What Is ISO/IEC 27001 Certification, How to Get It, and Which Companies Need It

TL;DR: ISO/IEC 27001 is the international standard for an information security management system (ISMS). It requires a company to manage its technical, administrative, and physical controls through a documented process. The certificate is issued by an audit body accredited by TURKAK, the Turkish Accreditation Agency. The process takes between 6 and 12 months. It is effectively mandatory for public tenders, the finance and health sectors, export, and the demands of large enterprise customers. In the 2022 version, Annex A contains 93 controls, grouped under four themes.

Every organization that invests in information security runs into the ISO/IEC 27001 question at some point. Our pillar article, Turkey's Cyber Threat Landscape 2026, shows why the ecosystem requires a structured ISMS. In this article, we explain in everyday language what the standard is, who needs it, the process of obtaining it, and the cost items involved.

What is ISO 27001?

ISO/IEC 27001 is an international standard that defines the requirements for establishing and maintaining an information security management system (ISMS). It can be thought of as the information security version of ISO 9001 quality management. It is process-oriented and covers not only technical controls but also management discipline.

It rests on three core principles:

  1. Risk-based approach - The organization first determines, through a risk assessment, which assets it protects and against what.
  2. Control implementation - The controls chosen to address the risks are implemented from the Annex A list or other sources.
  3. Continual improvement (PDCA) - The system is updated annually through the Plan, Do, Check, Act cycle.

Its difference from legal obligations such as KVKK, Turkey's personal data protection law, is this: ISO 27001 is voluntary (not legally mandatory), but it has become a de facto requirement in many contracts and tenders.

ISO 27001 vs ISO 27002

The two numbers are often confused:

  • ISO/IEC 27001 - The mandatory standard. It is the document you get certified against. It answers the question "what will you do."
  • ISO/IEC 27002 - A guidance document. It is the detailed guide to the question "how will you implement these controls." You do not get certified against it, but it is frequently referenced during audits.

In the 2022 version, ISO 27002 provides the implementation details of the Annex A controls. The two should be read together.

Which company needs it?

Mandatory (by regulation or tender)

  • Public tenders - BTK, health tenders, and finance digital-service procurements frequently impose an ISO 27001 requirement.
  • TUBITAK TEYDEB R&D grants - required in certain categories.
  • Critical infrastructure operators - within the regulatory framework of energy, telecom, and finance.

Effectively mandatory (by contract)

  • Supplier obligations of large enterprise customers - a supplier with "no certificate" finds the door closed.
  • Export and international sales - especially if you sell SaaS, software, or consulting into the EU and US markets.
  • SaaS and cloud service providers - the customer's request to "send us your SOC 2 and ISO 27001 certificate" has become standard.
  • KVKK compliance evidence - the certificate alone does not mean compliance with KVKK, but it is a strong supporter of that compliance.

Brand value and competition

  • Market differentiation - the phrase "ISO 27001 certified supplier" opens doors in B2B.
  • Cyber insurance premium discounts - some insurers offer favorable terms to certified organizations.
  • Investor scrutiny - a sign of maturity during due diligence.

The process step by step

Stage 1: Preparation (1 to 3 months)

The ISO 27001 process does not move forward without the written commitment of top management. The information security policy is approved, the scope definition is made (which units, which processes, which locations are included), and the risk assessment methodology is chosen. At this stage a consultant (internal or external) frequently steps in.

Stage 2: Risk analysis (1 to 2 months)

An asset inventory is produced (hardware, software, data, personnel, location, brand reputation). For each asset, threats and vulnerabilities are matched and a risk score is calculated. The risk appetite (acceptable risk) is determined with management approval. Controls are assigned to unacceptable risks. The SoA (Statement of Applicability) document lists whether each control in Annex A is implemented or not, along with the justification.

Stage 3: Control implementation (3 to 6 months)

The controls that emerge from the risk assessment are actually put in place. In a typical corporate project, more than 15 written policies are prepared (access policy, acceptable use policy, mobile device policy, password policy, vendor policy, incident management policy, and the like). Technical controls (MFA, EDR, SIEM, log management, backup, network segmentation) are deployed. Employee training is completed.

Stage 4: Internal audit (1 month)

An independent internal auditor audits the scope from end to end. The internal auditor may be a company employee (if trained) or hired from outside. A corrective action plan is drawn up for any nonconformities found.

Stage 5: Management review

Top management reviews ISMS performance in a formal meeting, makes decisions, and allocates resources. The meeting minutes are presented during the audit.

Stage 6: Certification audit (two stages)

A certification body accredited by TURKAK is chosen. Two stages:

  • Stage 1 - Documentation and readiness assessment. Policies, procedures, and records are reviewed. If there are gaps, you do not proceed to Stage 2.
  • Stage 2 - On-site implementation audit. Auditors inspect offices and systems, talk to employees, and verify that the controls genuinely work.

If there is a major nonconformity, the certificate is not issued until it is fixed. For minor nonconformities, a closure plan is accepted.

Stage 7: Certificate and continual improvement

The certificate is valid for 3 years. In the first and second years a surveillance audit is performed. At the end of the third year, a full audit is repeated for recertification.

Annex A 2022: 4 themes, 93 controls

The 2022 version consolidated the old 14 domains into 4 themes:

A.5 Organizational (37 controls)

Policy, responsibility, segregation of duties, contract management, asset management, classification, supplier relationships, cloud service usage, incident management, evidence management, business continuity.

A.6 People (8 controls)

Pre-employment screening, confidentiality agreement, employee training, disciplinary process, offboarding process, remote working.

A.7 Physical (14 controls)

Physical perimeter security, access control, office layout, equipment placement, cabling, waste disposal, clear desk policy.

A.8 Technological (34 controls)

Authentication, MFA, cryptography, key management, log collection, backup, network security, segmentation, vulnerability scanning, web filtering, development security, monitoring, anti-malware.

Cost items

Obtaining the certificate is not a single line item; it covers five main spending groups:

  1. Consultant fee - For mid-sized organizations there is a reasonable market range. Annual internal-auditor training and consultant support are a significant part of the total project.
  2. Certification body fee - Stage 1 and Stage 2 audits, the first-year certificate fee, and then the annual surveillance fee. It varies with the size of the organization.
  3. Technical investments - MFA, EDR, SIEM, log management, a backup platform, network segmentation tools. Whatever is missing relative to the existing infrastructure is filled in.
  4. Internal auditor training - Sending 1 to 2 people from within the company to ISO 27001 Internal Auditor training reduces consultant dependency in the long run.
  5. Employee training and awareness - Annual training for all staff, simulated phishing campaigns, and documentation time.

The total amount moves within a wide range depending on the scale of the organization and its current security maturity. For a firm quote, a solid budget is drawn up once the organization's scope is clarified.

How long does the process take?

The typical range is between 6 and 12 months. Three determining factors:

  • Organization size (a 50-person SME vs a 1,000-person holding company).
  • Current security maturity (if a discipline close to ISO 27001 already exists, it is shorter).
  • The consultant's experience and the company's stakeholder engagement.

Organizations that want to finish quickly take 6 months; those starting from scratch with organizational resistance can stretch to 12 months and beyond.

What does TURKAK accreditation mean?

TURKAK, the Turkish Accreditation Agency, is the official body that accredits certification bodies in Turkey. A certificate obtained from a body without TURKAK accreditation does not carry international validity under the IAF (International Accreditation Forum) MLA framework. So, to get a certificate, you must make sure that the body you choose is TURKAK accredited. A list of accredited bodies is published on the TURKAK website.

The difference from KVKK compliance

Two concepts are often confused:

  • KVKK - The Personal Data Protection Law No. 6698. Mandatory in Turkey, a legal regulation centered on personal data.
  • ISO 27001 - International, voluntary, for all information assets (not just personal data).

The two overlap, but one does not replace the other. An ISO 27001 certificate strengthens KVKK compliance evidence but is not sufficient on its own. KVKK additionally requires specific steps such as VERBIS registration, a privacy notice, explicit consent management, and breach notification processes. For the detailed process, see our KVKK data breach notification article.

5 common mistakes

  1. Defining the scope incorrectly - Too broad (everything included) wears the process out; too narrow (leaving out an important unit) makes the certificate meaningless.
  2. Top management support being lip service - Signing the first policy is not enough; if the monthly management review meeting is not held, the process collapses.
  3. Implementing controls "on paper" - A policy is written but not lived in practice. The auditor asks the employee, and the employee does not know the policy. This is the most frequent mistake that loses the certificate.
  4. Treating the risk assessment as a formality - Risk scores are copy-pasted and do not match reality. The auditor detects this quickly.
  5. Forgetting the ISMS after certification - You get a warning at the first-year surveillance audit, and the certificate is suspended in the second year. The continual improvement cycle must not be neglected.

The difference between ISO 27001:2013 and 2022

The 2013 version contained 114 controls, divided into 14 domains. In 2022 this was reduced to 93 controls, consolidated under 4 themes. Among the newly added controls are cloud service usage, threat intelligence, physical monitoring, web filtering, and data leakage prevention.

As of 2025, the transition period from the 2013 version to 2022 is fully over. New certification and renewal processes run on the 2022 version.

The Presidential Digital Transformation Office guide

The Information and Communication Security Guide from CBDDO, the Presidential Digital Transformation Office, provides a directive for public institutions based on ISO 27001. Organizations working in the public sector or on public projects must review this guide. The structure consolidated around TS ISO/IEC 27001 is the baseline that public buyers expect.

Frequently Asked Questions (FAQ)

My company is small, do I need ISO 27001?

If there is no regulatory obligation, it is not required. But keep in mind that large customers may request it as a supplier condition, and that it opens doors in export and B2B sales processes. Getting certified at the SME scale has become common in recent years.

Can I implement the process without getting certified?

Yes. Many organizations apply the ISO 27001 discipline without certification. The certificate is the verification of the process through an external audit; it is a marketing and trust tool. The benefit of applying the process exists independently of the certificate.

What happens if the certificate is not renewed?

The 3-year validity ends, and the organization loses its certified status. It is a step backward in tenders, contracts, and customer requests.

My suppliers are not ISO 27001 certified, what about my contract?

Annex A contains supplier security controls. You are expected to assess the security level of critical suppliers and ensure that their contracts contain information security clauses. They do not have to be certified, but equivalent assurance is required.

Our cloud service provider is ISO 27001 certified, does that cover me?

No. The provider's certificate covers the provider, not your organization. But the cloud provider's certificate makes your job easier when you implement your own Annex A 5.23 (cloud service usage) control.

If I am KVKK compliant, am I also considered to have ISO 27001?

No, they are two separate frameworks. KVKK compliance work overlaps with part of ISO 27001, but a significant portion of Annex A's technological controls is outside the scope of KVKK.

What is looked at during the audit?

The auditor looks for three things: is there a policy, is the policy implemented, and is a record of the implementation kept. The trio of talking to employees, reviewing records, and inspecting systems is the basic method.

Working with DSET

At DSET, in operation since 2003, we offer ISO 27001 readiness consulting as a combined package with KVKK compliance projects and penetration testing services. We have field experience in organizations ranging in scope from 50 to 500 people. Throughout the process we include monthly reporting, stakeholder training, internal auditor development, certification body selection, and audit accompaniment. Our pillar article, Turkey's Cyber Threat Landscape 2026, justifies why the process is necessary, and the KVKK data breach notification article is a complementary resource for KVKK compliance.

Contact: Hacettepe Teknokent, Ankara. Phone: +90 536 662 38 09. Email: [email protected].


Sources: ISO/IEC 27001 official page · ISO/IEC 27002 official page · TURKAK · KVKK · Presidential Digital Transformation Office