ISO/IEC 27001:2022 is the international standard for an Information Security Management System (ISMS) — not a law, but the certification enterprise procurement, vendor security questionnaires, and EU/UK partner contracts increasingly gate deals on. A-LIGN's 2025 benchmark found adoption among surveyed organizations jumped from 67% to 81% in a single year. For a founder who shipped an app with Lovable, Bolt, Replit, or Cursor, ISO 27001 becomes real the day a large customer's security team sends a questionnaire — and it's the one framework a quick code fix can't satisfy on its own, because it certifies the organization's management system, not just the app.
Get a Free Compliance Scan See Audit PricingISO 27001 isn't a law — nobody fines you for lacking it. The pressure is commercial: enterprise procurement teams, vendor-risk reviews, and tenders in regulated or security-sensitive markets increasingly list it as a qualification. ISO 27001 dominates EU/UK buying decisions the way SOC 2 dominates US ones, and the two increasingly get requested together.
| Trigger | What it requires |
|---|---|
| Enterprise procurement or security review demands ISO 27001 or SOC 2 before signing | A functioning ISMS (clauses 4–10): defined scope, leadership commitment, a documented risk assessment (6.1.2), and a Statement of Applicability (SoA) justifying which Annex A controls apply (6.1.3) |
| Entering regulated or security-sensitive markets (fintech, health, government supply chains) where tenders list it as a qualification | Annex A (2022 revision): 93 controls across 4 themes — Organizational (37), People (8), Physical (14), Technological (34) — down from 114 controls in 14 domains under the 2013 version; 11 new controls including threat intelligence (A.5.7), cloud services security (A.5.23), configuration management (A.8.9), and secure coding (A.8.28) |
| A deal is gated on “vendor shall maintain ISO 27001 certification” | An accredited certification audit (UKAS/ANAB-accredited body). Key distinction: “ISO 27001 compliant” or “aligned” is a self-claim with no external validation — buyers rarely deem a compliance claim sufficient; only certification carries weight |
| Renewing an old certificate | The 2022 transition is over: every ISO 27001:2013 certificate worldwide became invalid on 2025-10-31 (the IAF's 3-year transition window). Missing that deadline means starting over as a brand-new applicant requiring a full initial audit, not a renewal |
The distinction between “compliant” and “certified” is the one founders miss most: a self-assessment against Annex A controls is a useful internal exercise, but it carries no weight with a procurement team asking for the certificate itself.
Sources: SGS; LRQA; Drata; Secureframe; Hightable; URM Consulting; DataGuard.
The process is the same fixed shape for every ISO management-system standard: a Stage 1 documentation review, a Stage 2 certification audit, annual surveillance audits, and recertification on a 3-year cycle.
| Stage | What it covers |
|---|---|
| Stage 1 | Documentation review — confirms the ISMS scope, risk assessment, SoA, and policies exist and are internally coherent |
| Stage 2 | Certification audit — evidence the ISMS actually operates: records, logs, access reviews, an internal audit, and a management review |
| Surveillance (years 2–3) | Annual audits confirming the ISMS is still operating as certified |
| Recertification (year 3) | A renewed full audit; the certificate is valid for another 3-year cycle |
Cost estimates (vendor-published, 2025–2026): a first certification for an SMB typically runs – all-in. Certification-body fees alone (Stage 1 + Stage 2) for a small org run roughly – — a sub-10-person startup can see combined Stage 1+2 fees from around with total first-year cost near –. Audit day rates run –/day in the US (a 1–10 person company at ~5 days runs about ; a 46–65 person company at ~10 days runs about ). Surveillance audits run roughly –/year. Internal staff effort is estimated at 200–400 hours.
Automation changed the math. Vanta (from roughly /year) claims most teams certify in 12–24 weeks using automated evidence collection and an auto-generated SoA; Drata starts from roughly /year. The independent audit itself is always a separate line item, typically or more on top. Honest framing: a solo founder's AI-built app can be technically hardened in days, but certification can't be bought faster than the audit pipeline — realistically 3–6 months minimum even with automation tooling, because Stage 2 requires months of operating evidence, not a point-in-time fix.
Sources: Rhymetec; Konfirmity; SecureLeap; Vanta; ComplyJet.
ISO 27001 is roughly 60% organizational paperwork and process — no URL scan certifies an organization. But a technical scan can find exactly the control failures that sink a Stage 2 audit, and AI-built apps fail a predictable set of them:
The honest split: a technical scan surfaces the disqualifying evidence an auditor would flag; closing the paperwork and process side — the ISMS itself — is a separate, ongoing effort.
Sources: NVD / SentinelOne (CVE-2025-48757); Escape.tech methodology report (Oct 2025); Wiz (Base44, July 2025); The Register / Fortune (Replit / SaaStr, July 2025).
Two things are true at once: certification doesn't prevent breaches, and not having it increasingly costs revenue.
| Signal | What it shows |
|---|---|
| Certification ≠ security | Fidelity Investments disclosed a breach affecting 77,099 customers (Aug 17–19, 2024) while ISO 27001-certified; Oxebridge's public tracker also lists Okta, Equifax, and Airtable as breached while certified. |
| Vendors get cut for security gaps | 57% of surveyed security leaders have terminated a vendor over security concerns (Vanta State of Trust 2025, 3,500 leaders surveyed). |
| Adoption is accelerating | ISO 27001 adoption among surveyed organizations rose from 67% to 81% year-over-year; certifications overall grew roughly 20% year-over-year; 71% of enterprises now spend more than /year on audits (A-LIGN's 5th annual benchmark, Jan 2025). |
| Global certificate count | 96,709 valid ISO/IEC 27001 certificates worldwide across 179,877 certified sites (ISO Survey 2024, compiled from IAF CertSearch) — up from 71,549 certificates in 2022; growth is estimated at roughly 20–25% per year. |
Sources: Oxebridge; Vanta State of Trust 2025 (Businesswire, Oct 2025); A-LIGN 5th Annual Compliance Benchmark (Jan 2025); ISO Survey 2024.
Not legally — ISO 27001 isn't a law and nobody fines you for lacking it. In practice, it becomes a real requirement the moment an enterprise buyer's procurement team or security questionnaire asks for it, which is increasingly common in EU/UK sales cycles.
“Compliant” or “aligned” is a self-claim — you've assessed yourself against the Annex A controls with no outside verification. “Certified” means an accredited body (UKAS/ANAB) completed a Stage 1 and Stage 2 audit and issued a certificate. Buyers rarely accept a compliance claim as sufficient; only certification carries weight in a vendor security review.
Vendor-published estimates put a first certification for an SMB at roughly – all-in, including certification-body audit fees (~– for a small org), internal staff time (200–400 hours), and, if used, an automation platform (Vanta from ~/year, Drata from ~/year) on top of the audit itself.
Automation platforms claim 12–24 weeks for teams using continuous evidence collection, but that's optimistic for a young startup — Stage 2 requires months of real operating evidence, not just documentation, so 3–6 months minimum is more realistic even with automation.
No. SOC 2 is a US-centric attestation report on specific Trust Services Criteria; ISO 27001 is an internationally recognized certified management system. ISO 27001 dominates EU/UK enterprise buying, SOC 2 dominates US buying, and larger enterprise deals increasingly ask for both.
No. CVE-2025-48757 alone shows 170+ Lovable-generated apps shipped with broken access control, and Escape.tech found 400+ exposed secrets across 5,600 scanned vibe-coded apps. Those are exactly the technical findings that sink a Stage 2 audit — on top of the organizational ISMS work (risk assessment, policies, internal audit) that a scan can't touch at all.
We scan AI-built apps for the technical control failures — access control, secrets, logging, change management — that sink certification audits, and hand you a fix-it list before your auditor or a customer's security team finds the gap.
Get a Free Compliance ScanRelated searches: do I need ISO 27001 for my SaaS startup · ISO 27001 for a Lovable app · customer asking for ISO 27001 certification what do I do · ISO 27001 certification cost small business 2026 · cheapest way to get ISO 27001 certified startup · how long does ISO 27001 certification take with Vanta · ISO 27001 vs SOC 2 which one does my startup need · ISO 27001 compliant vs certified difference · can an AI-built app pass an ISO 27001 audit · ISO 27001 Statement of Applicability example startup · ISO 27001 2022 transition deadline what happens if I missed it · vendor security questionnaire startup ISO 27001