The transition deadline for the older ISO/IEC 27001:2013 standard passed on October 31, 2025. Organizations that had not moved to the 2022 version by that date saw their certificates lapse. Many now face a full recertification rather than the lighter transition audit that used to be available.
ISO 27001 certification keeps showing up as a contractual requirement, not just a competitive advantage. Small and mid-sized businesses in healthcare, software as a service (SaaS), and technology increasingly hear the same request from prospective customers overseas, particularly in Europe and Asia: proof of an internationally recognized information security certification before signing a contract.
This article walks through what the ISO 27001:2022 certification process actually involves for a small business. It covers scoping the Information Security Management System (ISMS), running a gap assessment, assembling mandatory documentation, and moving through the audit stages. It also compares the standard against System and Organization Controls 2 (SOC 2) certification for organizations that serve clients outside the United States.
What ISO 27001 Certification Actually Certifies
ISO 27001 is a standard published by the International Organization for Standardization (ISO), jointly with a technical commission, and formally designated ISO/IEC 27001. It defines the requirements for building and operating an ISMS: a structured set of policies, risk assessments, and controls that govern how an organization protects information.
Certification means an accredited third-party body has reviewed the ISMS and confirmed it meets those requirements. It does not certify a product or a single system. It certifies a management process, which is why scope matters so much at the outset.
Defining the ISMS Scope: The First Real Decision
Scope defines which parts of a business the ISMS covers: specific offices, product lines, data types, or the entire organization. A narrow scope shortens the audit and lowers cost, but a scope drawn too narrowly can frustrate customers who expect broader coverage.
A small SaaS company, for example, often scopes the ISMS around the production environment and the teams that support it, while leaving out unrelated internal functions. A healthcare technology vendor handling patient data across the whole company usually needs a wider scope to satisfy client due diligence. Getting this decision right early avoids a costly re-scoping conversation midway through implementation.
Gap Assessment: Measuring the Distance to Certification
A gap assessment compares current security practices against the requirements in ISO/IEC 27001:2022. It identifies which controls already exist, which need building, and which do not apply. It typically happens before the formal audit and often before the internal audit that the standard itself requires.
Most small businesses find gaps in a similar handful of areas:
- Formal risk assessment methodology and a documented risk treatment process
- Access control and asset management records
- Incident response procedures with defined roles
- Vendor and supplier security reviews
- Employee security awareness training records
The gap assessment produces a punch list, and that list drives the implementation timeline. A company with mature security practices already in place might need a few months. One starting from an informal, undocumented posture usually needs longer.
Mandatory Documentation: What the Standard Actually Requires
ISO 27001 explicitly requires a defined set of documented information. This includes the ISMS scope, an information security policy, the risk assessment and treatment process, a Statement of Applicability, a risk treatment plan, and related records. Missing any of these mandatory documents counts as a major nonconformity during the audit. This can delay certification until the gap gets closed.
The Statement of Applicability deserves particular attention. It lists all 93 controls in Annex A of the 2022 revision, organized under four themes: organizational, people, physical, and technological. For each one, the document states whether the control applies, and if so, how the organization implements it. A small business rarely needs every control; the Statement of Applicability is where that selection gets justified and recorded.
The Audit Stages: Stage 1, Stage 2, and What Follows
ISO 27001 certification runs through a two-stage audit performed by an accredited certification body. Stage 1 reviews documentation and readiness, while Stage 2 examines whether the ISMS operates as documented and evaluates evidence.
Certification bodies generally expect Stage 2 to happen within six months of Stage 1. The ISMS should have operated for at least three months beforehand. Once certification is granted, the certificate stays valid for three years, provided the organization completes annual surveillance audits in years one and two. A full recertification audit, similar in depth to the original Stage 2, takes place before the three-year certificate expires.
Skipping a surveillance audit or missing the recertification deadline causes the certificate to lapse. A lapsed certificate functions the same as having no certification at all in front of customers and auditors.
ISO 27001 vs SOC 2 Certification: Choosing for an International Client Base
ISO 27001 and SOC 2 certification both demonstrate a mature security program, but they serve different audiences and follow different structures. ISO 27001 is an internationally recognized certification issued against a published standard, making it the more familiar reference point for clients in Europe, Asia, and other regions outside the United States.
SOC 2 is an attestation report built around the Trust Services Criteria published by the American Institute of Certified Public Accountants (AICPA). Those criteria are aligned to the internal-controls model originally developed for financial reporting by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). That alignment makes SOC 2 especially familiar to United States-based enterprise buyers and their auditors, but less immediately recognizable to procurement teams abroad.
Businesses serving domestic SaaS or healthcare clients often find SOC 2 sufficient on its own. Organizations with a genuinely international customer base, or those working with professional services firms such as law offices that hold sensitive client data across multiple jurisdictions, tend to find ISO 27001 carries more weight in contract negotiations. Some businesses eventually pursue both certifications once the customer base spans enough regions to justify the added cost.
Either path sits under the broader umbrella of cybersecurity compliance. Either can serve as the foundation a business builds additional frameworks on top of later, depending on its industry and client requirements. Working with compliance advisors who understand both certifications helps a small business choose the right one first, rather than committing to a certification that does not match its actual client base.
Planet 9 is a Bay Area cybersecurity consulting firm specializing in ISO 27001 readiness for SMBs in healthcare, SaaS, and technology. Our vCISOs and compliance managers help organizations choose the right approach, configure compliance tools if needed, and get audit-ready without wasted time.





