Definition

ISO 27001

The international standard for information security management.

ISO 27001 is the international standard for information security management systems, demonstrating that an organisation systematically manages risks to the confidentiality, integrity and availability of information. Public sector tenders involving sensitive data, IT services or critical infrastructure frequently require it or accept it as strong evidence of security maturity.

What it covers and how it differs from Cyber Essentials

ISO 27001 requires an organisation-wide information security management system covering risk assessment, security policies, access control, incident management, business continuity, and supplier relationships, verified through independent certification audit. It is broader and more organisationally embedded than Cyber Essentials, which focuses on five specific technical controls; many organisations hold both, using Cyber Essentials as a baseline and ISO 27001 for more comprehensive assurance.

How suppliers evidence it in a tender

  • State the certificate number, scope statement, and certification body
  • Confirm the scope covers the systems and locations relevant to the contract
  • Where not certified, describe equivalent controls mapped against the standard's requirements
  • Note the date of the last surveillance audit to show the certification is actively maintained

Timescales and cost considerations

Achieving ISO 27001 from a standing start typically takes several months to a year, depending on the maturity of existing security practices, since it requires building a documented management system and passing a two-stage certification audit. Ongoing surveillance audits and full recertification every three years are needed to keep the certificate current.

Frequently asked questions

Is ISO 27001 the same as Cyber Essentials?
No. Cyber Essentials covers five basic technical controls and is quicker to achieve, while ISO 27001 is a comprehensive, organisation-wide information security management system verified by independent audit. Higher-risk contracts, particularly those involving sensitive data, often require ISO 27001 specifically.
Can a supplier bid without ISO 27001 if the tender asks for it?
Often yes, if the tender allows equivalent evidence; suppliers should describe their information security policies, controls and governance in detail, mapped against the standard where possible. Some tenders make it a strict mandatory requirement, so check the selection criteria carefully.
How long does ISO 27001 certification take to achieve?
Typically several months to around a year for an organisation building its information security management system from scratch, covering risk assessment, policy development, implementation, and a two-stage certification audit. Organisations with existing strong security practices may achieve it faster.

Related terms

Free tools for costing and planning your bid

See all free tender tools