Security and privacy

Information security management (ISO/IEC 27001)

Certification of a management system for information security, covering how an organisation protects its own and its customers’ data.

CodeISO 27001
RegionInternational
TypeVoluntary, contractual
Issued byAccredited certification bodies
Last verified2026-10-10
Quick answerCertification · last verified 2026-10-10

Certification of a management system for information security, covering how an organisation protects its own and its customers’ data. Status: Voluntary, contractual. Issued or recognised by Accredited certification bodies.

CodeISO 27001
RegionInternational
TypeVoluntary, contractual
Issued byAccredited certification bodies
GroupSecurity and privacy
Last verified2026-10-10
How to cite this pageIoT Atlas. "Information security management (ISO/IEC 27001)". https://hi-spark.net/certification/iso-27001.html Last verified 2026-10-10.

What it means

ISO/IEC 27001 certifies the organisation and its processes, not a specific device. For IoT companies it is most relevant to the cloud service, the mobile app backend and internal development practices, and it is frequently demanded in B2B procurement.

Applies to

  • Cloud platforms and app backends
  • Companies operating customer data at scale
  • Vendors responding to enterprise security questionnaires

What it does not cover

  • Device level security requirements
  • Privacy law compliance, which ISO 27701 addresses
  • Product certification of any kind

Verification checklist

  • Define the scope and statement of applicability
  • Assess risks and select controls
  • Operate the management system with evidence
  • Complete stage 1 and stage 2 audits and maintain surveillance audits