Skip to content
Cyber Experts

Glossary

ISO 27001

International standard that certifies the implementation of an information security management system.

ISO 27001 is the most internationally recognised cybersecurity standard. It certifies that an organisation has implemented an Information Security Management System (ISMS) covering 93 controls grouped in 4 themes: organisational, people, physical, technological.

Certification follows a two-stage process (Stage 1 and Stage 2) with an accredited body, followed by annual audits and full re-audit every 3 years. Total cost — preparation + certifier + audits — ranges from €30,000 to €100,000 for an SMB, over 12 to 18 months.

The primary value is commercial: ISO 27001 certification is increasingly required by enterprise customers and regulators. For an SMB selling to banks, insurers, large industrials, or the public sector, not being certified closes doors. Cyber Experts' Advisory engagement frames the preparation through Stage 1.