ISO/IEC 27001 Information Security Management

ISO 27001 Isn’t Law
But It Wins You Contracts

Customers, insurers and tenders increasingly demand it. Certification proves you manage information risk, not just claim it.

See what the standard requires

Two Parts, Both Required

Clauses 4–10 (the management system) and Annex A (93 controls). No clause can be excluded if you want to claim conformity.

Certification, Not Self-Declaration

Awarded only by an accredited external certification body after an audit. It isn’t something an organisation declares about itself.

Continuous, Not One-Time

Annual surveillance audits and multi-year recertification confirm the ISMS stays current after the first certificate is issued.

Trusted by 100+ Swedish Kommuner, Regions and
EU-Regulated Enterprises Since 2002

Why It Comes Up

Who Typically Works Toward It

ISO/IEC 27001 applies to any organisation, of any size or sector. In practice, most organisations start for one of four reasons.

Reality Check

Is Your ISMS Actually Audit-Ready?

Documentation and evidence are two different things. An auditor checks for both.

A Policy Without a Statement of Applicability

You have a security policy but no Statement of Applicability. The SoA records which of the 93 Annex A controls you have applied, which you have excluded and why and an auditor checks that reasoning as closely as the controls themselves.

A One-Off Risk Review, Not a Process

You have run a risk review once but there is no repeatable process behind it. Clauses 4–10 expect ongoing risk assessment and treatment, not a single exercise completed ahead of an audit.

No Internal Audits or Management Reviews

You have security tools but no internal audits or management reviews on record. The standard requires documented internal audits and leadership reviews as evidence the system is being run, not just built.

An ISMS Built Once and Left Alone

You built the ISMS for last year’s audit and nobody has touched it since. An ISMS is meant to be operated continuously which is exactly what surveillance audits and recertification exist to check.

ISO/IEC 27001:2022

What the Standard Actually Requires

An ISMS built to the standard has two connected parts plus an external audit to confirm it works.

Clauses 4–10

The Management System

Scope, leadership, risk assessment & treatment, documentation, internal audits and management review. None can be excluded to claim conformity.

Annex A

The Controls

93 controls across four themes: organisational, people, physical, technological. What’s applied or excluded and why, is recorded in a Statement of Applicability.

External Audit

Certification

An accredited certification body runs a two-stage audit, then annual surveillance and multi-year recertification to confirm the ISMS stays current.

ISO/IEC 27001 · Free Readiness Score

See Exactly Where Your ISMS Stands Against the Standard

Maps your current state against the five core ISMS elements an auditor checks first: scope and policy, risk assessment, the Statement of Applicability, internal audits and management review. Takes about 20 minutes. The output is board-ready.

  • Your score against each core ISMS element, not a generic checklist.
  • Your highest-priority gap, ranked by how closely an auditor is likely to examine it.
  • A board-ready summary, written in plain language, not audit-speak.

No obligation · EU data residency · Results reviewed in a 30-minute call.

ISO 27001 Readiness Score

See where your ISMS stands against the standard's core elements, scored in plain language. The output is board-ready.

No spam. EU data residency.

How We Help

We Build the ISMS. You Choose the Certifier.

We don’t certify organisations – that’s issued by an accredited external certification body. We build and operate the parts of an ISMS an auditor and your board expect to see.

Clauses 4–10

CISO as a Service

An ISMS roadmap, risk treatment, a policy set and internal-audit support, run by an advisor who stays with your programme.

Managed by CISO Advisory
Annex A 8.8

Vulnerability Management

Discover, prioritise, remediate to verified closure and report continuously producing the register and closure evidence an auditor asks to see.

Annex A 8.29

Penetration Testing

Independent, human-led testing from Sweden-based testers with a free retest on every engagement to confirm fixes hold.

Managed by Pen Testing
Annex A 6.3

Security Awareness Training

Managed training and phishing simulation in Swedish and English exporting the completion records auditors ask for at surveillance and recertification.

Managed by Security Awareness
Operating Evidence

24/7 MDR & SOC

Ongoing monitoring and incident records that show the ISMS operates continuously. Our own SOC is independently certified to ISO/IEC 27001.

Managed by MDR & SOC 24/7
Why eBuilder

Sweden-Based Security Built to Produce Audit Evidence

We’re not a global firm that adapted generic content for an ISO audit. Auditable evidence, Sweden-based delivery and continuous operation are what we design our services around.

See Full Annex A Coverage

Sweden-Based
24/7 SOC

Human analysts watching every signal, every minute, every day. Logs stay in Sweden.

3-minute
Median Response

Industry response times average 1–24 hours. We measure ours in minutes and escalate threats fast enough to matter.

Onboard in Days,
Not Quarters

Signed Monday. MDR live Thursday. Complorer rolled out by Wednesday.

20+ Years in SaaS

Cybersecurity practice within eBuilder, a Swedish enterprise-software company operating since 2002.

ISO 27001 Certified

Independently audited and certified to the ISO 27001 information-security standard for our own SOC.

ISO 27001 certification mark

Annex A Coverage

Services mapped across all four Annex A themes: organisational, people, physical and technological.

GDPR & Schrems II
Compliant

Human-led monitoring, secure data handling and infrastructure aligned with GDPR and Schrems II requirements.

Questions

ISO/IEC 27001, Answered

Real questions a board or compliance lead asks before engaging on ISO 27001, answered in two to three sentences.

Is ISO/IEC 27001 mandatory?

No. Unlike NIS2, GDPR or DORA, it’s a voluntary, certifiable standard. Organisations choose to pursue it, most often because a customer, tender, insurer or their own board asks for the proof.

What’s the difference between the management system and Annex A?

Clauses 4–10 are the mandatory operating structure. Annex A’s 93 controls are selected based on your own risk assessment, not every control applies to every organisation.

What is a Statement of Applicability?

A documented record of which Annex A controls you’ve applied, excluded and why. Auditors check this reasoning as closely as the controls themselves.

Do we need to implement all 93 Annex A controls?

No. You run a risk assessment, decide which controls address your risks and document that reasoning including exclusions, in the Statement of Applicability.

Who actually certifies us?

An accredited external certification body, after a two-stage audit. eBuilder Security doesn’t certify – no provider can promise that outcome on your behalf.

Does certification expire?

Certification is followed by annual surveillance audits and recertification on a multi-year cycle. An ISMS is meant to be operated continuously, not built once and left untouched.

How does eBuilder Security help if you don’t certify us?

Through CISO advisory, vulnerability management, penetration testing, security awareness training and MDR/SOC, each mapped to a specific clause or Annex A control, producing the evidence an auditor expects.

Is eBuilder Security’s own SOC certified?

Yes – our SOC is independently audited and certified to ISO/IEC 27001.

Talk to Us

ISO/IEC 27001 Is a Choice, Not a Deadline.
Let’s Make Sure It’s the Right One.

Book a free 30-minute briefing with a Sweden-based advisor. We’ll look at your current posture against the standard and talk through a realistic certification roadmap with no obligation.

Get Your Free ISO 27001 Readiness Score
No commitment required