Global · Adopted by choice
ISO 27001 compliance
Information Security Management System
Nobody by law. You adopt it because buyers ask, and because it is the most widely recognised security certification outside North America.
The context
What it actually asks of you
ISO 27001 is the most widely recognised information security certification outside North America, and for most SaaS companies selling into Europe, the UK, the Middle East or APAC it is the certificate procurement asks for by name.
What it certifies is a management system, not a product. The 2022 revision covers 93 Annex A controls plus the management clauses 4 to 10, and auditors spend most of Stage 2 testing whether the system you documented is the system you actually operate.
That distinction is why compliance tooling alone does not get companies through. A platform tracks evidence very well; it does not scope your ISMS, run a defensible risk assessment, conduct your internal audit or justify a control exclusion to an auditor.
The common mistake
What teams get wrong.
It certifies a management system, not a product. Auditors assess whether you can identify and treat risk over time, which is why a tool full of green checkmarks does not get you through Stage 2.
Our scope
What we do for ISO 27001.
- 01Gap analysis against all 93 Annex A controls and Clauses 4–10
- 02ISMS scope and Statement of Applicability
- 03Risk methodology, register and treatment plan
- 04Internal audit and management review
- 05Stage 1 and Stage 2 audit support
innsecs provides security and compliance services, not legal advice, and we are not a law firm. We build the technical and organisational measures, evidence and processes these obligations require, and work alongside your counsel on legal interpretation.
Questions
ISO 27001 FAQ
Two separate numbers. Implementation support typically runs $15,000 to $30,000 at market rate, ours starts at $9,500. The certification body's audit fees are separate and paid directly to them: budget roughly $8,000 to $25,000 for Stage 1 and Stage 2, plus annual surveillance.
Three years, with surveillance audits in years one and two and a full recertification in year three. Lapsing is usually a scheduling failure rather than a control failure, which is what continuous assurance is designed to prevent.
Yes, and you generally should. A tightly drawn scope around the product, its environments and the people who touch them is faster to certify and easier to maintain. What you cannot do is exclude something and still imply it is covered.
Find out whether ISO 27001 binds you.
Bring your product, your users and your markets. We will tell you what applies, what does not, and what it takes to close the gap.
No sales sequence. A scoping call and a written proposal cost nothing.