Skip to content
DEEN
Book a call

Standard Market-driven · Switzerland, EU, Germany

ISO/IEC 27001.

Short answer

ISO/IEC 27001 is the internationally recognised standard for an information security management system (ISMS); it is voluntary, but is frequently required by large customers, in tenders and in due-diligence reviews. The current version, ISO/IEC 27001:2022, requires a risk-based management system under chapters 4 to 10 and a justified selection from 93 controls in Annex A. A certificate from an accredited certification body is valid for three years and is confirmed through annual surveillance audits.

01 Triggers

When does ISO 27001 apply to you?

ISO 27001 may apply to you if one of these triggers applies. The Regulatory Check tests them against your details. Triggers marked “only together with industry or activity” only count if a trigger on industry or activity applies at the same time.

  • Role towards customers: Supplier (only together with industry or activity) (Likely applies): Large customers and corporate groups increasingly require their suppliers to demonstrate a certified ISMS before entering into a contractual relationship.
  • Activity: Public-sector clients (Recommend individual review): Public-sector tenders in many cases require an ISO 27001 certificate or an equivalent ISMS as an eligibility criterion.
  • Industry: Aviation (Likely applies): The European Part-IS regulations expressly allow aviation organisations an information security management system based on ISO/IEC 27001; anyone choosing this route needs the standard as a foundation.
  • Activity: Special category personal data, AI provider (own AI products) (Recommend individual review): Anyone processing special category data or providing AI systems is frequently asked by customers and investors about a documented information security management system.
  • Markets: EU, Germany (only together with industry or activity) (Recommend individual review): In the EU area, an ISO 27001 certificate is a common standard piece of evidence in due-diligence reviews for funding rounds and company sales.

Exceptions

  • No statutory obligation to be certified; an ISMS can also be operated in line with the standard's principles without external certification.
  • Micro-enterprises without a contractual requirement from a customer generally have no trigger.

02 Obligations

What does ISO 27001 require?

  • Build an ISMS meeting the requirements of chapters 4 to 10 (context of the organisation, leadership, planning, support, operation, performance evaluation, improvement)
  • Carry out risk assessment and treatment, including a justified selection of which of the 93 controls in Annex A are applied or excluded (Statement of Applicability)
  • Conduct internal audits and management review at defined intervals
  • Continually improve the ISMS

03 Evidence

What evidence is needed?

  • Certificate from an accredited certification body following a Stage 1 audit (document review) and Stage 2 audit (implementation review)
  • Annual surveillance audits
  • Recertification every three years
  • Statement of Applicability as an internal evidence document

04 Penalties

What are the consequences of violations?

No fine, since voluntary; in practice: without a valid certificate, exclusion from tenders, loss of large customers, or deductions in due-diligence valuations for investments or company sales are a risk.

05 Related

What is connected with it?

06 Open

What is still uncertain?

  • iso.org responded to direct retrieval in this session with HTTP 403 (bot block); the iso.org URL is kept only as a source reference (source type accordingly 'secondary', since no standard text was read). The facts on Annex A (93 controls, four themes: 37 organisational, 8 people, 14 physical, 34 technological) and on the certification process come from secondary sources (GRC Solutions, ANSI blog search result), not from the ISO original text.
  • That Part-IS expressly allows an ISMS 'based on ISO/IEC 27001' is evidenced via the FOCA (BAZL) page, but only as a secondary summary (search result), not as a verbatim reading of the regulation's text.
  • Specific thresholds (e.g. number of employees) from which customers require a certificate were not researched and are deliberately not listed as a trigger.

07 Sources

Sources

Information as of: 24 September 2026.

A professional assessment based on publicly available sources, not legal advice. Whether a given rule applies in your specific case depends on circumstances that are not fully captured here.

FAQ Answers

Questions about ISO 27001.

Does a start-up need to be certified to ISO 27001?

Not legally. But corporate customers, tenders and investors often ask about it. It makes sense to build your processes early on so that a later certification is a small step, not a rebuild.

What does an ISO 27001 certificate show, and what doesn't it show?

It shows that a company operates a functioning, audited information security management system and has made a justified selection of the measures in Annex A. It does not guarantee one hundred percent protection against incidents, but it evidences a structured, repeatedly reviewed approach to risk.

How long is an ISO 27001 certificate valid?

Three years, with annual surveillance audits by the certification body; recertification is then required.

What changes with the 2022 version compared with 2013?

Annex A was reorganised: instead of 114 controls in 14 categories, there are now 93 controls in four themes (organisational, people, physical, technological).

Does ISO 27001 apply to you?

The Regulatory Check gives an initial assessment. In a conversation, we clarify what really applies in your situation and in which order you address it.

Ivo Schönberner on a lakeside promenade in the morning light