ISO 27001 is the international standard for managing information security. Rather than a one-off checklist, it asks you to build and run a simple, documented system for keeping information safe, then have an independent auditor confirm it is real. This guide explains what that involves for a smaller business, and links every SecurSentry guide on the topic.
ISO 27001 is the international standard for an Information Security Management System, a documented, repeatable way of managing the security of the information your business holds. It is broader than any single technical control. It covers how you govern security, how you assess risk, the policies you set, the way you handle people and suppliers, and how you check that all of it is actually working. For the full picture for a smaller business, start with ISO 27001 for SMEs.
The shift to understand is that ISO 27001 is not a product you buy or a box you tick once. It asks you to build a system and then keep it running, and a certificate is issued only after an independent auditor has confirmed that the system is real and operating. That is what gives the certificate its weight with customers and procurement teams.
It also scales to your size and risk. A small business does not need the machinery of a large enterprise; it needs the same disciplines, done proportionately. For many smaller firms the sensible order is Cyber Essentials first, then ISO 27001 when a customer or a market genuinely asks for it. We set out that comparison in Cyber Essentials vs ISO 27001.
Strip away the jargon and an ISO 27001 project comes down to building, running and proving a handful of things. Each is a guide of its own below.
Do these well and the certificate follows. The effort is real, but much of it is work that also makes the business genuinely safer, and that carries across to other checks customers ask about.
Start wherever your question is. Each guide is a short, plain-English read, and they build on each other as you go.
Start here
What the standard asks
What the standard actually requires, from the mandatory clauses to the controls you select.
The 93 controls across four themes, and why you only implement the ones your risks call for.
A proportionate, repeatable way to assess and treat information security risk without overcomplicating it.
Getting certified
A plain-English, do-it-in-order path from where you are to ready for the certification audit.
The whole journey step by step, from scope to certificate, and how long the work tends to take.
Stage 1, Stage 2, surveillance and your own internal audit, explained without the mystery.
The security ISO 27001 asks for is the same everyday security work customers ask about and other standards expect. Do it once and write it down, and the same effort supports a certification, answers a questionnaire and keeps personal data safe. We're building SecurSentry around exactly that.
ISO 27001 is the international standard for managing information security. Rather than a single control or a one-off test, it asks you to build a documented, repeatable system for keeping information safe (an Information Security Management System), run it, and have an independent auditor confirm it works. The certificate is recognised by customers and procurement teams as evidence that your security is genuine and maintained.
It is worth it when customers or your market genuinely ask for it, for example enterprise buyers or a regulated supply chain that treats it as table stakes. If no one has asked, you may be buying ahead of need. For many smaller firms the sensible order is Cyber Essentials first, which is faster and far cheaper, with much of the groundwork carrying forward into an eventual ISO 27001 project.
The 2022 version of the standard lists 93 reference controls in Annex A, organised into four themes: organisational, people, physical and technological. You are not required to implement all of them. You select the controls that your risk assessment shows are relevant, and record which you have included or excluded, and why, in a document called the Statement of Applicability.
You build and run the management system, then an accredited certification body audits it in two stages: a Stage 1 review of your documentation and readiness, then a Stage 2 audit of how it works in practice. If you pass, a certificate is issued, typically valid for three years, with annual surveillance audits in between and a recertification audit at the end of the cycle. In the UK, look for a UKAS-accredited certification body.