Imperium Certific

ISO 27001 certification: what it is, who needs it and how it works

ISO 27001 is the standard for an information security management system. What certification means, who needs it, how the audit runs and what a certificate says.

When a partner asks you to "send over your ISO 27001", a single line of correspondence hides three different things: the standard itself, the management system built to it, and the paper outcome of an audit. Confusing the three costs companies months of work in the wrong direction. Here is how it looks from the certification body's side — the party that ultimately decides whether a certificate is issued.

ISO 27001 is a standard, not a certificate

What we have in front of us is a requirements document. It describes how an information security management system (ISMS) should be built: how a company identifies risks, selects protective measures, verifies that they work, and corrects what fails. You cannot buy or "install" a standard — you build a system to it.

The chain has three links:

  • The standard — requirements that are identical for everyone.
  • The ISMS — the company's own system, shaped by its risks and its declared scope.
  • The certificate — an independent body's conclusion that the system conforms.

The International Organization for Standardization only publishes documents; the verification is carried out by bodies accredited to ISO/IEC 17021-1. Imperium Certific is accredited by the National Accreditation Agency of Ukraine, accreditation certificate No. 8O007, and is a signatory to the IAF MLA — which means the certificates we issue are recognised in more than 40 countries.

What ISO 27001 is: full title and current edition

The official definition of ISO 27001 sits in the title of the document itself: "Information security, cybersecurity and privacy protection — Information security management systems — Requirements". The designation ISO/IEC 27001 points to two co-authors: the International Organization for Standardization and the International Electrotechnical Commission.

Ukraine has an identical adoption, DSTU ISO/IEC 27001:2023. The current edition of the source document dates from 2022. The three-year transition from the 2013 edition ended on 31 October 2025, so certificates issued against the older edition are no longer valid, and any material listing "114 controls in 14 clauses" is out of date. Amendment 1, published in February 2024, added the requirement to consider climate change among external issues — it left the list of controls untouched.

The structure of the document and the list of controls are covered in detail on the service page ISO 27001 certification.

Who needs certification

Ukrainian law leaves the procedure voluntary. Demand is almost always external: the people who ask for proof are the ones trusting you with their data. When a tender pack or a contract carries the line "ISO 27001", what it means in practice is that the supplier must produce a valid certificate from an accredited body, not its own security policy.

Typical triggers:

  • A contract clause. The customer makes a valid certificate a condition of cooperation or renewal.
  • A tender. In EU and NATO procurement, a certified ISMS is frequently part of the qualification criteria.
  • A parent company or investor. A group-wide security policy applies to every subsidiary.
  • Entering a new market. A European client will accept a recognised certificate far more readily than your internal documentation.
  • The aftermath of an incident. After a breach, the market asks for evidence of control rather than promises.
  • Cyber risk assessment. An insurer or a bank revises terms for a client with a certified system.
  • Cloud services. Providers extend the scope of certification with the 27017 and 27018 control sets.

How the procedure runs: the body's view

The sequence is the same for every accredited body, because 17021-1 defines it. The full description sits on the certification process page; below is the short view from the audit team.

Step What the body does Key decision
Application Review of scope, number of sites and employees Audit effort in auditor-days
Stage 1 Document review: policy, risk assessment, Statement of Applicability Readiness for stage 2
Stage 2 On-site review of how the system operates: evidence, records, staff awareness List of nonconformities
Decision Report reviewed by someone outside the audit team Issue of the certificate
Surveillance Annual surveillance audits, recertification in year three Continued validity

A surveillance audit covers a smaller sample than the certification audit, but it always examines internal audits, management review, complaint handling and correct use of the certification mark.

Three mistakes the body spots on day one

  • A scope that says "the whole company". The broadest boundary looks impressive, but it drags in every site, every system and every department. Draw the line where genuine control ends.
  • Documents without records. A policy signed the day before the audit is not evidence that the system works. The auditor looks for traces spanning months: logs, minutes, internal audit reports, management review.
  • An internal audit performed by the system's author. Reviewing your own work is impossible by definition. You need an independent person inside the company, or an external specialist who was not involved in building the ISMS.

What a certificate says and how to verify it

The most important line is not the reference numbers but the scope. It defines the boundaries of what was actually examined: specific services, sites, departments. A certificate covering one development office does not extend to the whole group, even though the logo on the sheet is the same. So when you receive a certificate from a counterparty, read that line first.

The minimum set of details:

  • the legal name of the holder;
  • the scope statement;
  • the standard reference including the edition year — ISO/IEC 27001:2022;
  • the issue date and the end of the three-year cycle;
  • the name of the certification body and the accreditation mark.

Validity can be checked two ways: in the body's certificate register and in the list of accredited bodies published by NAAU.

What certification does not do

The limits are worth stating up front; they save a good deal of disappointment:

  • It offers no guarantee against incidents. An audit confirms that processes are controlled, not that the infrastructure is invulnerable.
  • It does not replace legal compliance. Personal data protection requirements apply regardless of any certificate.
  • It does not automatically cover the whole company. Outside the declared scope, nothing was examined.
  • It does not come bundled with consultancy. Standard 17021-1 forbids the body from designing a client's system — writing policies or assessing risks on its behalf.

The best moment to approach a body is when the system has been running for a few months and has records to show: internal audit results, management review, a history of risk treatment. Records, rather than folders of policies, are what forms the evidence base at stage 2.

Ready to start? Submit an application — we will review the scope and calculate the audit effort.

Часті запитання

Повернутися до новин