The international reference standard for establishing an information security management system (ISMS).
Last updated — August 22, 2026
Any organization seeking to structure its security governance and formally demonstrate it to clients, partners, or procurement authorities, particularly in tenders or supplier relationships.
Defining the ISMS scope, risk assessment and treatment, implementation of relevant Annex A controls, a formalized security policy, management review, internal audit, and continual improvement of the system.
Deadlines
No regulatory deadline — this is a voluntary process. The certification cycle runs over three years, with annual surveillance audits and a recertification audit at the end of the cycle.
Sanctions
No direct legal sanction. The risk is commercial in nature: lost tenders, exclusion from supplier panels, or loss of trust from partners requiring this certification.
Gap analysis against the standard's requirements
Define the ISMS scope and conduct a risk assessment
Select and implement the applicable Annex A controls
Draft the documentation set (policies, procedures, registers)
Internal audit, management review, then certification audit
| Framework | Covered |
|---|---|
| nis2 | ✓ |
| loi-05-20-dgssi | ✓ |
| soc-2 | ✓ |
Get the checklist by email.
Typically 6 to 12 months, depending on the organization's starting maturity and the scope selected.
No, it is a voluntary process. It can nonetheless become a contractual prerequisite imposed by certain clients or tenders.
A security audit assesses a point-in-time state; ISO 27001 certifies a full management system, with governance, continual improvement, and ongoing oversight.
It provides a solid, largely overlapping foundation, but does not remove the need for a specific analysis of each applicable regulatory framework's own requirements.