ISO 27001 is the certification that actually is one - unlike SOC 2, there is a certificate, an accredited body behind it, and a formal audit cycle that never really ends. It certifies something subtle but powerful: not a list of security features, but a management system that keeps assessing risk, operating controls, and correcting itself year after year. This guide explains the ISMS concept, the 93 Annex A controls of the 2022 revision, how stage 1 and stage 2 audits work, the surveillance and recertification cycle, realistic cost and timeline ranges, the scope-statement trap that catches unwary buyers, and how ISO 27001 pairs with SOC 2 and IEC 62443 in a SCADA evaluation.
One of 60+ guides in our SCADA security and compliance series.
Most people assume ISO 27001 certifies that a company "is secure." It certifies something more durable: that the company operates an information security management system - a closed loop of risk assessment, control selection, measurement, internal audit, management review, and corrective action, modeled on the same plan-do-check-act discipline behind ISO 9001 quality systems. The insight is that security is not a state you reach but a process you run; a company with a genuine ISMS will find and fix its own weaknesses between audits, while a company with a binder of policies will not.
The standard - ISO/IEC 27001:2022, published jointly by ISO and IEC and available for purchase from the IEC webstore - has two halves. Clauses 4 through 10 define the mandatory management system itself: understanding context, leadership commitment, risk assessment and treatment, resources and competence, operational control, performance evaluation, and improvement. Annex A supplies the reference control set the risk process draws from. Critically, an organization does not implement Annex A wholesale - it selects controls justified by its risk assessment and documents every inclusion and exclusion in the Statement of Applicability (SoA), one of the most information-dense documents you can request from a vendor.
The 2022 revision (with ISO/IEC 27002:2022, likewise published by ISO and IEC, as its companion guidance) reorganized the old 114 controls into 93 controls across four themes:
The 2022 refresh also added controls that speak directly to modern SaaS reality - cloud services security, threat intelligence, secure coding, monitoring activities, web filtering, and data masking among them. For a SCADA buyer, the technological theme reads like a familiar checklist: it is the enterprise-generic cousin of what IEC 62443's foundational requirements demand in OT-specific form. Where 62443 asks about setpoint authorization and device identity, Annex A asks about privileged access management and logging - both matter, at different layers.
Not all certificates are equal. Certification bodies should themselves be accredited - by ANAB in the US, UKAS in the UK, or another member of the International Accreditation Forum - which subjects their auditing to oversight. Certificates from unaccredited "certificate mills" exist and are close to worthless. Checking the accreditation mark on the certificate takes ten seconds and is the cheapest due-diligence step in this entire article.
Every number here varies with headcount, scope, and starting maturity - but buyers deserve orders of magnitude, so: certification-body fees for the initial stage 1 plus stage 2 are commonly cited in the ten-to-fifty-thousand-dollar range for small and mid-sized organizations, with annual surveillance audits a fraction of that. Preparation costs - consultants, compliance automation tooling, remediation work - often equal or exceed the audit fees. The dominant cost is internal time: building the risk process, writing policies people actually follow, running internal audits. Across a full three-year cycle, sustained totals from the tens of thousands into the low six figures are typical of what organizations report publicly. Timeline from kickoff to certificate: 6 to 18 months, with 9–12 a common midpoint. As with SOC 2, the cost is the point - the certificate is credible because it cannot be improvised.
| Attribute | ISO 27001 | SOC 2 |
|---|---|---|
| Nature | Certification of a management system | Attestation report on controls (no certificate) |
| Issued by | Accredited certification bodies | Licensed CPA firms |
| Deliverable | Certificate + scope statement; SoA on request | Detailed Type I/II report, shared under NDA |
| Cadence | 3-year certificate, annual surveillance | Annual re-examination with new observation period |
| Geographic weight | Dominant internationally (Europe, APAC, Middle East) | Dominant in North American SaaS procurement |
| Depth for the buyer | Proves a system exists and operates; detail lives in the SoA | Shows control-by-control test results and exceptions |
| OT coverage | None - generic enterprise controls | None - service-organization controls |
The pragmatic answer for a SCADA buyer: either one, plus IEC 62443 evidence. The two enterprise frameworks overlap heavily - perhaps the bulk of the control substance is shared - and many vendors satisfy both from one internal control set. If your organization is US-based, SOC 2 will fit your procurement machinery; if you sell into or operate in Europe or APAC, ISO 27001 travels better. What neither does is evaluate the control-system layer - gateway architecture, device identity, telemetry integrity, command safety - which is why our certification pillar guide insists on pairing an enterprise framework with a 62443 mapping, and why the architectural checks in our OT network security guide remain non-negotiable regardless of paperwork.
Here is the sharpest thing a buyer can know about ISO 27001: the certificate only covers what the scope statement says it covers. Scope is defined by the organization, and it is entirely possible - and not unheard of - to certify a narrow slice (say, a corporate IT department or a single data-center operation) while the product engineering organization, the cloud platform, or an acquired subsidiary sits outside the boundary. The marketing then says "ISO 27001 certified" and is technically telling the truth.
Your countermeasures, in order:
Key takeaway: ISO 27001 certifies a living management system - stage 1 and stage 2 audits, then annual surveillance forever - which makes it one of the strongest generic security signals a vendor can hold. But its value is bounded by its scope statement, so read the certificate, request the Statement of Applicability, confirm the accreditation, and pair it with IEC 62443 evidence for the OT layer that no enterprise framework touches.
For industrial vendors, the frameworks stack cleanly: ISO 27001 (or SOC 2) governs the organization - who accesses what, how changes ship, how incidents are handled - while IEC 62443 governs the product and architecture: security levels, zones and conduits, device and component requirements. IEC 62443-2-1, the asset-owner part of the ISA/IEC 62443 series, even defines the asset owner's security program in ISMS-like terms, so operators running both frameworks find the vocabularies converge. Mature procurement teams in pipelines, manufacturing, and utilities increasingly write RFP language that assumes the pairing.
In the interest of practicing what this series preaches: Merobix does not hold an ISO 27001 certificate today. Its current program pairs a SOC 2 readiness effort - controls implemented, evidence collection underway - with a control mapping to IEC 62443 for the platform architecture, and independent penetration testing runs as part of the ongoing validation program. The shipped controls behind those mappings - MFA and passkeys, role and site-level authorization, tenant isolation with row-level security, encrypted sensitive data, immutable audit records, and an outbound-only gateway - are documented on the security page and demonstrable in a live demo. Apply this article's tests to us as strictly as to anyone: named frameworks, stated stage, verifiable controls.
ISO/IEC 27001 is the international standard for an information security management system (ISMS) - the ongoing management process by which an organization assesses its security risks, selects and operates controls, audits itself, and continually improves. The 2022 revision includes 93 reference controls in Annex A, grouped into organizational, people, physical, and technological themes; organizations select applicable controls through a risk assessment and document the result in a Statement of Applicability. Unlike SOC 2, ISO 27001 is a true certification: an accredited certification body audits the ISMS and issues a certificate valid for three years, subject to annual surveillance audits.
From a standing start, building the ISMS typically takes 6 to 12 months: risk assessment, control implementation, policy adoption, internal audit, and a management review must all exist and have operated before certification. The certification audit itself runs in two stages - stage 1 reviews documentation and readiness, stage 2 tests implementation - usually a few weeks to a couple of months apart. Overall, 6 to 18 months from kickoff to certificate is a realistic range, with the variance driven by starting maturity and scope. After certification, annual surveillance audits and a full recertification in year three keep the obligation permanent.
Costs split into three buckets and vary widely with organization size and scope, so treat figures as indicative. Certification-body fees for initial stage 1 and stage 2 audits are commonly cited in the range of ten to fifty thousand dollars for small-to-mid organizations, with surveillance audits a fraction of that annually. Preparation - consultants, compliance tooling, and gap remediation - often matches or exceeds audit fees. The largest cost is usually internal: staff time to build and run the risk process, write and live the policies, and conduct internal audits. Sustained totals across a three-year cycle commonly land in the tens of thousands to low six figures.
ISO 27001 certifies a management system: an accredited body confirms the organization runs a conforming ISMS, and the deliverable is a certificate plus a scope statement. SOC 2 is an attestation: a licensed CPA firm issues a detailed report with an opinion on controls against the AICPA Trust Services Criteria - there is no certificate. ISO 27001 dominates internationally and in RFPs from European and Asia-Pacific customers; SOC 2 dominates North American SaaS procurement. Content overlaps heavily, and many vendors pursue both from one control set. For industrial buyers, neither covers the control-system layer - that is IEC 62443's job - so the strongest vendor posture pairs one enterprise framework with a 62443 mapping.
Ask for the certificate itself and check four things. First, the scope statement - the certificate applies only to the legal entities, locations, and services it names, and narrow scopes that exclude the product or its engineering team are a known gaming tactic. Second, the certification body and its accreditation - the body should be accredited by a recognized member of the IAF, such as ANAB or UKAS; unaccredited certificates carry far less weight. Third, validity dates and surveillance status - certificates run on a three-year cycle with annual surveillance audits. Fourth, ask for the Statement of Applicability or a summary, which shows which Annex A controls were included and excluded. A vendor confident in its ISMS will discuss all four without friction.
MFA, tenant isolation, immutable audit trails, an outbound-only gateway - see the shipped controls behind our readiness programs and 62443 mapping, live.