ISO/IEC 27001 isn’t law. Increasingly, it’s what tenders ask for.
It’s a voluntary, certifiable standard, not a legal obligation like NIS2, GDPR or DORA. But tenders, enterprise customers and insurers increasingly ask for it as proof you manage information risk properly. Here’s what an auditor actually checks.
See what the standard requiresAssessment Done
Docs Review Done
Cert. Audit In Progress
Two Parts, Both Required
Clauses 4–10 (the management system) and Annex A (93 controls). No clause can be excluded if you want to claim conformity.
Certification, Not Self-Declaration
Awarded only by an accredited external certification body after an audit. It isn’t something an organisation declares about itself.
Continuous, Not One-Time
Annual surveillance audits and multi-year recertification confirm the ISMS stays current after the first certificate is issued.
Trusted by 40+ Swedish Kommuner, Regions and
EU-regulated Enterprises Since 2003








Who Typically Works Toward It
ISO/IEC 27001 applies to any organisation, of any size or sector. In practice, most organisations start for one of four reasons.
Increasingly Listed in Tenders
It’s increasingly listed as a requirement or scoring factor in supplier onboarding, especially where sensitive or citizen data is handled.
Often Asked Before Signing
Enterprise customers and financial-sector partners often want proof of a managed, auditable security approach before contracting.
One ISMS, Several Regulations
Organisations already working through NIS2, GDPR or DORA often use a single ISMS to manage documentation and evidence for all of them.
Board-Level Risk Discipline
Some pursue it for a structured, internationally recognised way to run information security, independent of any one regulation.
Is Your ISMS Actually Audit-Ready?
Documentation and evidence are two different things. An auditor checks for both.
You have a security policy. You don’t have a Statement of Applicability.
The SoA records which of the 93 Annex A controls you’ve applied, excluded, and why – an auditor checks this reasoning as closely as the controls themselves.
You’ve run a risk review once. You don’t have a repeatable process.
Clauses 4–10 expect ongoing risk assessment and treatment, not a single exercise completed ahead of an audit.
You have security tools. You don’t have internal audits or management reviews on record.
The standard requires documented internal audits and leadership review – evidence the system is being run, not just built.
You built the ISMS for last year’s audit. Nobody has touched it since.
An ISMS is meant to be operated continuously – surveillance audits and recertification exist specifically to check for that.
What the Standard Actually Requires
An ISMS built to the standard has two connected parts, plus an external audit to confirm it works.
The Management System
Scope, leadership, risk assessment & treatment, documentation, internal audits and management review. None can be excluded to claim conformity.
The Controls
93 controls across four themes: organisational, people, physical, technological. What’s applied or excluded, and why, is recorded in a Statement of Applicability.
Certification
An accredited certification body runs a two-stage audit, then annual surveillance and multi-year recertification to confirm the ISMS stays current.
See Exactly Where Your ISMS Stands Against the Standard
Maps your current state against the five core ISMS elements an auditor checks first: scope and policy, risk assessment, the Statement of Applicability, internal audits and management review. Takes about 20 minutes. The output is board-ready.
- Your score against each core ISMS element, not a generic checklist.
- Your highest-priority gap, ranked by how closely an auditor is likely to examine it.
- A board-ready summary, written in plain language, not audit-speak.
No obligation · EU data residency · Results reviewed in a 30-minute call.
ISO 27001 Readiness Score
See where your ISMS stands against the standard’s core elements, scored in plain language. The output is board-ready.
No spam. EU data residency. Unsubscribe any time.
We Build the ISMS. You Choose the Certifier.
We don’t certify organisations – that’s issued by an accredited external certification body. We build and operate the parts of an ISMS an auditor and your board expect to see.
CISO as a Service
An ISMS roadmap, risk treatment, a policy set and internal-audit support, run by an advisor who stays with your programme.
Vulnerability Management
Discover, prioritise, remediate to verified closure and report continuously, producing the register and closure evidence an auditor asks to see.
Penetration Testing
Independent, human-led testing from Sweden-based testers, with a free retest on every engagement to confirm fixes hold.
Security Awareness Training
Managed training and phishing simulation in Swedish and English, exporting the completion records auditors ask for at surveillance and recertification.
24/7 MDR & SOC
Ongoing monitoring and incident records that show the ISMS operates continuously. Our own SOC is independently certified to ISO/IEC 27001.
Sweden-Based Security Built to Produce Audit Evidence
We’re not a global firm that adapted generic content for an ISO audit. Auditable evidence, Sweden-based delivery and continuous operation are what we design our services around.
See Full Annex A CoverageSweden-Based
24/7 SOC
Human analysts watching every signal, every minute, every day. Logs stay in Sweden.
3-minute
Median Response
The industry talks in hours. We measure in minutes and escalate threats fast enough to matter.
Onboard in Days,
Not Quarters
Signed Monday. MDR live Thursday. Complorer rolled out by Wednesday.
20+ Years in SaaS
Cybersecurity practice within eBuilder, a Swedish enterprise-software company operating since 1999.
ISO 27001 Certified
Independently audited and certified to the ISO 27001 information-security standard for our own SOC.
Annex A Coverage
Services mapped across all four Annex A themes: organisational, people, physical and technological.
GDPR & Schrems II
Compliant
Human-led monitoring, secure data handling and infrastructure aligned with GDPR and Schrems II requirements.
ISO/IEC 27001, Answered
Real questions a board or compliance lead asks before engaging on ISO 27001, answered in two to three sentences.
Is ISO/IEC 27001 mandatory?
No. Unlike NIS2, GDPR or DORA, it’s a voluntary, certifiable standard. Organisations choose to pursue it, most often because a customer, tender, insurer or their own board asks for the proof.
What’s the difference between the management system and Annex A?
Clauses 4–10 are the mandatory operating structure. Annex A’s 93 controls are selected based on your own risk assessment, not every control applies to every organisation.
What is a Statement of Applicability?
A documented record of which Annex A controls you’ve applied, excluded, and why. Auditors check this reasoning as closely as the controls themselves.
Do we need to implement all 93 Annex A controls?
No. You run a risk assessment, decide which controls address your risks, and document that reasoning, including exclusions, in the Statement of Applicability.
Who actually certifies us?
An accredited external certification body, after a two-stage audit. eBuilder Security doesn’t certify – no provider can promise that outcome on your behalf.
Does certification expire?
Certification is followed by annual surveillance audits and recertification on a multi-year cycle. An ISMS is meant to be operated continuously, not built once and left untouched.
How does eBuilder Security help if you don’t certify us?
Through CISO advisory, vulnerability management, penetration testing, security awareness training and MDR/SOC, each mapped to a specific clause or Annex A control, producing the evidence an auditor expects.
Is eBuilder Security’s own SOC certified?
Yes – our SOC is independently audited and certified to ISO/IEC 27001.
ISO/IEC 27001 Is a Choice, Not a Deadline.
Let’s Make Sure It’s the Right One.
Book a free 30-minute briefing with a Sweden-based advisor. We’ll look at your current posture against the standard and talk through a realistic certification roadmap, with no obligation.
Get Your Free ISO 27001 Readiness Score