Registrar Index

Standards / Security

ISO/IEC 27001 Information Security

The information-security management system standard that turns policies, risk treatment, and Annex A controls into something a customer or regulator can trust.

ISO/IEC 27001 · Path stage: Security · IT, security, and compliance leads

ISO/IEC 27001 is the management-system standard for information security. If ISO 9001 asks whether you can deliver consistently, 27001 asks whether you can protect information — and prove it — across people, process, and technology.

Mid-market professional-services firms, software-enabled manufacturers, and any company that sits in a customer’s vendor-risk queue meet 27001 as a sales gate. It is not a penetration test and it is not SOC 2, though many organizations run those programs alongside it.

What changes versus 9001

The Annex SL high-level structure will look familiar if you already hold 9001. The substance does not. You will need a scoped Statement of Applicability, a risk-treatment process that security owners actually use, and evidence that controls operate — not only that policies exist.

Certification bodies that are excellent on factory quality are not automatically excellent on 27001. Look for CBs whose auditors regularly work in your technology stack and threat model.

Registrar selection notes

  • Confirm accredited 27001:2022 (or the current edition) scope for the legal entity on the quote.
  • Ask how they handle cloud, multi-site, and remote-work scoping.
  • If ISO/IEC 42001 is on the roadmap, ask whether the same CB can integrate AIMS evidence later.

Compare bodies in the directory. For quote anatomy, read what a CB quote includes.

Path context

On this site’s framing, 27001 is the security layer between operational quality and AI governance. Organizations that skip 9001 can still certify 27001. Organizations that skip security and jump at 42001 usually discover that AI risk is mostly information-risk and vendor-risk in a new wrapper.

Registrars tagged for this page

London, United Kingdom

BSI

Long-standing standards publisher that also operates as a global management-system certification body.

ISO 9001ISO/IEC 27001ISO 14001ISO 45001ISO/IEC 42001

Neuilly-sur-Seine, France

Bureau Veritas

Long-established TIC group used by manufacturers and asset-intensive operators for system certification.

ISO 9001ISO/IEC 27001ISO 14001ISO 45001

Stuttgart, Germany

DEKRA

German testing and certification group with North American and global management-system certification entities.

ISO 9001ISO/IEC 27001ISO 14001ISO 45001ISO/IEC 42001

Høvik, Norway

DNV

Assurance and risk-management group with a large accredited business-assurance certification practice.

ISO 9001ISO/IEC 27001ISO 14001ISO 45001ISO/IEC 42001