For the complete documentation index, see /llms.txt. Markdown version of this page: /en/insights/compliance/your-customer-requires-iso-27001-what-now.md.
Compliance ↗

Your customer requires ISO 27001. What do you do now?

Your customer requires ISO 27001. Here is how to read the requirement, what you can answer today, and the realistic route to the certificate.

The email is short. Your largest customer now requires ISO 27001 from its suppliers, and they want an answer within weeks. Or you just lost a tender on a qualification requirement, or a security questionnaire arrived with a deadline attached. However it starts, you are now holding a requirement, a date, and no certificate.

Three of the calls I took this spring opened exactly like that. A worried leader, a requirement in writing, and a deadline that looked impossible. In each case the first hour of work changed the picture, because when they read the requirement closely, it asked for less than they first thought. So start there.

Find out exactly what the customer requires

Get the requirement in writing and read it closely, because “we require ISO 27001” does not mean the same thing from every buyer.

In practice the requirement comes in three versions. Some buyers want a valid certificate from an accredited certification body. Some accept evidence that certification is underway, meaning a plan with dates and a named partner. And some send a security questionnaire where the certificate is one question among many.

The deadlines differ just as much. A customer renewing a contract may need the answer this quarter. A tender may require the certificate at contract start, months after the bid. Ask the person who sent the requirement two questions: what counts as sufficient evidence, and by which date. I have yet to see that email make a situation worse, and the answer usually gives you more room than the first message suggested.

Take stock of what you can already answer

You can answer more of this today than the email suggests.

In the readiness reviews I run, the underlying security work is mostly in place already. Access control, backups, and incident handling exist in practice. What is missing is the management system around them: written decisions about who owns which risk, and evidence that the routines happen on schedule. That gap is documentation rather than capability, and it closes far faster.

ISO 27001 asks you to run information security as a managed system and prove it. What the standard contains, and why buyers lean on it, is covered in our explainer on what ISO 27001 is and why tenders require it. For the answer to your customer, the point is simpler: you rarely start from zero, so do not answer as if you did.

The realistic routes to the certificate

A focused run with FM CyberSecurity typically makes you certification-ready in four to six weeks.

How quickly you answer our questions sets the pace. We assemble the management system from what you already do, so your answers about systems, access, and routines are the raw material. Certification-ready means the documentation, the risk assessment, and the evidence are ready for the accredited certification body. Then comes the body’s audit: Stage 1 reviews the documentation, Stage 2 checks that the system works in practice. The body sets audit dates from its own calendar, so ask for dates early.

You can also run the project yourselves. Our ISO 27001 checklist for Norwegian SMBs lays out the order of work. Plan for a longer timeline in that case, because the work competes with everyone’s day job.

What to tell the customer in the meantime

Send a short plan with dates before the deadline, and skip the reassurances.

A useful plan fits on one page: the gaps you have found, the actions with dates, who is responsible, and when you expect the certification audit. The procurement teams I meet look for two things. They want to see that you have started, and that you know your own gaps. A supplier who names their weaknesses reads as lower risk than one who claims to have none.

The plan does not settle the deal on its own. But the customer set the requirement because they have to manage supplier risk, and a plan with dates gives them something concrete to take into their own decision. Silence gives them nothing.

Next step

Bring the requirement you received to our ISO 27001 practice for a 30-minute conversation about what it asks for, and which route is realistic within your deadline.

If you are a small or medium-sized business without your own security team, the whole run is packaged as one subscription in Secured by FM CyberSecurity, from the first review to the day the certificate comes up for renewal.

Drafted with AI assistance, reviewed and edited by Johan Vorgaard and the FM CyberSecurity editorial team.

FAQ

Can we bid while certification is in progress?

Often, yes. Some tenders require a valid certificate at the bid deadline. Others require it at contract start, or accept documented progress with a date. The tender documents decide, so read the qualification requirements word for word. If the wording is unclear, ask the contracting authority. Questions before the bid deadline are a normal part of the competition.

Is a declaration of intent enough?

On its own, rarely. A letter saying you plan to certify is not evidence. Together with a dated plan, a named partner, and an agreed audit it becomes something the buyer can defend internally. Buyers weigh the dates, not the wording.

What if the deadline is eight weeks away?

Then the preparation fits, and the audit is the open question. A run with FM CyberSecurity typically makes you certification-ready in four to six weeks, with the pace set by how quickly you answer our questions. The certification body sets its own audit dates, and those vary with its calendar. Tell the customer both parts: when you will be certification-ready, and when the audit is planned. Starting this week matters more than any single date.

How much of our own time does this take?

Less than a full project, more than nothing. The work on your side is answering how your systems run today: who has access, what gets backed up, how incidents are handled. That knowledge sits with your IT lead and a few others, and how quickly they answer sets the pace. Expect interviews and document reviews, not a production stop.

← Back to all insights
Questions or inquiry? [email protected] Contact us →