ISO 27001 is the international standard for information security. The standard helps you to systematically manage risks to your information. From data leaks to ransomware, from human errors to system failures.
In this guide you will read everything you need to know: from the basic principles to the costs, from preparation to choosing a certifier. No sales pitches, just clear information.
1. What is ISO 27001?
ISO 27001 is an international standard for information security. The standard describes requirements for an Information Security Management System (ISMS): a structured approach to protect the confidentiality, integrity and availability of information.
In short: ISO 27001 helps you to systematically identify, manage and reduce information security risks.
With an ISO 27001 certificate you demonstrate that your company has a working ISMS, actively manages risks and continuously improves in the field of information security.
1.1 The three pillars of information security
ISO 27001 is built on three core principles, often referred to as the CIA Triad:
| Principle | What it means |
|---|---|
| Confidentiality | Only authorized persons have access to information |
| Integrity | Information is correct and complete and has not been changed without authorisation |
| Availability (Availability) | Information is accessible when needed |
The gist: it’s about protecting information against all types of threats, whether technical, human or physical.
1.2 Annex A: the 93 controls
An important part of ISO 27001 is Annex A. This is a catalogue of 93 management measures (controls) divided into four categories:
| Category | Number of controls | Examples |
|---|---|---|
| Organizational | 37 | Policies, roles, risk management, supplier management |
| Human | 8 | Screening, awareness, working from home, confidentiality |
| Physical | 14 | Access control, security monitoring, equipment |
| Technological | 34 | Authentication, encryption, network security, logging |
You don’t have to apply all 93 controls. In your Statement of Applicability you record which controls are relevant to your organisation and why.
1.3 Current version: ISO 27001:2022
The current version is ISO 27001:2022. This replaces the 2013 version. Most important changes: a completely revised Annex A with 93 controls (was 114) and eleven new measures for, among other things, cloud security and threat intelligence.
Transition deadline: October 31, 2025. After that date, all certificates based on the 2013 version are invalid.
2. Why certify ISO 27001?
A certificate is not a goal in itself. It is a means. The question is: does it help your business?
2.1 Five concrete benefits
In addition to access to assignments, there are more benefits:
- Better risk management - You systematically identify and manage information security risks. The number of incidents is decreasing.
- Demonstrated compliance - Demonstrate compliance with the GDPR and prepare for NIS2. Auditors and supervisors appreciate a certificate.
- Protection of reputation - A data breach can haunt your company for years. Prevention is cheaper than recovery.
- Customer trust - You show that you take information security seriously. This makes a difference, especially with sensitive data.
- Foundation for extension - ISO 27001 shares the same structure with ISO 9001 (Quality) and ISO 22301 (Business Continuity).
2.2 For whom is it relevant?
ISO 27001 is relevant for any organisation that processes information. But some sectors benefit more from it:
| Sector | Why relevant |
|---|---|
| IT services | Customers demand it, processing customer data |
| Finance | Legal requirements, sensitive financial data |
| Care | Patient data, NEN 7510 as a supplement |
| Government | BIO standards framework, tender requirements |
| Ecommerce | Customer data, payment data |
| Suppliers to large companies | Chain responsibility |
2.3 When it may not be necessary
Honest advice: certification is not the best choice for everyone.
Ask yourself this question: Are my customers asking for it? Do I process sensitive information? If not, carefully consider whether the investment is worth it.
Other situations in which you have to be critical:
- Sole proprietorships without sensitive customer data are unlikely to have the ROI
- If you just want a certificate for the sake of having it, without actually improving the processes, it is of little use to you
- In very small organisations, the overhead may outweigh the benefits
3. The ISO 27001 certification process
You go through six steps from decision to certificate. Count on six to eighteen months, depending on your starting position and IT complexity.
3.1 The six steps to certification
Determine scope - Which parts of your organisation, systems and locations are covered by the ISMS? Start small if necessary and expand later.
Perform risk analysis - Identify information security risks and determine what measures are needed. This is the heart of ISO 27001.
Set up ISMS - Implement controls, establish policies, train employees, and document processes.
Complete proof period - Work under your ISMS for a minimum of three months. Auditors want proof that the system works in practice.
Internal audit and management review - Check yourself whether everything is working and have management formally assess the ISMS.
External audit - The certifier carries out the audit in two phases. If successful you will receive the certificate.
3.2 The external audit: phases one and two
Phase 1 (Stage 1) is a documentation and readiness check. The auditor assesses your ISMS documentation, Statement of Applicability and risk analysis. Usually lasts one to two days.
Phase 2 (Stage 2) is the on-site practical audit. The auditor speaks with employees, checks processes and verifies whether paper and practice correspond. Lasts two to five days.
3.3 Timeline
| Your situation | Lead time | Audit duration |
|---|---|---|
| Already have a management system (e.g. ISO 9001) | 5-9 months | 2-3 days |
| Good IT basis, but no ISMS yet | 6-12 months | 3-4 days |
| Complex IT environment or multiple locations | 12-18 months | 4-5 days |
3.4 Who does what?
| Party | Role |
|---|---|
| You | Risk analysis, setting up ISMS, internal audits, training employees |
| IT department | Implementing technical measures, logging, monitoring |
| Consultant (optional) | Guidance, gap analysis, templates, training |
| Certifier | Perform audit, issue certificate |
| Accreditation body | Checks the certifier (RvA, UKAS, etc.) |
Good to know: A consultant is not mandatory. Many organisations with experienced IT and compliance people do it themselves.
4. What does ISO 27001 cost?
The costs vary greatly. They depend on your company size, IT complexity and whether you engage a consultant. ISO 27001 is generally more expensive than ISO 9001 due to the more intensive audit.
Rule of thumb for SMEs: Count on €5,000 - €15,000 in the first year, then €2,000 - €5,000 per year.
4.1 Cost items overview
| Cost item | Indication |
|---|---|
| Certification audit (year 1) | €4,000 - €10,000 |
| Surveillance audit (per year) | €2,000 - €5,000 |
| Recertification (every three years) | €3,500 - €8,000 |
| Consultant (optional) | €10,000 - €25,000 |
| Tooling/software (optional) | €1,000 - €5,000 per year |
| Internal hours | 150 - 300+ hours |
4.2 Price indication per company size
| Company size | First year | Annually thereafter |
|---|---|---|
| Small (up to 10 FTE) | €4,000 - €8,000 | €2,000 - €3,500 |
| Medium (10-50 FTE) | €6,000 - €15,000 | €3,000 - €6,000 |
| Large (50-250 FTE) | €10,000 - €25,000 | €5,000 - €10,000 |
| Enterprise (250+ FTE) | €20,000 - €50,000+ | €8,000 - €15,000+ |
Prices indicative, excl. VAT, excl. consultant and internal hours.
4.3 What influences the price?
Five factors determine your costs:
- Number of employees (more = more audit time)
- IT complexity (in-house development, cloud, data centers)
- Number of locations (each location is assessed)
- Current maturity (starting from scratch is more expensive than optimizing)
- Certifier’s choice (prices vary 20-40%)
5. Preparation for ISO 27001
Good preparation is half the battle. Most of the time is spent on the risk analysis and setting up your ISMS, not on the audit itself.
5.1 What do you need to arrange internally?
Then follow these steps:
- Appoint project leader - Someone with a mandate, IT knowledge and time commitment
- Determine scope - Which systems, processes and locations are covered by the ISMS?
- Perform Risk Analysis - Identify threats, vulnerabilities and risks
- Implement measures - Technical and organizational, based on the risk analysis
- Create awareness - Train employees, phishing testing, communicate policies
- Start proof period - Work for at least three months according to the ISMS
- Perform internal audit - Test whether everything works before the certifier arrives
5.2 What documentation is needed?
The standard requires at least:
| Document | What it is |
|---|---|
| Information Security Policy | Your vision and objectives in the field of information security |
| Scope of the ISMS | Which parts of your organisation will be certified |
| Risk analysis and treatment plan | Identified risks and chosen measures |
| Statement of Applicability (SoA) | Which controls you apply and which you do not, with substantiation |
| Process descriptions | How you work (incident management, access management, change management) |
| Registrations | Proof that you do what you say (audits, incidents, training) |
No need for a thick manual. Many organisations work with a digital system or compact documents. The form is free, as long as it is current and accessible.
5.3 Three common mistakes
Mistake 2: Paper tiger
Your documents must correspond with practice. If you write down that you will check logs every week, you should actually do so. Auditors ask for evidence.
Mistake 3: Starting the proof period too late
You must have worked under your ISMS for at least three months before the external audit can take place. Plan this, otherwise your certification date will be postponed.
6. The ISO 27001 audit
The external audit is the moment of truth. Exciting, but if you are well prepared there is little to worry about.
6.1 Phases one and two
The audit consists of two parts:
Phase 1: Documentation and readiness check (often partly remote)
The auditor assesses your ISMS documentation: policy, risk analysis, Statement of Applicability. Is everything present and consistent? Are you ready for the on-site audit? After phase one you will receive feedback and time to make adjustments.
Phase 2: On-site audit (on location)
Now the auditor comes along. He or she speaks to employees at all levels, reviews systems and processes, checks logs and registrations, and verifies whether paper and practice match.
The gist: The auditor is looking for evidence that your ISMS is effective. Not only that procedures exist, but that they work and actually manage risks.
6.2 Possible outcomes
| Outcome | What’s happening? |
|---|---|
| Certificate | You meet the requirements |
| Minor deviations | Certificate, but resolve points for next audit |
| Major deviations | Fix first, then reaudit within 90 days |
| Requirements not met | Restart the process |
6.3 Tips for a smooth audit
- Know your own system - Know where your documents are and how your processes work
- Prepare employees - Tell them what to expect. They do not need to know the standard, but they do need to know their own tasks
- Be honest - Don’t try to hide anything. Auditors value openness more than perfection
- Have proof ready - Logs, registrations, training records. Make sure you can quickly show what the auditor is asking
- View it as an opportunity - A good auditor provides valuable feedback. Use it to really improve
7. Choosing an ISO 27001 Certifier
There are more than 25 certifiers active in the Netherlands for ISO 27001. They differ in price, approach and specialisation. How do you choose the right one?
7.1 Five criteria to pay attention to
| Criterion | Why important |
|---|---|
| Accreditation | Non-accredited certificates are often not recognised |
| Industry experience | An auditor who understands IT and security adds more value |
| Price | Differences of 20-40% are normal |
| Service | Permanent contact person? Quick responses? Flexibility? |
| Working relationship with the auditor | You will work together for at least three years |
7.2 What is accreditation?
Accreditation bodies audit certifiers. They check whether auditors are qualified for ISO 27001, whether the certifier works independently, and whether the audit is carried out correctly.
Each country has its own authority: the RvA in the Netherlands, UKAS in the United Kingdom, DAkkS in Germany. They recognise each other’s certificates through the IAF (International Accreditation Forum). A certificate from a UKAS-accredited certifier is therefore just as valid as one from an RvA-accredited one.
7.3 Questions to ask
Before you choose, ask potential certifiers these questions:
- Are you accredited for ISO 27001? At which agency?
- What is your experience in my sector (IT, finance, healthcare)?
- Does the auditor have experience with our technology (cloud, development, specific systems)?
- Who will be my auditor? Can I speak to that person in advance?
- What is the lead time from quotation to certificate?
- What are the total costs for three years (including surveillance)?
- How do you deal with deviations during the audit?
The right choice is not necessarily the cheapest. An auditor who understands your IT environment and provides constructive feedback is worth more than a few hundred euros in savings.
Ready to compare? View our overview of certification bodies in the Netherlands and find one that fits your company.
8. Frequently asked questions about ISO 27001
How much does ISO 27001 certification cost?
For an SME (10-50 employees): €5,000 - €15,000 in the first year, then €2,000 - €5,000 per year. ISO 27001 is more expensive than ISO 9001 due to the more intensive audit and technical component. The exact price depends on company size, IT complexity and number of locations.
How long does certification take?
With an existing management system (e.g. ISO 9001): five to nine months. From scratch: six to twelve months. Complex IT environments: twelve to eighteen months. The audit itself takes two to five days.
Is ISO 27001 mandatory?
No, it’s voluntary. But many clients and sectors do demand it - especially in IT services, finance, healthcare and government. It also helps with GDPR and NIS2 compliance.
What changes in ISO 27001:2022?
The Annex A has been completely revised. Where the old version had 114 controls in fourteen categories, there are now 93 controls in four categories (organizational, human, physical, technological). Eleven new controls have been added, including for threat intelligence, cloud security and data leakage prevention. Transition deadline: October 31, 2025.
Can I do it without a consultant?
Yes. Especially if you already have experience with management systems or have a strong IT department. A consultant can speed things up and prevent pitfalls, but is not mandatory.
What is accreditation?
Accreditation bodies (such as RvA, UKAS, DAkkS) inspect certifiers. Their certificates are internationally recognised through the IAF. Always choose an accredited certifier.
How often is an audit after certification?
A surveillance audit (control) every year. Full recertification every three years. Your certificate is valid for three years, provided you successfully complete the annual audits.
Can I switch certifiers?
Yes, anytime. Your new certifier will take over your file and plan a transfer audit. Your certificate remains valid during the transfer. Many organisations switch because of price, service or a better connection with the auditor.
What is the difference between ISO 27001 and NEN 7510?
NEN 7510 is the Dutch standard for information security in healthcare. It is based on ISO 27001 but contains additional requirements specific to the healthcare sector. Often both standards are combined in an audit.
Want to know more? Read our complete guide to NEN 7510 certification.
Does ISO 27001 help with GDPR?
Yes. ISO 27001 demonstrably helps to meet the requirement of “appropriate technical and organizational measures” from the GDPR. It does not guarantee full GDPR compliance, but covers a large part of the security requirements.
This guide is updated regularly. Last checked: December 2025.
