ISO 27001 Certification: ISMS & Buyer Sharing¶
As of the ISO Survey 2023, there were 71,549 valid ISO 27001 certificates across 175 countries — making it the second most adopted ISO management system standard after ISO 9001. In a 2024 Vanta survey, 78% of companies reported that ISO 27001 certification directly helped them close deals faster. The transition from ISO 27001:2013 to ISO 27001:2022 completed in October 2025, and any organization still holding a certificate against the 2013 version must now recertify against the updated standard. The market message is unambiguous: in B2B procurement, ISO 27001 has become less a security posture indicator and more a market access prerequisite.
ISO 27001 is the international standard for Information Security Management Systems (ISMS). For B2B companies — SaaS platforms, IT service providers, cloud infrastructure companies, and any organization handling client data — it is the single most requested compliance credential in vendor assessments. On the Sustalium platform, we see the real bottleneck is rarely the technical controls themselves — it is the inability to produce the certificate, Statement of Applicability, and audit reports in a single verifiable package when procurement asks for them.
What ISO 27001 Actually Requires¶
ISO 27001:2022 (the current version) specifies the requirements for establishing, implementing, maintaining, and continually improving an ISMS. It is not a checklist of technical controls — it is a management system standard that defines how you govern information security.
The standard is structured around four mandatory clauses (Clauses 4–7 define the context, leadership, planning, and support of the ISMS; Clauses 8–10 define operation, performance evaluation, and improvement) and Annex A, which contains 93 controls organized into four themes:
| Annex A Theme | Number of Controls | Focus |
|---|---|---|
| Organizational | 37 controls | Policies, roles, supplier security, incident management, business continuity |
| People | 8 controls | Screening, awareness, disciplinary process, remote working |
| Physical | 14 controls | Secure areas, equipment, cabling, clear desk, storage media |
| Technological | 34 controls | Access control, cryptography, secure development, network security |
Core Documentation Requirements¶
To achieve ISO 27001 certification, you must produce and maintain:
- ISMS Scope: A documented definition of what parts of your organization the ISMS covers.
- Information Security Policy: The top-level policy approved by management.
- Risk Assessment and Treatment Plan: A systematic assessment of information security risks and the controls selected to treat them.
- Statement of Applicability (SoA): The document every external auditor and B2B buyer requests. It lists all 93 Annex A controls and states whether each is applicable, implemented, and effective — with justification for any exclusions.
- Risk Treatment Plan: The plan for implementing the selected controls, including owners, timelines, and resources.
- Internal Audit Program and Results: Evidence of regular internal audits of the ISMS.
- Management Review Minutes: Evidence that top management reviews the ISMS at planned intervals.
The Certification Process¶
ISO 27001 certification is not self-declared — it must be awarded by an accredited certification body. The process typically follows three stages:
Stage 1: Documentation Review¶
The auditor reviews your ISMS documentation — scope, policy, risk assessment, SoA — to determine whether it meets the standard's requirements. Many organizations fail at this stage because their SoA is incomplete or their risk assessment does not demonstrate a systematic methodology.
Stage 2: Implementation Audit (Certification Audit)¶
The auditor verifies that your ISMS has been implemented as documented and is effective. They will sample evidence: checking that access control reviews actually happened, interviewing staff about security awareness, and tracing a risk from identification through to treatment. A successful Stage 2 audit results in certification.
Ongoing: Surveillance Audits¶
Certification is valid for three years, but the certification body conducts annual surveillance audits to confirm ongoing compliance. Missing a surveillance audit or failing to close identified nonconformities can result in certification suspension or withdrawal.
Why B2B Procurement Teams Demand ISO 27001¶
From the buyer's perspective, ISO 27001 certification serves a specific purpose: it transfers the cost of initial security assessment from the buyer to a trusted third party (the accreditation body). Instead of sending you a 200-question security assessment spreadsheet, the buyer asks for three documents:
- The ISO 27001 certificate (valid, from an accredited body)
- The Statement of Applicability (to verify which controls you have implemented)
- The latest surveillance audit report (to confirm the certification is actively maintained)
If these three documents are available and current, many procurement teams will significantly reduce or eliminate their supplementary security assessment — saving both sides weeks of back-and-forth.
How Sustalium Makes ISO 27001 Work for Buyer Relationships¶
Getting certified is the hard part. But the daily operational reality — responding to dozens of vendor assessments, sharing certificates, and keeping documentation current — is where most certified companies stumble.
Sustalium's ISO 27001 compliance module is built for the buyer-facing side of certification:
- Instant Certificate Sharing: Upload your ISO 27001 certificate, SoA, and audit reports once. Sustalium generates a public-facing verification URL that buyers can access directly — eliminating the email-PDF loop entirely.
- Integrated Compliance Profile: Your ISO 27001 documentation sits alongside your GDPR declarations, NIS2 cybersecurity compliance, and any other frameworks relevant to your buyer base. One link covers multiple procurement requirements.
- Expiry and Audit Tracking: Sustalium tracks your certification expiry date, surveillance audit schedule, and key control review dates. You get automated reminders before anything lapses — preventing the nightmare scenario of a lapsed certificate discovered during a buyer audit.
- Supplier and Buyer Portals: If you manage supplier ISO 27001 requirements, Sustalium provides a portal where your suppliers can upload their certificates and SoAs, mapped to your internal risk assessment framework.
Stop Losing Deals Over Discoverable Compliance
The most common ISO 27001 failure isn't security — it's discoverability. Make your certificate, SoA, and audit reports instantly accessible to every buyer that asks.
With Sustalium, build your ISO 27001 documentation profile for just €10 per document.
Frequently Asked Questions¶
Can I self-declare ISO 27001 compliance?
No. ISO 27001 certification must be awarded by an accredited certification body after passing both Stage 1 and Stage 2 audits. Self-declaration has no standing with buyers or auditors. Only an accredited third-party certificate is recognized in B2B procurement.
How long does ISO 27001 certification take?
For a typical SME, 6 to 12 months from scoping to Stage 2 audit completion. The timeline depends on the maturity of existing security practices, the complexity of your ISMS scope, and whether you use external consultants to accelerate documentation. Implementing an ISMS from scratch in under 6 months is unrealistic for most organizations.
What is the difference between ISO 27001 and SOC 2?
ISO 27001 is an international standard for building and certifying an entire information security management system. SOC 2 is a US-specific attestation report focused on controls relevant to service organizations. ISO 27001 certifies the system; SOC 2 reports on the effectiveness of specific controls at a point in time. Many B2B companies maintain both to cover EU and US buyer requirements.
How often do surveillance audits occur?
Annually. The certification body must conduct a surveillance audit at least once per calendar year during the three-year certification cycle. Missing a surveillance audit can result in certification suspension.
Last updated: July 14, 2026