ISO 27001: What Certification Actually Requires
ISO 27001 certifies an entire management system, not a checklist of controls — and companies that treat it as a checklist tend to struggle at recertification.
The business problem
ISO 27001 is often requested by international customers and partners as an alternative or complement to SOC 2, and companies pursuing it for the first time frequently underestimate what’s actually required — treating it as a controls checklist to complete rather than an ongoing management system to operate, which is what the standard actually certifies.
What ISO 27001 actually requires
ISO 27001 certifies an organization’s Information Security Management System (ISMS) — the ongoing process of identifying risks, selecting and implementing controls (from Annex A, now aligned to 93 controls across four themes), and continuously reviewing and improving the system. The certificate isn’t awarded for having the right controls at a point in time; it’s awarded for having a functioning management process that keeps finding and fixing gaps.
How it differs from SOC 2
SOC 2 is an attestation report describing specific controls and, for Type II, whether they operated effectively over a period. ISO 27001 is a certification against an international management-system standard, with a formal certification body, a three-year certification cycle, and annual surveillance audits in between. Many companies pursuing both find that a mature ISO 27001 ISMS makes SOC 2 evidence collection easier, since the underlying risk and control discipline overlaps significantly.
“ISO 27001 doesn’t certify that you have the right controls today. It certifies that you have a real process for finding out you don’t, and fixing it.”
Signs ISO 27001 is being treated as a checklist, not a system
- A Statement of Applicability was written once for the initial audit and never revisited
- Risk assessments happen only immediately before an audit, not on an ongoing basis
- Management review meetings — a formal requirement of the standard — don’t actually happen or aren’t documented
- Internal audits are skipped or done superficially rather than surfacing real findings
- The certification is treated as "done" after the initial audit, with no plan for the ongoing surveillance cycle
Practical guidance
Build the ISMS as an operating process from the start — regular risk assessments, a living Statement of Applicability, real internal audits, and documented management reviews — rather than a one-time project to pass the certification audit. The three-year certification cycle with annual surveillance audits means the system has to keep functioning, not just exist on the day of the initial assessment.
See the platform’s ISO 27001 readiness tracker built around an ongoing ISMS, not a one-time checklist.
Explore the ISO 27001 TrackerQuestions, answered directly.
They measure different things and aren’t directly comparable in difficulty, but ISO 27001 requires an ongoing management system with recurring internal audits and management reviews, which is a heavier operational commitment than a SOC 2 attestation period alone.
A required ISO 27001 document listing every Annex A control, whether it applies to your organization, and why — it’s meant to be a living document reviewed regularly, not a one-time artifact produced for the initial certification audit.
Yes — certification runs on a three-year cycle with annual surveillance audits in between to confirm the ISMS is still functioning; a lapse in the ongoing process can put recertification at risk even if the initial audit went well.
Yes, and many companies do — the underlying risk assessment and control discipline overlaps substantially, so a well-run ISMS often reduces the incremental effort of maintaining SOC 2 evidence alongside it.
Want ISO 27001 readiness built around a real management system, not a binder?
30 minutes. No obligation. No sales pitch.