ISO 27001 guides & explainers
Practical, source-backed guides to ISO 27001 costs, timelines, certification-body selection, and certification prep — written for the person who has to get it done.
How to Choose an ISO 27001 Certification Body: 8 Questions to Ask
The vetting checklist we recommend: accreditation verification, audit teams, audit-day math, fees, and the red flags that signal a bad fit.
ISO 27001 Stage 1 vs Stage 2 Audits: What's Actually Different
Documentation review vs effectiveness testing: what each stage checks, how long each takes, and what sinks companies at each stage.
ISO 27001 vs SOC 2: Which One Do Your Customers Actually Need?
Certificate vs attestation report, international vs US expectations, and the combined program that covers both — sequenced honestly.
How ISO 27001 Audit Fees Are Actually Calculated (Audit Days Explained)
ISO/IEC 27006 tables, day rates, and why two CBs quote different fees for the same company — plus how to sanity-check any quote.
Accredited vs Non-Accredited ISO 27001 Certificates: The Expensive Mistake
Why the cheaper certificate costs more in the end: procurement rejection, what accreditation actually checks, and how to verify a CB.
ISO 27001:2022 Annex A: The 93 Controls, Grouped for Humans
The 2022 version's four control themes — organizational, people, physical, technological — and the 11 new controls that trip up 2013 holdouts.
Reading is step one. Quotes are step two.
When you're ready, get scoped quotes from accredited certification bodies matched to your company.
How it works: tell us once (4 questions, 2 min) → we match licensed auditors to your size and scope → they send scoped quotes directly. Free, no obligation.