Standard Market-driven · Switzerland, EU, Germany
ISO/IEC 27001.
ISO/IEC 27001 is the internationally recognised standard for an information security management system (ISMS); it is voluntary, but is frequently required by large customers, in tenders and in due-diligence reviews. The current version, ISO/IEC 27001:2022, requires a risk-based management system under chapters 4 to 10 and a justified selection from 93 controls in Annex A. A certificate from an accredited certification body is valid for three years and is confirmed through annual surveillance audits.
01 Triggers
When does ISO 27001 apply to you?
ISO 27001 may apply to you if one of these triggers applies. The Regulatory Check tests them against your details. Triggers marked “only together with industry or activity” only count if a trigger on industry or activity applies at the same time.
- Role towards customers: Supplier (only together with industry or activity) (Likely applies): Large customers and corporate groups increasingly require their suppliers to demonstrate a certified ISMS before entering into a contractual relationship.
- Activity: Public-sector clients (Recommend individual review): Public-sector tenders in many cases require an ISO 27001 certificate or an equivalent ISMS as an eligibility criterion.
- Industry: Aviation (Likely applies): The European Part-IS regulations expressly allow aviation organisations an information security management system based on ISO/IEC 27001; anyone choosing this route needs the standard as a foundation.
- Activity: Special category personal data, AI provider (own AI products) (Recommend individual review): Anyone processing special category data or providing AI systems is frequently asked by customers and investors about a documented information security management system.
- Markets: EU, Germany (only together with industry or activity) (Recommend individual review): In the EU area, an ISO 27001 certificate is a common standard piece of evidence in due-diligence reviews for funding rounds and company sales.
Exceptions
- No statutory obligation to be certified; an ISMS can also be operated in line with the standard's principles without external certification.
- Micro-enterprises without a contractual requirement from a customer generally have no trigger.
02 Obligations
What does ISO 27001 require?
- Build an ISMS meeting the requirements of chapters 4 to 10 (context of the organisation, leadership, planning, support, operation, performance evaluation, improvement)
- Carry out risk assessment and treatment, including a justified selection of which of the 93 controls in Annex A are applied or excluded (Statement of Applicability)
- Conduct internal audits and management review at defined intervals
- Continually improve the ISMS
03 Evidence
What evidence is needed?
- Certificate from an accredited certification body following a Stage 1 audit (document review) and Stage 2 audit (implementation review)
- Annual surveillance audits
- Recertification every three years
- Statement of Applicability as an internal evidence document
04 Penalties
What are the consequences of violations?
No fine, since voluntary; in practice: without a valid certificate, exclusion from tenders, loss of large customers, or deductions in due-diligence valuations for investments or company sales are a risk.
05 Related
What is connected with it?
- Directive on measures for a high common level of cybersecurity across the Union (NIS2): The NIS2 Directive (Directive (EU) 2022/2555) obliges operators in critical and important sectors to manage risk and report significant security incidents.
- Regulation on cybersecurity requirements for products with digital elements (Cyber Resilience Act): The Cyber Resilience Act (Regulation (EU) 2024/2847) sets EU-wide, uniform cybersecurity requirements for hardware and software products with digital elements across their entire life cycle.
- TISAX (Trusted Information Security Assessment Exchange): TISAX is an information security assessment procedure for the automotive supply chain, run by the ENX Association based on the VDA ISA assessment catalogue.
- IEC 62443 — Industrial communication networks, network and system security: IEC 62443 is the international standards series for cybersecurity in industrial automation and control systems (OT/ICS).
- EU regulations on information security in aviation (Part-IS): Part-IS requires aviation organisations - from airports to airlines to air navigation services - to operate an information security management system (ISMS), which may be based on ISO/IEC 27001, together with risk management and reporting of security-relevant occurrences.
- Digital Operational Resilience Act (Regulation (EU) 2022/2554): DORA obliges EU financial entities - banks, insurers, investment firms, payment service providers and others - to comply with uniform requirements for ICT risk management, incident reporting, resilience testing and the management of ICT third-party providers.
- FINMA Circular 2023/1 "Operational risks and resilience – banks": FINMA Circular 2023/1 sets out in detail, for Swiss banks under the Banking Act, how operational risks are to be managed - including ICT risk management, cyber risk management and business continuity management.
06 Open
What is still uncertain?
- iso.org responded to direct retrieval in this session with HTTP 403 (bot block); the iso.org URL is kept only as a source reference (source type accordingly 'secondary', since no standard text was read). The facts on Annex A (93 controls, four themes: 37 organisational, 8 people, 14 physical, 34 technological) and on the certification process come from secondary sources (GRC Solutions, ANSI blog search result), not from the ISO original text.
- That Part-IS expressly allows an ISMS 'based on ISO/IEC 27001' is evidenced via the FOCA (BAZL) page, but only as a secondary summary (search result), not as a verbatim reading of the regulation's text.
- Specific thresholds (e.g. number of employees) from which customers require a certificate were not researched and are deliberately not listed as a trigger.
07 Sources
Sources
Information as of: 24 September 2026.
- ISO/IEC 27001:2022 — Information security management systems, ISO, retrieved on 24 September 2026
- ISO/IEC 27001:2022 – Information Security Systems, ANSI National Accreditation Board (Suchergebnis), retrieved on 24 September 2026
- ISO/IEC 27001:2022 – The Information Security Management Standard, GRC Solutions, retrieved on 24 September 2026
- BAZL: EU-Verordnungen zur Informationssicherheit (Part-IS), Bundesamt für Zivilluftfahrt (BAZL), retrieved on 24 September 2026
A professional assessment based on publicly available sources, not legal advice. Whether a given rule applies in your specific case depends on circumstances that are not fully captured here.
FAQ Answers
Questions about ISO 27001.
Does a start-up need to be certified to ISO 27001?
Not legally. But corporate customers, tenders and investors often ask about it. It makes sense to build your processes early on so that a later certification is a small step, not a rebuild.
What does an ISO 27001 certificate show, and what doesn't it show?
It shows that a company operates a functioning, audited information security management system and has made a justified selection of the measures in Annex A. It does not guarantee one hundred percent protection against incidents, but it evidences a structured, repeatedly reviewed approach to risk.
How long is an ISO 27001 certificate valid?
Three years, with annual surveillance audits by the certification body; recertification is then required.
What changes with the 2022 version compared with 2013?
Annex A was reorganised: instead of 114 controls in 14 categories, there are now 93 controls in four themes (organisational, people, physical, technological).
Does ISO 27001 apply to you?
The Regulatory Check gives an initial assessment. In a conversation, we clarify what really applies in your situation and in which order you address it.
