Skip to content

No ISO 27001 certificate? Here is how to still answer well.

The first question in many security questionnaires is: which certifications do you hold? For a young SaaS provider the honest answer is often “none”. That need not be a problem, as long as the rest of your answers show that you have things under control.

Why the question is asked

A certificate such as ISO 27001, or an audit report such as SOC 2 or ISAE 3402, is a quick shortcut for a buyer: someone else has already checked. Without one, the buyer has to judge your security themselves. Your job is to make that easy.

What to show instead of a certificate

Use the ISO 27001 structure without a certificate

The controls in Annex A of ISO/IEC 27001:2022 are a good framework, even without certification. Many questionnaires refer to them. If you organise your evidence along the same themes (organisational, people, physical and technological), a reviewer recognises it immediately. Do make clear that you use the standard as a framework and are not certified.

How to phrase the answer

Do not just write “no”. Write, for example: “We are not ISO 27001 certified. We work with an information security policy based on ISO/IEC 27001:2022 Annex A (see document X). Our hosting provider is ISO 27001 certified (see report Y). Certification is planned for [period].” Only mention a plan if one really exists.

When certification becomes necessary

If customers make it a hard requirement, for example in tenders or at large financial institutions, you will not get through without it. If you notice this happening more often, that is a signal to start a certification project. Until then, honest, supported answers win a lot.

Common mistakes

How Holdvero helps

We complete your questionnaire based on what you do have, with the source for every answer, and make visible where evidence is missing. That also shows you what to arrange first before certification makes sense. Up to 150 questions this costs €695 with Questionnaire Rescue. Holdvero does not certify and is not a certification body.

Frequently asked questions

Can I win a customer without ISO 27001?

Often yes, especially with small and mid-sized customers. An honest, supported answer with concrete evidence carries a lot of weight. With a hard requirement in a tender, it will not work.

May I say I am ISO 27001 compliant?

Preferably not. Without an audit that can come across as misleading. Say that you use the standard as a framework and are not certified.

Does my cloud provider's certification count?

For their part of the service, such as the data centre and infrastructure. Not for what you build and run yourself. Make that distinction in your answer.

What is the difference between ISO 27001 and SOC 2?

ISO 27001 is an international certification standard for a management system. SOC 2 is a US audit report on controls. Which one your customer expects often depends on its market.

Need help with your questionnaire?

Within 1 working day you'll hear the price and when you get it back. You only pay after agreeing the price.

Get a fixed price
Cover: NIS2 checklist for suppliers
Free: NIS2 checklist for suppliersThe 7 topics that keep coming back, with the evidence to have ready for each.
Download the checklist