How to Answer ISO/IEC 27001 Certification Questions
Your customer asked: “Are you ISO 27001 certified?”
The short answer
ISO/IEC 27001:2022 defines requirements for an information security management system. A company can use the standard without being certified. Answer “certified” only when the organization actually holds a valid certificate covering the relevant scope.
Educational guidance only. This page does not determine what is true about your company and does not create a security, compliance, testing, or certification claim.
What the customer is really asking
Understand the question before you answer it.
The reviewer is usually asking for independent assurance that the company's information security management system has been certified against ISO/IEC 27001. ISO itself notes that organizations may implement the standard without choosing certification.
How to answer accurately
Start with the version that matches reality.
If your company is certified
State the certification accurately and ensure the scope and current certificate support the claim. The official reference is ISO/IEC 27001:2022.
If you use ISO/IEC 27001 as guidance
Say that the company uses or aligns certain practices with the standard only if that statement is supportable. Do not call that certification.
If you are not certified
Answer “no” and continue with the underlying security questions. Lack of certification does not prevent you from accurately describing your security practices.
A useful answer structure
Status → scope → current practice → supporting information. Start with the direct answer, narrow it to what you can verify, explain how the practice works, and reference evidence only when that evidence actually exists.
Evidence that may help
These are examples, not requirements and not proof that your company has the practice. Use only evidence that really exists and is appropriate to share.
- Current ISO/IEC 27001 certificate
- Certification scope
- Certification body information
- ISMS documentation for underlying questions
What not to say
- “ISO 27001 certified” without a valid certificate and relevant scope.
- That following an ISO checklist equals certification.
- That a vendor's ISO certification transfers to your company.
How Oredra handles this
Answer it once. Keep the truth behind the answer.
Oredra treats independent certification as its own status—separate from policy, practice, control, evidence, or internal testing.
Inside Oredra, a written policy, stated company practice, implemented control, available evidence, tested control, and independent certification remain distinct. Oredra uses approved information to draft future answers and flags questions that the approved profile cannot support.
Authoritative references
Oredra uses primary guidance where a technical or assurance concept benefits from verification. These references do not determine your company's answer.
Related questionnaire questions
Do you maintain a written information security policy?
Answer “yes” only if a written policy actually exists in a current, approved form. A policy describes expectations and requirements; it does not by itself prove that every stated practice or control is operating.
Do you assess the security of vendors and third parties?
Describe how your company evaluates vendors that can affect customer data or important operations. A small business may perform practical due diligence without running a formal enterprise vendor-risk program; the answer should reflect the process that actually exists.
Are you SOC 2 compliant, certified, or do you have a SOC 2 report?
SOC 2 is an examination and resulting report on controls at a service organization; it is not a SOC 2 certification. If your company does not have a current SOC 2 report, do not describe the business as SOC 2 certified or imply that a policy set makes you SOC 2 compliant.