İçeriğe geç
wedevit

July 28, 2026 · 7 min read · cyber security

İlhan Buğra Aslan

What an ISO 27001 certificate actually proves, and whether you need one


ISO 27001 is the only international standard that treats information security as a management system and can be certified against. What the certificate proves is widely misread. It does not say your company cannot be breached. It says that inside a declared scope you assessed your risks, implemented the controls you chose, and proved it to an independent auditor. The current edition is ISO/IEC 27001:2022, read together with Amendment 1 published in February 2024. If a customer is asking for the certificate in a contract or a tender, the decision is easy. If you want the certificate to make you meaningfully safer, the answer depends entirely on how you draw the scope.

The standard has spread fast, though the numbers need reading carefully. The ISO Survey 2024 counted 96,709 valid ISO/IEC 27001 certificates covering 179,877 sites. That looks like a near doubling from 48,671 the year before, but 2024 was the first edition compiled from the IAF CertSearch database instead of voluntary reporting by certification bodies, so much of the jump is better data coverage rather than new certificates. By country, China leads by a wide margin with 33,359, followed by India (6,758), Japan (6,644), the UK (4,455) and the US (4,260).

The line everyone skips: the scope statement

ISO 27001 does not certify a product, a server, or a company as a whole. It certifies an information security management system (ISMS) operated for defined processes, assets, and organisational units. That makes the scope statement the most useful line on any certificate. If a supplier's certificate is scoped to "operation of the Istanbul data centre," it tells you nothing about their development team, their support desk, or the laptop their account manager carries around. When you assess vendors, read the scope before you look at the logo.

Two halves: Clauses 4 to 10, and Annex A

Clauses 4 through 10 are the mandatory part and there is no negotiating them: context of the organisation, top management commitment, a risk assessment and treatment process, objectives, competence, internal audit, and management review. Most of that has to exist in writing, including the scope, the policy, risk assessment and treatment results, objectives, monitoring results, the internal audit programme and its findings, and management review records. Amendment 1:2024 added one small concrete item here. Clause 4.1 now asks you to determine whether climate change is a relevant issue for your organisation, which means asking the question and recording your answer, not assuming it applies.

The second half is Annex A: 93 controls, sorted by the 2022 revision into four themes. 37 organisational (5.1 to 5.37), 8 people (6.1 to 6.8), 14 physical (7.1 to 7.14), and 34 technological (8.1 to 8.34). A common misreading is that all 93 are expected to be in place. They are not. Your risk assessment decides which apply, you record those decisions in the Statement of Applicability, and the auditor checks two things: that the controls you claim are genuinely working, and that every exclusion holds up. Most of the controls are work you already recognise: backup (A.8.13), technical vulnerability management (A.8.8), incident response (A.5.24 to A.5.28), and secure use of cloud services (A.5.23).

How certification actually runs

Certification is a two stage audit. Stage 1 reviews documentation and readiness, usually runs one or two days depending on size, and exists to surface the big gaps before you sit the real exam. Stage 2 normally follows six to eight weeks later, hunts for evidence in the field, and its duration comes from headcount, scope, and risk profile rather than a fixed price list. Pass it and the certificate runs for three years: a surveillance audit in year one and year two, then a recertification audit at the end of the cycle that goes as deep as Stage 2. ISO 27001 is not a project with an end date. It is a three year calendar.

One date has already closed. The IAF set 31 October 2025 as the final deadline for moving from ISO 27001:2013 to the 2022 edition, and certificates issued against the 2013 version during the transition window expired on that date instead of running their usual three years. An organisation still holding a 2013 certificate today holds nothing valid, and restarting means being treated as a new client with a full initial audit. If a supplier file in your records shows a 2013 certificate, that certificate is dead.

Accredited, or just printed?

Not every certificate on the market is accredited. Accreditation is not compulsory either, so a non-accredited certification body is not automatically a bad one. But an accredited certificate has one concrete advantage: you can verify it in IAF CertSearch, and a non-accredited one never appears there at all. When you check, confirm two separate things. Is the certification body's accreditation currently active, and does its accreditation scope actually cover ISO 27001? Being accredited for ISO 9001 says nothing about 27001. Turkey's national accreditation body is TÜRKAK, which is why public sector IT contracts there usually name a TÜRKAK-accredited TS EN ISO/IEC 27001 certificate specifically.

Where it turns mandatory in practice

In Turkey ISO 27001 is not a blanket legal requirement. It becomes mandatory contractually and by sector, and most companies meet it for the first time in public IT tenders. Separately, Presidential Circular 2019/12 on Information and Communication Security Measures (Official Gazette, 6 July 2019) and the Information and Communication Security Guide that followed from the Digital Transformation Office created a distinct obligation for public bodies and operators of critical infrastructure services: compliance with the guide must be audited at least once a year and the results reported to the Digital Transformation Office. The guide does not demand an ISO 27001 certificate on its own, but implementing it assumes a working ISMS underneath. Running both from one set of processes usually costs less than managing two separate programmes.

An ISO 27001 certificate is not KVKK compliance

These two get conflated constantly. ISO 27001 helps you cover a good share of the technical and organisational measures Article 12 of Turkey's data protection law requires, since access control, logging, backup, staff awareness, and supplier security all live inside Annex A. But compliance is more than security measures: a lawful basis for processing, privacy notices, a retention and destruction policy, handling data subject requests, VERBİS registration. No ISMS certificate produces any of those for you. If you want the privacy side certified too, the standard to look at is ISO/IEC 27701. Its 2025 edition, published on 14 October 2025, is no longer an extension of ISO 27001 but a standalone standard on the harmonised Clause 4 to 10 structure, so it can now be certified without holding ISO 27001 at all.

Should you go for it?

Two questions settle it. First: who is asking? If the answer is a customer contract, a tender specification, or an overseas partner running vendor due diligence, the maths is simple and the certificate is a cost of sale. Second: what do you want besides the certificate? There are two kinds of ISO 27001 project. In one, the company genuinely inventories what it has, argues about its real risks, tightens access rights, and the audit is a by-product of that work. In the other, a folder of policies gets written, everyone performs on audit day, the certificate goes up on the wall, and six months later nobody can name a single policy. Both types get certified. Only one of them stops an attack.

The useful first step costs nothing. Before you call a single certification body, write two pages: your candidate scope (which unit, which service, which locations) and an honest gap analysis of where you stand against the standard today. Without those, every quote you receive and every timeline you are handed is guesswork. At Wedevit we draw that scope around what you commercially need it to cover, run the gap analysis against Annex A, build the Statement of Applicability and the mandatory documents, and carry out the internal audit before the external one arrives. We do not issue the certificate, an accredited body does. Our job is that you pass first time and that a real system is still running behind the certificate afterwards.


Need help with this topic?

get in touchall posts