Skip to content

ISO 27001 certification

ISO 27001 certification externally assesses an ISMS within a defined scope. The system connects risks, controls, evidence and continual improvement.

Book an informal conversation

ISO Ready helps you align policy, risk, and evidence, without endless document churn.

Run the ISO 27001 readiness scan

ISO/IEC 27001 defines an information security management system, or ISMS. Certification is an external assessment of that system within an agreed scope. A certificate is not a promise that incidents can never occur and does not automatically cover activities outside its stated scope.

Connect five kinds of evidence

Link scope and context, information risk assessment, selected controls, evidence of operation, and evaluation with improvement. A policy without implementation cannot demonstrate operation. A technical safeguard alone does not explain how the organisation makes and reviews security decisions.

From risk to observable practice

Consider a fictional example: a former employee retains access. Record who reports departure, who removes access and who verifies completion. A departure ticket, account-removal record and review provide an evidence trail. The example illustrates a method; it is not a claim about results achieved by clients of this site.

The certification route

Move from scope and risk assessment through implementation, internal audit, management review and external assessment. Agree the stages, timetable and evidence requirements with the certification body. The eight-step roadmap gives a practical sequence.

Budget assumptions

This knowledge base uses an editorial estimate of EUR 4,000–15,000 in external first-year expenditure for a small, bounded project, excluding internal time. It is not a market average or price promise. The cost guide separates the main components. Request a quotation for your actual scope and check exclusions.

Relationship with NIS2

ISO 27001 supplies a management-system framework. NIS2 and the Dutch Cyberbeveiligingswet impose legal duties on entities within scope. Certification does not replace scope assessment, registration or incident reporting. Existing risk, supplier and incident processes can nevertheless support both kinds of work.

Where to start

Define your ISMS scope before selecting documents or software. If controls exist but evidence is fragmented, connect them to risk owners and repeatable checks. If an audit is approaching, review real examples from the relevant period. ISO develops standards but does not itself certify organisations. Neither this knowledge base nor ISO Ready issues ISO certificates.

Primary sources for this topic

Frequently asked questions

What does an ISO 27001 certificate demonstrate?
It indicates that an information security management system has been externally assessed against ISO 27001 within a stated scope. It does not guarantee that incidents cannot happen or automatically cover activities outside that scope. When using a certificate as supplier evidence, check the organisation, services, locations, edition and validity rather than relying on the logo alone.
Does certification replace NIS2 obligations?
No. Certification assesses a management system, while NIS2 and the Dutch Cyberbeveiligingswet impose legal duties on entities within scope. Registration, reporting and sector-specific obligations require their own assessment. An organisation may reuse risk, incident and supplier processes, but a certificate alone does not establish that every applicable legal requirement has been met.

Need help with the next step?

Explore support for your next step at ISO Ready. ISO Ready and this knowledge base are operated by Oosterwal Consultancy.

Explore your next step at ISO Ready

isocertificering.org is operated by Oosterwal Consultancy (oosterwal.com). ISO Ready (iso-ready.nl) has the same owner. Links to ISO Ready refer to our own commercial offering. About us (Dutch)

AI reading guide (llms.txt)