ISO 27001 certification, run as a managed programme.
Businesses winning EU and global deals need ISO 27001. Uzado runs the ISMS, prepares the audit evidence, and keeps the certification current.
ISO 27001 certifies the system, not just the controls
ISO/IEC 27001:2022 is the international standard for an Information Security Management System (ISMS). Certification proves that your business runs security as a continuous, governed, auditable system.
ISO 27001 has two parts. The main clauses (4 to 10) define the management system: context, leadership, planning, support, operation, performance evaluation, and improvement. Annex A defines the 93 controls grouped into Organizational, People, Physical, and Technological themes. The Statement of Applicability records which controls you have deemed applicable and why.
Certification runs through a Stage 1 audit (documentation and readiness) and a Stage 2 audit (operational effectiveness), then annual surveillance audits and a three-year recertification audit. The auditor evaluates the system, not just the controls. A common failure mode is implementing the controls without standing up the management system; Uzado treats both as one programme.
When to pick one, and when to carry both
SOC 2 is a control attestation aimed at North American buyers. ISO 27001 is a management system certification aimed at international buyers. For businesses selling primarily into the US, SOC 2 first; for those selling into the EU, UK, or APAC, ISO 27001 first. For businesses selling across both, Uzado runs a shared control set mapped to both frameworks so the marginal cost of the second certification is small.
Why businesses pursue ISO 27001
ISO 27001 is the international information security standard. Buyers in the EU, UK, APAC, and Latin America expect it. For businesses selling abroad, it is often the first ask in a vendor questionnaire.
ISO 27001 maps cleanly to GDPR Article 32, the UK's NCSC guidance, Singapore's MAS TRM, and Australia's Essential Eight. Certification accelerates regulator and procurement reviews across multiple jurisdictions.
Once your ISMS is in place, the cloud-specific (ISO 27017) and PII-protection (ISO 27018) extensions are incremental. The hardest work is the underlying management system; the extensions ride on top.
A six-step certification programme
From scope and ISMS design through Stage 2 certification and into the three-year surveillance cycle.
Define the scope statement, governance structure, roles, and the management review cadence. The ISMS is the system the auditor evaluates, not just the controls.
Run the risk assessment, build the risk treatment plan, and produce the Statement of Applicability that explains which Annex A controls apply and why.
Implement the 93 controls grouped into Organizational, People, Physical, and Technological themes. Vanta automates evidence on the technological controls; Uzado runs the rest as managed work.
Stage 1 is a documentation and readiness review. Uzado runs an internal audit dry-run so the formal Stage 1 finds nothing the team has not already addressed.
Stage 2 evaluates operational effectiveness. Uzado supports the audit interviews, evidence pulls, and findings response so certification is delivered on schedule.
Annual surveillance audits and a three-year recertification cycle. Uzado runs the management reviews, internal audits, and continuous improvement loop so each surveillance audit is incremental.
Common ISO 27001 questions
How long does ISO 27001 take?+
From a low-maturity starting point, six to nine months to Stage 2 is typical for an SMB. Mature security posture can compress to four months. The drivers are scope size, control gap depth, and how aggressively leadership wants to move.
How does the ISO 27001:2022 update affect us?+
The 2022 revision restructured Annex A from 114 controls into 93 grouped under four themes: Organizational, People, Physical, and Technological. New controls were added for threat intelligence, cloud services, ICT readiness for business continuity, and secure coding. Uzado scopes against ISO 27001:2022 from day one and migrates clients carrying ISO 27001:2013 certifications during their next surveillance window.
Do I need both SOC 2 and ISO 27001?+
It depends on your buyer geography. SOC 2 dominates North American procurement; ISO 27001 dominates EU, UK, and APAC procurement. If you sell into both regions, carrying both is usually less expensive than constantly answering parity questions in security questionnaires.
What is the difference between ISO 27001 and SOC 2?+
ISO 27001 certifies an Information Security Management System, the governance and continuous improvement loop around your security programme. SOC 2 attests that a defined set of controls operate effectively over a window. ISO 27001 is broader and management-system focused; SOC 2 is narrower and control-focused. They map cleanly onto each other on shared underlying controls.
What is the surveillance audit cycle?+
ISO 27001 certifications run on a three-year cycle. Stage 1 and Stage 2 deliver the initial certification. Surveillance audits run annually for the next two years to confirm the ISMS is still operating. The third-year audit is a recertification audit, which is broader than a surveillance audit but narrower than the original Stage 2.
Can Vanta automate ISO 27001 evidence?+
Yes, for the technological controls. Vanta integrates with cloud, identity, MDM, and ticketing systems to collect evidence continuously. Organizational, People, and Physical controls require workflow Uzado runs separately, with Vanta as the system of record so audit pulls are uniform.
Do we need a CISO to get certified?+
You need accountable security leadership. That can be a full-time CISO, a board-level sponsor, or Uzado's vCISO acting as the named owner. The auditor evaluates whether security has clear ownership and management review, not whether the title is on a permanent payroll line.
What does the Statement of Applicability actually contain?+
The SoA is the auditable record of which Annex A controls apply, which are excluded, and the justification for each decision. It is one of the most-scrutinised artefacts in Stage 2. Uzado writes the SoA against your real environment so it survives auditor questions without retroactive editing.
Ready to scope ISO 27001?
Talk to Uzado's compliance team. We will scope your ISMS, plan the audit cycle, and run the work through certification and surveillance.
