 27001 defines the ISMS requirements. ISO/IEC 27002 provides detailed recommendations on security controls. You certify an ISMS against 27001; 27002 is guidance, not a certification framework. See Annex A.
No, not on its own. ANSSI states that an ISO 27001 certification does not in itself create NIS2 compliance, even though it is a useful tool for structuring the security approach. See ISO 27001 and NIS2.
No, not on its own. The CNIL cites ISO/IEC 27001 as a relevant element when assessing the security level, but this remains distinct from overall GDPR compliance. An ISO 27001 certification is not a GDPR certificate.
An independent external certification body. ISO and IEC develop and publish the standard but do not certify organisations. Complianz System supports, structures and prepares the organisation, without issuing the certificate. See who does what.
It depends on the scope, initial maturity and the ability to actually deploy the ISMS. As a guide, a project often lasts between 9 and 24 months. A gap analysis gives a more precise timeline.
The budget is not a single price. Plan for support, possible technical implementation, certification body fees and ISMS maintenance. Complianz support fees, from €7,900 excl. VAT, are not the price of certification. See what costs to plan for.
The ISMS covers a defined scope: processes, sites, systems and information included, plus justified exclusions. It is therefore possible to certify part of the organisation, provided the scope is coherent, documented and defensible at audit. It is not a way to artificially exclude exposed activities. See the support scope.
Not systematically. A pentest may be relevant depending on the risks, selected controls and context. ISO 27001 does not require a pentest as such: the decision belongs in risk treatment and evidence of control. See ISO 27001 and technical audit.
Our ISO 27001 Lead Auditor experts support you from A to Z. Security maturity diagnostic offered at kick-off. First conversation free, no commitment.
Quick, free estimate with no commitment — we usually reply within 24 hours.
By submitting this form, you accept our privacy policy.
Choose a day and then a time slot. We will confirm your appointment by email or phone.
Preferred time slot
Request sent successfully
We will get back to you shortly to confirm your time slot.
Availability shown is indicative; final confirmation is provided by our team.