Customer requirement
Your customer requires ISO 27001 in the contract — what now?
In short
First, find out whether the customer requires a certificate from an accredited certification body or that you “work in accordance with” ISO 27001 — those are two different projects. A company with 10–100 employees and no existing management system can normally reach certification in 3–6 months if the work is run in a structured way: scope, risk assessment, Annex A controls, evidence and an internal audit before the certification body’s stage 1 and stage 2 audits. What you can promise the customer today is a timeline, a gap analysis and the first policies.
Last reviewed: September 2026
Step 1: Clarify what the customer actually requires
The contract wording sets the bar. “The supplier shall be certified to ISO/IEC 27001” means a certificate issued by an accredited body. “The supplier shall operate an information security management system in accordance with ISO/IEC 27001” can often be met with a documented management system and evidence, without an external audit. Ask what deadline applies and whether the customer will accept a timeline as a contract annex.
- Certificate required: plan for 3–6 months of work plus the certification body’s lead time.
- “In accordance with”: a management system, risk assessment and statement of applicability are often enough, but get the customer’s confirmation in writing.
- No deadline stated: propose one yourself, with the stage 1 audit as the milestone.
Step 2: Set the scope as small as is honest
The certificate covers the scope you define: which services, systems, locations and people. A SaaS supplier can often limit it to the product, the production environment and the teams working on them. A narrow but honest scope shortens the project and lowers audit cost — but the scope must cover what the customer buys from you, or the certificate is worthless in their supplier assessment.
Step 3: Gap analysis, risk assessment and controls
- 1Map the current state against the standard’s clauses 4–10 and the 93 Annex A controls. Most documentation is missing at a company that has never done this — that is normal.
- 2Do the risk assessment: which information assets you have, which threats, which consequences. The risk assessment drives which controls you choose.
- 3Write the statement of applicability (SoA): which controls apply, which do not, and why.
- 4Implement the missing controls: access control, backups, supplier requirements, incident management, training. Many already exist in your systems but lack an owner and evidence.
- 5Collect evidence continuously — not the week before the audit.
Step 4: Internal audit, management review and certification
The standard requires an internal audit and a management review before the certification audit. The certification body then performs a stage 1 audit (document review) and a stage 2 audit (does the system work in practice). Book the certification body early — lead time is often 4–8 weeks. In Sweden choose a body accredited by Swedac; many customers will not accept the certificate otherwise.
What you can tell the customer today
- A written timeline with stage 1 and stage 2 as milestones.
- The gap-analysis result and which controls are already in place.
- The first policies: information security policy, access policy, incident management.
- An offer to attach the timeline to the contract instead of delaying the deal.
How Isodora helps when a customer requires ISO 27001
Isodora reproduces the ISO 27001 requirement text verbatim under licence from SIS, runs the gap analysis against your reality and keeps requirement, control, owner and evidence linked so the auditor sees the whole chain. The platform costs SEK 500 a month plus SEK 1,200 a month for the ISO 27001 project.
Gap analysis in days, not weeks
Import what you already have, answer questions about the business and get a prioritised list of what is missing against each requirement.
Documents auditors recognise
Policies, risk assessment and statement of applicability are generated against the requirement text and owned by you — no consultant’s binder.
Evidence collected continuously
Automated controls against your systems time-stamp evidence so the stage 2 audit is not a reconstruction.
Answers for the customer meanwhile
Trust Center and exportable status reports let you show progress while the project is under way.
Isodora prepares and maintains your management system. The certificate is issued by an accredited certification body after its own audit. No software can guarantee certification.
Frequently asked questions
- How fast can a small company get ISO 27001 certified?
- With a structured process and a tool that keeps requirements, controls and evidence together, 3–6 months is realistic for a company with 10–100 employees. Add the certification body’s lead time, often 4–8 weeks to book stage 1.
- Do we need a consultant?
- No. The standard does not require one, only that the management system meets the requirements. Consultants are common when nobody in the company can free up time, but cost SEK 80,000–300,000 according to public Swedish price guides. Many 10–100-person companies run the project themselves with a platform and buy a few hours of review when needed.
- What do we tell the customer while we work towards certification?
- Give a written timeline with stage 1 and stage 2 as milestones, the gap-analysis result and the policies already in place. Offer to attach the timeline to the contract. Most customers accept that once they see the work is under way.
- Is our cloud provider’s SOC 2 or ISO 27001 enough?
- No. Your provider’s certificate covers their service, not how you use it. The customer wants evidence of your management system. You can, however, reuse the provider’s reports as evidence for the controls you inherit.