Kardu
Internacional · ISO 27001

The security standardmost recognized in Europe

ISO/IEC 27001 is a voluntary international standard for managing information security. It’s not a law — it’s a certification that demonstrates your security posture to clients and auditors. At Kardu it’s the backbone: one piece of evidence satisfies ISO 27001 and automatically maps to the other frameworks.

This guide summarizes the standard in plain language and does not replace advice from an accredited auditor.

What ISO 27001 is

It applies to any organization that wants to demonstrate its security posture in a verifiable way, and rests on three pillars.

A management system

It’s not just technical controls — it’s how your organization identifies risks, decides what measures to take, and reviews them over time.

93 controls in 4 themes

Organizational, people, physical and technological — you choose the ones that apply to your organization based on your risk analysis.

External certification

An accredited auditor verifies your management system meets the standard — it’s not a self-assessment.

Certification cycle

01 / Initial audit

Documentation and implementation phase

The auditor first reviews your documentation, then verifies the controls actually work in practice.

02 / Certification

Valid for 3 years

If you pass the audit, you get the ISO 27001 certificate, valid for three years.

03 / Surveillance and recertification

Annual audit, recertification every 3 years

Annual surveillance audits keep the certificate active; the full audit repeats every three years.

By the numbers

93

Controls

4

Themes

3 years

Certificate validity

12 months

Surveillance audit cycle

What you risk without certification

ISO 27001 is voluntary — there’s no authority that fines you for not having it. The risk is commercial and reputational, not legal.

AreaWhat you loseDetail
CommercialYou lose RFPs and contracts that require itMore and more large clients require ISO 27001 as a condition to sign or renew a contract.
TrustYou can’t demonstrate your security posture in a verifiable wayWithout certification, you depend on answering security questionnaires manually, one for every client that asks.

The base for everything else

According to Kardu’s internal control mapping, implementing ISO 27001 covers a large part of what the other European frameworks require — without duplicating the work.

FrameworkISO 27001 coverageControls
ENS98.9%92 of 93 controls
DORA82.8%77 of 93 controls
NIS276.3%71 of 93 controls
GDPR46.2%43 of 93 controls

What it means for your SME

Even though no law forces you, more large clients ask for ISO 27001 before signing a contract. It’s also the most efficient starting point if NIS2, DORA, ENS or GDPR apply to you.

6 minimum requirements

  • A defined management system scope
  • An information security policy
  • Risk analysis and treatment
  • Documentation of applicable controls
  • An internal audit plan
  • Management review

Official sources

This guide is a summary. For the standard’s detail, consult ISO directly.

ISO 27001 on iso.org →
How Kardu helps

ISO 27001 is your starting point

Kardu builds your management system on ISO 27001 and automatically maps every piece of evidence to NIS2, DORA, ENS and GDPR, so you upload each document only once.