What is ISO 27001?
ISO/IEC 27001 is the international standard for implementing an Information Security Management System (ISMS). Instead of a loose list of technical measures, it defines a framework to identify your risks, decide which controls to apply and improve continuously. The current version is ISO 27001:2022.
It's a certifiable standard: an accredited body audits your system and, if it complies, issues the certificate. That's what you show a client or submit in a tender as proof you take security seriously.
Who is it for (and who requires it)?
It's not legally mandatory in general, but it has become a de facto market requirement. It's for you if:
- You want to sell to large clients or the public sector, who require it in contracts and tenders.
- You're a technology provider, SaaS or service handling third-party data.
- You want to organise your security and stand out from those who can't prove it.
In the Spanish public sector the equivalent framework is the ENS. If you work with the Administration you probably need the ENS; if your market is private or international, ISO 27001.
What does it require?
Getting certified means building and maintaining an ISMS. In practice you'll have:
- Context and scope of the system.
- Security policy approved by management.
- Risk assessment and treatment.
- Statement of Applicability (SoA) over the 93 Annex A controls.
- Staff training and awareness.
- Internal audits and management review.
- Continuous improvement.
The key: it's not paperwork for its own sake. It's proving you manage risk for real and keep it alive over time.
How we help you get it
- Diagnosis and gap analysis. Where you stand against the standard.
- Scope and risk assessment. What to certify, prioritised by real risk.
- Implementation. Policies, controls, evidence and training, without drowning you in documents.
- Internal audit and management review.
- Certification audit and maintenance with the accredited body.
If you already work with Tria, you're most of the way there. Our way of working keeps policies, controls and evidence up to date on the platform — so when you decide to certify, the step to ISO 27001 is almost a formality.
ISO 27001, ENS, NIS2… what's the difference?
ISO 27001 is a voluntary international standard that the market demands. The ENS is mandatory for the Spanish public sector and its suppliers. NIS2 is an EU directive for essential sectors. They overlap heavily: a solid ISMS gets you most of the way to ENS and NIS2.
Frequently asked questions
How long does certification take?
It depends on size and starting point, but usually between 4 and 9 months from diagnosis to the certification audit.
How much does ISO 27001 cost?
Two parts: the implementation project (consulting) and the certification body's audit (an independent third party). We break it down with no fine print before we start.
How long is the certificate valid?
Three years, with annual surveillance audits to keep it.
Do I need ISO 27001 or the ENS?
If you work with the Administration, the ENS. If your market is private or international, ISO 27001. Sometimes both.
Does it help with NIS2?
Yes — many controls overlap with the measures NIS2 requires.