ISO/IEC 27001 defines an information security management system, or ISMS. Certification is an external assessment of that system within an agreed scope. A certificate is not a promise that incidents can never occur and does not automatically cover activities outside its stated scope.
Connect five kinds of evidence
Link scope and context, information risk assessment, selected controls, evidence of operation, and evaluation with improvement. A policy without implementation cannot demonstrate operation. A technical safeguard alone does not explain how the organisation makes and reviews security decisions.
From risk to observable practice
Consider a fictional example: a former employee retains access. Record who reports departure, who removes access and who verifies completion. A departure ticket, account-removal record and review provide an evidence trail. The example illustrates a method; it is not a claim about results achieved by clients of this site.
The certification route
Move from scope and risk assessment through implementation, internal audit, management review and external assessment. Agree the stages, timetable and evidence requirements with the certification body. The eight-step roadmap gives a practical sequence.
Budget assumptions
This knowledge base uses an editorial estimate of EUR 4,000–15,000 in external first-year expenditure for a small, bounded project, excluding internal time. It is not a market average or price promise. The cost guide separates the main components. Request a quotation for your actual scope and check exclusions.
Relationship with NIS2
ISO 27001 supplies a management-system framework. NIS2 and the Dutch Cyberbeveiligingswet impose legal duties on entities within scope. Certification does not replace scope assessment, registration or incident reporting. Existing risk, supplier and incident processes can nevertheless support both kinds of work.
Where to start
Define your ISMS scope before selecting documents or software. If controls exist but evidence is fragmented, connect them to risk owners and repeatable checks. If an audit is approaching, review real examples from the relevant period. ISO develops standards but does not itself certify organisations. Neither this knowledge base nor ISO Ready issues ISO certificates.