The necessary ones make the site work. The others measure which pages help and which ads bring the people who need DM11. Your choice, and you can revisit it from the footer.
ISO/IEC 27001
It is the international standard that shows up most often in tenders, contracts and vendor questionnaires, and the only one on this list that certifies how a company manages risk rather than a technology. DM11 runs the work from scope to audit, with a senior specialist leading and your team learning to operate what remains.
DM11 prepares your company and runs the implementation. The audit and the certificate come from an accredited certification body that you contract. That separation is not our choice: whoever prepares cannot certify, and it works that way in any serious scheme.
Who runs the implementation
ISO/IEC 27001 Lead Auditor certified by BSI
ISO/IEC 27002 Foundation
17 years of governance, risk and compliance
Experience with bank and Big Four audits
WHAT IT ACTUALLY IS
ISO/IEC 27001 sets the requirements for an information security management system. It lists no tool and demands no vendor: it demands that the company know its risks, decide what to do about each one, carry out what it decided and prove that over time. This is why it fits a thirty-person fintech and a three-thousand-person manufacturer alike, and why the certificate travels across industries.
Unlike TISAX and TPN, here there is a real certificate, issued by an accredited body. It is valid for three years, with surveillance audits in between. Missing a surveillance audit costs you the certificate, so the standard rewards routine rather than a concentrated push.
The 2022 revision reorganised Annex A from 114 controls to 93, grouped into four themes instead of fourteen sections. Anyone certified under the 2013 version has already had to migrate. A proposal still talking about 114 controls is out of date.
The standard lets you define what is included: one site, one product, the whole company. Too broad and you multiply evidence, time and cost; too narrow and your customer asks why their area was left out. That conversation is the first thing we have, before any project starts.
The 93 controls are a reference, not a block obligation. The Statement of Applicability is where the company records what applies, what does not and why. A well-written exclusion carries more weight in an audit than a control implemented with no purpose.
WHEN THE DEMAND ARRIVES
In seventeen years almost every project started down one of these three roads. Recognising yours sets the scope and the timeline with the right frame.
A clause asks for the certification, or the customer's security questionnaire came back rejected. Here the deadline is theirs, not yours, and the conversation starts with what can be shown next week while the programme runs.
Tenders and RFPs list 27001 as a qualifying requirement. Without it the proposal is not even read. The scope here has to cover exactly what the tender names and nothing beyond it, so you do not pay for certification nobody asked for.
A funding round, entry into a regulated market, or an incident that gave everyone a fright. On this road the deadline is yours, and it is the cheapest scenario: the work can be done in the right order instead of the urgent one.
Translation
With ISO 27001 the scope is the decision that changes everything: which units are in, which services are in, and what stays out, written so that anyone in the company can repeat it. A smaller scope is not cheating; it is what the standard expects. A badly written scope is what stalls the audit.
| What arrives by email | What it means | What changes in the work |
|---|---|---|
| “We need you to have ISO 27001” | Incomplete request. It does not say whether the customer wants the whole company certified or only the service they buy. | Ask before quoting. Certifying the whole company when the customer only needs one service multiplies the work with no commercial gain. |
| “Certification for the service you provide us” | Service scope. It covers the people, systems and suppliers that support that service, and nothing else. | The most common and the cheapest scope. It requires drawing the boundary carefully: whatever crosses the boundary still needs control, even from outside. |
| “Corporate certification, all sites” | Organisational scope. All units, all services, all material suppliers. | Multiplies the assessment and the audit per site. It makes sense when many customers are asking, not when one is. |
| “We need the full Annex A” | A common misunderstanding. Annex A is a reference list of 93 controls, and the standard does not require all of them. | What the standard requires is a statement of applicability saying which control applies and why. Excluding with justification is normal practice. |
| “The deadline is contract renewal, four months away” | Below the minimum cycle. The standard requires a period of operation with evidence before the certification audit. | You can be ready in four months, but not certified. The honest route is a progress statement for the customer now and the certificate afterwards. |
| “We already have SOC 2, does that count?” | It does not replace it, but it does shorten it. Both ask for similar controls, in different evidence formats. | The work drops considerably: much of the evidence already exists. What is usually missing is risk management and the management review. |
None of this is price. Scope changes the effort by orders of magnitude, which is why the conversation starts there and not with a figure.
The cycle
ISO 27001 is not a single exam. Two audits to issue it, then two surveillance audits before the cycle restarts. Treat it as an event and you lose the certificate at the first surveillance, when the auditor asks for evidence from the months in between.
Certification body
The auditor checks whether the system exists on paper: scope, policy, statement of applicability, risk assessment. It ends with a list of what to fix before stage 2.
Certification body
The auditor checks whether what is written actually happens, through interviews and evidence. This is where the certificate is issued, or the nonconformity recorded.
Certification body
One shorter audit a year, covering part of the system. A major nonconformity at surveillance suspends the certificate.
Certification body
The cycle restarts, with the whole system re-examined. A company that kept the routine passes without drama; one that stopped redoes almost everything.
STORIES
We change our clients' names with the same confidentiality that will protect your company later. The names change; the pattern repeats. Where a client agrees, we give named references in a conversation.
Technology, software as a service
A large customer made renewal conditional on an ISO 27001 certificate, with a twelve-month deadline. The company had good technical practice and no management system: the security decisions lived in two people's heads and in no document at all.
We started with scope, limited to the platform that customer used rather than the whole company. In the first two months we raised technical hygiene in parallel: MFA on every critical access and a backup policy, things that improve the posture before any paperwork. Risk analysis, the Statement of Applicability and evidence collection followed.
Certified within the contract deadline. What the board did not expect was the side effect: months later the same evidence set answered the security questionnaires of two other customers, with no new project.
Manufacturing, three sites
The company was going to certify all three plants at once, because it looked simpler and more impressive. Only one of them handled the customer information behind the requirement; the other two ran production on their own designs.
We stopped the project before it started and wrote down, with the board, what the customer was actually asking for. The scope settled on one plant and the corporate processes behind it. The other two joined the management programme without joining the certificate.
Certification took far less effort. The other two plants were folded in at the following year's surveillance audit, at their own pace, and the cost spread across two financial years instead of landing in one.
Financial services
The company had bought a pack of ready-made policies from a vendor and believed it was one step from certification. The policies were good and described nothing the company actually did. In the first rehearsal interview, nobody in operations recognised the process on paper.
We rewrote the policies from what the company actually did, keeping what already worked and fixing what could not survive a question. Then we rehearsed the audit with interviews, including the people who run the process and not only those who signed it.
The rehearsal found what the audit would find, with time to fix it. At the certification audit the gap between the written process and the practised one had already closed, which is exactly what the auditor tests.
SELF-ASSESSMENT
Twenty questions about what the certification audit actually examines: clauses 4 to 10 and the 2022 Annex A controls. The full result appears on screen, with a score for each area. It is self-declared, so it works as a picture of what you know today rather than as a conformity assessment.
HOW WE RUN IT
Most certification projects spend months producing documents before anything changes in the environment. Ours accelerates technical hygiene alongside the governance, so the company is safer from the second month rather than only at the twelfth. Led by an external specialist, with one focal point from your team. Each requirement is assessed on a binary scale: met, not met, partially met or not applicable, with no subjective score nobody can defend in an audit.
We define and approve the scope and boundaries of the management system (clause 4), engage top management and set up the security committee (clause 5). In parallel we map and catalogue the critical information assets and put the basic technical hygiene in place.
Scope and boundaries of the management system approved
Security committee formed, with management engaged
Inventory of critical information assets
Information security policy approved
MilestoneScope approved, policy signed off and MFA live on 100% of critical access.
We define the risk methodology and run the gap analysis against clauses 6 and 7, with identification and assessment workshops alongside the business areas. Out of that come the risk treatment plan and the first version of the Statement of Applicability.
Risk management methodology defined and approved
Gap analysis against clauses 6 and 7
Risk treatment plan
Initial Statement of Applicability
MilestoneStatement of Applicability signed and risk matrix approved by the board.
We document and apply the operational security planning (clause 8) and formalise the complementary policies. This is where the advanced controls land: business continuity, disaster recovery and the technical testing that produces evidence a control actually works.
Operational planning documented and in use
Complementary organisational policies published
Business continuity and disaster recovery plans
Vulnerability scanning and preventive testing
MilestonePolicies published, a continuity simulation run and the first scan completed.
We run the internal audit (clause 9) with a consultant independent of whoever implemented, conduct the management review and handle the findings (clause 10). We consolidate the evidence repository and stay with you through both stages of the external audit.
Internal audit run by an independent consultant
Management review, with findings addressed
Central repository of technical evidence
Support through stage 1 and stage 2 of the external audit
MilestoneCertification audit completed and the certificate issued by the accredited body.
HOW LONG IT TAKES
We do not publish a standard timeline, because a published timeline becomes a promise, and this is a promise that depends more on you than on us. Our clients have certified at nine, at twelve and at eighteen months. What separated them is below, and the first conversation is already enough to estimate honestly.
One site and one product move far faster than the whole company. It is the variable with the largest effect on the timeline, and the only one you can settle at the very start.
A company with an asset inventory, tested backups and access control already in order effectively begins at phase two. A company without them spends the first two months building the base.
This is the variable that surprises people most. A committee that meets and decides takes months off; a committee that exists on paper stretches the project without anyone being able to point at where. The standard demands management participation for exactly this reason.
THE ROLES ARE KEPT APART
The separation shows up twice on this journey, and both times it protects you. At the external audit, the certificate comes from an accredited body you contract, never from DM11. At the internal audit required by clause 9, whoever runs it must be independent of whoever implemented: where DM11 did the implementation, the internal audit is run by a consultant who took no part in it.
DM11 prepares, implements and supports. It does not audit to certify and issues no certificate
You contract the certification body, and the choice is yours
The clause 9 internal audit is carried out by someone who did not implement
We help you compare accredited bodies, with no interest of our own in the answer
FREQUENTLY ASKED
The questions that come up in almost every first meeting, answered straight.
No, and nobody who implements is allowed to. The certificate is issued by an accredited certification body that you contract. DM11 prepares the company, implements the management system alongside your team and supports you through both stages of the external audit. That separation is a rule of the accreditation scheme rather than a choice of ours, and it is what gives the certificate its worth.
Between nine and eighteen months, and the spread is not random. Three things decide it: the size of the scope, how much is already in place, and how genuinely committed leadership is. Companies that arrive with an asset inventory, tested backups and access control in order effectively start at phase two. We can estimate honestly in the first conversation rather than repeat a brochure number.
No. Annex A is a reference, and the Statement of Applicability is where the company records what applies, what does not and the justification for each exclusion. A well-founded exclusion is accepted without difficulty in an audit; a control implemented with no purpose, just to be on the list, tends to generate more questions than its absence would.
27001 carries the requirements, and it is the one you certify against. 27002 is the guide that details how to implement each Annex A control, and it cannot be certified. In practice you certify against 27001 using 27002 as the reference manual. A proposal offering certification in 27002 has it wrong.
It counts for a good deal, and the reverse holds too. Much of the evidence serves both, because the controls overlap on access, change, continuity and suppliers. What ISO 27001 asks for on top is the management system itself: formal risk analysis, a Statement of Applicability, an internal audit and a management review. Companies with SOC 2 usually arrive with the technical work well advanced and the governance still to do.
It was, and it is a fair question. The standard fixes no team size, no document count and no departmental structure: it requires that risks be known and treated proportionately. A thirty-person company certifies with a lean management system, and a well-defined scope is what stops the project turning into multinational bureaucracy.
It lasts three years, with surveillance audits in between, usually annual. If surveillance fails, the certificate is suspended or withdrawn. That is why the last phase of our method is called sustainability: the goal is not passing the audit, it is the company being able to run the system on its own after we leave.
Failing is rare where an internal audit and a rehearsal came first, which is exactly why both sit in the method. Minor non-conformities are common and are cleared with an action plan, without losing the process. A major non-conformity requires correction and re-verification by the body. In both cases we stay with the treatment until it closes.
With the contract clause or the questionnaire in hand, we set the right scope, what you already have that counts toward it, and a timeline estimate that holds.
Comparisons on this subject
See all 13 comparisons