Compliance · Certifiable standard

ISO/IEC 27001 — information security management

The international standard your global customers recognize.

ISO/IEC 27001 certifies that you run a working information security management system (ISMS) — not just a pile of controls, but a governed cycle of risk assessment, treatment, measurement, and improvement. It's the security credential most recognized outside the US.

93

Annex A controls (2022)

3 yr

Certification cycle

Stage 1+2

Audit structure

What ISO 27001 requires

The controls get the attention, but auditors certify the management system. Most first-time failures are governance gaps, not missing tools.

A real ISMS

Scope, leadership commitment, objectives, risk assessment and treatment, internal audit, and management review. The clauses are the standard; Annex A is the control menu you select from.

Annex A (2022)

The 2022 revision restructured controls into 93 across four themes — organizational, people, physical, and technological — including cloud services, threat intelligence, and data masking.

Statement of Applicability

The SoA documents which Annex A controls apply, which don't, and why. It's the spine of the audit, and the document auditors read first.

Who needs ISO 27001

Anyone selling internationally, or into industries where it's table stakes.

  • Companies selling into the EU, UK, Middle East, or APAC
  • Vendors whose RFPs specify ISO 27001 certification
  • Organizations that want one framework to anchor everything else
  • Providers standardizing security across multiple business units

How intSignal gets you there

We do the readiness, build and run the controls, and support you through the audit — we are not the auditor, and we keep that separation deliberate.

Gap assessment

We measure your current state against the clauses and Annex A, and tell you honestly how far certification is.

ISMS build

We stand up the management system — scope, roles, objectives, and the cadence that keeps it alive after the auditor leaves.

Risk assessment & treatment

We run a defensible risk methodology and produce a treatment plan that drives control selection, rather than the reverse.

Statement of Applicability

We build the SoA with justifications that hold up under questioning.

Control implementation

We close technical and organizational gaps across identity, logging, change, vendors, and physical security.

Audit support

We prepare you for Stage 1 and Stage 2, run internal audit and management review, and support surveillance audits.

How the engagement runs

1

Scope & gap

Define the ISMS boundary and assess against clauses + Annex A.

2

Risk & SoA

Run the risk assessment, choose controls, write the SoA.

3

Implement

Close gaps and put the governance cadence into operation.

4

Internal audit

Audit yourself and hold management review — both are mandatory.

5

Certification

Stage 1 documentation review, Stage 2 effectiveness audit, then surveillance.

Frequently asked questions

How long does ISO 27001 certification take?

For most mid-sized organizations, 4–9 months from kickoff to Stage 2 — driven mostly by how much of the management system already exists. The ISMS also needs to have actually operated (internal audit and management review completed) before certification.

Is intSignal the certification body?

No. Certification must come from an accredited certification body, which has to be independent of the people who built your ISMS. intSignal builds and runs the ISMS, closes the gaps, and prepares you for audit — and we help you select an accredited body.

ISO 27001 or SOC 2 — which first?

Follow your buyers. US-centric B2B usually asks for SOC 2; international and enterprise RFPs ask for ISO 27001. If you'll eventually need both, ISO 27001 makes a strong backbone because its ISMS governance carries most of SOC 2's requirements.

What changed in the 2022 version?

Annex A was restructured from 114 controls into 93 across four themes, with new controls covering areas like cloud services, threat intelligence, secure coding, and data masking. Existing certificates transitioned to the 2022 revision, and new certifications use it.

Does certification ever expire?

Certificates run on a three-year cycle with annual surveillance audits, then recertification. Skipping the governance cadence between audits is the most common way organizations lose certification.

Other frameworks we support

Most of the work transfers. Once controls are mapped and evidenced, a second framework costs a fraction of the first.

ISO 27001 for your environment

Tell us where you are and who’s asking for it — we’ll come back with scope, gaps, and a realistic timeline.