ISO 27001 Certification in USA

Been asked for ISO 27001 by a customer? Start with your scope, not your paperwork. Talk to IAS about ISO 27001 certification in the USA.

✓ IAS is accredited by UQAS | ✓ Scope stated on the certificate | ✓ Audits by information security auditors | ✓ US-based clients across sectors

Why someone asks you for ISO 27001 certification

Most US companies do not wake up wanting an information security management system. They get an email. A customer’s procurement team, a prime contractor, or a security questionnaire asks whether the company holds ISO 27001. The request usually arrives with a deadline attached.

ISO/IEC 27001 is the international standard for an information security management system, normally shortened to ISMS. It sets out how an organization decides what information matters, what could go wrong, and what it will do about it. It describes how you run security, not which firewall to buy. ISMS certification sits in the same family as the other schemes covered under system certification in the USA. The audit looks at decisions, records, and follow-through, not your technology stack against a shopping list.

Scope decides almost everything

Before anything else, you choose a scope. Scope is the boundary of the ISMS: which services, which teams, which locations, which systems are inside it, and what sits outside.

This single choice drives the cost, the effort, the audit, and — critically — the value of the certificate to the person who asked for it. A narrow scope is faster to certify. A narrow scope also tells your customer less.

Here is where it goes wrong. A company certifies one product team, prints the certificate, and sends it to a customer who buys a different service entirely. The customer reads the scope line, sees that their service is not named, and asks the question again. The work was real. The certificate just did not cover what the buyer cared about.

Write your scope as though a skeptical buyer will read it out loud. Because one will.

Scope decisionWhat it gets youWhat it costs youWhen it fits
Single product or platformFast route to a certificateBuyers of other services are not coveredOne flagship SaaS product, one customer segment
One legal entity, all servicesCovers the whole commercial offerEvery team must run the ISMSSmall to mid-size company with one operating entity
Named sites onlyContains physical and facility riskRemote staff and cloud systems need explicit treatmentData centers, labs, manufacturing with site-bound risk
Corporate group, all entitiesOne certificate answers most questionsSlowest to build, hardest to keep consistentGroups with shared IT and shared leadership

Do not pick the narrowest scope by reflex. Pick the scope that answers the question you keep being asked.

Who IAS is, and who assesses IAS

IAS is a certification body. IAS is accredited by UQAS. That accreditation is an assessment of IAS — of our impartiality, our auditor competence, our decision-making, and the way we run certification. It is not an endorsement of any organization we certify, and it says nothing about the security of your systems.

This matters because accreditation language is often used loosely in marketing. The honest version is simple. The standard sets the requirements. UQAS assesses IAS against the rules for certification bodies. IAS audits your ISMS against ISO 27001. Your customer reads the result.

The accreditation chain: UQAS accredits IAS as a certification body, IAS audits the client's information security management system against ISO/IEC 27
The accreditation chain: UQAS accredits IAS as a certification body, IAS audits the client’s information security management system against ISO/IEC 27001, and the client receives a certificate naming a defined scope.

Each link in that chain does one job. Nobody further up the chain has looked at your servers. When a buyer asks who stands behind the certificate, that is the accurate answer. More on how IAS works is on the about us page, alongside the list of associate partners in the USA, and on the wider range of ISO certification in the USA.

The Statement of Applicability, in plain terms

ISO 27001 comes with an annex of information security controls. The Statement of Applicability — everyone calls it the SoA — is the document where you state, control by control, whether it applies to you, why, and whether it is in place.

The SoA is not a checklist you tick. It is the record of your reasoning. Auditors read it as a map of your judgment.

Two failure patterns show up again and again. The first is marking every control applicable because excluding one felt risky. That leaves you defending controls you never intended to run. The second is excluding controls with a one-word justification like “not relevant,” which invites the auditor to ask exactly the question you were avoiding.

A usable SoA connects three things: a risk you identified, the control you chose, and the evidence that the control runs. If any of the three is missing, expect a finding. The ISO 27001 requirements article covers the clause structure in more detail.

What buyers actually read on a certificate

Security teams have become better readers. A decade ago, a certificate logo satisfied a questionnaire. Now the reviewer opens the PDF and looks for four things.

  • The scope statement, and whether it names the service they are buying.
  • The certification body, and who accredits it.
  • The validity dates, and whether surveillance is current.
  • The certificate number, so they can verify it independently.

If your scope statement is vague, the reviewer treats it as a red flag rather than a convenience. “Information security management system for the company” tells them nothing. “Development, hosting, and support of the [named platform] delivered from [named locations]” tells them everything.

Guidance on using marks correctly is set out in the guideline for usage of logos.

The route to ISO 27001 certification

The path is more predictable than most people assume. What varies is how long the preparation stage takes, and that depends entirely on how much you already do.

The certification pathway from scope definition and risk assessment, through the Stage 1 documentation review and the Stage 2 implementation audit, to
The certification pathway from scope definition and risk assessment, through the Stage 1 documentation review and the Stage 2 implementation audit, to the certification decision and the surveillance that follows.

Stage 1 is a readiness review. The auditor checks your scope, your SoA, your risk assessment, your policy, and whether internal audit and management review have actually happened. Stage 1 exists to find gaps while they are still cheap to fix. Treat it as useful rather than as a hurdle.

Stage 2 is the real audit. The auditor samples evidence against what you said you do. Access reviews, incident records, supplier assessments, change approvals, backup restoration tests, training records. The question is never “do you have a policy.” It is “show me the last three times this happened.”

The ISO 27001 certification process page walks through the stages, and the certification process in the USA page explains how IAS handles applications.

What an auditor accepts, and what draws a finding

Auditors do not grade on ambition. They grade on whether the thing you described is the thing that happens.

AreaDefensibleHard to defend
Risk assessmentNamed risks tied to real assets and owners, reviewed on a scheduleA generic risk register copied from a template, last touched at implementation
Statement of ApplicabilityEach decision justified, cross-referenced to evidenceEvery control marked applicable, no justification column filled in
Access controlJoiner, mover, leaver records that match HR recordsAccounts for people who left, discovered during the audit
Supplier managementSecurity requirements in contracts, reviews on fileA vendor list with no assessment of any vendor
Incident handlingLogged incidents with root cause and closure, including minor onesAn empty incident log presented as evidence of good security
Internal auditIndependent, covers the full scope, findings closed outOne audit, done by the person who wrote the procedures
Management reviewMinutes showing decisions, resources, and changed prioritiesAn agenda with no recorded outcome
AwarenessRole-specific training, records per personOne all-staff slide deck, attendance not tracked

An empty incident log deserves its own warning. It almost never means nothing happened. It usually means nothing was recorded, which is a worse answer.

Who does what

Certification involves three parties with clearly separated jobs. Confusing them causes problems, especially around consulting.

TaskYour organizationIASAccreditation body (UQAS)
Define ISMS scopeOwns the decisionReviews it for clarity and coverageNot involved
Build the ISMS and write the SoAOwns it entirelyCannot design or write itNot involved
Run internal auditOwns itChecks it was done properlyNot involved
Conduct Stage 1 and Stage 2Provides access and evidencePlans and conducts the auditNot involved
Make the certification decisionNot involvedIndependent decision from the audit teamNot involved
Assess the certification bodyNot involvedSubject of assessmentAssesses IAS

A certification body cannot consult on the system it audits. That independence is part of what the accreditation assesses. If you want help building the ISMS, that help comes from somewhere else. IAS audits it.

Where ISO 27001 certification projects usually stall

The standard is not the hard part. Four things slow companies down more than the clauses do.

  • Scope drift. The scope was written before the risk assessment and never revisited. By Stage 2 it no longer describes the business.
  • Documentation without practice. Policies written in a month, then unread. Auditors find this within an hour.
  • No owner. Security is “everyone’s responsibility,” which means nobody scheduled the access review.
  • Internal audit done late. It must happen before Stage 2 and must cover the whole scope. Leaving it until the last week produces a thin audit and a visible gap.

A short foundation training course early on gives the people involved a shared vocabulary, which removes some of this friction. Fixing these is mostly calendar work — assigning owners and putting recurring reviews in place months before the audit, not weeks.

Keeping ISO 27001 certification once you have it

A certificate is not a finish line. Certification runs on a cycle, with surveillance audits between the initial audit and recertification.

The ISO 27001 certification cycle: initial certification, followed by scheduled surveillance audits that sample parts of the ISMS, leading to recertif
The ISO 27001 certification cycle: initial certification, followed by scheduled surveillance audits that sample parts of the ISMS, leading to recertification at the end of the cycle.

Surveillance samples. It does not repeat the whole Stage 2. The auditor looks at changes, at findings from last time, and at a rotating selection of controls. Recertification is a fuller review of the whole ISMS.

Tell IAS when your scope changes. New services, new sites, a major platform migration, or an acquisition can all take the ISMS outside what was certified. A scope that quietly grew and was never notified is a problem discovered at the worst moment — usually when a customer asks why their service is not named.

The ISO 27001 audit article explains what happens in each audit type.

How buyers should read your certificate

Say this plainly, because it prevents arguments later.

An ISO 27001 certificate means that, at the time of the audit, IAS assessed your information security management system against the requirements of the standard, within the scope written on the certificate, and found it conforming on the basis of sampled evidence.

It does not mean every control worked on every day. It does not mean you cannot suffer a breach. It does not cover services, sites, or entities outside the stated scope. It is not a technical security test — for that, look at something like VAPT, which is a different activity with a different purpose. It is not a guarantee of any outcome, commercial or technical.

Auditing is sampling. Sampling has limits, and honest certification bodies say so.

A note on legal duties

This page takes no position on the law of any jurisdiction. Nothing here states what any statute, regulator, or contract requires of you.

ISO 27001 is a voluntary international standard. Whether any legal or contractual obligation applies to your organization is a question for your own legal advisers. Customers may require certification by contract. That is a commercial matter between you and them, and it is not something this page can decide.

Building capability in-house

Most of the long-term work is internal. Someone has to run the internal audit program, keep the risk assessment alive, and prepare evidence each cycle. Training that role pays off faster than most people expect.

ISO 27001 lead auditor training suits people who will lead audits or manage the program. ISO 27001 internal auditor training suits the people doing the internal audits themselves. Both sit in the wider ISO lead auditor training catalogue. Both are listed under ISO training in the USA, and dates appear on the training schedule. Auditors who also cover quality or continuity often add ISO 9001 lead auditor training or ISO 22301 lead auditor training.

If your ISMS sits alongside quality or continuity work, the ISO 9001 and ISO 22301 pages cover those schemes. Companies running one integrated management system often certify to several at once, so the ISO 14001, ISO 45001 and ISO 20000 pages are worth a look.

Frequently asked questions

Do we need ISO 27001 certification, or is an internal ISMS enough?

That depends on who is asking. If a customer’s contract asks for a certificate, an internal system will not close the request. If nobody is asking and you simply want better security, you can implement the standard without certifying. Certification is the independent check, and it is what buyers can verify.

How should we word the scope on the certificate?

Name the services, the activities, and the locations. Avoid words like “all operations” unless that is literally true and you can support it. A reviewer should be able to match your scope line to the service they are buying without asking a follow-up question.

Can we exclude parts of the business?

Yes. Scope exclusions are normal and legitimate. What is not acceptable is an exclusion that makes the certificate misleading — for example, certifying a support function while the customer-facing service sits outside. Be able to explain any boundary in one sentence.

Can IAS help us build the management system?

No. A certification body cannot consult on a system it will audit. That separation is part of what accreditation assesses. IAS audits and certifies. Building the ISMS is your work, with whatever external help you choose.

Who accredits IAS?

IAS is accredited by UQAS. That accreditation covers how IAS operates as a certification body. It is an assessment of IAS, not an endorsement of any certified organization.

How many controls do we have to implement?

There is no fixed number. The controls you implement come from your risk assessment and are recorded in your Statement of Applicability. Two companies in the same industry can end up with genuinely different sets, and both can be correct.

What happens if the auditor raises a nonconformity?

You investigate the cause, propose a correction, and submit evidence that it was addressed. Minor findings are usually handled through documented follow-up. Major findings need resolution before a certification decision. A finding is not a failure; it is a defined part of the process.

Does ISO 27001 certification cover our cloud providers?

No. Your providers are not certified by your certificate. What is assessed is how you manage them — the security requirements you set, how you assess them, and how you monitor them. Supplier management is one of the areas auditors examine closely.

How long does ISO 27001 certification take?

It depends almost entirely on your starting point and your scope. A company already running access reviews, incident logging, and supplier assessments moves quickly. A company starting from an empty folder spends most of its time before the audit, not during it.

Do we need to recertify if we change what we do?

Tell IAS about material changes to scope, services, or sites. Depending on the change, it may be handled at the next surveillance audit or may need a separate assessment. Do not wait for recertification to mention it.

Where can I see what IAS charges?

Cost depends on scope, sites, and complexity, so it is quoted per organization. The general ISO 27001 certification cost article explains the factors involved. For a figure, contact IAS.

What else should we read first?

Start with ISO 27001 requirements, then the iso audit procedure. The frequently asked questions page covers the administrative side, and the blog has wider background.

Get the scope right before you apply. IAS is accredited by UQAS and certifies information security management systems across the United States. Request a quote or read more about ISO 27001 certification in the USA.