The necessary ones make the site work. The others measure which pages help and which ads bring the people who need DM11. Your choice, and you can revisit it from the footer.
ISO/IEC 27001
It is the international standard that shows up most often in tenders, contracts and vendor questionnaires, and the only one on this list that certifies how a company manages risk rather than a technology. DM11 runs the work from scope to audit, with a senior specialist leading and your team learning to operate what remains.
DM11 prepares your company and runs the implementation. The audit and the certificate come from an accredited certification body that you contract. That separation is not our choice: whoever prepares cannot certify, and it works that way in any serious scheme.
Who runs the implementation
ISO/IEC 27001 Lead Auditor certified by BSI
ISO/IEC 27002 Foundation
17 years of governance, risk and compliance
Experience with bank and Big Four audits
WHAT IT ACTUALLY IS
ISO/IEC 27001 sets the requirements for an information security management system. It lists no tool and demands no vendor: it demands that the company know its risks, decide what to do about each one, carry out what it decided and prove that over time. This is why it fits a thirty-person fintech and a three-thousand-person manufacturer alike, and why the certificate travels across industries.
Unlike TISAX and TPN, here there is a real certificate, issued by an accredited body. It is valid for three years, with surveillance audits in between. Missing a surveillance audit costs you the certificate, so the standard rewards routine rather than a concentrated push.
The 2022 revision reorganised Annex A from 114 controls to 93, grouped into four themes instead of fourteen sections. Anyone certified under the 2013 version has already had to migrate. A proposal still talking about 114 controls is out of date.
The standard lets you define what is included: one site, one product, the whole company. Too broad and you multiply evidence, time and cost; too narrow and your customer asks why their area was left out. That conversation is the first thing we have, before any project starts.
The 93 controls are a reference, not a block obligation. The Statement of Applicability is where the company records what applies, what does not and why. A well-written exclusion carries more weight in an audit than a control implemented with no purpose.
WHEN THE DEMAND ARRIVES
In seventeen years almost every project started down one of these three roads. Recognising yours sets the scope and the timeline with the right frame.
A clause asks for the certification, or the customer's security questionnaire came back rejected. Here the deadline is theirs, not yours, and the conversation starts with what can be shown next week while the programme runs.
Tenders and RFPs list 27001 as a qualifying requirement. Without it the proposal is not even read. The scope here has to cover exactly what the tender names and nothing beyond it, so you do not pay for certification nobody asked for.
A funding round, entry into a regulated market, or an incident that gave everyone a fright. On this road the deadline is yours, and it is the cheapest scenario: the work can be done in the right order instead of the urgent one.
Translation
With ISO 27001 the scope is the decision that changes everything: which units are in, which services are in, and what stays out, written so that anyone in the company can repeat it. A smaller scope is not cheating; it is what the standard expects. A badly written scope is what stalls the audit.
| What arrives by email | What it means | What changes in the work |
|---|---|---|
| “We need you to have ISO 27001” | Incomplete request. It does not say whether the customer wants the whole company certified or only the service they buy. | Ask before quoting. Certifying the whole company when the customer only needs one service multiplies the work with no commercial gain. |
| “Certification for the service you provide us” | Service scope. It covers the people, systems and suppliers that support that service, and nothing else. | The most common and the cheapest scope. It requires drawing the boundary carefully: whatever crosses the boundary still needs control, even from outside. |
| “Corporate certification, all sites” | Organisational scope. All units, all services, all material suppliers. | Multiplies the assessment and the audit per site. It makes sense when many customers are asking, not when one is. |
| “We need the full Annex A” | A common misunderstanding. Annex A is a reference list of 93 controls, and the standard does not require all of them. | What the standard requires is a statement of applicability saying which control applies and why. Excluding with justification is normal practice. |
| “The deadline is contract renewal, four months away” | Below the minimum cycle. The standard requires a period of operation with evidence before the certification audit. | You can be ready in four months, but not certified. The honest route is a progress statement for the customer now and the certificate afterwards. |
| “We already have SOC 2, does that count?” | It does not replace it, but it does shorten it. Both ask for similar controls, in different evidence formats. | The work drops considerably: much of the evidence already exists. What is usually missing is risk management and the management review. |
None of this is price. Scope changes the effort by orders of magnitude, which is why the conversation starts there and not with a figure.
The cycle
ISO 27001 is not a single exam. Two audits to issue it, then two surveillance audits before the cycle restarts. Treat it as an event and you lose the certificate at the first surveillance, when the auditor asks for evidence from the months in between.
Certification body
The auditor checks whether the system exists on paper: scope, policy, statement of applicability, risk assessment. It ends with a list of what to fix before stage 2.
Certification body
The auditor checks whether what is written actually happens, through interviews and evidence. This is where the certificate is issued, or the nonconformity recorded.
Certification body
One shorter audit a year, covering part of the system. A major nonconformity at surveillance suspends the certificate.
Certification body
The cycle restarts, with the whole system re-examined. A company that kept the routine passes without drama; one that stopped redoes almost everything.
STORIES
We change our clients' names with the same confidentiality that will protect your company later. The names change; the pattern repeats. Where a client agrees, we give named references in a conversation.
Technology, software as a service
A large customer made renewal conditional on an ISO 27001 certificate, with a twelve-month deadline. The company had good technical practice and no management system: the security decisions lived in two people's heads and in no document at all.
We started with scope, limited to the platform that customer used rather than the whole company. In the first two months we raised technical hygiene in parallel: MFA on every critical access and a backup policy, things that improve the posture before any paperwork. Risk analysis, the Statement of Applicability and evidence collection followed.
Certified within the contract deadline. What the board did not expect was the side effect: months later the same evidence set answered the security questionnaires of two other customers, with no new project.
Manufacturing, three sites
The company was going to certify all three plants at once, because it looked simpler and more impressive. Only one of them handled the customer information behind the requirement; the other two ran production on their own designs.
We stopped the project before it started and wrote down, with the board, what the customer was actually asking for. The scope settled on one plant and the corporate processes behind it. The other two joined the management programme without joining the certificate.
Certification took far less effort. The other two plants were folded in at the following year's surveillance audit, at their own pace, and the cost spread across two financial years instead of landing in one.
Financial services
The company had bought a pack of ready-made policies from a vendor and believed it was one step from certification. The policies were good and described nothing the company actually did. In the first rehearsal interview, nobody in operations recognised the process on paper.
We rewrote the policies from what the company actually did, keeping what already worked and fixing what could not survive a question. Then we rehearsed the audit with interviews, including the people who run the process and not only those who signed it.
The rehearsal found what the audit would find, with time to fix it. At the certification audit the gap between the written process and the practised one had already closed, which is exactly what the auditor tests.
SELF-ASSESSMENT
Twenty questions about what the certification audit actually examines: clauses 4 to 10 and the 2022 Annex A controls. The full result appears on screen, with a score for each area. It is self-declared, so it works as a picture of what you know today rather than as a conformity assessment.
The reading for each area, across the three result ranges. It is the same text emailed to those who identify themselves, published here for anyone who wants to understand what the score measures before answering.
Below 50
With no written scope and no decision forum, everything else loses its reference: there is no way to say which controls apply or who answers for them. Start with a scope sentence anyone in the company can repeat, name the sites and services that are in, and write down what is left out. Then put the first management meeting in the diary, with an agenda and a record, however short.
50 to 79
The understanding is there and the formalisation is not. In practice that means the auditor will hear three different answers about where the scope ends. The cheapest step is writing down what is already consensus, approving it in a meeting and dating it. The policy is usually the easiest item to unblock, because it almost always exists already: the work is bringing it closer to what the company really does, and not the other way round.
80 or above
Scope, policy and leadership are in place. The risk in this band is the distance between the document and the people who execute: ask two people outside IT to explain what the policy requires of them. If the answer does not come, the problem is not the text, it is how it was communicated, and that shows up in the audit as an awareness non-conformity.
Below 50
This is the domain that best predicts the size of the project, and it is where a low score costs the most later. Without a risk method whose acceptance criteria were set beforehand, every risk is argued from scratch and the decisions do not hold up in front of the auditor. Without an inventory, the analysis becomes an exercise in imagination. The order that works is inventory, method, assessment, treatment plan and only then the Statement of Applicability.
50 to 79
There is material, and what is missing is the thread between the pieces. The classic symptom is a risk spreadsheet that does not speak to the treatment plan, and a plan that does not speak to the Statement of Applicability. The auditor reads the three documents together, and the inconsistency shows up in the seams. Before assessing more risk, it is worth closing the cycle on what has already been assessed, with an owner, a deadline and a recorded decision.
80 or above
The cycle is in place. From here what holds the score up is frequency: risk reassessed when the context changes, and not once a year out of obligation. It is worth checking that every exclusion in the Statement of Applicability has a justification that survives a question, because a poorly justified exclusion is the most common finding in this band.
Below 50
It is the cheapest domain to improve and one of the most visible in an audit, because the auditor tests it alone: they ask for the list of people who left in recent months and check whether the access was revoked. Start with offboarding, which is the point of greatest risk and the quickest to fix. Awareness training with a record of who completed it comes next, and it settles a good part of clause 7.
50 to 79
The pieces exist and depend on somebody remembering. A process that depends on the area giving notice fails precisely on the day nobody gave notice, and that day is the one that becomes the finding. What closes the gap is tying the trigger to a system rather than to a person. In training, what is usually missing is not the content, it is the evidence of completion.
80 or above
The people cycle is covered. What sets you apart in this band is separating competence from awareness clearly: whoever holds a defined security role has to demonstrate qualification, and the rest of the company has to understand why. An experienced auditor asks about the two in different ways.
Below 50
Here the gap is operational and quick to fix relative to the rest of the standard. In order of return: two-step authentication on administrative and remote access, then access review with a record, then remediation deadlines by severity. None of the three requires a large purchase, and all three come up in any audit.
50 to 79
The protection exists and the evidence does not. That is the difference between being secure and being able to prove it, and the audit only sees the second. An access review with no record of who reviewed it and what was removed does not count. A scan with no remediation queue being followed does not either. The work here is less technical than it looks.
80 or above
The controls operate with a record. The thing to watch in this band is the exceptions: service accounts, legacy integrations and suppliers with permanent access tend to sit outside the rule and surface late. A documented exception with a compensating control is fine; an exception nobody mapped is what becomes a finding.
Below 50
If the company is remote, much of this domain moves to the equipment outside the office and to documents on paper, and that remains your responsibility. On the supplier side, the first step is the list: who accesses your information, your systems or your network. Without that list nobody can be assessed, and it almost never exists ready-made.
50 to 79
There are contracts with clauses and no assessment before the supplier comes in, which is the order the standard expects. Assessing afterwards turns the analysis into a formality. The practical route is classifying by criticality and applying a proportional questionnaire, because assessing every supplier with the same rigour is neither sustainable nor required.
80 or above
Third-party control is mature. What is usually missing in this band is periodic reassessment of the critical ones, and the exit: a supplier whose contract ends while their access stays live is a silent finding, and the test is the same one used when people leave.
Below 50
With no incident record there is no history, and with no history there is no demonstrable improvement, which is what clause 10 asks for. Start by recording what never became a crisis too, because it is the small volume that builds the series. On the continuity side, the first exercise does not have to be big: restoring one backup and recording the result already answers the most important question.
50 to 79
The team knows how to act and the organisation cannot prove it. A written process with defined roles is what separates a response that depends on the right people being available from one that works on a public holiday. If the plans exist and have never been exercised, the exercise is worth more than any improvement to their wording.
80 or above
The process and the exercise exist. From here the value is in closing the loop: every relevant incident should change something, a control, a playbook or a piece of training. Auditors ask what changed after the last incident, and the absence of an answer weighs more than the incident itself.
Below 50
It is the domain that delays certification most, and the reason is that it cannot be settled with a concentrated push: the internal audit, the management review and the treatment of non-conformities have to have happened, with dates. If the certification has a deadline, this is the item to start now, even with the rest still under construction, because it is the only one that will not be compressed at the end.
50 to 79
There is review, and what is missing is independence or the record. Whoever implemented cannot see their own flaw, and the standard treats that as a requirement. If there is no independent person inside, the usual route is an internal audit run by a third party who took no part in the implementation. On the leadership side, receiving a report is not a management review: what the standard asks for is a recorded decision.
80 or above
The improvement cycle is alive, and it is what protects the certificate most over time. The thing to watch is the effectiveness check: recording the action is common, verifying months later that it worked is rare, and it is exactly what the auditor looks for when testing the maturity of the system.
HOW WE RUN IT
Most certification projects spend months producing documents before anything changes in the environment. Ours accelerates technical hygiene alongside the governance, so the company is safer from the second month rather than only at the twelfth. Led by an external specialist, with one focal point from your team. Each requirement is assessed on a binary scale: met, not met, partially met or not applicable, with no subjective score nobody can defend in an audit.
We define and approve the scope and boundaries of the management system (clause 4), engage top management and set up the security committee (clause 5). In parallel we map and catalogue the critical information assets and put the basic technical hygiene in place.
Scope and boundaries of the management system approved
Security committee formed, with management engaged
Inventory of critical information assets
Information security policy approved
MilestoneScope approved, policy signed off and MFA live on 100% of critical access.
We define the risk methodology and run the gap analysis against clauses 6 and 7, with identification and assessment workshops alongside the business areas. Out of that come the risk treatment plan and the first version of the Statement of Applicability.
Risk management methodology defined and approved
Gap analysis against clauses 6 and 7
Risk treatment plan
Initial Statement of Applicability
MilestoneStatement of Applicability signed and risk matrix approved by the board.
We document and apply the operational security planning (clause 8) and formalise the complementary policies. This is where the advanced controls land: business continuity, disaster recovery and the technical testing that produces evidence a control actually works.
Operational planning documented and in use
Complementary organisational policies published
Business continuity and disaster recovery plans
Vulnerability scanning and preventive testing
MilestonePolicies published, a continuity simulation run and the first scan completed.
We run the internal audit (clause 9) with a consultant independent of whoever implemented, conduct the management review and handle the findings (clause 10). We consolidate the evidence repository and stay with you through both stages of the external audit.
Internal audit run by an independent consultant
Management review, with findings addressed
Central repository of technical evidence
Support through stage 1 and stage 2 of the external audit
MilestoneCertification audit completed and the certificate issued by the accredited body.
HOW LONG IT TAKES
We do not publish a standard timeline, because a published timeline becomes a promise, and this is a promise that depends more on you than on us. Our clients have certified at nine, at twelve and at eighteen months. What separated them is below, and the first conversation is already enough to estimate honestly.
One site and one product move far faster than the whole company. It is the variable with the largest effect on the timeline, and the only one you can settle at the very start.
A company with an asset inventory, tested backups and access control already in order effectively begins at phase two. A company without them spends the first two months building the base.
This is the variable that surprises people most. A committee that meets and decides takes months off; a committee that exists on paper stretches the project without anyone being able to point at where. The standard demands management participation for exactly this reason.
THE ROLES ARE KEPT APART
The separation shows up twice on this journey, and both times it protects you. At the external audit, the certificate comes from an accredited body you contract, never from DM11. At the internal audit required by clause 9, whoever runs it must be independent of whoever implemented: where DM11 did the implementation, the internal audit is run by a consultant who took no part in it.
DM11 prepares, implements and supports. It does not audit to certify and issues no certificate
You contract the certification body, and the choice is yours
The clause 9 internal audit is carried out by someone who did not implement
We help you compare accredited bodies, with no interest of our own in the answer
FREQUENTLY ASKED
The questions that come up in almost every first meeting, answered straight.
No, and nobody who implements is allowed to. The certificate is issued by an accredited certification body that you contract. DM11 prepares the company, implements the management system alongside your team and supports you through both stages of the external audit. That separation is a rule of the accreditation scheme rather than a choice of ours, and it is what gives the certificate its worth.
Between nine and eighteen months, and the spread is not random. Three things decide it: the size of the scope, how much is already in place, and how genuinely committed leadership is. Companies that arrive with an asset inventory, tested backups and access control in order effectively start at phase two. We can estimate honestly in the first conversation rather than repeat a brochure number.
No. Annex A is a reference, and the Statement of Applicability is where the company records what applies, what does not and the justification for each exclusion. A well-founded exclusion is accepted without difficulty in an audit; a control implemented with no purpose, just to be on the list, tends to generate more questions than its absence would.
27001 carries the requirements, and it is the one you certify against. 27002 is the guide that details how to implement each Annex A control, and it cannot be certified. In practice you certify against 27001 using 27002 as the reference manual. A proposal offering certification in 27002 has it wrong.
It counts for a good deal, and the reverse holds too. Much of the evidence serves both, because the controls overlap on access, change, continuity and suppliers. What ISO 27001 asks for on top is the management system itself: formal risk analysis, a Statement of Applicability, an internal audit and a management review. Companies with SOC 2 usually arrive with the technical work well advanced and the governance still to do.
It was, and it is a fair question. The standard fixes no team size, no document count and no departmental structure: it requires that risks be known and treated proportionately. A thirty-person company certifies with a lean management system, and a well-defined scope is what stops the project turning into multinational bureaucracy.
It lasts three years, with surveillance audits in between, usually annual. If surveillance fails, the certificate is suspended or withdrawn. That is why the last phase of our method is called sustainability: the goal is not passing the audit, it is the company being able to run the system on its own after we leave.
Failing is rare where an internal audit and a rehearsal came first, which is exactly why both sit in the method. Minor non-conformities are common and are cleared with an action plan, without losing the process. A major non-conformity requires correction and re-verification by the body. In both cases we stay with the treatment until it closes.
With the contract clause or the questionnaire in hand, we set the right scope, what you already have that counts toward it, and a timeline estimate that holds.
Comparisons on this subject
See all 13 comparisonsISO/IEC · ISO/IEC 27001:2022, edição 3, com a emenda 1:2024 · accessed on
ISO/IEC · ISO/IEC 27701:2025, edição 2, publicada em outubro de 2025 · accessed on
NIST, instituto nacional de padrões e tecnologia dos Estados Unidos · NIST CSWP 29, publicado em 26/02/2024 · accessed on
This page is informational and describes how DM11 reads and applies the sources above. It does not reproduce the text of any standard, does not replace reading the official document, and does not replace an audit, a certification, an independent assessment or legal advice. Where a standard requires formal assessment, it is carried out by an accredited body, auditor or assessor, always separate from whoever did the preparation.