Certificates issued in 3–7 working days

ISO/IEC 27001 : 2022

The standard your customers check before trusting you with their data

Information Security Management

ISO/IEC 27001 specifies the requirements for an information security management system. It is the certification enterprise buyers, financial institutions and government departments ask for before sharing data with a supplier — and increasingly a condition of winning the contract at all.

The 2022 revision

ISO/IEC 27001:2022 restructured the Annex A controls from 114 into 93, organised under four themes — organisational, people, physical and technological — and introduced controls addressing cloud services, threat intelligence, data leakage prevention and secure coding. Organisations certified to the 2013 version transition to 2022.

What implementation involves

  • Defining the scope: which systems, data, sites and people are covered.
  • Risk assessment and a documented risk treatment plan.
  • A Statement of Applicability justifying each control you apply or exclude.
  • Policies, access control, supplier security, incident response and business continuity.
  • Internal audit and management review before certification assessment.

Who needs it

Software and SaaS companies, IT services and BPO providers, data centres, fintech, healthcare technology, and any organisation processing personal or commercially sensitive data on behalf of clients.

Not sure whether this is the standard your customer is actually asking for? Send us the requirement and we will tell you — even if the answer is a smaller job than you expected.

Start your ISO/IEC 27001 certification

Fixed price agreed up front. Certificate issued in 3 to 7 working days.