ISO/IEC 27001: the certificate Europe understands
ISO 27001 is the international standard for an information security management system (ISMS). If SOC 2 opens the US market, ISO 27001 opens Europe, the UK and Asia. Together they cover almost every security requirement in tenders and due diligence.
What ISO 27001:2022 is
The standard defines management-system requirements: organisational context, leadership, risk assessment and treatment, the 93 Annex A controls (organisational, people, physical, technological), internal audits and continual improvement. The certificate is issued by an accredited certification body after a two-stage audit and is valid for 3 years with annual surveillance audits.
Why do ISO 27001 together with SOC 2
ISO 27001 Annex A controls and the SOC 2 TSC overlap by roughly 70–80 %: policies, access management, cryptography, logging, incident, vendor and continuity management. We build a single control system and a single evidence set, then map it to both standards. The second examination mostly adds only risk assessment, the Statement of Applicability (SoA), internal audit and management review.
Result: two documents for two markets, one project, one team, roughly 30–40 % cheaper than two separate projects. See SOC 2 vs ISO 27001.
Who issues the certificate
The BALTUM group includes an accredited ISO/IEC 27001 certification body, so you go through certification without searching for a third-party body — on a transparent schedule and price. The consulting team and the certification body are separate legal entities with separate staff, as ISO/IEC 17021 requires: whoever helped implement does not audit. On request we also support certification with another body.
What you get
- ISMS scope and context definition
- Risk methodology and register, risk treatment plan
- Statement of Applicability across 93 controls
- Full policy and procedure set
- Staff training and internal audit
- Support through the certification audit (stage 1 and 2)