💻 Digital & healthVoluntaryOutside the scope of Qualiopi

ISO 27001 certification (information security)

Voluntary: the international information-security management standard (current version: 2022), increasingly required in IT tenders and supply chains.

Issued by: Accredited certification bodies (AFNOR Certification, Bureau Veritas, LNE…)

Who it concerns

Software vendors, hosting providers, IT services firms, fintech and health companies, and any organisation handling sensitive customer data.

Scope

What this scheme covers

  • C.1An information-security management system (ISMS): risk assessment, statement of applicability, Annex A controls.
  • C.2Confidentiality, integrity and availability of information, beyond GDPR compliance alone.
  • C.3The foundation of other sector requirements, such as France's HDS certification for health-data hosting.
How it fits

The link with Qualiopi

Outside vocational training: ISO 27001 targets the information system. A training provider handling much learner data may pursue it, but it does not count towards training funding.

How to proceed

The process, summarised

  1. 1.Define the ISMS scope and run the information-security risk assessment.
  2. 2.Select and implement controls (statement of applicability), document and train staff.
  3. 3.Run the system in (internal audits, review), then pass the two-stage certification audit and annual surveillance.
Frequently asked questions

FAQ — ISO 27001

+Does ISO 27001 make you GDPR-compliant?

Not automatically: the standard covers information security broadly and strongly supports compliance, but GDPR has its own legal requirements (lawful bases, data-subject rights) outside its scope.

+How long does certification take?

Usually several months between ISMS scoping and the audit, depending on scope size and existing security maturity.

+How does it differ from SOC 2?

ISO 27001 certifies a management system against an international standard; SOC 2 is a US-style attestation report. European customers tend to ask for ISO 27001, American ones for SOC 2 — many SaaS companies end up with both.

Our articles on ISO 27001
Same sector
Related guides