ISO 27001 for international assurance
When SOC 2 doesn't satisfy an enterprise or international customer, ISO 27001 usually does. We build the information security management system (ISMS) the certification body actually audits, not just the binder they expect to see.
Who this applies to
Companies selling into Europe, Asia, or any market where ISO certification is the recognized standard, and US companies whose enterprise customers ask for it specifically instead of, or in addition to, SOC 2. Many organizations end up holding both.
What certification actually requires
ISO 27001 certifies an ISMS: a management system for identifying information security risks and treating them, not a fixed checklist. The current revision organizes controls into 93 items across organizational, people, physical, and technological categories (Annex A), selected based on your own risk assessment rather than applied uniformly.
Certification runs through an accredited external body in two stages: a documentation review (Stage 1), then an on-site or remote audit of whether the controls actually operate (Stage 2). Certificates run on a 3-year cycle with annual surveillance audits in between, which is where a lot of companies lose momentum without a maintained evidence trail.
How we help
Snapshot Assessment
Risk assessment and gap analysis against Annex A, scoped to the controls your risk profile actually requires. $9,500, 2 to 3 weeks.
ISMS build-out
Risk treatment plan, Statement of Applicability, and the policy and procedure set a certification body expects to see, tied to real technical controls.
Certification audit prep
Internal audit dry runs before Stage 1 and Stage 2, and a surveillance-audit rhythm so year two and three don't start from scratch.
Frequently asked questions
Do we need both SOC 2 and ISO 27001?
Only if your customer base genuinely spans both expectations. Many US-focused SaaS companies start with SOC 2 and add ISO 27001 later once international or larger enterprise customers ask for it specifically. Because both draw on similar underlying controls, adding the second is usually incremental, not a rebuild.
How long does certification take?
Most companies take 6 to 12 months from a standing start, largely driven by how mature your existing security controls already are and certification body scheduling.
What happens at the annual surveillance audit?
A narrower check that your ISMS is still operating as certified, not a full re-audit. Companies with a maintained evidence trail treat this as routine; companies without one relive the original certification stress every year.
Scope your path to certification
A short conversation covers your current controls, target market, and a realistic certification timeline.