Why ISO 27001 matters for global businesses
For SaaS companies, fintech, and any organisation handling customer data across borders, ISO 27001 is increasingly the baseline that procurement teams check before signing. It is the international standard for an information security management system (ISMS) — a structured, auditable way of identifying information risks and managing them with controls that are reviewed and improved over time.
An ISO 27001 certificate issued in one country is accepted by buyers, partners and regulators in the UK, EU, US, Middle East and beyond. For an exporting business, that means one certification can unlock contracts in several markets at once.
What the certification audit covers
Certification is a two-stage assessment carried out by a qualified lead auditor. The Stage 1 audit reviews your ISMS documentation, scope, risk assessment and Statement of Applicability to confirm you are ready. The Stage 2 audit tests how the controls in Annex A actually operate in practice — access management, supplier security, incident response, business continuity, cryptography and the rest of the control set relevant to your scope.
After certification, surveillance audits in years one and two confirm the ISMS is being maintained, with full recertification at the end of the three-year cycle. Many ISO 27001 audits — including Stage 1 and surveillance visits — can be conducted remotely, which keeps cost and disruption low for distributed teams.
Climate change: since ISO’s February 2024 climate action amendment (ISO/IEC 27001:2022/Amd 1:2024), the standard requires you to determine whether climate change is a relevant issue for your organisation, and notes that interested parties can have climate-related requirements. Certification audits include it.
How ABS helps
We prepare you for the certification audit in five steps, tailored to ISO 27001:
- Scope and gap assessment — we agree the scope of your ISMS and assess what you already have against the standard, so you know exactly what to close.
- Implementation — we help you run the information security risk assessment, write the Statement of Applicability, and implement the policies and Annex A controls relevant to your scope.
- Internal audit and management review — we help you run the internal audit and management review the standard requires, so the system has a record of operating before the audit.
- Readiness check — a pre-assessment, approached the way an auditor would approach it, highlights anything still to close.
- Audit support — we support you through the certification body’s Stage 1 and Stage 2 audits and help you close any findings.
Typical timeline
For a single-site organisation with an ISMS already operating, certification typically takes around 10–14 weeks from kick-off. The timeline depends on the scope you certify, the size of your organisation, the number of sites and the shifts they run, so larger or multi-site organisations take longer. You receive a firm timeline with your initial fixed-price quote, so there are no open-ended engagements.
Common questions
Do we need to write our own ISMS from scratch?
No. If you already have security policies and controls in place, we assess what exists against the standard. Where there are gaps, our gap assessment tells you exactly what to close before the audit — you are never left guessing.
Can the audit be done remotely?
In most cases, yes. ISO 27001 lends itself well to remote assessment, with audits held over video and secure document review. We support organisations through Stage 1, Stage 2 and surveillance audits conducted by their independent certification body, and confirm the approach with you upfront.
Who needs ISO 27001?
Any organisation that needs to show it manages information security risk; the standard applies to every sector and size. It is increasingly the baseline that procurement teams check for SaaS companies, fintech and any organisation handling customer data across borders.
How long does ISO 27001 certification take?
For a single-site organisation with an ISMS already operating, certification typically takes around 10–14 weeks from kick-off. The timeline depends on the scope you certify, the size of your organisation, the number of sites and the shifts they run, so larger or multi-site organisations take longer. You receive a firm timeline with your initial fixed-price quote, so there are no open-ended engagements.
What does ABS do, and what does the certification body do?
ABS prepares you for certification: we agree the scope of your information security management system, assess the gaps, help you implement it, support your internal audit and management review, check readiness and support you through the audits. The certification body, an independent, accredited organisation you choose, carries out the Stage 1, Stage 2 and surveillance audits, makes the certification decision and issues the certificate.
How long is an ISO 27001 certificate valid?
Three years. The certification body carries out surveillance audits in the first and second years, and a recertification audit before the three-year cycle ends.
Can ISO 27001 be combined with other standards?
Yes. ISO 27001 shares the harmonised structure of ISO management system standards, so it can run as one integrated management system with, for example, ISO 9001, ISO 22301 or ISO 27701, and certification bodies can often audit them together.
Which edition of ISO 27001 is current, and is there a transition?
The current edition is ISO/IEC 27001:2022, with the climate change amendment added in 2024. The transition from the 2013 edition ended on 31 October 2025, so 2013-edition certificates are no longer valid.