ISO/IEC 27001 Information Security Management

ISO/IEC 27001 isn’t law. Increasingly, it’s what tenders ask for.

It’s a voluntary, certifiable standard, not a legal obligation like NIS2, GDPR or DORA. But tenders, enterprise customers and insurers increasingly ask for it as proof you manage information risk properly. Here’s what an auditor actually checks.

See what the standard requires

Two Parts, Both Required

Clauses 4–10 (the management system) and Annex A (93 controls). No clause can be excluded if you want to claim conformity.

Certification, Not Self-Declaration

Awarded only by an accredited external certification body after an audit. It isn’t something an organisation declares about itself.

Continuous, Not One-Time

Annual surveillance audits and multi-year recertification confirm the ISMS stays current after the first certificate is issued.

Trusted by 40+ Swedish Kommuner, Regions and
EU-regulated Enterprises Since 2003

Why It Comes Up

Who Typically Works Toward It

ISO/IEC 27001 applies to any organisation, of any size or sector. In practice, most organisations start for one of four reasons.

Procurement

Increasingly Listed in Tenders

It’s increasingly listed as a requirement or scoring factor in supplier onboarding, especially where sensitive or citizen data is handled.

Due Diligence

Often Asked Before Signing

Enterprise customers and financial-sector partners often want proof of a managed, auditable security approach before contracting.

Regulatory Overlap

One ISMS, Several Regulations

Organisations already working through NIS2, GDPR or DORA often use a single ISMS to manage documentation and evidence for all of them.

Governance

Board-Level Risk Discipline

Some pursue it for a structured, internationally recognised way to run information security, independent of any one regulation.

Reality Check

Is Your ISMS Actually Audit-Ready?

Documentation and evidence are two different things. An auditor checks for both.

You have a security policy. You don’t have a Statement of Applicability.

The SoA records which of the 93 Annex A controls you’ve applied, excluded, and why – an auditor checks this reasoning as closely as the controls themselves.

You’ve run a risk review once. You don’t have a repeatable process.

Clauses 4–10 expect ongoing risk assessment and treatment, not a single exercise completed ahead of an audit.

You have security tools. You don’t have internal audits or management reviews on record.

The standard requires documented internal audits and leadership review – evidence the system is being run, not just built.

You built the ISMS for last year’s audit. Nobody has touched it since.

An ISMS is meant to be operated continuously – surveillance audits and recertification exist specifically to check for that.

ISO/IEC 27001:2022

What the Standard Actually Requires

An ISMS built to the standard has two connected parts, plus an external audit to confirm it works.

Clauses 4–10

The Management System

Scope, leadership, risk assessment & treatment, documentation, internal audits and management review. None can be excluded to claim conformity.

Annex A

The Controls

93 controls across four themes: organisational, people, physical, technological. What’s applied or excluded, and why, is recorded in a Statement of Applicability.

External Audit

Certification

An accredited certification body runs a two-stage audit, then annual surveillance and multi-year recertification to confirm the ISMS stays current.

ISO/IEC 27001 · Free Readiness Score

See Exactly Where Your ISMS Stands Against the Standard

Maps your current state against the five core ISMS elements an auditor checks first: scope and policy, risk assessment, the Statement of Applicability, internal audits and management review. Takes about 20 minutes. The output is board-ready.

  • Your score against each core ISMS element, not a generic checklist.
  • Your highest-priority gap, ranked by how closely an auditor is likely to examine it.
  • A board-ready summary, written in plain language, not audit-speak.

No obligation · EU data residency · Results reviewed in a 30-minute call.

ISO 27001 Readiness Score

See where your ISMS stands against the standard’s core elements, scored in plain language. The output is board-ready.

No spam. EU data residency. Unsubscribe any time.

How We Help

We Build the ISMS. You Choose the Certifier.

We don’t certify organisations – that’s issued by an accredited external certification body. We build and operate the parts of an ISMS an auditor and your board expect to see.

Clauses 4–10

CISO as a Service

An ISMS roadmap, risk treatment, a policy set and internal-audit support, run by an advisor who stays with your programme.

Managed by CISO Advisory
Annex A 8.8

Vulnerability Management

Discover, prioritise, remediate to verified closure and report continuously, producing the register and closure evidence an auditor asks to see.

Annex A 8.29

Penetration Testing

Independent, human-led testing from Sweden-based testers, with a free retest on every engagement to confirm fixes hold.

Managed by Pen Testing
Annex A 6.3

Security Awareness Training

Managed training and phishing simulation in Swedish and English, exporting the completion records auditors ask for at surveillance and recertification.

Managed by Security Awareness
Operating Evidence

24/7 MDR & SOC

Ongoing monitoring and incident records that show the ISMS operates continuously. Our own SOC is independently certified to ISO/IEC 27001.

Managed by MDR & SOC 24/7
Why eBuilder

Sweden-Based Security Built to Produce Audit Evidence

We’re not a global firm that adapted generic content for an ISO audit. Auditable evidence, Sweden-based delivery and continuous operation are what we design our services around.

See Full Annex A Coverage

Sweden-Based
24/7 SOC

Human analysts watching every signal, every minute, every day. Logs stay in Sweden.

3-minute
Median Response

The industry talks in hours. We measure in minutes and escalate threats fast enough to matter.

Onboard in Days,
Not Quarters

Signed Monday. MDR live Thursday. Complorer rolled out by Wednesday.

20+ Years in SaaS

Cybersecurity practice within eBuilder, a Swedish enterprise-software company operating since 1999.

ISO 27001 Certified

Independently audited and certified to the ISO 27001 information-security standard for our own SOC.

ISO 27001 certification mark

Annex A Coverage

Services mapped across all four Annex A themes: organisational, people, physical and technological.

GDPR & Schrems II
Compliant

Human-led monitoring, secure data handling and infrastructure aligned with GDPR and Schrems II requirements.

Questions

ISO/IEC 27001, Answered

Real questions a board or compliance lead asks before engaging on ISO 27001, answered in two to three sentences.

Is ISO/IEC 27001 mandatory?

No. Unlike NIS2, GDPR or DORA, it’s a voluntary, certifiable standard. Organisations choose to pursue it, most often because a customer, tender, insurer or their own board asks for the proof.

What’s the difference between the management system and Annex A?

Clauses 4–10 are the mandatory operating structure. Annex A’s 93 controls are selected based on your own risk assessment, not every control applies to every organisation.

What is a Statement of Applicability?

A documented record of which Annex A controls you’ve applied, excluded, and why. Auditors check this reasoning as closely as the controls themselves.

Do we need to implement all 93 Annex A controls?

No. You run a risk assessment, decide which controls address your risks, and document that reasoning, including exclusions, in the Statement of Applicability.

Who actually certifies us?

An accredited external certification body, after a two-stage audit. eBuilder Security doesn’t certify – no provider can promise that outcome on your behalf.

Does certification expire?

Certification is followed by annual surveillance audits and recertification on a multi-year cycle. An ISMS is meant to be operated continuously, not built once and left untouched.

How does eBuilder Security help if you don’t certify us?

Through CISO advisory, vulnerability management, penetration testing, security awareness training and MDR/SOC, each mapped to a specific clause or Annex A control, producing the evidence an auditor expects.

Is eBuilder Security’s own SOC certified?

Yes – our SOC is independently audited and certified to ISO/IEC 27001.

Talk to Us

ISO/IEC 27001 Is a Choice, Not a Deadline.
Let’s Make Sure It’s the Right One.

Book a free 30-minute briefing with a Sweden-based advisor. We’ll look at your current posture against the standard and talk through a realistic certification roadmap, with no obligation.

Get Your Free ISO 27001 Readiness Score
No commitment required Sweden-based advisor responds same business day