Framework · ISO/IEC 27001:2022

ISO 27001 compliance

ISO 27001 is the certificate international and public-sector buyers ask for before they trust a vendor with their data. If you sell outside North America, someone will ask for it.

What is ISO 27001

ISO 27001 is a certificate that says an independent auditor checked how you protect customer data and found it working.

It applies to almost any B2B company handling customer data. There is no law forcing it; your customers' security teams are what make you get it. It is the one most often asked for outside North America.

What ISO 27001 includes

Four categories of work, plus the audit that certifies them. SCADABLE does the work, keeps the evidence current, and hands the auditor what they ask for.

CategoryWhat it covers
TeamSecurity training, role-based access, onboarding and offboarding, screening
TechEncryption, MFA, logging and monitoring, backups, secure development
CompanyRisk assessment and treatment, Statement of Applicability, vendor management, asset inventory, incident response
PoliciesWritten policy set, policy acceptance records, management review
The auditIndependent internal audit, then an accredited certification body runs Stage 1 and Stage 2

How long it takes

These are SCADABLE timelines. The first three steps are ours. The last two belong to the certification body, which is why the range exists.

Platform setup2 hours
Gap analysis / ISMS1 week
Internal audit and fixes1 week
Audit (1 & 2)1 to 3 weeks
CompliantValid 3 years

Between these steps SCADABLE runs the risk assessment, writes the Statement of Applicability and the policy set, and implements the controls you are missing. None of it needs you.

Get ISO 27001-ready. Without the busywork.

Frequently asked questions

Stage 1 is a documentation review: the certification body checks your program and Statement of Applicability for readiness. Stage 2 examines whether the controls are actually implemented and operating.
No. There is no law forcing it. Your customers' security teams are what make you get it, most often buyers outside North America and public-sector tenders.
Three years, with one check-in audit each year confirming the program is still running.
They cover similar ground but are asked for by different buyers. SOC 2 is a US-centric attestation report. ISO 27001 is an international certification issued by an accredited body, and it is the one most often asked for outside North America. Companies selling into both markets often end up with both.
Yes. Unlike a SOC 2 report, which is shared under NDA, an ISO 27001 certificate is public and is typically listed in the certification body's public register.

This page is educational information, not legal advice. Confirm your company's ISO 27001 scope with an accredited certification body.