Skip to content

After ISO 27001 Certification

 

Learn about verifying ISO 27001 certification, revoking certification, unplanned ISO 27001 audit, AI risk and ISO 27001, and more, through the Frequently Asked Questions (FAQs) below. Please schedule a meeting if you are looking for an authorized certifying body for your ISO 27001 Certification. 

Table of Contents

How can an organization verify another company’s ISO 27001 certification is valid? 

 

Verifying the validity of an ISO 27001 certificate requires checking the certificate document itself, confirming the certification body’s accreditation status, and optionally verifying the certificate number directly with the certification body. 

A valid certificate should clearly identify: the certified organization, the ISMS scope, the standard (ISO/IEC 27001:2022), the certificate issue date and expiry date, the certification body’s name, and the accreditation body’s mark (such as ANAB, IAS, or UKAS). To verify the certification body’s accreditation, check the body’s name against the relevant accreditation authority’s public directory (e.g., anab.org or iasonline.org). Organizations should be cautious of certificates referencing ISO 27001:2013 (which expired October 31, 2025), certificates without an accreditation body mark, or certification bodies that cannot be found in a recognized accreditation directory. Most accredited certification bodies also maintain a public certificate verification service accessible by certificate reference number. 

 

Can ISO 27001 certification be revoked? 

 

ISO 27001 certification can be suspended or fully withdrawn by the certification body under specific circumstances. Suspension occurs when: the certified organization fails a surveillance audit with unresolved major nonconformities, refuses to cooperate with the audit program, allows the ISMS to lapse in a way that undermines certification validity, or misrepresents the scope of certification to customers. A suspended certificate is temporarily invalid, giving the organization typically 90 to 180 days to resolve the underlying issues. If issues are not resolved within the suspension period, the certificate is withdrawn entirely, at which point the organization loses certified status and must pursue recertification from scratch. Organizations must also promptly notify their certification body of material changes, such as mergers, acquisitions, or significant security incidents, that may affect the ISMS, as failure to disclose can itself trigger suspension.

 

What triggers a special or unplanned ISO 27001 audit? 

 

A special audit is initiated by the certification body in response to specific events calling into question whether the certified organization’s ISMS continues to meet ISO 27001:2022 requirements between scheduled surveillance or recertification audits. 

Common triggers include: a significant security incident (such as a major data breach or ransomware attack) suggesting ISMS controls have failed; a substantial organizational change (such as a merger, acquisition, or major scope expansion) not anticipated at the last audit; substantiated complaints from customers or regulators about security practices; changes in certification body requirements or accreditation conditions; or information indicating that the organization has misrepresented the scope or effectiveness of its ISMS. Special audits may also be initiated at the organization’s own request, for example, to verify that corrective actions for a major nonconformity have been effectively implemented before the next scheduled audit. 

 

How does an organization maintain ISO 27001 certification as the business grows or changes scope? 

 

Maintaining ISO 27001 certification through organizational growth requires proactive ISMS management, controlled change processes under Clause 6.3, and close coordination with the certification body when scope or structure changes materially. 

When the business grows, through new products, new markets, acquisitions, or additional locations, the organization must assess whether changes fall within or outside the current ISMS scope. Changes within the existing scope require updating the risk assessment, SoA, and relevant controls. Significant scope expansions typically require formal notification to the certification body and may result in a scope extension audit. Acquisitions require careful ISMS integration planning: the acquired entity’s information assets, risks, and controls must be assessed and incorporated into the parent organization’s ISMS. The certification body must be notified of material changes promptly, failure to disclose significant organizational changes can result in certificate suspension.

 

What is the average cost of a data breach for organizations without strong information security controls? 

 

The global average cost of a data breach reached $4.88 million in 2024, according to IBM’s Cost of a Data Breach Report 2024, a 10% increase from the $4.45 million average reported in 2023. For US organizations specifically, the average breach cost was $9.36 million in 2024, the highest country average in the world. In the healthcare sector, breaches averaged $9.77 million in 2024, the fourteenth consecutive year healthcare ranked as the most expensive industry for data breach incidents, per IBM’s report. The IBM 2025 Cost of a Data Breach Report subsequently reported that US breach costs increased further to a new record of $10.22 million, reinforcing the trajectory. The total investment in ISO 27001 certification for a small to medium, sized organization, typically $30,000 to $150,000 over three years, represents a fraction of a single breach event’s cost, making a compelling financial case for structured information security investment. 

 

How has ISO 27001 adoption grown globally in the last decade? 

 

ISO 27001 adoption has grown substantially over the past decade, with the ISO Survey 2022, the most recent comprehensive dataset, confirming 71,549 valid certificates across 150 countries, up from approximately 22,000 certificates in 2013, representing more than a threefold increase. 

China, Japan, the United Kingdom, India, and Italy consistently rank among the countries with the highest certificate counts according to ISO Survey data. Growth has been driven by multiple converging factors: increasing enterprise buyer requirements for security certification as a vendor qualification, the emergence of data protection regulations (GDPR in 2018, CCPA in 2020, NIS2 in 2024) that elevated information security governance expectations, the surge in ransomware and data breach incidents that highlighted the consequences of inadequate security programs, and the rapid growth of cloud, based SaaS businesses where security assurance is a commercial requirement from the earliest stages of operation. The ISO Survey is published annually by ISO in collaboration with the IAF; survey participation by certification bodies is voluntary, and year, to, year fluctuations in reported numbers can reflect changes in reporting participation rather than actual certification growth.

 

What documents does an auditor review during an ISO 27001 certification audit? 

 

During an ISO 27001 certification audit, auditors review a comprehensive set of ISMS documents across two distinct stages, Stage 1 (documentation review) and Stage 2 (operational assessment), and the SoA is scrutinized at both. 

At Stage 1, the auditor from the accredited certification body reviews the organization’s ISMS documentation to assess whether the ISMS has been designed in conformance with ISO 27001:2022. Key documents reviewed at Stage 1 include: the ISMS scope statement, the Information Security Policy, the risk assessment methodology and risk register, the risk treatment plan, the Statement of Applicability (SoA), the asset inventory, internal audit records and reports, management review minutes, and corrective action records. Based on Stage 1 findings, the auditor develops the audit plan for Stage 2. 

At Stage 2, the auditor evaluates whether the ISMS is not only designed correctly but actually implemented, operational, and effective. In addition to revisiting the Stage 1 documents, auditors review operational evidence including: topic, specific security policies covering access control, cryptography, acceptable use, and supplier security; training and awareness completion records showing that all employees within scope have received security awareness training; incident logs demonstrating that security events are being recorded and managed; vulnerability scan reports and penetration test results providing evidence of technical security testing; access control configurations and access review records; change management records; supplier contracts containing information security clauses; business continuity and disaster recovery plans; and documented ISMS measurement and monitoring records. 

The SoA is a pivotal document at both stages, the auditor cross, references it against the risk register to verify that every applicable control selection is genuinely driven by an identified risk rather than copied from a generic template. Controls marked as applicable in the SoA without corresponding risk register entries are a common and significant audit finding. Organizations preparing for their first certification audit should ensure that all documentation is current, internally consistent, and accurately reflects actual operational practices, auditors will interview employees to verify that documented procedures match how the organization actually operates. 

 

What is the average cost of a data breach for organizations without strong information security controls? (2025 Update) 

 

IBM’s Cost of a Data Breach Report 2025 reported that the global average cost of a data breach fell slightly to $4.44 million, the first global decrease in five years, while US breach costs set a new record at $10.22 million, a 9.2% increase from the $9.36 million US average reported in 2024. Healthcare breaches in the US fell to $7.42 million in 2025 from $9.77 million in 2024, though healthcare maintained its position as the most expensive industry for breaches globally for the fourteenth consecutive year.  

The IBM 2025 Cost of a Data Breach Report found that organizations using AI, driven security and automation extensively in their security operations reduced breach costs by an average of $1.9 million compared to those without such capabilities, and reduced the breach lifecycle by an average of 80 days, reinforcing the case for structured, technology, supported security governance. Organizations should use the most recent IBM report as the baseline for breach cost justification in ISO 27001 business cases.

 

How does AI risk factor into ISO 27001, and what is ISO 42001? 

 

ISO 27001:2022 does not directly regulate artificial intelligence, but AI, related information security risks must be assessed and treated within the ISO 27001 risk management process, while ISO/IEC 42001:2023 provides the dedicated AI governance management system standard that organizations can implement alongside ISO 27001 for comprehensive coverage. 

Organizations using AI systems, whether for internal automation, customer, facing product features, data analysis, or decision support, must identify the information security risks those systems introduce and address them through the ISO 27001 risk assessment and treatment process required under Clause 6.1.2. AI, specific information security risks include: risks to data confidentiality through exposure of training datasets containing sensitive personal or proprietary information; integrity risks from adversarial inputs or data poisoning that could corrupt model outputs; availability risks from AI system failures or attacks targeting AI infrastructure; and supply chain risks from third, party AI models or platforms that process sensitive organizational data. Each of these risks must be evaluated, assigned a risk owner, and treated through appropriate Annex A controls, such as access control (Controls 5.15, 5.18), supplier security management (Controls 5.19, 5.23), data classification (Control 5.12), and monitoring (Control 8.16). 

ISO/IEC 42001:2023 is the dedicated Artificial Intelligence Management System (AIMS) standard published by ISO and IEC in 2023. It provides a full management system framework specifically for AI governance, addressing responsible AI development and deployment, AI, specific risk identification and treatment, transparency and accountability in AI systems, and ethical AI practices. ISO 42001 follows the same ISO Harmonized Structure used by ISO 27001, meaning the management system clauses (4, 10) are structurally identical across both standards. This shared structure makes it significantly more efficient for organizations to implement ISO 27001 and ISO 42001 in an integrated manner, sharing governance processes, documentation frameworks, risk assessment methodologies, internal audit programs, and management reviews across both standards rather than running entirely separate programs. 

For organizations operating in AI, intensive environments, such as SaaS platforms with AI features, healthcare technology companies using AI for clinical decision support, or financial services firms using AI for fraud detection, the combination of ISO 27001 (information security governance) and ISO 42001 (AI governance) provides the most comprehensive and defensible risk management framework currently available. As regulatory expectations around AI governance accelerate globally, including the EU AI Act and emerging US federal AI guidance, the intersection of ISO 27001 and ISO 42001 is one of the most strategically important areas in the information security compliance landscape.

 

How has the ISO 27001:2022 transition affected organizations that were certified under the 2013 version? 

 

The October 31, 2025 transition deadline for ISO 27001:2022 has divided the certified organization landscape into two groups: those that completed transition audits before the deadline and maintained certification, and those that did not and must now pursue full initial certification under ISO 27001:2022. 

Organizations that completed their transition audits before October 31, 2025 now hold valid ISO/IEC 27001:2022 certificates and continue through the normal three, year certification cycle with annual surveillance audits. The transition process required those organizations to: purchase the official ISO/IEC 27001:2022 standard document; conduct a gap analysis comparing their existing ISMS against the 2022 requirements; evaluate the 11 new Annex A controls, including Threat Intelligence (Control 5.7), Data Leakage Prevention (Control 8.12), Cloud Service Security (Control 5.23), Secure Coding (Control 8.28), and others, for applicability to their risk environment; update their Statement of Applicability to reflect the new four, theme control structure; revise their risk treatment plan to incorporate newly applicable controls; update affected policies, procedures, and documentation; and complete a formal transition audit with their certification body. The transition audit could be conducted as a stand, alone special audit, combined with a scheduled surveillance audit, or combined with a recertification audit depending on the organization’s audit cycle timing. 

Organizations that missed the October 31, 2025 deadline have certificates that expired automatically and are no longer recognized as valid by any accredited certification body or national accreditation authority worldwide. These organizations cannot reinstate their expired certificates, they must begin the full initial certification process under ISO 27001:2022, which includes a complete two, stage audit (Stage 1 documentation review and Stage 2 operational audit) conducted by an accredited certification body, as though they are being certified for the first time. The practical commercial consequences of expired certification are immediate: enterprise contracts requiring valid ISO 27001 certification as a vendor qualification condition may lapse; responses to security questionnaires claiming active ISO 27001 certification are no longer accurate; and in some regulated industries or government contract contexts, expired certification may trigger compliance review or contract renegotiation. Any organization continuing to display or market an expired ISO 27001:2013 certificate as current valid certification is misrepresenting its security assurance standing to customers, partners, and regulators. The recommended course of action for organizations in this position is to immediately contact an accredited certification body, conduct a gap analysis against ISO 27001:2022, and begin the initial certification process as a priority.

 

Explore Blogs, Webinars and other Resources

Trusted by Reputed Companies

pVerify, Inc.
Electronic Data Solutions
Bernard Robinson & Company
Avance Care
iCliniq
Botsplash
Logically
Mr.Internet Systems
Vision Radiology
Tangible Solutions
Tangible Solutions
WorkSmart
Triyam
Med First Primary and Urgent Care
Arizona State Radiology
DataCaliper
Dose Spot Company Logo
DoseSpot
Forsyte I.T. Solutions
Tego Data

Accreditations and Associations

* Disclaimer: This list of accreditations is held by our team of employees and consultants.

What Our Clients Say

We used databrackets (formerly EHR 2.0) in our small medical practice for our risk analysis assessment to be in compliance with meaningful use. Their response was fast, the final report is detailed but simple and easy to follow. They were always available to answer our questions.
E. Compres
Pulmonary and Sleep Center of the Valley
I never miss the opportunity to learn something new …that’s why I am always registering to all free seminars offered on the web. databrackets (formerly EHR 2.0) happened to be the friendliest, comprehensive and up-to- date source of HIPAA Privacy and Security updates.
Alexandra V.
Community Healthcare Network
Today’s presentation was great! Thank you for sending the slides. My only feedback is that it would be fabulous to have the slides ahead of time so I could print them and take notes on the slides.Thanks for your time and knowledge today!
T.B., PM
Community Health Network
Particularly interesting was the flow chart on Administrative Simplification. I utilize all of the Security subcategories you list under the Security tile and appreciate knowing that I am hitting all of the relevant topics during my employee training.
Jessica B.
JD, CHC
I have re-worked our original risk assessment….We are using databrackets' (formerly EHR 2.0) Meaningful Use Security Risk Analysis Toolkit and it meets our needs. It was easy to use and I believe that it very beneficial to our meeting meaningful use.
Bill Curtis
Neurosurgical Associates Of Texarkana, TX
Information (webinars) presented by databrackets (formerly EHR 2.0) highlights some of today’s most demanding healthcare topics. The webinars help to direct those operating in today’s rapidly changing environment in the right direction.
Candace M.
Privacy and Security Officer, Springhill Medical Center

Our Growing List of Credentials

0 +
Assessments
0 +
Clients
0 +
Assessment Libraries
0 +
Years of Experience
0 +
No. of Staff Trained
0 +
HIPAA
0 +
SOC 2 Readiness
0 +
Pen Testing
0 +
ISO 27001 Certifications
0 +
Dollars Saved in Compliance Penalties