ISO 27001 certification (information security)
Voluntary: the international information-security management standard (current version: 2022), increasingly required in IT tenders and supply chains.
Issued by: Accredited certification bodies (AFNOR Certification, Bureau Veritas, LNE…)
Software vendors, hosting providers, IT services firms, fintech and health companies, and any organisation handling sensitive customer data.
What this scheme covers
- C.1An information-security management system (ISMS): risk assessment, statement of applicability, Annex A controls.
- C.2Confidentiality, integrity and availability of information, beyond GDPR compliance alone.
- C.3The foundation of other sector requirements, such as France's HDS certification for health-data hosting.
The link with Qualiopi
Outside vocational training: ISO 27001 targets the information system. A training provider handling much learner data may pursue it, but it does not count towards training funding.
The process, summarised
- 1.Define the ISMS scope and run the information-security risk assessment.
- 2.Select and implement controls (statement of applicability), document and train staff.
- 3.Run the system in (internal audits, review), then pass the two-stage certification audit and annual surveillance.
FAQ — ISO 27001
+Does ISO 27001 make you GDPR-compliant?
Not automatically: the standard covers information security broadly and strongly supports compliance, but GDPR has its own legal requirements (lawful bases, data-subject rights) outside its scope.
+How long does certification take?
Usually several months between ISMS scoping and the audit, depending on scope size and existing security maturity.
+How does it differ from SOC 2?
ISO 27001 certifies a management system against an international standard; SOC 2 is a US-style attestation report. European customers tend to ask for ISO 27001, American ones for SOC 2 — many SaaS companies end up with both.
- ISO 27001 Statement of Applicability: Building Your SoA from Annex A8 min
- ISO 27001 certification cost: the real budget lines explained7 min
- How to get ISO 27001 certified in 2026: the concrete steps8 min
- ISO 27001 vs SOC 2: differences, overlaps and how to choose7 min
- ISO 27001:2022 explained: Annex A, 93 controls, transition over7 min
- Is ISO 27001 mandatory? GDPR, NIS2, French HDS and tenders8 min
- HDSMandatory
- HAS certificationMandatory