What is ISO 27001 certification and when can a client require it?
By Carles Latorre on Sep 10, 2026, 9:00:00 AM

More and more companies require their suppliers to demonstrate that they adequately protect the information they manage. This is not a minor issue: according to the Cost of a Data Breach 2026 report from IBM and the Ponemon Institute, the average global cost of a data breach reached $4.99 million, 12% higher than the previous year. This reality has made cybersecurity a key factor in maintaining the trust of customers and partners.
For this reason, many organizations are considering obtaining ISO 27001 certification. However, before starting the process, it is important to understand what this standard actually certifies, when a client can require it, and what preparing for certification involves.
What is ISO 27001 certification?
ISO/IEC 27001:2022 is the international standard for implementing an Information Security Management System (ISMS). Its goal is to help organizations protect the confidentiality, integrity, and availability of information through continuous risk management.
More than a technology certification, ISO 27001 demonstrates that a company has processes, controls, and procedures in place to protect its data and respond appropriately to potential security incidents.
Is ISO 27001 certification mandatory?
No Spanish or European regulation generally requires a company to obtain ISO 27001 certification. However, different regulations do establish obligations related to information security and protection: the GDPR requires appropriate technical and organizational measures, the ENS establishes security requirements for the public sector and certain providers, and NIS2 requires entities within its scope to implement cybersecurity risk-management measures. ISO 27001 is a recognized way to structure and demonstrate this work, but the certification itself is not a legal requirement.
In practice, the requirement can come through a contractual agreement. It is increasingly common for companies to require their suppliers to hold ISO 27001 certification as a condition for providing certain services or participating in strategic projects, particularly when access to sensitive information or a supply-chain relationship is involved. Once included as a requirement in a contract, tender document, or supplier qualification process, certification is no longer optional for that provider.
When can a client require it?
More and more companies are assessing the cybersecurity level of their suppliers before signing a contract. In many selection processes, ISO 27001 is already part of the evaluation criteria.
It is particularly common for organizations in sectors such as these to request it:
- Financial services.
- Technology and software development.
- Digital infrastructure and cloud services.
- Healthcare.
- Manufacturing.
- Large corporations with complex supply chains.
In these cases, certification allows a company to demonstrate that it has appropriate controls in place to protect information and reduce the risk of an incident affecting its customers as well.
An important point if your client is a public administration
When the client is a Spanish public administration, the applicable framework is not ISO 27001, but the National Security Framework (ENS). Royal Decree 311/2022 establishes that public-sector contract tender documents must include the requirements necessary to ensure ENS compliance for the information systems supporting the services provided by contractors, including the submission of the corresponding Statements or Certifications of Conformity. This requirement may also extend to the contractor's supply chain.
Having an ISO 27001-certified ISMS makes this alignment much easier —a significant part of the risk analysis, policies, and controls work is shared by both frameworks— but it does not replace the ENS: they are two different frameworks, with their own conformity and certification mechanisms.
What does a client actually check?
It is important to keep in mind that certification is not granted to a company as a whole, but to an ISMS within a defined scope: specific services, locations, or systems. This is important from both perspectives.
When responding to a client, simply having a certificate is not enough: you must be able to demonstrate that the contracted service falls within the certified scope. When evaluating a provider, what matters is not just verifying that the certificate exists, but checking what it covers, which certification body issued it, and whether it is still valid.
For this reason, properly defining the scope before starting the project is one of the decisions that has the greatest impact on the outcome: a poorly defined scope may leave out precisely the service the client wanted to have covered.
What does ISO 27001 actually require?
Obtaining certification involves implementing an Information Security Management System based on continuous improvement. It is not simply about creating documentation, but about demonstrating that the organization manages security in a structured way.
The standard is structured around two areas that should not be confused. On the one hand, there are the management system requirements, which establish how information security must be organized and managed. On the other, there are the Annex A controls, which allow organizations to implement specific measures to address identified risks.
The management system requirements, which are mandatory for any organization seeking certification, include:
- Continuous risk assessment and management.
- Definition of security policies, responsibilities, and objectives.
- Internal audits and periodic management reviews.
- Continuous improvement of the management system.
The Annex A security controls, which are not all applied by default. The standard includes 93 controls grouped into four domains —organizational, people, physical, and technological— and each organization selects those that apply based on its risk assessment, documenting the rationale in a document called the Statement of Applicability. Common controls include:
- Information access control.
- Security incident management.
- Employee training and awareness.
- Backups and service continuity.
- Security in supplier relationships.
In other words, ISO 27001 does not require every company to implement the same controls, but rather to have a management system that allows it to identify risks and determine which measures are necessary to address them.
How long does it take to obtain certification?
The time required depends on the organization's level of maturity. For organizations starting from scratch, the process typically takes between 6 and 10 months, although it may be shorter when security measures are already in place.
During this period, the organization must assess its initial situation, adapt internal processes, implement controls, prepare the required documentation, and get ready for the certification audit. The audit is carried out by an accredited certification body —in Spain, accredited by ENAC.
The certificate is valid for three years, with annual surveillance audits and a recertification audit at the end of the cycle. In other words, certification is not a one-time milestone, but an ongoing commitment to maintaining the system: this ongoing monitoring is what supports continuous improvement.
Planning the project sufficiently in advance helps prevent delays in tenders, contracts, or commercial processes that require proof of compliance with the standard.
What benefits does it provide to a company?
Beyond compliance, ISO 27001 certification provides benefits that have a direct impact on the business.
The main benefits include:
- Accessing customers that require security assurances.
- Making supplier qualification easier.
- Reducing the time required for customer audits.
- Building greater commercial trust.
- Differentiating from competitors without certification.
Why prepare for ISO 27001 certification with ESED?
Preparing for ISO 27001 certification requires much more than checking off a list of requirements. It is necessary to assess the company's current situation, implement the appropriate measures, and ensure that all processes meet the standard's requirements.
At ESED, we support companies throughout the entire ISO 27001 compliance process: we assess the initial situation, implement the necessary controls, prepare the documentation, and get the organization ready to successfully complete the audit.
Beyond obtaining certification, the goal is to implement a management system that strengthens the company's security and delivers long-term value.


