Frequently asked questions

Practical answers for organisations and credential checkers.

This page explains the programme at a high level. For a specific organisation, scope, or record, please contact the assurance team or use the public registry.

What is ISO/IEC 27001?

ISO/IEC 27001 is an international standard for information security management systems. It provides requirements for managing information-security risk through a structured, continually improved system.

Does ISO certify organisations?

No. ISO develops and publishes standards. Organisations that seek certification are assessed through certification or assurance programmes; the status of an Assurevance credential is shown in this site’s public registry.

Who can use an ISO 27001 management-system approach?

Organisations of different sizes and sectors can use an ISMS approach. The useful scope and safeguards depend on the information handled, services provided, obligations, risk appetite, and operating context.

What does an organisation need before it applies?

Start with a defined scope, accountable leadership, a suitable risk process, selected controls, and evidence that the ISMS is being operated and reviewed. The requirements guide provides a useful high-level checklist.

Is an application an automatic approval?

No. An application starts a review process. A certificate or registry entry is created only where the applicable programme requirements have been satisfied and an issuance decision is made.

How do I check whether a certificate is current?

Use the verification ID, certificate number, or QR code to open the public credential record. The registry displays the current status, dates, organisation, and approved scope.

Why is the registry more important than the PDF?

A PDF is a document issued at a point in time. The public registry is designed to show the current record, including a status change such as expiry, suspension, or revocation where applicable.

What does the certificate scope mean?

The scope describes the activities, services, and organisational boundaries addressed by the issued credential. It should be read carefully; it does not necessarily cover every product, site, supplier, or activity of an organisation.

Need something specific?

Talk through your organisation’s context before you apply.

Our team can help you understand the information requested by the programme and point you to the relevant published rules. They cannot provide legal advice through this site.