Access to tenders and contracts
Buyers in Europe, the Middle East and Asia often name ISO 27001 in tenders. Without it you may not be shortlisted.
Tenders and global buyers increasingly name ISO 27001. Summit runs gap analysis, penetration testing and control validation so your technical controls arrive at the assessor with evidence, and stays with you through audit queries.
Human-led VAPT · NDA first · report in 48h
The work is technical. The consequences of getting ISO 27001 wrong show up in revenue, liability and reputation, which is why we report on it in the language of the boardroom first.
Buyers in Europe, the Middle East and Asia often name ISO 27001 in tenders. Without it you may not be shortlisted.
A managed risk register and tested controls show leadership has governed information risk, not just delegated it.
An independently audited management system tells customers that security is run as a discipline.
Stage 1 and Stage 2 dates are fixed. Named owners and a dated plan keep the audit on schedule.
Buyers in Europe, the Middle East and Asia often name ISO 27001 specifically in tenders.
Government and enterprise contracts commonly require an ISMS with an independent certificate from suppliers.
A certificate can answer many security questionnaire lines in one document.
If you handle client information, certification shows structured, audited control.
One accountable team takes you from scoping to retest. The people who test your systems are the people who explain the findings to your leadership.
Your ISMS and Annex A controls compared with the standard, with a prioritised list of what is missing.
Human-led testing supporting Annex A 8.8 and 8.29 on the systems in scope.
Technical checks that configuration, access and logging controls work as documented.
Test reports and fix records organised for the Statement of Applicability and assessor requests.
Practical fix guidance, then a retest and confirmation letter.
Risk and progress in language executives can use for management review.
Timelines are typical ranges, not promises. Yours depends on scope, team size and how much is already in place.
Decide which products, locations and teams the ISMS covers and who sponsors it at leadership level.
Identify assets, threats and weaknesses, then rate and prioritise the risks.
Write the Statement of Applicability and put the chosen Annex A controls in place.
Run penetration testing and an internal audit to prove technical controls work.
Leadership reviews results, risks and resources and signs off.
Stage 1 reviews documents, Stage 2 tests operation, then the certificate is issued.
Every engagement ends with material written for two audiences: a plain-language view for executives and the board, and full technical detail for the engineers who fix things.
Where the ISMS stands and which risks matter most to the business.
Test results and risk data formatted for the review leadership must hold.
Milestones from scope to Stage 2 with named owners.
Reports, scope notes and retest confirmation ready to share.
The same Summit team stays with you while assessors ask follow-ups.
ISO/IEC 27001 specifies the requirements for an Information Security Management System (ISMS): a structured way to find risks to your information, decide how to treat them and keep improving. Unlike SOC 2, it leads to a certificate issued by an accredited certification body.
The standard has two halves. Clauses 4 to 10 describe the management system itself: context, leadership, planning, support, operation, performance evaluation and improvement. Annex A lists 93 reference controls in four themes. You select the controls that apply based on your risk assessment and record the decision in a Statement of Applicability (SoA).
Certification runs in a three-year cycle. A Stage 1 audit reviews your documentation, Stage 2 tests that the system works, and surveillance audits follow each year. The 2013 edition was withdrawn from certification after the October 2025 transition deadline, so new work should follow the 2022 version.
The clauses read like a management system; Annex A reads like a control catalogue. Here is each part in plain language.
You define what is in scope, who your interested parties are and what they expect. Top management must own the ISMS, set an information security policy and assign roles.
This is the engine of the standard. You identify information security risks, rate them with a consistent method, choose treatments and set measurable objectives.
Support covers people, awareness, communication and documented information. Operation is where planned controls actually run and risks are re-assessed as things change.
You measure the ISMS, run internal audits and hold management reviews. When something fails, you record a nonconformity and fix the cause.
Policies, roles, asset management, supplier relationships, incident management, business continuity, screening, awareness and remote working all sit here.
Technological controls include access control, cryptography, secure development, logging, vulnerability management and security testing. Physical controls cover premises, equipment and secure disposal.
ISO 27001 does not prescribe a penetration test every year, but several Annex A controls expect you to identify and manage technical weaknesses and to test security before release. Human-led testing gives assessors objective proof for those controls.
Obtain information about vulnerabilities, assess exposure and act. Test findings with severity and fix status document the full cycle.
Define and implement testing processes for new or changed systems. A scoped application test supports this directly.
Hardware, software and network configurations must be established and reviewed. Testing shows where defaults or drift remain.
Management reviews whether information security is implemented as planned. Independent test results feed that review.
Assessors look for fit. Policies that do not describe how your team really works fail Stage 2 quickly.
Starting with the product and teams customers care about is faster, and you can widen scope later.
The Statement of Applicability should come out of the risk assessment, not be filled in at the end to look complete.
Assessors expect to see at least one full internal audit and a management review before certification.
No. ISO 27001 certifies an ISMS against an international standard and results in a certificate. SOC 2 is an auditor’s attestation report on controls. Many companies pursue both.
Annex A lists 93 controls in four themes. You are not required to implement all of them, but you must justify every exclusion in the Statement of Applicability.
The standard does not use that wording, but controls on managing technical vulnerabilities and security testing mean most organisations pursuing ISO 27001 run regular penetration tests.
Three years. In between, the certification body carries out annual surveillance audits, and you recertify at the end of the cycle.
Yes, many teams do, but the risk assessment and Statement of Applicability reward experience. Summit can run the gap analysis, testing and retest so your evidence is ready for the assessor.
Browse all 23 security and compliance frameworks or see our penetration testing services.
Last reviewed October 2026. Requirements change; confirm current texts and dates before you commit to a plan.
Tell us your scope, your deadline and who is asking. You get a fixed-scope quote in 15 minutes and a named lead from day one.
Get a Quote in 15 mins →Disclaimer. Summit provides independent technical and risk assessments. This is not legal advice or a regulatory certification. Acceptance of any report is decided by the requesting auditor, customer or regulator.