Free Consultation
#iso27001
#audit

ISO 27001 Certification: A Realistic Roadmap for Small Businesses

September 3, 2026

The transition deadline for the older ISO/IEC 27001:2013 standard passed on October 31, 2025. Organizations that had not moved to the 2022 version by that date saw their certificates lapse. Many now face a full recertification rather than the lighter transition audit that used to be available.

ISO 27001 certification keeps showing up as a contractual requirement, not just a competitive advantage. Small and mid-sized businesses in healthcare, software as a service (SaaS), and technology increasingly hear the same request from prospective customers overseas, particularly in Europe and Asia: proof of an internationally recognized information security certification before signing a contract.

This article walks through what the ISO 27001:2022 certification process actually involves for a small business. It covers scoping the Information Security Management System (ISMS), running a gap assessment, assembling mandatory documentation, and moving through the audit stages. It also compares the standard against System and Organization Controls 2 (SOC 2) certification for organizations that serve clients outside the United States.

What ISO 27001 Certification Actually Certifies

ISO 27001 is a standard published by the International Organization for Standardization (ISO), jointly with a technical commission, and formally designated ISO/IEC 27001. It defines the requirements for building and operating an ISMS: a structured set of policies, risk assessments, and controls that govern how an organization protects information.

Certification means an accredited third-party body has reviewed the ISMS and confirmed it meets those requirements. It does not certify a product or a single system. It certifies a management process, which is why scope matters so much at the outset.

Defining the ISMS Scope: The First Real Decision

Scope defines which parts of a business the ISMS covers: specific offices, product lines, data types, or the entire organization. A narrow scope shortens the audit and lowers cost, but a scope drawn too narrowly can frustrate customers who expect broader coverage.

A small SaaS company, for example, often scopes the ISMS around the production environment and the teams that support it, while leaving out unrelated internal functions. A healthcare technology vendor handling patient data across the whole company usually needs a wider scope to satisfy client due diligence. Getting this decision right early avoids a costly re-scoping conversation midway through implementation.

Gap Assessment: Measuring the Distance to Certification

A gap assessment compares current security practices against the requirements in ISO/IEC 27001:2022. It identifies which controls already exist, which need building, and which do not apply. It typically happens before the formal audit and often before the internal audit that the standard itself requires.

Most small businesses find gaps in a similar handful of areas:

The gap assessment produces a punch list, and that list drives the implementation timeline. A company with mature security practices already in place might need a few months. One starting from an informal, undocumented posture usually needs longer.

Mandatory Documentation: What the Standard Actually Requires

ISO 27001 explicitly requires a defined set of documented information. This includes the ISMS scope, an information security policy, the risk assessment and treatment process, a Statement of Applicability, a risk treatment plan, and related records. Missing any of these mandatory documents counts as a major nonconformity during the audit. This can delay certification until the gap gets closed.

The Statement of Applicability deserves particular attention. It lists all 93 controls in Annex A of the 2022 revision, organized under four themes: organizational, people, physical, and technological. For each one, the document states whether the control applies, and if so, how the organization implements it. A small business rarely needs every control; the Statement of Applicability is where that selection gets justified and recorded.

The Audit Stages: Stage 1, Stage 2, and What Follows

ISO 27001 certification runs through a two-stage audit performed by an accredited certification body. Stage 1 reviews documentation and readiness, while Stage 2 examines whether the ISMS operates as documented and evaluates evidence.

Certification bodies generally expect Stage 2 to happen within six months of Stage 1. The ISMS should have operated for at least three months beforehand. Once certification is granted, the certificate stays valid for three years, provided the organization completes annual surveillance audits in years one and two. A full recertification audit, similar in depth to the original Stage 2, takes place before the three-year certificate expires.

Skipping a surveillance audit or missing the recertification deadline causes the certificate to lapse. A lapsed certificate functions the same as having no certification at all in front of customers and auditors.

ISO 27001 vs SOC 2 Certification: Choosing for an International Client Base

ISO 27001 and SOC 2 certification both demonstrate a mature security program, but they serve different audiences and follow different structures. ISO 27001 is an internationally recognized certification issued against a published standard, making it the more familiar reference point for clients in Europe, Asia, and other regions outside the United States.

SOC 2 is an attestation report built around the Trust Services Criteria published by the American Institute of Certified Public Accountants (AICPA). Those criteria are aligned to the internal-controls model originally developed for financial reporting by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). That alignment makes SOC 2 especially familiar to United States-based enterprise buyers and their auditors, but less immediately recognizable to procurement teams abroad.

Businesses serving domestic SaaS or healthcare clients often find SOC 2 sufficient on its own. Organizations with a genuinely international customer base, or those working with professional services firms such as law offices that hold sensitive client data across multiple jurisdictions, tend to find ISO 27001 carries more weight in contract negotiations. Some businesses eventually pursue both certifications once the customer base spans enough regions to justify the added cost.

Either path sits under the broader umbrella of cybersecurity compliance. Either can serve as the foundation a business builds additional frameworks on top of later, depending on its industry and client requirements. Working with compliance advisors who understand both certifications helps a small business choose the right one first, rather than committing to a certification that does not match its actual client base.

Planet 9 is a Bay Area cybersecurity consulting firm specializing in ISO 27001 readiness for SMBs in healthcare, SaaS, and technology. Our vCISOs and compliance managers help organizations choose the right approach, configure compliance tools if needed, and get audit-ready without wasted time.

Book a Free Consultation

Schedule a free consultation today to explore how Planet 9 can help you achieve your security and compliance goals.
Book Free Consultation

FAQs

How does a vCISO service differ from hiring a full-time CISO?
A part-time CISO offers the same strategic oversight and expertise as a full-time CISO but on a flexible, cost-effective basis. It’s ideal for small to mid-sized businesses that need executive-level guidance without the overhead.
Is a virtual CISO service suitable for regulated industries like healthcare or finance?
Yes, virtual CISOs (or fractional CISOs) are especially valuable for industries with strict compliance requirements such as HIPAA, PCI DSS, or GLBA. They help ensure your organization meets regulatory standards and is prepared for audits.
What can I expect during a vCISO engagement?
Our vCISO service typically includes cybersecurity assessments, program development, compliance planning, incident response strategy, vendor risk management, and ongoing executive reporting tailored to your business.
How do I know if my business needs a CISO-as-a-Service?
If you lack in-house security leadership, struggle with compliance, or face growing cyber risks, a vCISO can fill that gap, providing strategic direction, improving resilience, and helping you make smarter security investments.

FAQs

What is ISO 27001 certification?
ISO 27001 certification confirms that an accredited third-party auditor has reviewed an organization's Information Security Management System and found it meets the requirements published in the ISO/IEC 27001:2022 standard. It covers policies, risk management, and a defined set of security controls rather than certifying a single product or system.
How long does ISO 27001 certification take for a small business?
Timelines vary based on the size of the organization and how mature its existing security practices already are. Many small businesses move from gap assessment through Stage 2 certification within several months, though organizations starting from an informal security posture often need longer to build out required documentation and controls.
Is ISO 27001 certification better than SOC 2 certification?
Neither certification is universally better; the right choice depends on where clients are located and what they expect to see. ISO 27001 tends to carry more recognition with international clients, while SOC 2 certification remains the more familiar reference point for United States-based enterprise buyers.
Does ISO 27001 certification expire?
Yes. A certificate remains valid for three years, provided the organization completes annual surveillance audits in years one and two, followed by a full recertification audit before the three-year period ends.
What happens if a company misses a surveillance audit?
Missing a scheduled surveillance audit or the recertification deadline causes the certificate to lapse, and a lapsed certificate carries no more weight than having no certification at all. Reinstating it typically requires a fresh assessment, and in some cases a full Stage 1 and Stage 2 audit repeated from the beginning.

Related blog posts