Compliance
ISO 27001
ISMS
certification

ISO 27001: What It Is and How to Get Certified

ISO 27001:2022 explained: ISMS, 93 Annex A controls, prerequisites, Stage 1 and 2, real cost and timelines, choosing an accredited body and the mistakes that fail audits.

, COO and co-founderMay 2, 2026Updated on September 15, 2026Reviewed by Javier Paradelo Rodríguez on September 10, 202620 min readHow we produce our content

ISO 27001:2022 is the international standard for information security management, and it exists so an organisation can demonstrate that it protects its own data and its clients' data through a formal, auditable management system that can be certified by independent third parties. It is not a technical norm with closed mandatory controls, it is a framework to design, implement and continuously improve an Information Security Management System (ISMS). The 2022 version introduces 93 controls in Annex A, organised across 4 domains (organisational, people, physical, technological). Getting certified requires an external audit by an accredited certification body (ENAC in Spain) and is renewed every 3 years, with annual surveillance audits. For an SME of 50-200 employees, full implementation typically takes 5 to 9 months. It is the base on which other frameworks stack: it covers around 70% of NIS2 article 21, around 75% of ENS, and is increasingly required in tenders.

Key takeaways on ISO 27001

  • ISO 27001:2022 is the international standard for managing information security in companies.
  • It exists to prove in an auditable way that the organisation protects its own data and its clients' data.
  • Defines an Information Security Management System (ISMS) with 93 controls in Annex A.
  • Certification is issued by an accredited body (ENAC in Spain), renewed every 3 years.
  • Typical SME implementation: 5 to 9 months. Covers around 70% of NIS2 and 75% of ENS.

What ISO 27001 is (2022 version)

ISO/IEC 27001:2022 is the current version of the international standard for information security management, published by ISO and IEC in October 2022. It replaces the 2013 version, in force for almost a decade. The transition period for certificates issued against the 2013 version ended on 31 October 2025, so any certificate valid today is issued against ISO/IEC 27001:2022.

ISO 27001 doesn't impose technologies or closed controls. It defines a management framework (the ISMS) that each organisation adapts to its context, risks and risk appetite. The audit checks that the framework exists, is implemented, works and improves continuously.

The two key parts of the standard:

  • Clauses 4-10: ISMS requirements (context, leadership, planning, support, operation, performance evaluation, improvement). These clauses are mandatory and non-negotiable.
  • Annex A: list of 93 reference controls grouped in 4 categories. Application gets decided in the Statement of Applicability (SoA) based on each organisation's risks.

What is ISO 27001 used for?

Commercial benefits

  • Access to tenders: more and more public and private tenders demand it as a prerequisite.
  • Access to enterprise clients: banks, insurers, healthcare and public administrations require it from their providers.
  • Reduction of security questionnaires: a valid certificate replaces a good chunk of SIG/CAIQ questionnaires.
  • Competitive differentiation: in sectors where only a minority is certified, it's a maturity signal.

Security benefits

  • Structured framework to manage risks instead of fighting fires.
  • Continuous improvement documented (PDCA) that prevents security from degrading over time.
  • Leadership involvement formally required by clause 5.
  • Defensible evidence in front of incidents, regulatory audits or expert assessments.

Fit with NIS2, DORA, ENS and GDPR

FrameworkApproximate coverage with ISO 27001:2022
NIS2 (article 21)65-75%
DORA50-60% (DORA additionally demands TLPT, provider register, CTPP oversight)
ENS Spanish Royal Decree 311/202270-80% (ENS adds ACIDA categorisation and public sector obligations)
GDPR60-70% in technical and organisational measures (article 32)

ISO 27001 is the foundation on which to stack the rest: saves you from redoing work when you enter the next framework.

ISMS: the heart of ISO 27001

The Information Security Management System (ISMS) is the coordinated set of policies, procedures, roles, controls, resources and improvement activities the organisation deploys to manage information security.

Clauses 4-10 the ISMS must cover:

ClauseWhat it demands
4. ContextDetermination of interested parties, ISMS scope, internal and external context
5. LeadershipSenior management commitment, security policy, roles and responsibilities (including the CISO or formal equivalent)
6. PlanningRisk analysis, treatment, measurable security objectives, change management
7. SupportResources, competence and training, awareness, communication, documented information
8. OperationOperational planning, periodic risk assessment, applied treatment
9. Performance evaluationMonitoring, measurement, internal audit, management review
10. ImprovementNon-conformities, corrective actions, continuous improvement

These clauses are identical to other ISO management standards (9001, 14001, 22301, 27701). If you already have one of them, you start with 30-40% of the ISMS done.

The 93 Annex A controls (2022 version)

The 2022 version reorganised the old 114 controls in 14 domains into 93 controls grouped in 4 categories, and incorporated 11 new controls aligned with modern threats.

Annex A 2022 structure

CategoryControlsFocus
A.5 Organisational controls37Policies, governance, vendor management, incident management
A.6 People controls8HR, training, discipline, remote work
A.7 Physical controls14Perimeter, secure areas, equipment, maintenance
A.8 Technological controls34Access, cryptography and PKI, operations security, communications, development

The 11 new controls in 2022

ControlWhat it requires
A.5.7 Threat intelligenceCollect and analyse intelligence on relevant threats
A.5.23 Cloud services securitySpecific risk management of cloud providers
A.5.30 ICT readiness for continuitySpecific ICT plans within the BCP
A.7.4 Physical security monitoringIntrusion detection on premises
A.8.9 Configuration managementSystematic hardening of configurations
A.8.10 Information deletionSecure deletion procedures
A.8.11 Data maskingAnonymisation/pseudonymisation in non-production environments
A.8.12 Data leakage prevention (DLP)DLP technology and processes
A.8.16 Monitoring activitiesSIEM, anomaly detection, alerting
A.8.23 Web filteringWeb browsing control
A.8.28 Secure codingSecure SDLC, code review, OWASP

Prerequisites: what you need before requesting the audit

Not every organisation is ready to engage a certification body. Before requesting the audit, check four objective conditions; if any of them fails, Stage 1 will pick it up on the first day.

An ISMS that operates, not a manual on a shelf

The most expensive mistake is producing a flawless set of documents nobody uses. The external audit looks for evidence that the ISMS works: security committee minutes, management reviews, an up-to-date risk assessment, an executed treatment plan and measured indicators. If the documentation is perfect but the minutes are 18 months old, the auditor notices immediately.

A formal, traceable risk assessment

The standard does not impose a specific methodology, but it requires risks to be identified, evaluated and treated with consistent criteria (clauses 6.1.2 and 6.1.3). In Spain the most common methodology is Magerit, although ISO/IEC 27005, ISO 31000, NIST SP 800-30 or a well-justified in-house method also work. What the auditor verifies:

  • A living asset inventory, not last year's spreadsheet.
  • Consistent valuation criteria across assets.
  • A decided and recorded treatment for each risk (accept, mitigate, transfer, avoid).
  • A treatment plan with actions, owners and deadlines.

An internal audit completed before the external one

Clause 9.2 requires an internal audit of the ISMS at planned intervals. Arriving at Stage 2 without one means a non-conformity from the outset. It can be carried out by in-house staff independent of the area audited, or by an external consultant other than the one who implemented the ISMS.

A documented management review

Clause 9.3 requires top management to review the ISMS at planned intervals and to record in writing what it decides, what it approves and which resources it allocates. Without management review minutes, an explicit requirement of the standard fails.

How to get certified step by step

1. GAP analysis

Duration: 2-4 weeks. Compare the current state against clauses 4-10 + Annex A. Identify which policies, procedures and controls exist, which to create and which to improve.

2. ISMS design

Duration: 4-8 weeks. Define scope, policy, roles, risk analysis methodology (typically Magerit or ISO 27005), risk treatment procedure, Statement of Applicability (SoA) and the procedures required by the clauses (documentary management, internal audit, non-conformities, management review).

3. Control implementation

Duration: 2-4 months. Real deployment of the controls selected in the SoA. The longest phase and the most dependent on prior maturity.

4. Internal audit

Duration: 2-3 weeks. Internal auditor (or subcontracted external, independent from the implementing team) verifies that the ISMS meets requirements before exposing it to the certification body. Identifies non-conformities and improvement opportunities.

5. Certification audit (Stage 1 + Stage 2)

Carried out by an accredited certification body:

  • Stage 1: Documentary review: scope, policy, SoA, risk analysis, procedures. Identifies if the organisation is ready for Stage 2.
  • Stage 2: On-site audit: control sampling, interviews, evidence verification. If it passes, the certificate valid for 3 years gets issued.

Stage 2 findings fall into three categories:

  1. Major non-conformities: block certification until they are corrected and the correction is evidenced with an action plan accepted by the audit team.
  2. Minor non-conformities: do not prevent issuance, but require an action plan closed within a deadline (typically 90 days) that is verified at the next surveillance audit.
  3. Observations or opportunities for improvement: suggestions with no formal obligation.

If no majors remain open, the body's technical committee issues the certificate, usually between 4 and 8 weeks after Stage 2. For that certificate to be recognised in tenders and corporate markets, the body must be accredited by ENAC in Spain against ISO/IEC 17021-1 (with ISO/IEC 27006 as the specific requirement for ISMS certification bodies), or by an equivalent accreditation body that is a signatory of the IAF multilateral recognition arrangement.

6. Three-year renewal and annual surveillance

  • Surveillance audit annually (years 1 and 2 of the cycle): verifies the ISMS continues working.
  • Renewal audit at year 3: similar to the initial, renews the certificate for 3 more years.

If a surveillance audit is failed or major non-conformities remain open, the certificate is suspended; recovering it requires verified corrective actions and, in serious cases, repeating Stage 2.

Project components and duration

Components involved

A full ISO 27001:2022 implementation from scratch typically includes:

  • Implementation consulting: GAP analysis, ISMS design, support to deploy the 93 Annex A controls.
  • Internal audit: independent of the implementing team; usually outsourced in small organisations.
  • Certification audit: Stage 1 (documentary review) + Stage 2 (on-site audit), carried out by an ENAC-accredited body (not Secra; you choose the body: AENOR, Bureau Veritas, TÜV Rheinland, SGS, DNV, LRQA, etc.).
  • Annual surveillance audits during the certificate's validity.
  • Renewal audit at the end of the three-year cycle.
  • Technical investment if there are major gaps (MFA, SIEM, DLP, EDR, document management). This depends entirely on your starting point.

Duration

  • Initial implementation: 5-9 months depending on prior maturity.
  • Certification: 6-10 additional weeks after finishing implementation.
  • If you already have ISO 9001 or another management ISO: the clauses 4-10 part is practically done and duration drops to 3-5 months.

Indicative timeline for an SME of 50-200 employees

  • Month 1: ISMS scope, asset inventory, interested parties and legal requirements, project plan.
  • Month 2: full risk assessment, valuation criteria and first version of the Statement of Applicability.
  • Months 3-4: drafting of policies and procedures, deployment of the most urgent controls.
  • Months 5-6: effective operation, living records, indicators being collected.
  • Month 7: internal audit, management review and closure of the organisation's own non-conformities.
  • Month 8: Stage 1 with the certification body.
  • Month 9: Stage 2; the certificate is issued 4 to 8 weeks later, after the decision of the body's technical committee.

Organisations that start from prior documentation (ISO 9001, SOC 2, ENS) shorten the calendar to 5-7 months; those starting from scratch without clear dedication can stretch to 12-15 months.

Real cost of getting certified in Spain

It helps to separate three cost blocks. The figures below are indicative ranges observed in the Spanish market for projects with external consulting; they are not a quote, and the scope of each case moves them up or down.

Implementation cost

The largest and most variable item. It depends on size, ISMS scope, prior maturity and whether the project is run with consultants or an internal team:

  • SME up to 50 employees, narrow scope: around 8,000-18,000 euros.
  • SME of 50-200 employees, medium scope: typically 15,000-35,000 euros.
  • Mid-sized company of 200-500 employees, broad scope: from 30,000-60,000 euros.

If implemented by an internal team with prior experience, external spend drops but is replaced by internal hours: budget between 300 and 600 hours of effective dedication in the first year.

External audit cost (Stage 1 + Stage 2)

Invoiced by the certification body. The amount depends mainly on auditor days, which the body calculates from the effective headcount within scope and the complexity of the ISMS, following the audit time criteria of ISO/IEC 27006:

  • SME up to 50 employees: approximately 3,000-5,500 euros for the first certification.
  • SME of 50-200 employees: 5,500-9,000 euros.
  • Mid-sized company: 9,000-18,000 euros or more depending on auditor days.

Annual surveillance audits run at around 50-60% of the initial certification cost, and the year 3 recertification sits between 70 and 85% of the initial cost.

Costs that surface during the project

  • Technical tooling supporting controls (vulnerability management, EDR, encryption, document management). Can be zero if already in place.
  • Staff training and awareness (control A.6.3).
  • Technical testing that evidences control A.8.8 on management of technical vulnerabilities: typically an annual penetration test plus periodic scans.
  • Internal audit, if outsourced.
  • Security committee and process owner time.

Adding the three blocks, an SME of 50-200 employees can expect a total first-year cost in the range of 25,000 to 60,000 euros to reach the certificate, and a recurring maintenance cost (surveillance audits, tooling, training and testing) of 8,000 to 20,000 euros in each of the following two years.

How to choose a certification body

Several ENAC-accredited bodies certify ISO/IEC 27001 in Spain: AENOR, Bureau Veritas, TÜV Rheinland, LRQA, DNV, SGS and Applus+, among others. All are formally valid: once accredited by ENAC, their certificates carry the same legal and commercial weight. The up-to-date list is available in the ENAC accredited bodies search. The real differences worth weighing:

  1. Recognition by your end client. If your main market is Spain and the public sector, AENOR has long-standing reputation; if your client is international, the multinational certification bodies have global presence.
  2. Auditors with experience in your sector. Before signing, ask which auditors are assigned, what experience they have with organisations like yours and how much of the team is in-house versus subcontracted.
  3. Cost and scheduling. Rates vary and so do calendars: some bodies have a 3-5 month waiting list for Stage 2.
  4. Combined certification. Some offer integrated audits (ISO 27001 + 27701 + 22301) that save auditor days if the package is of interest.

Accreditation is non-negotiable. Some entities issue "ISO 27001 certificates" without recognised accreditation; neither serious B2B clients nor public administrations accept them. For certificates issued under the IAF multilateral arrangement, the IAF CertSearch platform allows you to check the validity of those that accredited bodies have registered on it.

Common mistakes that fail audits

Patterns that recur in failed audits or audits with many non-conformities:

  1. A scope too ambitious for the available resources. It is better to certify a narrow scope first (one service, one site) and extend it in the next cycle than to start with everything and reach Stage 2 without evidence.
  2. A theoretical risk assessment. If treatment decisions are not reflected in budgets, projects or real configurations, the auditor notices.
  3. Lifeless documentation. Two-year-old versions, blank records or minutes reconstructed after the fact: the fastest way to lose credibility with the audit team.
  4. Skipping the internal audit or having it done by the same person who implemented the ISMS. Both situations produce a major non-conformity.
  5. Confusing consulting with certification. The same company cannot implement and certify; if you are offered both under the same seal, it is not an accredited certification.
  6. Neglecting training and awareness. Control A.6.3 fails frequently: staff who do not know the ISMS exists, do not remember the acceptable use policy or have not completed the annual awareness plan.
  7. Not testing continuity plans. A written continuity plan with no documented test exercise in the last year (control A.5.30) is an almost certain non-conformity.

Keeping the certificate: the day after

Obtaining the certificate is half the job. Keeping it for 3 years with two intermediate surveillance audits requires three disciplines:

  • Indicators that are actually measured. Clause 9.1 requires measuring ISMS performance and presenting the results at the management review. The most useful ones in SMEs: number and severity of incidents, mean time to detect and respond (the MTTD and MTTR a SOC manages), open critical vulnerabilities and mean remediation time, percentage of staff with up-to-date training and degree of completion of the treatment plan.
  • Traceable continuous improvement. Every incident, every internal audit finding and every relevant vulnerability should translate into a corrective action with an owner, a deadline and effectiveness verification (clause 10). The auditor asks to see the register and the traceability.
  • Anticipating significant changes. Scope changes, mergers, new critical cloud services, regulatory changes such as NIS2 or DORA and new threats require revisiting the risk assessment and, sometimes, updating the Statement of Applicability. Doing it between audits avoids surprises at the next one.

ISO 27001 vs ISO 27002 vs ISO 27017 vs ISO 27018

StandardWhat it isCertifiable
ISO/IEC 27001:2022ISMS requirements + Annex A of controlsYes
ISO/IEC 27002:2022Detailed implementation guide for the 93 Annex A controlsNo (guidance)
ISO/IEC 27017:2015Code of practice for cloud services, complementary to 27001Yes (extension)
ISO/IEC 27018:2019Personal data protection in cloud (PII), complementary to 27001Yes (extension)
ISO/IEC 27701:2019PIMS: Privacy Information Management System, extension of 27001Yes

The usual move: certify in 27001 and then add 27017+27018 if running cloud services, or 27701 if personal data management is critical.

What we see in our engagements

The Annex A controls that generate the most nonconformities in the stage 2 audit are incident management (A.5.24 to A.5.28), because there is no evidence of incidents handled, and management of technical vulnerabilities (A.8.8), because there is no documented patching cycle. A 50-person SME with a dedicated internal owner reaches the certificate in 12 to 16 weeks from kick-off.

Frequently asked questions

How much does ISO 27001 certification cost?

Depends on four factors: organisation size and complexity, ISMS scope (whole company or a unit/site/service), prior maturity (if you already have ISO 9001 or another management ISO, part of the ISMS is done) and technical gaps to remediate (MFA, SIEM, DLP, EDR, etc.). The external audit is contracted with an ENAC-accredited body and is independent from consulting. Indicative ranges by organisation size are in the real cost section of this article. For a budget tailored to your case, get in touch. More on related budget logic in penetration testing pricing in Spain.

How long does certification take?

Between 5 and 9 months from start to certification audit, depending on prior maturity and internal dedication. If you already have another management ISO (9001, 14001), it drops to 3-5 months.

Can the internal audit be done in-house?

Yes, as long as the internal auditor is independent from the team that implemented the ISMS. In small organisations it's usually outsourced to guarantee independence.

Which certification body to choose?

Any body accredited by ENAC in Spain (Bureau Veritas, AENOR, TÜV Rheinland, SGS, DNV, LRQA, etc.) or by an equivalent accreditation body from IAF MLA. The difference is in price, scheduling and sectoral reputation.

Does the certificate expire?

The certificate is valid for 3 years, conditional on passing the annual surveillance audits. At the end of the third year the renewal audit is carried out.

If I have ISO 27001 do I comply with NIS2?

Partially. ISO 27001:2022 covers approximately 70% of article 21 obligations of NIS2. Typical gaps are 24/72h notification, supply chain and specific board training. More in NIS2 in Spain: a compliance guide for 2026.

Can I certify only part of the organisation?

Yes. The ISMS scope gets defined in the SoA and can be a business unit, a site, a specific service. You have to be careful not to exclude critical interfaces that compromise ISMS coherence.

Is ISO 27001 mandatory?

Not by law in general terms. It is increasingly demanded as a contractual requirement in public tenders, banking, energy, healthcare, telecoms and by large companies that assess the security of their supply chain. In the context of NIS2 and DORA, certification is the most efficient way to evidence a good part of the required controls.

Is a certificate issued without ENAC accreditation worth the same?

Not for the purposes that matter in Spain. Certificates issued by bodies without ENAC accreditation (or without equivalent accreditation recognised by the IAF) are not accepted in public tenders and do not convince demanding B2B clients. Their lower price usually turns them into spend with no return.

Sources

Conclusion

The decision that most shapes the outcome is scope: certifying a narrow perimeter first with real evidence is worth more than a company-wide scope that reaches Stage 2 without records. What must be measured from month one are the clause 9.1 indicators (incidents, detection and response times, open critical vulnerabilities, up-to-date training), because they are what the auditor will ask for at the management review. The mistake that fails most certifications is lifeless documentation: flawless policies with no minutes, no independent internal audit and no executed treatment plan. If you need support with the GAP analysis, the ISMS design or the internal audit, see the GRC consulting service.

About the author

, COO and co-founder

Ethical hackers with OSCP, OSEP, OSWE, CRTO, CRTL and CARTE certifications, 7+ years of experience in offensive cybersecurity, and authors of CVE-2025-40652 and CVE-2023-3512.

Share article

👋Hi! Have any questions? Write to us, we reply in minutes.

Open WhatsApp →