ISO 27001 · Management systems
ISO 27001. Information security that builds trust
The leading standard for information security management systems (ISMS). It systematically protects your data against loss, manipulation and unauthorized access.
Overview
What is ISO 27001?
ISO 27001 is the internationally leading standard for information security management systems (ISMS). It describes how organizations protect the confidentiality, integrity and availability of information on a risk-based and lasting basis.
At its heart is a systematic approach to information security risks. From risk assessment through the selection of controls (Annex A) to ongoing effectiveness monitoring.
Purpose of certification
Certification independently proves that your ISMS meets the requirements of the standard. A strong signal to customers, partners and authorities, and increasingly a prerequisite in tenders and regulated industries (including NIS2).
Core requirements of the standard
- Risk-based information security management system (ISMS)
- Statement of Applicability
- Controls from Annex A (including access, cryptography, suppliers)
- Management of security incidents
- Business continuity and regular effectiveness reviews
For whom
Is this certification right for you?
For companies that process sensitive information and need to demonstrate security to customers, partners and authorities.
Your benefits
What the certificate does for you
- Structured protection of confidential information
- Demonstrable compliance (including GDPR, NIS2, customer requirements)
- Fewer security incidents and reduced liability risk
- Competitive advantage in security-critical tenders
Our services
Our role in ISO 27001 certification
- 1Planning and conducting certification audits to assess the conformity of your management system with the requirements of the standard
- 2Independent decision on certification based on the audit results
- 3Issuing and maintaining certificates
- 4Conducting surveillance and recertification audits in accordance with the applicable rules and defined time intervals
Impartiality
Consulting or support services for the introduction, implementation or improvement of management systems are not part of our activity as a certification body.
Process
The path to certification
Certification audit
Planning and conducting certification audits to assess conformity of the information security management system with the requirements of ISO 27001.
Certification decision and issuance of the certificate
Certification decision based on the audit results, as well as issuance and maintenance of ISO 27001 certificates.
Surveillance and recertification
Conducting surveillance and recertification audits in accordance with applicable rules and defined time intervals.
Getting a quote
What does ISO 27001 certification cost for you?
The costs of certification depend on various factors such as company size, scope, processes, etc. This differentiated calculation results from the requirements of the relevant standards and regulations. For a binding quotation, we provide you with a service-request questionnaire. Upon receipt of the completed documentation, an individual quotation will be prepared based on the information provided.
FAQ
Frequently asked questions about ISO 27001
Does ISO 27001 cover the requirements of NIS2?
An ISMS to ISO 27001 provides a very solid basis for NIS2 and many customer requirements. But, depending on the sector, does not necessarily cover them in full.
What is the Statement of Applicability?
The Statement of Applicability documents which Annex A controls are relevant to you, how they are implemented and. If not. Why not.
More standards

