ISO 27001:2022
ISO 27001 certification online: Information Security Management by self-assessment
With the ISO 27001 certificate from Zertify, you demonstrate your management system online. ISO 27001 certification works by self-assessment: you receive the certificate within 4 hours and pay once, CHF 849. It is not an accredited certificate and does not replace an audit.
- Questions
- 30
- Validity
- 3 years
- One-time price
- CHF 849
01: Overview
What is ISO 27001?
ISO 27001:2022 is the international standard for information security management systems (ISMS). It provides a systematic approach to protecting confidential information through risk management and the implementation of security controls. The 2022 edition contains updated controls that address modern threats such as cloud security, data protection and cyber risks.
02: Benefits
Your benefits
- Protection of sensitive company and customer data
- Fewer cyber risks and security incidents
- Fulfilment of compliance requirements (GDPR, NIS2)
- Increased trust among customers and business partners
- Competitive edge with security-conscious customers
- Structured response to security incidents
03: Who it is for
Who is ISO 27001 for?
- IT service providers and software companies
- Cloud service providers
- Financial service providers and banks
- Healthcare
- E-commerce and online services
- Companies handling sensitive customer data
04: Requirements
Key requirements
Assess information security risks
Define a security policy and objectives
Implement security controls (Annex A)
Prepare a Statement of Applicability (SoA)
Raise awareness and train employees
Manage security incidents and learn from them
05: Demand
Who asks for ISO 27001?
ISO 27001 is what customers with a security questionnaire ask about most often. It usually comes up shortly before the contract is signed.
- Corporate customers in procurement
- Banks, insurers and corporations vet service providers that process their data with a security questionnaire. Proof of an ISMS shortens that review.
- Software and SaaS
- Cloud software vendors are asked about ISO 27001 and encryption early in contract talks. Without an answer, deals stall.
- Regulated industries and tenders
- Healthcare, finance and the public sector require proof of information security, partly by contract, partly through supervision and tender documents.
06: Cost
What does ISO 27001 cost? Audit, consulting or self-assessment
ISO 27001 takes more effort than quality or environment, because an ISMS with risk analysis and policies has to be built. For 10 to 50 employees, these orders of magnitude apply.
| Route | Indicative range | What is behind it |
|---|---|---|
| Accredited audit | CHF 8,000 to 20,000 initial audit, then 4,000 to 8,000 per year | Audit days grow with headcount, sites and the scope of the ISMS. A scope limited to one product line is much cheaper than the whole company. |
| Consulting and implementation | CHF 15,000 to 50,000 one-off | Risk analysis, statement of applicability, policies and training are built externally. Technically strong teams save the most here. |
| Zertify self-assessment | CHF 849 once, valid 3 years | You check whether risk analysis, statement of applicability, policies, training and incident management are demonstrably in place. It replaces neither a penetration test nor an audit. |
All amounts are non-binding indicative ranges for Swiss SMEs, not quotes. The offers of the individual providers are what counts.
07: Duration
How long does ISO 27001 take?
An accredited ISMS is rarely ready in under six months, usually it takes nine to twelve. The bottleneck is not the audit but the build.
| Phase | Accredited | Zertify |
|---|---|---|
| Build the ISMS | 6 to 12 months for scope, risk analysis, SoA, policies and training | None. You rate the current state of your information security |
| External audit | Stage 1 (documents) and stage 2 (implementation), plus 4 to 8 weeks of lead time | About 20 to 30 minutes online, scored immediately |
| Certificate | Release after 2 to 6 weeks, annual surveillance audits, recertification after three years | PDF with QR verification within 4 hours |
08: Sample questions
Sample questions from the ISO 27001 assessment
Four of 30 questions from the catalog, with the reason each one counts.
Is an information security risk assessment carried out?
The risk assessment decides which measures you need. Without it every security measure is guesswork and its selection cannot be justified.
Is there a Statement of Applicability (SoA)?
The SoA links risks to measures and is the first document auditors and customers want to see.
Are employees aware of information security?
Most incidents start with people, for example through phishing. What is asked for is training with evidence, not just a policy on the intranet.
Are nonconformities and security incidents addressed?
Incidents cannot be ruled out. What matters is whether you detect, report and assess them and learn from them.
09: Assessment
How the assessment works
The assessment consists of 30 yes/no questions. You answer them online, at your own pace. With 20 or more yes answers you pass.
| The questions are grouped by these topics: | Questions |
|---|---|
| Context of the organization | 4 questions |
| Leadership | 5 questions |
| Planning | 4 questions |
| Support | 6 questions |
| Operation | 5 questions |
| Performance evaluation | 3 questions |
| Improvement | 3 questions |
10: Price
Price and validity
What is included
- Online assessment with 30 questions
- Certificate as PDF, issued by SICE
- QR code for public verification
- 3 years of validity
- Support by email
The certificate is based on a self-assessment. It is not an accredited certification. Read more in the FAQ
11: More standards
More standards
Many companies combine several standards. From two standards you get a discount.
- ISO 27017:2015: View standard
Cloud Security
If you run or use cloud services, you extend your ISMS with the cloud controls and settle responsibility between provider and customer.
from CHF 799
- ISO 27018:2019: View standard
Cloud Privacy
If you process personal data for customers in the cloud, ISO 27018 proves data protection on top of the ISMS.
from CHF 799
- ISO 20000-1:2018: View standard
IT Service Management
IT service providers combine security with service quality. Incident and change processes are anchored in both standards.
from CHF 799
12: Questions
Frequently asked questions about ISO 27001
ISO 27001 certificate within 4 hours.
Start the assessment for free. You only pay after you pass.
The certificate is based on a self-assessment. It is not an accredited certification.