Security

Real offensive depth

Testing and defence led by a published security researcher with six CVEs, including a CVSS 9.1 Mirai botnet kill-switch.

All security →
Compliance

Audit-ready, fixed scope

SOC 2, ISO, CPCSC, and the Canadian privacy stack, run end to end with an independent auditor.

All frameworks →
/var/www/traztech.ca/html/blog/post.php on line 12748
22; color:
Warning: Undefined array key "Compliance" in /var/www/traztech.ca/html/blog/post.php on line 12748
;">Compliance

What Is ISO 27001? A Plain-Language Guide (2026)

If you've been asked by a customer, an investor, or a procurement team whether your company is "ISO 27001 certified," you're not alone in not knowing exactly what that means. It's one of the most requested credentials in B2B sales, and one of the least understood outside of security teams. Here's what it actually is, who needs it, and what getting there really looks like.

What ISO 27001 actually is

ISO 27001 is an international standard for an information security management system, usually shortened to ISMS. It's published jointly by the International Organization for Standardization and the International Electrotechnical Commission, which is why you'll sometimes see it written as ISO/IEC 27001.

The key thing to understand is that ISO 27001 doesn't certify a product or a piece of software. It certifies a system, specifically, the way your organization identifies security risks, decides how to handle them, and proves it's actually following through. That system covers policies, people, processes, and technical controls, all documented and reviewed on an ongoing basis.

Certification is issued by an accredited third-party certification body after an audit. It isn't self-declared and it isn't something you can print off a template and call done. An auditor examines your ISMS against the standard's requirements and the 93 controls listed in Annex A, then decides whether to issue the certificate.

Who actually needs it

ISO 27001 shows up most often in a few recurring situations:

  • Selling into Europe or the UK. ISO 27001 is the dominant security standard outside North America, similar to how SOC 2 dominates in the US.
  • Enterprise procurement requirements. Large buyers, particularly in financial services, telecom, and government-adjacent sectors, often list ISO 27001 as a hard requirement in vendor security questionnaires.
  • Multinational operations. Companies operating across several jurisdictions like having one recognized standard rather than juggling different regional frameworks.
  • Investors and boards asking for proof of a mature security program, not just a policy binder nobody has opened in a year.

If your buyers are mostly US-based SaaS companies, you'll more often be asked for SOC 2. Many Canadian companies selling on both sides of the Atlantic end up pursuing both, and there's real overlap in the underlying controls, so the second certification is rarely starting from zero.

What the process actually involves

At a high level, getting certified involves five stages, and none of them are optional shortcuts:

  • Risk assessment. You identify the information assets that matter (customer data, source code, infrastructure) and the risks to them.
  • Statement of Applicability. You decide which of the 93 Annex A controls apply to your business and document why others don't.
  • Implementation. You put the chosen controls into practice: access management, encryption, incident response, vendor risk management, employee training, and more.
  • Internal audit and management review. Before the real audit, you test your own system and fix what's broken.
  • Certification audit. This happens in two stages, typically weeks apart: a documentation review, then an on-site or remote assessment of whether the controls are actually operating as described.

Certification isn't a one-time event either. It's valid for three years, with surveillance audits typically each year to confirm the ISMS is still functioning, not just filed away.

Realistic timeline

Most companies starting from a reasonably mature security baseline should plan for three to six months to prepare for the initial audit. Companies starting from scratch, with no formal policies or documented processes, are usually looking at six to twelve months. The variables that move the needle most are the size of the organization, how much of the infrastructure is cloud-based versus custom, and how much internal bandwidth is available to do the work rather than hire it out.

Vendors selling "ISO 27001 in 30 days" are selling a document package, not a functioning ISMS that will survive an audit. Be skeptical of any timeline that sounds too fast for the amount of organizational change involved.

For a structured breakdown of the phases and what each one costs in time and effort, our ISO 27001 implementation service walks through the full readiness process we run with Canadian companies, including how to scope the ISMS before you start burning calendar time on the wrong controls.

Common misconceptions

"It's just a checklist." Annex A gives you a list of controls, but the standard requires you to justify, implement, and operate them in a way specific to your actual risks. An auditor testing evidence will notice a checklist masquerading as a management system.

"It's the same as SOC 2." They cover a lot of the same ground but aren't interchangeable. SOC 2 is an attestation report built around Trust Services Criteria and is more common in the US. ISO 27001 is a certification against an international standard and is more commonly requested outside North America. Some companies need one, some need both.

"Once you're certified, you're done." Certification requires ongoing operation of the ISMS, annual surveillance audits, and recertification every three years. Treating it as a one-time project is the most common reason companies fail their first surveillance audit.

"It covers privacy compliance too." ISO 27001 is a security management standard, not a privacy law. Canadian companies still need to separately address PIPEDA obligations, and Quebec-based companies or those handling Quebec residents' data have additional requirements under Law 25. There's real overlap between good security controls and privacy compliance, but ISO 27001 certification alone doesn't satisfy either law on its own.

"Small companies don't need it." Company size matters less than who your customers are. A ten-person company selling to a European enterprise buyer may need ISO 27001 well before a two-hundred-person company selling only within Canada does.

Where to start

The most useful first step isn't buying software or hiring an auditor, it's a gap assessment against the current state of your security program. That tells you which controls already exist, which need to be built, and roughly how much work is involved before you set a target audit date. If security and compliance work in your organization is still scattered across a few different owners, it's also worth looking at how a broader compliance program ties ISO 27001 into whatever else you're already tracking, rather than treating it as an isolated project.

If you're weighing ISO 27001 against SOC 2, or trying to figure out how PIPEDA and Law 25 fit into an ISMS you're building for a Canadian company, that's exactly the kind of question worth a direct conversation before you commit budget or a target date. Get in touch and we'll help you figure out the right starting point.

Not ready for a call? Same.

Get the playbook, not a sales pitch

If this was useful, Jacob sends a few short, practical notes on the unglamorous side of building a startup. No fluff, unsubscribe in one click. Just reply if you want to talk; it reaches him directly.

From Jacob Masse, founder of traztech. No spam, unsubscribe in one click.

Need help with any of this?

We help startups build secure, scalable infrastructure. Book a free strategy call and let's talk about your stack.

Book a free consultation