Topics/ISO 27001
ISO 27001 HUB

Everything on ISO 27001.

The 93 Annex A controls, the certification path, Statement of Applicability, audit preparation, realistic costs — plus industry-specific implementations for SaaS, manufacturing, healthcare, pharma.

English articles

Deutsche Artikel

Frequently asked questions

How long does ISO 27001 certification take?+

6-9 months typical from zero: 2-3 months ISMS build (scope, policies, risk assessment, SoA), 2-3 months implementation and evidence collection, 1 month Stage 1 audit + gap remediation, 1 month Stage 2 audit + certificate. Matproof customers frequently finish in 4-5 months.

What's new in ISO 27001:2022?+

Annex A reorganized from 114 controls in 14 categories to 93 controls in 4 themes (Organizational, People, Physical, Technological). New controls: threat intelligence, ICT continuity, physical security monitoring, configuration management, information deletion, data masking, DLP, monitoring, web filtering, secure coding. Companies certified under 2013 must transition by October 31, 2025.

How does ISO 27001 cost?+

EU mid-market SaaS (50-150 employees): EUR 25-80k total Year 1. Breakdown: EUR 10-22k compliance platform, EUR 8-20k certification body, EUR 5-15k pentest, EUR 5-25k internal time. Year 2: 40-50% less since setup is amortized.

Ready to tackle ISO 27001?

Matproof covers ISO 27001 in one EU-hosted platform alongside 10 other frameworks. 30-minute demo tailored to your scope.