What is ISO 27001, and does my small business need it?
The short answer: ISO 27001 is the international standard for managing information security. Getting certified shows customers that you identify your security risks, control them properly and keep improving, checked by an independent auditor every year. You don't legally need it, but larger customers, regulated industries and international clients increasingly ask for it, and it can be the difference between winning and losing a contract.
What ISO 27001 actually is
Its full name is ISO/IEC 27001, and the current version is from 2022. It sets out how to run an information security management system, usually shortened to ISMS.
That sounds heavy, but the idea is simple. Instead of a fixed checklist, you:
- work out what information matters to your business, from customer data to finance records;
- identify the risks to it, such as a hacked account, a lost laptop or a supplier being breached;
- decide how to deal with each risk;
- put the right controls in place;
- check they work, and keep improving.
It covers people and processes as well as technology, for example how you vet staff, train them, handle a breach and work with suppliers.
The controls in Annex A
ISO 27001 comes with a list of security controls called Annex A. The 2022 version has 93 controls in four themes:
- Organisational: policies, supplier security, incident management, business continuity.
- People: screening, training and awareness, responsibilities when someone leaves.
- Physical: office security, equipment, clear desks and screens.
- Technological: access control, MFA, encryption, backups, logging, secure configuration, malware protection.
You don't have to use every control. You decide which ones apply based on your risks, and explain your choices in a document called the Statement of Applicability.
What certification involves
Certification is carried out by an independent certification body. In the UK, look for one accredited by UKAS.
- Get ready. Agree the scope, carry out a risk assessment, put the controls and policies in place, train your people, and run an internal audit and management review.
- Stage 1 audit. The auditor reviews your documents and checks you're ready.
- Stage 2 audit. The auditor checks that you really work the way your documents say, by talking to people and looking at evidence.
- Certificate. It's valid for three years.
- Surveillance audits. Shorter audits each year check that the system is still working. In year three you're recertified.
If the auditor finds something that doesn't meet the standard (a "nonconformity"), you fix it. Minor ones don't stop you being certified.
How long does it take, and what does it cost?
For a small business, getting ready typically takes several months. The biggest factors are:
- What's already in place. A business with a well set up Microsoft 365, MFA everywhere and managed laptops is already a long way there.
- Scope. Certifying one service or office is quicker than the whole business.
- Time. Someone has to own it. Consultants can do much of the writing, but your people still need to be involved.
Costs are made up of the certification body's audit fees (based on your size and scope), any consultancy and tools, and the time your people spend on it. Ask certification bodies for quotes, as prices vary.
Is it worth it for a small business?
It's worth it when:
- customers ask for it, especially larger firms, the public sector or international clients;
- you handle sensitive data, such as financial, health, legal or personal information at scale;
- you're tired of security questionnaires: a certificate answers most of them in one go;
- you want to grow, because it opens doors to bigger contracts.
If nobody's asking yet, Cyber Essentials is the sensible first step: quicker, cheaper and UK-recognised. Many businesses get Cyber Essentials first and build up to ISO 27001. See Cyber Essentials, Cyber Essentials Plus or ISO 27001: which do I need?
Where Microsoft 365 fits
A lot of the technical controls in Annex A can be delivered with Microsoft 365, especially Business Premium:
- MFA and Conditional Access for access control;
- Intune for device management, encryption and updates;
- Defender for malware protection;
- audit logging, retention and data loss prevention;
- secure sharing settings for SharePoint, OneDrive and Teams.
The standard is about proving it works, though: auditors will want to see evidence, such as reports showing every device is encrypted or every account has MFA.
Common questions
What's the difference between ISO 27001 and ISO 27002?
ISO 27001 is the standard you certify against. ISO 27002 is a companion guide that explains each Annex A control in more detail. You can't be certified to 27002.
Our certificate is from the 2013 version. Is that a problem?
The transition period for moving to the 2022 version ended on 31 October 2025, so certificates to the old version are no longer valid. If yours hasn't been moved over, talk to your certification body.
Do we need ISO 27001 to work with the government?
Not usually. UK government contracts more often ask for Cyber Essentials or Cyber Essentials Plus. ISO 27001 is more common in requirements from large private-sector customers and for international work.
Can you help us get certified?
Yes. We help small businesses get ready for Cyber Essentials, Cyber Essentials Plus and ISO 27001, from fixing the technical gaps in Microsoft 365 to the policies and evidence. See our certification support, or start with a free Microsoft 365 audit to see where you stand.
Want us to check yours?
Our free Microsoft 365 audit looks at your licences, security, email and backups, and tells you in plain English what to fix first. No card, no obligation.