Skip to content
EUROTECH Certification logoEUROTECHCertification

Services / ISO 27001 certification

ISO 27001 certification for information security, from $800

Certify your information security management system to ISO/IEC 27001:2022 and answer customer security questionnaires with a certificate they can verify.

From $800Certified by EUROTECH

Quiet data centre aisle with closed server racks and soft blue reflections

What ISO 27001 certification covers

ISO/IEC 27001 sets the requirements for an information security management system, usually called an ISMS. It is not a technical checklist. It asks you to define what information you need to protect, assess the risks to its confidentiality, integrity and availability, choose controls to treat those risks and manage the whole system so it keeps working as the business changes.

The current edition is ISO/IEC 27001:2022. Its Annex A lists 93 controls grouped into four themes: organizational, people, physical and technological. You decide which apply through your risk assessment and record the decision, with reasons, in a Statement of Applicability. The auditor tests that document against reality.

The scope of the certificate defines the organization, locations, services and systems covered. A software company might scope its SaaS platform and the teams that build and run it; a managed service provider might scope its operations centre. A clear, honest scope is what customers check first.

  • Stage 1 review of scope, risk assessment, Statement of Applicability and documentation
  • Stage 2 audit of controls in operation, with evidence from your systems
  • Certification decision and three-year certificate
  • Certificate listed on verify.eurotechcertification.com
  • Surveillance audits in years one and two, recertification in year three

Online audit, cloud environments and integrated audits

Information security audits suit remote work well, because most evidence lives in systems: access reviews, configuration settings, logs, vulnerability scans, backup records, ticketing systems and training records. The auditor will ask you to share screens and show evidence live, not only send exports.

Physical controls still matter where you have offices, server rooms or data centres in scope. If you run fully in the cloud, the audit focuses on how you manage your cloud providers: what the shared responsibility model leaves to you, how you configure services and how you review the providers' own assurance reports.

ISO 27001 uses the same high-level structure as ISO 9001 and other management system standards. If you already hold ISO 9001, management review, internal audit, document control and corrective action can be shared. Some clients also combine ISO 27001 with ISO 42001 for AI systems or ISO 22301 for business continuity, which overlap in risk and incident management.

Whichever format, the standard of evidence is the same: the auditor must see that controls work, not just that a policy describes them.

What drives the cost of ISO 27001

ISO 27001 certification with EUROTECH starts at $800. Audit time depends on the size and complexity of what is in scope.

  • Number of people working within the scope, including contractors with access
  • Complexity of the IT environment: number of systems, platforms and critical services
  • Number of sites, including data centres and offices in scope
  • Regulated or sensitive data, such as health, payment or personal data at scale
  • Outsourcing: key suppliers and cloud services you depend on
  • Integration with other certified management systems

The written quote lists audit days and all fees for the three-year cycle. You keep audit time down by having the Statement of Applicability, risk register and evidence for each applicable control organized before Stage 2.

How ISO 27001 certification works with us

  1. Application and scoping

    Step 1

    Scope and quote

    We agree the ISMS scope, people, systems and sites, and quote the ISO 27001 audit in writing.

  2. Stage 1 document review

    Step 2

    Stage 1 review

    We check the risk assessment, Statement of Applicability, policies, internal audit and management review.

  3. Stage 2 on-site audit

    Step 3

    Stage 2 audit

    The auditor samples Annex A controls with live evidence from your systems and interviews.

  4. Certificate and surveillance

    Step 4

    Certificate and surveillance

    After the decision you receive the ISO 27001 certificate, with yearly surveillance audits.

Customers, laws and markets

We certify ISO 27001 for organizations in the USA, Europe, Asia and Africa. Most clients pursue it because customers ask: enterprise buyers, public sector tenders and partners use it to cut down long security questionnaires.

ISO 27001 also asks you to identify the legal, regulatory and contractual requirements that apply to your information, such as data protection laws in the regions you serve and contractual security clauses. In the European Union this often includes GDPR and, for certain sectors, the NIS2 rules; in the USA, sector and state privacy laws. Certification does not make you compliant with these laws, but a working ISMS gives you the structure to meet them.

US buyers sometimes ask for a SOC 2 report instead of, or as well as, ISO 27001. SOC 2 is an attestation report under AICPA standards, not a certification. Many controls overlap, so one well-designed control set can serve both.

What to expect during the audit

Stage 1 checks that the ISMS is designed and ready: scope, information security policy, risk assessment and treatment method, Statement of Applicability, objectives, internal audit and management review. Gaps found here are cheaper to fix than at Stage 2.

Stage 2 samples controls across the four Annex A themes. Expect requests such as: show the last access review for a critical system, the joiner and leaver records for a sample of staff, evidence that backups are tested by restoring, how vulnerabilities are tracked to closure, how a recent incident was handled, and how suppliers are assessed.

People controls are checked as well: screening where it applies, security awareness training, confidentiality agreements and disciplinary processes. The auditor may ask a few staff members how they would report a suspected phishing email or a lost laptop.

Findings are graded as major or minor, and the certification decision rests on the evidence. You receive a written report with every finding explained.

After certification

Security risks change faster than most business risks, so review your risk assessment when you add systems, suppliers or services, and at planned intervals. Keep monitoring, incident handling, internal audits and management reviews running. Surveillance audits focus on these and on any significant incidents since the last visit.

The transition from ISO/IEC 27001:2013 to the 2022 edition ended in October 2025, so all valid certificates now refer to the 2022 version. In 2024 ISO also amended the standard, as it did other management system standards, to ask whether climate change is a relevant issue for your organization.

Tell us about major changes in scope, such as a new product, a merger or moving to a new cloud platform. They may change audit time, and planning them into a surveillance visit keeps your certificate accurate.

Metrics help both you and the auditor. Track a small set of indicators such as patching times, access review completion, incident counts and training completion, and take them to management review.

Questions buyers ask

How much does ISO 27001 certification cost?

With EUROTECH it starts at $800. People in scope, IT complexity, sites, sensitive data and outsourcing set the final price.

Which version of ISO 27001 is current?

ISO/IEC 27001:2022, amended in 2024 for climate change. The transition from the 2013 edition ended in October 2025.

How many controls are in Annex A?

93 controls in four themes: organizational, people, physical and technological. You choose which apply through your risk assessment.

Is ISO 27001 the same as SOC 2?

No. ISO 27001 is a certification of a management system. SOC 2 is an attestation report under AICPA standards. Many controls overlap.

Can a cloud-only company get ISO 27001?

Yes. The audit focuses on how you configure and manage cloud services and suppliers, and on your own people and processes.

Can the audit be fully online?

Often yes, especially for cloud-based companies. Offices or server rooms in scope may need an on-site visit.

Get a quote for ISO 27001 certification

Tell us your company, sites and the standard you need. We reply with a written quote and the audit plan.

Prefer to talk? Call +1 307 205 1833
Monday to Friday, 09:00 to 18:00 (US Mountain Time)

We use your details only to reply to this request. See our privacy policy.