No ISO 27001 certificate? Here is how to still answer well.
The first question in many security questionnaires is: which certifications do you hold? For a young SaaS provider the honest answer is often “none”. That need not be a problem, as long as the rest of your answers show that you have things under control.
Why the question is asked
A certificate such as ISO 27001, or an audit report such as SOC 2 or ISAE 3402, is a quick shortcut for a buyer: someone else has already checked. Without one, the buyer has to judge your security themselves. Your job is to make that easy.
What to show instead of a certificate
- An approved policy, with a date, an owner and a next review date
- A risk analysis, even a short one
- Concrete measures with evidence: MFA on for all accounts, encryption, backups, logging, screenshots of settings
- A penetration test by an external party, and what you did with the findings
- Tested recovery: when did you last restore a backup?
- Your suppliers: much of the assurance sits with your hosting and cloud provider, which are often certified. Refer to their reports for their part, and show what you arrange yourself.
Use the ISO 27001 structure without a certificate
The controls in Annex A of ISO/IEC 27001:2022 are a good framework, even without certification. Many questionnaires refer to them. If you organise your evidence along the same themes (organisational, people, physical and technological), a reviewer recognises it immediately. Do make clear that you use the standard as a framework and are not certified.
How to phrase the answer
Do not just write “no”. Write, for example: “We are not ISO 27001 certified. We work with an information security policy based on ISO/IEC 27001:2022 Annex A (see document X). Our hosting provider is ISO 27001 certified (see report Y). Certification is planned for [period].” Only mention a plan if one really exists.
When certification becomes necessary
If customers make it a hard requirement, for example in tenders or at large financial institutions, you will not get through without it. If you notice this happening more often, that is a signal to start a certification project. Until then, honest, supported answers win a lot.
Common mistakes
- Implying you are certified because your hosting provider is
- Writing “ISO 27001 compliant” without an audit, which can be read as a certificate
- Promising a certification date that is not planned
How Holdvero helps
We complete your questionnaire based on what you do have, with the source for every answer, and make visible where evidence is missing. That also shows you what to arrange first before certification makes sense. Up to 150 questions this costs €695 with Questionnaire Rescue. Holdvero does not certify and is not a certification body.
Frequently asked questions
Can I win a customer without ISO 27001?
Often yes, especially with small and mid-sized customers. An honest, supported answer with concrete evidence carries a lot of weight. With a hard requirement in a tender, it will not work.
May I say I am ISO 27001 compliant?
Preferably not. Without an audit that can come across as misleading. Say that you use the standard as a framework and are not certified.
Does my cloud provider's certification count?
For their part of the service, such as the data centre and infrastructure. Not for what you build and run yourself. Make that distinction in your answer.
What is the difference between ISO 27001 and SOC 2?
ISO 27001 is an international certification standard for a management system. SOC 2 is a US audit report on controls. Which one your customer expects often depends on its market.
Need help with your questionnaire?
Within 1 working day you'll hear the price and when you get it back. You only pay after agreeing the price.
Get a fixed price