← Glossary

ISO 27001

ISO 27001 is the international standard for information security management systems (ISMS), the most commonly requested security certification in European B2B procurement.

Updated

ISO/IEC 27001 is the international standard for information security management systems (ISMS): a certifiable framework for how an organization identifies, manages and reduces information security risk. In European B2B procurement it is the most commonly requested security credential, often alongside or instead of SOC 2. The standard is published by ISO/IEC.

Key facts:

  • Certification is issued by accredited bodies after auditing your ISMS, with surveillance audits annually and recertification on a three-year cycle.
  • The current version (ISO/IEC 27001:2022) organizes Annex A into 93 controls across organizational, people, physical and technological themes.
  • ISO 27001 certifies the management system, the way you run security, not any single technology.

ISO 27001 vs SOC 2

Many vendors end up doing both; the underlying control work overlaps heavily. For financial entities, DORA layers operational resilience on top; for regulated critical sectors, NIS2 maps naturally onto the same ISMS foundations.

The Annex A controls that run through email

Several controls are decided in the mailbox: protection against malware, information transfer, technical vulnerability management, incident management and response, supplier relationships, and user access management all have email as a primary exposure surface, because phishing and business email compromise are how most information security incidents actually begin. An ISMS that treats email as an afterthought fails where attacks actually start.

Where email security fits, honestly

No product delivers ISO 27001; the certificate covers your whole management system. Sentaro contributes the email-layer controls and their evidence: threat protection as the operating control, continuous logs as audit evidence for surveillance audits, incident detection feeding the incident management process, and OAuth/app visibility supporting access and supplier controls. The risk assessments, policies, Statement of Applicability and management reviews remain yours.

This page is general guidance, not legal advice.

Questions we get asked.

What is ISO 27001 in simple terms?

An international, certifiable standard for how an organization manages information security: risk assessment, controls, documentation and continuous improvement, audited by an accredited third party.

How long does ISO 27001 certification take?

Commonly 6 to 18 months depending on scope and maturity: building the ISMS, operating it, then a two-stage certification audit followed by annual surveillance.

Is ISO 27001 mandatory?

No, it is voluntary, but customers and tenders increasingly require it, and frameworks like NIS2 map naturally onto an existing ISMS.

Does email security help with ISO 27001?

Yes, concretely: several Annex A controls (malware protection, incident management, supplier relationships, access) run through email, and continuous email-layer monitoring produces the evidence auditors test. But certification covers the management system, not any single tool.

Stop reading about it. Watch it get blocked.

Free for one account. Four minutes to connect.