How to Answer ISO/IEC 27001 Certification Questions

Your customer asked: “Are you ISO 27001 certified?”

The short answer

ISO/IEC 27001:2022 defines requirements for an information security management system. A company can use the standard without being certified. Answer “certified” only when the organization actually holds a valid certificate covering the relevant scope.

Educational guidance only. This page does not determine what is true about your company and does not create a security, compliance, testing, or certification claim.

What the customer is really asking

Understand the question before you answer it.

The reviewer is usually asking for independent assurance that the company's information security management system has been certified against ISO/IEC 27001. ISO itself notes that organizations may implement the standard without choosing certification.

How to answer accurately

Start with the version that matches reality.

1

If your company is certified

State the certification accurately and ensure the scope and current certificate support the claim. The official reference is ISO/IEC 27001:2022.

2

If you use ISO/IEC 27001 as guidance

Say that the company uses or aligns certain practices with the standard only if that statement is supportable. Do not call that certification.

3

If you are not certified

Answer “no” and continue with the underlying security questions. Lack of certification does not prevent you from accurately describing your security practices.

A useful answer structure

Status → scope → current practice → supporting information. Start with the direct answer, narrow it to what you can verify, explain how the practice works, and reference evidence only when that evidence actually exists.

Evidence that may help

These are examples, not requirements and not proof that your company has the practice. Use only evidence that really exists and is appropriate to share.

  • Current ISO/IEC 27001 certificate
  • Certification scope
  • Certification body information
  • ISMS documentation for underlying questions

What not to say

  • “ISO 27001 certified” without a valid certificate and relevant scope.
  • That following an ISO checklist equals certification.
  • That a vendor's ISO certification transfers to your company.

How Oredra handles this

Answer it once. Keep the truth behind the answer.

Oredra treats independent certification as its own status—separate from policy, practice, control, evidence, or internal testing.

Inside Oredra, a written policy, stated company practice, implemented control, available evidence, tested control, and independent certification remain distinct. Oredra uses approved information to draft future answers and flags questions that the approved profile cannot support.

Authoritative references

Oredra uses primary guidance where a technical or assurance concept benefits from verification. These references do not determine your company's answer.

Related questionnaire questions