London, United Kingdom
BSI
Long-standing standards publisher that also operates as a global management-system certification body.
Standards / Security
The information-security management system standard that turns policies, risk treatment, and Annex A controls into something a customer or regulator can trust.
ISO/IEC 27001 · Path stage: Security · IT, security, and compliance leads
ISO/IEC 27001 is the management-system standard for information security. If ISO 9001 asks whether you can deliver consistently, 27001 asks whether you can protect information — and prove it — across people, process, and technology.
Mid-market professional-services firms, software-enabled manufacturers, and any company that sits in a customer’s vendor-risk queue meet 27001 as a sales gate. It is not a penetration test and it is not SOC 2, though many organizations run those programs alongside it.
The Annex SL high-level structure will look familiar if you already hold 9001. The substance does not. You will need a scoped Statement of Applicability, a risk-treatment process that security owners actually use, and evidence that controls operate — not only that policies exist.
Certification bodies that are excellent on factory quality are not automatically excellent on 27001. Look for CBs whose auditors regularly work in your technology stack and threat model.
Compare bodies in the directory. For quote anatomy, read what a CB quote includes.
On this site’s framing, 27001 is the security layer between operational quality and AI governance. Organizations that skip 9001 can still certify 27001. Organizations that skip security and jump at 42001 usually discover that AI risk is mostly information-risk and vendor-risk in a new wrapper.
London, United Kingdom
Long-standing standards publisher that also operates as a global management-system certification body.
Neuilly-sur-Seine, France
Long-established TIC group used by manufacturers and asset-intensive operators for system certification.
Stuttgart, Germany
German testing and certification group with North American and global management-system certification entities.
Høvik, Norway
Assurance and risk-management group with a large accredited business-assurance certification practice.