ISO 27001

ISO 27001 is the international standard for information security management systems (ISMS), the most commonly requested security certification in European B2B procurement.

ISO/IEC 27001 is the international standard for information security management systems (ISMS): a certifiable framework for how an organization identifies, manages and reduces information security risk. In European B2B procurement it is the most commonly requested security credential, often alongside or instead of SOC 2. The standard is published by ISO/IEC.

Key facts:

ISO 27001 vs SOC 2

ISO 27001SOC 2
What you getA certificateAn auditor's attestation report
Defined byISO/IEC (international)AICPA (US)
FocusThe management system (ISMS)Controls against Trust Services Criteria
Typical demandEuropean and global procurementNorth American enterprise buyers

Many vendors end up doing both; the underlying control work overlaps heavily. For financial entities, DORA layers operational resilience on top; for regulated critical sectors, NIS2 maps naturally onto the same ISMS foundations.

The Annex A controls that run through email

Several controls are decided in the mailbox: protection against malware, information transfer, technical vulnerability management, incident management and response, supplier relationships, and user access management all have email as a primary exposure surface, because phishing and business email compromise are how most information security incidents actually begin. An ISMS that treats email as an afterthought fails where attacks actually start.

Where email security fits, honestly

No product delivers ISO 27001; the certificate covers your whole management system. Sentaro contributes the email-layer controls and their evidence: threat protection as the operating control, continuous logs as audit evidence for surveillance audits, incident detection feeding the incident management process, and OAuth/app visibility supporting access and supplier controls. The risk assessments, policies, Statement of Applicability and management reviews remain yours.

This page is general guidance, not legal advice.

Frequently asked questions

What is ISO 27001 in simple terms?

An international, certifiable standard for how an organization manages information security: risk assessment, controls, documentation and continuous improvement, audited by an accredited third party.

How long does ISO 27001 certification take?

Commonly 6 to 18 months depending on scope and maturity: building the ISMS, operating it, then a two-stage certification audit followed by annual surveillance.

Is ISO 27001 mandatory?

No, it is voluntary, but customers and tenders increasingly require it, and frameworks like NIS2 map naturally onto an existing ISMS.

Does email security help with ISO 27001?

Yes, concretely: several Annex A controls (malware protection, incident management, supplier relationships, access) run through email, and continuous email-layer monitoring produces the evidence auditors test. But certification covers the management system, not any single tool.