Framework · ISO/IEC 27001:2022

ISO 27001 compliance

ISO 27001 certifies that your information security management system actually works, on an ongoing basis. Scadable builds it, runs it, and keeps it certified.

What is ISO 27001?

ISO 27001 is an internationally recognized standard for an Information Security Management System, an ISMS: the set of policies, risk assessments, and controls a company runs to manage information security on an ongoing basis. Certification is issued by an accredited third-party body after an audit, which is a real, structural difference from SOC 2's attestation report.

The current version, ISO/IEC 27001:2022, defines 93 controls across four themes (organizational, people, physical, technological) in Annex A, selected and justified per company in a Statement of Applicability.

Who does ISO 27001 apply to?

Nothing forces a private company into ISO 27001 by law. It shows up the same way SOC 2 does, as a buyer or tender requirement, but with a different buyer profile: international and EU enterprise customers, public-sector and government tenders, and buyers outside the US where SOC 2, an AICPA artifact, is not the default ask.

Companies selling into Europe or doing business with governments run into ISO 27001 more often than SOC 2. Many eventually need both.

ISO 27001 or SOC 2, or both?

Start from the buyer, not the framework. A US enterprise security review usually asks for SOC 2. An EU enterprise, a public tender, or an international customer more often asks for ISO 27001. If you sell into both markets, plan for both eventually, but implement in the order your actual pipeline demands it.

There is real technical overlap between the two, and between both of them and the CRA's own risk-management and vulnerability-handling requirements, so building one well makes the next one meaningfully cheaper.

The certification cycle: two stages, then three years of audits

Certification runs in two stages: a documentation review (Stage 1), then an on-site or remote audit of whether the ISMS is actually operating (Stage 2). Once certified, the certificate is valid for three years, with annual surveillance audits in between confirming the ISMS is still running, not just still on paper.

StageWhat happens
Stage 1Auditor reviews your ISMS documentation and Statement of Applicability for readiness.
Stage 2Auditor examines whether the controls are actually implemented and operating.
CertificationIssued for three years upon a successful Stage 2 audit.
Surveillance auditsAnnual checks during the three-year cycle that the ISMS is still live, not archived.

What you actually have to do

Define the ISMS scope. Run a formal risk assessment and treatment process. Select and implement the relevant Annex A controls and document why each one is or is not in scope in a Statement of Applicability. Run internal audits and a management review. Then pass the external certification audit.

The hard part: the Statement of Applicability isn't a form, it's a system

Of every framework Scadable covers, ISO 27001 is the least like a one-time audit. "Management system" is the operative word: the risk assessment has to be revisited, the controls have to keep operating, and the annual surveillance audits will catch an ISMS that quietly stopped being followed after the certificate was issued.

Scadable's difference here is the same as everywhere else: implement the control and keep it running, don't just document that it should exist. If you are already doing CRA work with Scadable, ISO 27001's risk-management and vulnerability-handling controls overlap directly with the CRA's own requirements, so the two build on each other instead of duplicating work.

What's actually at stake

No statutory fine for skipping ISO 27001. The cost is a disqualified tender, a stalled international enterprise deal, or a renewal that does not happen because the surveillance audit lapsed. For companies selling into the EU or into government procurement, that can be the difference between being eligible to bid at all.

How Scadable gets you through ISO 27001

Scadable defines your ISMS scope, runs the risk assessment, implements the Annex A controls that are actually missing, and builds the Statement of Applicability. It keeps the evidence current through the annual surveillance audits instead of leaving the ISMS to decay the moment the certificate is issued.

Delivered the same concierge way as every framework that is new: a real team doing the work behind the curtain, not a dashboard promising automation that does not exist yet for this framework.

Frequently asked questions

No. SOC 2 is a US-centric attestation report. ISO 27001 is an internationally recognized certification of an ongoing information security management system, issued by an accredited third-party body. They cover similar ground but are structured differently and are asked for by different buyers.
Yes, in part. ISO 27001's risk assessment and vulnerability-handling controls overlap with essential requirements under the EU Cyber Resilience Act. A company doing both should build them together rather than duplicating the work twice.
Most companies take a few months to build the ISMS and implement the missing controls, followed by the two-stage audit itself. The certificate is then valid for three years, with annual surveillance audits in between.
The 2022 revision defines 93 controls across four themes: organizational, people, physical, and technological. Not every control applies to every company; which ones apply, and why, is documented in a Statement of Applicability.
Only if a buyer, market, or tender specifically asks for it. Many companies eventually hold both because their customer base spans US enterprise (SOC 2) and EU or international/public-sector buyers (ISO 27001).
Yes. Certification scope is defined by the company, not a headcount minimum. Smaller companies typically have a smaller ISMS scope, which makes implementation faster, not impossible.
No certification guarantees against every incident. ISO 27001 certifies that a real risk-management system and its controls are in place and operating, which materially reduces risk and gives a buyer or auditor evidence of that, but it is not an absolute guarantee.

Get ISO 27001-ready. Without the busywork.