The security standardmost recognized in Europe
ISO/IEC 27001 is a voluntary international standard for managing information security. It’s not a law — it’s a certification that demonstrates your security posture to clients and auditors. At Kardu it’s the backbone: one piece of evidence satisfies ISO 27001 and automatically maps to the other frameworks.
This guide summarizes the standard in plain language and does not replace advice from an accredited auditor.
What ISO 27001 is
It applies to any organization that wants to demonstrate its security posture in a verifiable way, and rests on three pillars.
A management system
It’s not just technical controls — it’s how your organization identifies risks, decides what measures to take, and reviews them over time.
93 controls in 4 themes
Organizational, people, physical and technological — you choose the ones that apply to your organization based on your risk analysis.
External certification
An accredited auditor verifies your management system meets the standard — it’s not a self-assessment.
Certification cycle
01 / Initial audit
Documentation and implementation phase
The auditor first reviews your documentation, then verifies the controls actually work in practice.
02 / Certification
Valid for 3 years
If you pass the audit, you get the ISO 27001 certificate, valid for three years.
03 / Surveillance and recertification
Annual audit, recertification every 3 years
Annual surveillance audits keep the certificate active; the full audit repeats every three years.
93
Controls
4
Themes
3 years
Certificate validity
12 months
Surveillance audit cycle
What you risk without certification
ISO 27001 is voluntary — there’s no authority that fines you for not having it. The risk is commercial and reputational, not legal.
| Area | What you lose | Detail |
|---|---|---|
| Commercial | You lose RFPs and contracts that require it | More and more large clients require ISO 27001 as a condition to sign or renew a contract. |
| Trust | You can’t demonstrate your security posture in a verifiable way | Without certification, you depend on answering security questionnaires manually, one for every client that asks. |
The base for everything else
According to Kardu’s internal control mapping, implementing ISO 27001 covers a large part of what the other European frameworks require — without duplicating the work.
| Framework | ISO 27001 coverage | Controls |
|---|---|---|
| ENS | 98.9% | 92 of 93 controls |
| DORA | 82.8% | 77 of 93 controls |
| NIS2 | 76.3% | 71 of 93 controls |
| GDPR | 46.2% | 43 of 93 controls |
What it means for your SME
Even though no law forces you, more large clients ask for ISO 27001 before signing a contract. It’s also the most efficient starting point if NIS2, DORA, ENS or GDPR apply to you.
6 minimum requirements
- A defined management system scope
- An information security policy
- Risk analysis and treatment
- Documentation of applicable controls
- An internal audit plan
- Management review
Official sources
This guide is a summary. For the standard’s detail, consult ISO directly.
ISO 27001 on iso.org →ISO 27001 is your starting point
Kardu builds your management system on ISO 27001 and automatically maps every piece of evidence to NIS2, DORA, ENS and GDPR, so you upload each document only once.