Hael
Book a meeting
ISO 27001 · Compliance

ISO 27001 compliance

Hael · Published 7 August 2026 · Last reviewed 7 August 2026 · 8 min read
Key takeaways
  • Compliance means operating an ISMS that meets Clauses 4 to 10 and the Annex A controls you selected.
  • You can comply without certifying, though buyers almost always want the certificate because a claim is not checkable.
  • Total first-year cost commonly runs £20,000 to £70,000 including implementation and certification.
  • Holding SOC 2 reduces the work materially, and the two can be run from one control set.
  • The annual internal audit and management review are permanent commitments, not one-off steps.

What compliance means

ISO 27001 compliance means running an information security management system that meets ISO/IEC 27001:2022: a defined scope, an information security policy, assigned roles, a risk assessment and treatment process, the controls you selected in your Statement of Applicability, internal audit, management review and continual improvement.

Certification is separate. You can meet the standard without being certified, and some organisations do. Most that were asked for it by a customer certify anyway, because a certificate is verifiable and a statement is not.

The five stages

Scope. Which parts of the organisation, which services, which locations, which information. Too narrow and the certificate does not cover what your buyer cares about. Too wide and you are governing things nobody asked about, at cost.

Build. Policy, roles, risk assessment method, risk treatment plan, the Statement of Applicability, and the controls themselves: access management, change control, logging and monitoring, supplier security, incident response, business continuity, secure development. Plus the eleven controls new in the 2022 edition, which is where most of the work concentrates.

Operate. The ISMS has to run long enough to produce records. Access reviews performed, risks reviewed, incidents handled, suppliers assessed, changes approved. An auditor samples this period.

Audit. The Clause 9.2 internal audit, then management review, then the certification body's Stage 1 and Stage 2.

Maintain. Surveillance in years two and three, recertification at year three, and the internal audit every year.

What it costs

ComponentTypical range
Gap analysis£5,000 to £15,000
Implementation and readiness£15,000 to £50,000
Certification body, initial cycle£5,000 to £20,000
Annual surveillance audit20% to 40% of the initial audit fee
Annual internal audit, outsourced£4,000 to £12,000
Total first year, small to mid-sized organisationRoughly £20,000 to £70,000

Cost is driven by scope, number of sites, headcount within scope, and how mature your existing security practice is. Internal team time is frequently the largest line and rarely appears in the budget.

How long it takes

Three to six months for an organisation with reasonable security practice already in place. The floor is set by the operating period and by certification body availability, neither of which you control by working harder.

The eleven new controls

The 2022 edition added controls that did not exist in 2013, and they are where most implementation effort now goes: threat intelligence, information security for use of cloud services, ICT readiness for business continuity, physical security monitoring, configuration management, information deletion, data masking, data leakage prevention, monitoring activities, web filtering, and secure coding.

Organisations transitioning from an older ISMS often find these are the gaps. Organisations starting fresh build them alongside everything else and barely notice them as separate.

Where programmes go wrong

A Statement of Applicability that does not reason. Excluding controls is allowed. Excluding them without justification is a nonconformity, and the document is the first thing an auditor reads.

Risk assessment as a formality. The controls you select are supposed to follow from the risks you identified. Where the risk register was written after the control list, auditors notice.

Policies describing a company that does not exist. It surfaces in Stage 2 interviews, when someone describes what actually happens.

Records that only exist for the audit period. Surveillance samples the year, and a system that stopped in month three shows up in month fourteen.

Internal audit left late, or performed by whoever built the ISMS. It is required annually and it has to be independent in substance.

The climate consideration missed. Amendment 1 of February 2024 requires your context analysis to record whether climate change is a relevant issue. It is a one-paragraph fix and a routine finding when absent.

How it relates to other frameworks

SOC 2. Heavy overlap in control substance. An organisation holding one can usually reach the other for a fraction of the original cost, running one control set and one evidence base. See our SOC 2 service page.

ISO/IEC 42001. The AI management system standard, which shares the same management system structure. Annex D of ISO/IEC 42001 addresses integrating the two, and running them together is materially cheaper than separately. See our ISO/IEC 42001 service page.

GDPR. The security-of-processing obligations map onto ISO 27001 controls, though the standard says nothing about lawful basis, data subject rights or transfers.

What has to keep running

The annual internal audit. The management review. Risk reviews. Access reviews. Supplier assessments. Incident records. Corrective actions closed and verified.

This is what surveillance tests, and it is the part organisations most often let lapse once the certificate arrives. Our continuous governance and assurance service exists for it.

What to do next

Settle scope, then get an honest view of your position against the 2022 structure.

Our free readiness diagnostic gives a first view, our readiness and gap assessment produces the detailed position for a fixed fee, and the ISO 27001 service page sets out how we run the programme.

References

FAQ

Can we comply with ISO 27001 without certifying?

Yes. Certification is voluntary. Most organisations asked for it by a customer certify anyway, because a certificate is verifiable.

How much does ISO 27001 compliance cost?

Commonly £20,000 to £70,000 in the first year including implementation and certification, driven by scope and headcount within scope.

Does SOC 2 make it cheaper?

Materially. The control substance and evidence discipline transfer, and the two can be run from one control set.

How long does it take?

Three to six months for an organisation with reasonable security practice, limited by the operating period and audit availability.

What is the climate amendment?

Amendment 1 of February 2024 requires your context analysis to consider whether climate change is a relevant issue. Small to address, routinely raised when missing.

About Hael

Hael is an advisory firm specialising in AI governance and security compliance. We do the work, hold the deadline and stand behind the evidence, across ISO 27001, SOC 2, ISO/IEC 42001 and the EU AI Act. We are not a certification body and we take no commission from certification bodies or platform vendors. On engagements involving regulated financial services firms we work alongside Buckingham Capital Consulting, the partner firm that has advised payment and e-money firms on authorisation and compliance since 2013.

This guide is general information and is not professional advice on your particular circumstances.

Free check

See where you stand on ISO 27001, free.

Answer a short set of questions and see what ISO 27001 expects of your AI systems and where you stand today. No sign-up to see your result.

Applicability

Whether ISO 27001 applies to how you use AI, and to which systems.

What is expected

Risk classification, governance, documentation and human oversight.

Where you stand

A banded result, pointed at the gaps that matter most.

What you get

On screen in about five minutes, pre-scoped to ISO 27001.

Or speak to us about your deadline. Book a meeting.