
We wouldn’t have been able to get ISO 27001 compliant, without Scrut’s help and expertise.
Manage ISO 27001 compliance without relying on spreadsheets and manual follow-ups.


































We wouldn’t have been able to get ISO 27001 compliant, without Scrut’s help and expertise.


Scrut was key during our ISO 27001:2022 transition, as the platform and their support made everything faster and smoother for our team.


Compliance with SOC 2 and ISO 27001 delivered without hassle, guesswork, or drama.

Connect Scrut to your tech stack via native integrations

Run automated tests across your tech stack and map relevant controls

Tailor controls to your environment and surface gaps

Enjoy continuous monitoring and 24/7 audit readiness
ISO/IEC 27001 is the international standard for building and operating an information security management system (ISMS). It requires organizations to identify and manage their information security risks rather than follow a fixed checklist of security tools.
The current edition is ISO/IEC 27001:2022. Amendment 1:2024 requires organizations to determine whether climate change is a relevant issue. The 2013 edition has been withdrawn, and accredited certificates referring only to ISO/IEC 27001:2013 are no longer valid.
An ISMS combines the policies, processes, roles, controls, and recurring activities an organization uses to manage information security risk.
It is an operating management system, not merely a folder of policies or a software tool. Auditors look for evidence that it works in practice.
Certification gives customers, procurement teams, and other stakeholders independent evidence that your ISMS meets the standard’s requirements. It may also be required for contracts, tenders, or regulatory purposes.
Certification applies only to the scope stated on the certificate and does not guarantee that you will never experience a security incident. You can implement ISO/IEC 27001 without seeking certification if third-party assurance is not required.
Two things to know before choosing a certification body. First, ISO and IEC publish the standard but do not conduct audits or issue certificates. Independent certification bodies do that.
Second, not every certification body is accredited. Accreditation is granted by accreditation bodies such as UKAS, ANAB, and DAkkS and provides independent confirmation of the certification body’s competence. An unaccredited certificate may not be accepted during enterprise procurement.
Do not rely on the accreditation mark alone. Verify the certification body’s accreditation for ISO/IEC 27001 in the relevant accreditation body’s directory before signing a contract.
ISO/IEC 27001 contains the ISMS requirements against which organizations are certified. ISO/IEC 27002 provides guidance for selecting and implementing information security controls.
Organizations can be certified to ISO/IEC 27001, but not to ISO/IEC 27002.
Any organization can seek certification, regardless of its size, sector, or country. This includes startups, enterprises, nonprofits, and public-sector organizations.
Certification is generally voluntary, but it may be required by a customer, contract, tender, applicable law, or regulator.
No. ISO/IEC 27001 certifies an organization’s ISMS within a defined business scope, not an individual.
Individuals can earn credentials such as Lead Implementer or Lead Auditor. Some are issued by personnel-certification bodies accredited to ISO/IEC 17024, while others are course-completion certificates.
A sole proprietor or sole trader can seek certification for the business’s ISMS, but not as an individual.
No. You determine which controls are necessary based on your risks and applicable legal, contractual, and business requirements. You then compare them with the 93 Annex A controls to confirm that none have been overlooked.
This flexibility applies only to control selection. The requirements in Clauses 4 through 10 apply to every certified organization and cannot be excluded.
A Statement of Applicability (SoA) records the controls your organization has determined are necessary, their implementation status, and why Annex A controls have been included or excluded.
It can also contain controls that do not appear in Annex A. Auditors use the SoA to connect your risk assessment with your control decisions.
An ISO/IEC 27001 certificate is typically valid for three years. To keep it valid, the organization must complete surveillance audits during that period. A recertification audit is required before the certificate expires to renew it for another three-year cycle.
There is no standard price, and costs vary considerably. They usually fall into several categories:
Multiple locations and a more complicated scope can increase audit time and costs. Compare quotes from two or three accredited certification bodies using the same scope and check which audit stages are included.
Because it is a system you have to operate, not a document you produce once.
You need a defensible scope, consistent risk assessments, named owners, controls that operate as intended, evidence that those controls ran, internal audits, management reviews, and a process for correcting failures.
The work involves leadership, security, IT, engineering, HR, legal, and procurement. That makes ISO/IEC 27001 as much a coordination challenge as a security one. The teams that struggle most are those that treat it as a six-week audit sprint rather than an ongoing program.