StructureClerk

ISO/IEC 27001

Also known as: ISO 27001 · information security management system · ISMS

ISO/IEC 27001 is the international standard for information security management: it certifies that an organization manages its security risks through a documented process.

It certifies a management system, not a product. The certificate does not claim an application is secure; it claims the organization identifies its risks, selects controls, applies them and reviews them.

The core of the work is the statement of applicability: for each control listed in the annex, the organization says whether it applies, how it is implemented, or why it is excluded.

It is the certification most often demanded in international tenders, frequently before anyone looks at the product.

What it means for a small business

The real cost is not the audit, it is the internal preparation time. Many small companies start by answering the requirements honestly without pursuing the certificate, which already unlocks a good share of customer questionnaires.

So what actually applies to you?

A definition tells you what a term means, not what your organization must do. The assessment answers the second question — free, no credit card.

Updated September 1, 2026 · Educational definition; not legal advice.