Home › ISO/IEC 27001: the certificate Europe understands
Standard

ISO/IEC 27001: the certificate Europe understands

ISO 27001 is the international standard for an information security management system (ISMS). If SOC 2 opens the US market, ISO 27001 opens Europe, the UK and Asia. Together they cover almost every security requirement in tenders and due diligence.

What ISO 27001:2022 is

The standard defines management-system requirements: organisational context, leadership, risk assessment and treatment, the 93 Annex A controls (organisational, people, physical, technological), internal audits and continual improvement. The certificate is issued by an accredited certification body after a two-stage audit and is valid for 3 years with annual surveillance audits.

Why do ISO 27001 together with SOC 2

ISO 27001 Annex A controls and the SOC 2 TSC overlap by roughly 70–80 %: policies, access management, cryptography, logging, incident, vendor and continuity management. We build a single control system and a single evidence set, then map it to both standards. The second examination mostly adds only risk assessment, the Statement of Applicability (SoA), internal audit and management review.

Result: two documents for two markets, one project, one team, roughly 30–40 % cheaper than two separate projects. See SOC 2 vs ISO 27001.

Who issues the certificate

The BALTUM group includes an accredited ISO/IEC 27001 certification body, so you go through certification without searching for a third-party body — on a transparent schedule and price. The consulting team and the certification body are separate legal entities with separate staff, as ISO/IEC 17021 requires: whoever helped implement does not audit. On request we also support certification with another body.

What you get

  • ISMS scope and context definition
  • Risk methodology and register, risk treatment plan
  • Statement of Applicability across 93 controls
  • Full policy and procedure set
  • Staff training and internal audit
  • Support through the certification audit (stage 1 and 2)

How the project runs

Gap analysis1–2 weeks
Risks and documents4–8 weeks
Implementation4–8 weeks
Internal audit1–2 weeks
Certification3–6 weeks

Frequently asked questions

How long does ISO 27001 implementation take?
Typically 3–6 months for a company of 20–200 people. Paired with SOC 2 about the same, since the work is combined.
Which version is current?
ISO/IEC 27001:2022. Certificates against the 2013 version are no longer issued.
Is ISO 27001 required to work with the EU?
Not legally, but in EU tenders and contracts it has become a standard requirement, especially alongside GDPR.

Get a quote within one business day

Get a quote