Your Customer Wants ISO 27001. What Happens Next?
What to do when a client, tender or security questionnaire says you need ISO 27001: what is really being asked, what it involves, and what it costs in time.
By Julian Russell, Managing Director
Lead Auditor: ISO 9001, ISO 14001, ISO 27001, ISO 45001 and ISO 50001
The short answer. Most organisations do not decide to pursue ISO 27001. They are told to, by a customer, a tender or a security questionnaire. Before committing, establish exactly what is being asked, because "ISO 27001" in a procurement document can mean three quite different things.
Very few businesses wake up wanting an information security management system. What usually happens is that a contract renewal arrives with a security schedule attached, or a tender lists ISO 27001 under mandatory requirements, or a prospect's IT team sends over a questionnaire with a certification question near the top.
If that is where you are, this page is about what to do next rather than what the standard contains. For the standard itself, see our ISO 27001 guide.
First, find out what is actually being asked
"You need ISO 27001" can mean at least three different things, and they carry very different costs.
Certification. A UKAS-accredited certificate covering a defined scope. This is the most common requirement in formal tenders and the most demanding.
Alignment. Some contracts ask you to operate "in accordance with" or "aligned to" ISO 27001 without requiring a certificate. That is a materially lower bar, and often satisfied with documented controls and evidence.
Something else entirely. A surprising number of security questionnaires name ISO 27001 when what the buyer actually wants is Cyber Essentials Plus, a completed SIG or CAIQ questionnaire, or a SOC 2 report. These are not interchangeable, and buying the wrong one is expensive.
Ask the buyer directly, in writing, which of these they need and by when. It is a reasonable question, it does not weaken your position, and the answer determines everything that follows.
Second, work out your scope
Scope is the single biggest driver of cost and effort, and it is where most people either overreach or get caught out later.
Your certificate covers a defined boundary: which parts of the organisation, which locations, which services and which information assets. A scope covering one product line and one office is a fundamentally different project from one covering a whole group.
Two failure modes. Scoping too narrowly to save money produces a certificate that does not cover the service the customer is buying, and procurement teams do read the scope statement. Scoping too broadly turns a six-month project into an eighteen-month one for no commercial gain.
The right scope is the smallest one that genuinely covers what your customer is buying.
Third, be realistic about the timeline
For an organisation starting from nothing, a first certification typically takes six to twelve months. That breaks down roughly as:
- establishing scope, context and the risk assessment method
- running the risk assessment and selecting controls
- writing and implementing the policies and procedures that follow from it
- operating the system long enough to generate records, which is the part people forget
- an internal audit and a management review, both of which the certification body will expect to see
- the Stage 1 and Stage 2 certification audits
That fifth point is the one that catches people. A certification body needs evidence that the system has actually run, not just that documents exist. You cannot compress that below a few months, whatever else you accelerate.
If your customer's deadline is shorter than this, say so early. A credible plan with dates usually holds a contract better than a missed deadline does.
What it gets you beyond the contract
Organisations that go into this purely to satisfy one customer often find the wider return is the part they did not budget for.
Fewer security questionnaires. Once certified, you can frequently answer with your certificate and Statement of Applicability instead of completing a fifty-question spreadsheet for every prospect. For businesses selling into enterprise or public sector, this alone can justify the exercise.
A defensible position after an incident. Certification does not stop attacks. What it gives you is documented evidence that you identified risks, selected proportionate controls and reviewed them, which matters considerably in the aftermath of a breach.
Scale without fragmentation. Ad hoc security decisions taken as each situation arises tend to produce gaps. A management system gives you a structure that grows with the organisation.
A genuine gap analysis. Almost every organisation that runs a proper risk assessment finds something it did not know about. That is uncomfortable and useful in equal measure.
"We saw achieving ISO 27001 as a vital part of our risk management strategy and continuous improvement programme. For us it was important from a regulatory, professional and commercial perspective to ensure our information security systems within the business were robust."
Tamsin Cooper, Partner, Risk and Compliance, Langleys Solicitors
What it does not do
Worth being straight about, because it is oversold.
ISO 27001 does not make you GDPR compliant. The two overlap substantially and a well-run ISMS supports data protection compliance, but they are separate regimes with separate requirements, and no certification body certifies GDPR compliance.
It does not reduce the number of attacks you face. It reduces the likelihood that they succeed and the damage when one does.
And it does not, on its own, satisfy every buyer. Some will still send the questionnaire.
Where to go next
For what the standard requires, see our ISO 27001 guide. If certification needs to be accredited to count with your customer, and it usually does, read accredited vs non-accredited certification.
If you have a deadline and want a realistic view of whether it is achievable, see our implementation support or get in touch.
If your customer's questions are as much about service levels, incident handling and change control as they are about security, they may also value ISO 20000-1, the international standard for IT service management.
Frequently asked questions
How long does ISO 27001 certification take?
For an organisation starting from nothing, typically six to twelve months. The limiting factor is usually not writing the documentation but operating the system long enough to generate the records a certification body expects to see, including an internal audit and a management review.
Does ISO 27001 make us GDPR compliant?
No. The two overlap substantially and a well-run information security management system supports data protection compliance, but they are separate regimes and no certification body certifies GDPR compliance. Treat ISO 27001 as strong supporting evidence rather than proof.
Our customer asked for ISO 27001. Do we definitely need the certificate?
Not always. Some contracts require certification, others ask you to operate in accordance with the standard, and some name ISO 27001 when they actually want Cyber Essentials Plus or a SOC 2 report. Ask the buyer in writing which they need before committing budget.
What should our ISO 27001 scope cover?
The smallest boundary that genuinely covers the service your customer is buying. Scoping too narrowly produces a certificate procurement teams will reject once they read the scope statement. Scoping too broadly adds months and cost for no commercial gain.
Is ISO 27001 the same as Cyber Essentials?
No. Cyber Essentials is a UK government-backed scheme covering a defined set of technical controls and is quicker and cheaper to obtain. ISO 27001 is an international management system standard covering governance, risk assessment and continual improvement as well as controls.
