ISO Certifications

ISO 27001 — Information Security Management

Globally recognised certification for information security management systems (ISMS).

Book a consultation
ISO 27001 information security management implementation
10-14 weeks Indicative timeline — varies with scope, size, sites and shifts
ISO Governing body / standard owner
Advisory Consulting, training & audit readiness
What this covers
ISO 27001ISMSInformation Security

Why ISO 27001 matters for global businesses

For SaaS companies, fintech, and any organisation handling customer data across borders, ISO 27001 is increasingly the baseline that procurement teams check before signing. It is the international standard for an information security management system (ISMS) — a structured, auditable way of identifying information risks and managing them with controls that are reviewed and improved over time.

An ISO 27001 certificate issued in one country is accepted by buyers, partners and regulators in the UK, EU, US, Middle East and beyond. For an exporting business, that means one certification can unlock contracts in several markets at once.

What the certification audit covers

Certification is a two-stage assessment carried out by a qualified lead auditor. The Stage 1 audit reviews your ISMS documentation, scope, risk assessment and Statement of Applicability to confirm you are ready. The Stage 2 audit tests how the controls in Annex A actually operate in practice — access management, supplier security, incident response, business continuity, cryptography and the rest of the control set relevant to your scope.

After certification, surveillance audits in years one and two confirm the ISMS is being maintained, with full recertification at the end of the three-year cycle. Many ISO 27001 audits — including Stage 1 and surveillance visits — can be conducted remotely, which keeps cost and disruption low for distributed teams.

Climate change: since ISO’s February 2024 climate action amendment (ISO/IEC 27001:2022/Amd 1:2024), the standard requires you to determine whether climate change is a relevant issue for your organisation, and notes that interested parties can have climate-related requirements. Certification audits include it.

How ABS helps

We prepare you for the certification audit in five steps, tailored to ISO 27001:

  • Scope and gap assessment — we agree the scope of your ISMS and assess what you already have against the standard, so you know exactly what to close.
  • Implementation — we help you run the information security risk assessment, write the Statement of Applicability, and implement the policies and Annex A controls relevant to your scope.
  • Internal audit and management review — we help you run the internal audit and management review the standard requires, so the system has a record of operating before the audit.
  • Readiness check — a pre-assessment, approached the way an auditor would approach it, highlights anything still to close.
  • Audit support — we support you through the certification body’s Stage 1 and Stage 2 audits and help you close any findings.

Typical timeline

For a single-site organisation with an ISMS already operating, certification typically takes around 10–14 weeks from kick-off. The timeline depends on the scope you certify, the size of your organisation, the number of sites and the shifts they run, so larger or multi-site organisations take longer. You receive a firm timeline with your initial fixed-price quote, so there are no open-ended engagements.

Common questions

Do we need to write our own ISMS from scratch?

No. If you already have security policies and controls in place, we assess what exists against the standard. Where there are gaps, our gap assessment tells you exactly what to close before the audit — you are never left guessing.

Can the audit be done remotely?

In most cases, yes. ISO 27001 lends itself well to remote assessment, with audits held over video and secure document review. We support organisations through Stage 1, Stage 2 and surveillance audits conducted by their independent certification body, and confirm the approach with you upfront.

Who needs ISO 27001?

Any organisation that needs to show it manages information security risk; the standard applies to every sector and size. It is increasingly the baseline that procurement teams check for SaaS companies, fintech and any organisation handling customer data across borders.

How long does ISO 27001 certification take?

For a single-site organisation with an ISMS already operating, certification typically takes around 10–14 weeks from kick-off. The timeline depends on the scope you certify, the size of your organisation, the number of sites and the shifts they run, so larger or multi-site organisations take longer. You receive a firm timeline with your initial fixed-price quote, so there are no open-ended engagements.

What does ABS do, and what does the certification body do?

ABS prepares you for certification: we agree the scope of your information security management system, assess the gaps, help you implement it, support your internal audit and management review, check readiness and support you through the audits. The certification body, an independent, accredited organisation you choose, carries out the Stage 1, Stage 2 and surveillance audits, makes the certification decision and issues the certificate.

How long is an ISO 27001 certificate valid?

Three years. The certification body carries out surveillance audits in the first and second years, and a recertification audit before the three-year cycle ends.

Can ISO 27001 be combined with other standards?

Yes. ISO 27001 shares the harmonised structure of ISO management system standards, so it can run as one integrated management system with, for example, ISO 9001, ISO 22301 or ISO 27701, and certification bodies can often audit them together.

Which edition of ISO 27001 is current, and is there a transition?

The current edition is ISO/IEC 27001:2022, with the climate change amendment added in 2024. The transition from the 2013 edition ended on 31 October 2025, so 2013-edition certificates are no longer valid.

More services

Related services

ISO Certifications / 01 ISO 27701 privacy information management implementation

ISO 27701:2025 — Privacy Information Management (PIMS)

Privacy Information Management System (PIMS) consulting — establish, implement and maintain a PIMS that can stand alone or integrate with ISO 27001 and other management systems.

ISO 27701PIMSPrivacyPIIData Protection
Get a quote
ISO Certifications / 02 ISO 27017 cloud security controls implementation

ISO/IEC 27017:2026 — Cloud Security Controls

Cloud security control implementation support — the cloud-specific controls that extend ISO 27001 for cloud service providers and their customers. ISO 27017 is guidance implemented alongside ISO 27001, not a standalone certification.

ISO 27017Cloud SecurityISO 27001Cloud Controls
Get a quote
ISO Certifications / 03 ISO 27018 protection of PII in public clouds implementation

ISO 27018:2025 — PII Protection in Public Clouds

Cloud privacy control implementation support — the controls for protecting personally identifiable information in public clouds, extending ISO 27001. ISO 27018 is guidance implemented alongside ISO 27001, not a standalone certification.

ISO 27018Cloud PrivacyPIIISO 27001
Get a quote
Cyber Security / 04 SOC 2 controls readiness for a cloud service provider

SOC 2 — Type I & Type II Reports

Readiness and support for SOC 2 reports on security, availability and confidentiality controls, for SaaS and cloud providers.

SOC 2Type IType IITrust Services
Get a quote
Cyber Security / 05 Vulnerability assessment and penetration testing of IT systems

VAPT — Vulnerability Assessment & Penetration Testing

Security testing that finds and helps you fix weaknesses before attackers do. VAPT is a service that produces a report — not a certification.

VAPTPenetration TestingVulnerability AssessmentSecurity Testing
Get a quote

Get started

Ready to get certified?

Get a free, fixed-price quote within one business day. No obligation, no sales pressure, no follow-up spam — just a clear path to certification.

Book a 30-min consultation
24-hour response time Fixed price, multi-currency Consulting & audit readiness Remote & on-site delivery
Call us