Definition
ISO 27001
ISO 27001 is the international standard for building and certifying an information security management system. A company earns certification when an accredited body audits its ISMS and confirms it meets the standard's requirements for risk assessment, control selection, and continual improvement. Unlike a SOC 2 report, which delivers a CPA's opinion, ISO 27001 delivers a certificate that is recognized worldwide and stays valid for 3 years with annual surveillance audits in between. Buyers across Europe and Asia often ask for it by name, so it pairs well with SOC 2 for companies selling across borders.
Keep exploring
← Back to the full glossary