Articles tagged: ISO 27001
17 articles on ISO 27001 from the Top Floor insights library.
2026-08-25
What Does ISO 27001 Certification Cost?
For a 51 to 200 person company, we plan against four ISO 27001 lines: gap analysis, remediation, certification audit fees, and the recurring maintenance that outlives them all. Here are our planning bands, what sits inside each, and why size moves every line.
2026-08-25
What Is an ISMS? The Thing ISO 27001 Actually Certifies
An ISMS is the management system ISO/IEC 27001 specifies in clauses 4 to 10, scoped by you and certified as a whole. The controls in Annex A are a reference list, not the system, and the certificate covers the scope you wrote down, not the company.
2026-08-25
What Is an ISO 27001 Nonconformity? Major, Minor, and What Each Costs You
A nonconformity is the non-fulfilment of a requirement. Whether it is major or minor turns on one test in ISO/IEC 17021-1, whether the management system can still achieve its intended results, and that grade decides what happens to the certificate.
2026-08-25
What Is a Risk Treatment Plan? The ISO 27001 Document Between the Risk Assessment and the SoA
ISO/IEC 27001 clause 6.1.3 requires the organization to formulate a risk treatment plan and to obtain risk owners' approval of it and acceptance of the residual risk. The standard never lists the plan's columns; the signature is what the auditor checks.
2026-08-23
How Long Does ISO 42001 Certification Take?
Four to nine months, and the audit is days of it. Stage 2 tests whether the AI management system operated rather than whether it was designed, which puts a floor under the calendar that no budget removes.
2026-08-23
How Much Do Compliance Frameworks Actually Overlap?
Overlap between two frameworks is two numbers, not one, and the two can differ by 79 percentage points on the same intersection. Measured from our own published mapping dataset, with the denominators named.
2026-08-22
How Long Does ISO 27001 Certification Take?
Six to nine months, and the audit is not what holds the clock. ISO/IEC 17021-1 requires your Stage 2 auditor to see the ISMS operating, so there is a floor no budget removes. Here is where the months actually go.
2026-08-22
What Does ISO 42001 Certification Actually Cost?
Published estimates for ISO 42001 run from a few thousand dollars to $650,000, and every one of them is defensible. Here is why they disagree, what the certification body actually charges, and how to place your own company on the range.
2026-08-21
ISO 27001 Stage 1 vs Stage 2: What Auditors Actually Check
Stage 1 asks whether you have what you need. Stage 2 asks whether you are doing what you say. Here is what each auditor pulls, what a Stage 1 finding costs you, and why you cannot fail Stage 1 in the way people fear.
2026-08-20
How to Write an ISO 27001 Statement of Applicability That Survives Audit
The SoA is mandatory under clause 6.1.3 d and it is where most Stage 1 findings live. You do not have to implement all 93 Annex A controls; you do have to justify every inclusion and exclusion from your risk assessment.
2026-08-19
ISO 27001 Surveillance Audits: What Years 2 and 3 Actually Take
The certificate runs three years, but your auditor comes back annually. Plan on about a third of your initial audit time for each surveillance visit and about two-thirds for recertification. Here is what they check and how certificates get suspended.
2026-08-18
Do You Need an ISO 27001 Consultant, or Just a Platform?
A platform automates evidence. It does not run your risk assessment, justify your Statement of Applicability, or perform your internal audit. Here is the split that decides the buy, plus the certification-body red flags nobody selling this mentions.
2026-08-16
Do You Need a Readiness Assessment Before Your Audit?
A readiness assessment is a paid dress rehearsal, not a requirement. Here is what it costs, what it cannot do, the independence rule that decides who is allowed to run yours, and the three situations where the honest answer is to skip it.
2026-08-16
Comply Once, Prove Many: Reusing Evidence Across Frameworks
Most of the work for your second framework is already done, if you tagged the evidence the first time. Here is the mechanism, an honest account of the parts that never transfer, and what the overlap is really worth.
2026-08-16
Can You Outsource Your ISO 27001 Internal Audit?
Yes. Clause 9.2 requires internal audits, not internal auditors, and the binding constraint is impartiality rather than employment. Here is what the clause actually demands, the three ways companies break the rule, and how to compare quotes.
2026-03-28
Why Top Floor: The Boutique GRC Advantage
The compliance market is split between premium-priced Big Four firms, solo consultants who lack breadth, and automated platforms that miss nuance. Here is what makes a senior-practitioner boutique firm different, and why it matters for your audit outcome.
2026-01-29
ISO 27001 vs SOC 2: Which Should You Get First?
Both frameworks prove your security posture to customers, but they differ in scope, cost, geography, and approach. Here is how to decide which to pursue first, and how to leverage overlap when you eventually need both.