Adding ISO 27001 when you already hold ISO 9001

If you already run a certified quality system, roughly seven of the ten ISO 27001 clauses are structurally the same as ones you already satisfy. The other three are the entire job, and they are the ones nobody who sold you ISO 9001 has ever walked you through.

Daniel Grigorovich
Daniel Grigorovich
Founder · 14 Sept 2026 · 6 min read
ISO 27001AuditSME
Adding ISO 27001 when you already hold ISO 9001

Who should read this: a manufacturer, engineering firm or supplier that already holds ISO 9001, and possibly ISO 14001, ISO 45001, AQAP 2110 or TISAX, and has now been asked for ISO 27001 by a customer, a prime contractor or a tender.

This is a better starting position than most companies have, and it is routinely undersold to you by people quoting for the work. You have already proved you can operate a management system: document control, an internal audit programme, a management review that produces decisions, corrective action that closes. That is the part companies without a certificate find hardest, and you did it years ago.

What follows is an honest account of what transfers, what does not, and where the actual effort sits.

Why the overlap exists

Since 2012 every ISO management system standard has been written to a common template, originally called Annex SL and now the Harmonized Structure. It fixes the same ten clauses in the same order across ISO 9001, ISO 14001, ISO 45001, ISO 22301 and ISO 27001.

  1. Scope
  2. Normative references
  3. Terms and definitions
  4. Context of the organisation
  5. Leadership
  6. Planning
  7. Support
  8. Operation
  9. Performance evaluation
  10. Improvement

This is not a marketing similarity. The requirement text in clauses 4, 5, 7, 9 and 10 is close to identical between standards, differing mainly in whether the subject is quality or information security. If you satisfy them for one, the machinery satisfies them for the other.

What genuinely transfers

In the assessments we run for companies in this position, the following come across almost intact:

  • Document and record control. Your existing system for versioning, approving and retaining documents works unchanged. Information security policies slot into it.
  • The internal audit programme. Same programme, same auditors if they are competent in the subject, new scope. Clause 9.2 is the same requirement.
  • Management review. Clause 9.3 inputs differ in content but not in structure. One meeting can review both systems if the agenda covers both sets of inputs properly.
  • Corrective action and nonconformity. Clause 10.2 is the same process. You already run it.
  • Competence, awareness and training. Clause 7.2 and 7.3. You have induction, training records and a competence matrix. Information security awareness becomes another strand.
  • Leadership and policy. Clause 5 requires top management commitment and a documented policy. You have the habit and the approval route.
  • Interested parties and context. Clause 4. The analysis exists, it needs an information security lens added.
  • The certification body relationship. You know how an audit runs, how nonconformities are graded, and how to prepare. That is worth more than it sounds.

For a company with a mature quality system, this genuinely is most of the management system work already done.

What does not transfer at all

Three things. They are the whole job.

Clause 6.1.2, information security risk assessment. ISO 9001 risk thinking is about things that threaten conformity of product and process. ISO 27001 risk is about confidentiality, integrity and availability of information, assessed against assets, threats and vulnerabilities, with defined criteria and risk owners. The two are not the same exercise and a 9001 risk table will not be accepted as one. If you want the specifics of what that record has to carry, they are in the risk register that survives an audit.

Clause 6.1.3 and Annex A. Ninety three controls across four themes, each of which you must consider, then either apply or justify excluding. Nothing in a quality system prepares you for this. It is the part that takes months, because a fair number of the controls describe technical capability you may not currently have. The grouping that makes this tractable is in the 93 Annex A controls grouped the way you will actually work through them.

The Statement of Applicability. A single document listing all ninety three controls, whether each applies, why, and its implementation status. ISO 9001 has no equivalent artefact. It is the document an ISO 27001 auditor opens first and the one that determines the shape of the rest of the audit. How to write it without drowning is in scope and Statement of Applicability, explained without the jargon.

The trap: assuming your risk process already covers it

This is the single most expensive assumption we see, and it usually surfaces at Stage 1.

A quality manager reasonably concludes that because the quality system has a risk and opportunity process satisfying ISO 9001 Clause 6.1, the ISO 27001 requirement is met by extension. It is not. ISO 9001 deliberately does not mandate a formal risk methodology. ISO 27001 does: defined criteria, a repeatable process, identified risk owners, a treatment plan, documented acceptance of residual risk.

Companies that discover this at Stage 1 lose a month. Companies that discover it at Stage 2 get a major nonconformity. Treat the information security risk work as a separate build from day one and the problem disappears.

What a combined audit actually saves

Certification bodies will audit multiple standards together and the shared clauses are assessed once. Fewer days than two separate audits, yes. Half, no.

The reason is that the auditor still has to cover Annex A, and Annex A is the bulk of an ISO 27001 audit. What combines is clauses 4 to 10. What does not combine is the ninety three controls, the risk assessment and the Statement of Applicability. Expect a meaningful discount against two standalone audits rather than a dramatic one, and ask your certification body for the day count in writing before you assume a number. The general shape of certification cost for a company your size is in what ISO 27001 really costs an SME, and the timeline in how long ISO 27001 really takes.

One practical point: using the same certification body for both is usually worth it even at slightly higher day rates, because combined audits require the body to hold accreditation for both standards and to schedule one visit.

What your certificate wall says to a customer

Worth being blunt about this, because it cuts both ways.

Five certificates and no ISO 27001 tells a customer’s security reviewer two things at once. It tells them you are an organisation that can sustain an audited system, which is genuinely reassuring and puts you ahead of most suppliers they assess. It also tells them that information security is the one discipline you have not submitted to external examination, which in a tender that is asking about information security is precisely the wrong gap to have.

That is why the request usually arrives from procurement rather than from anyone technical, and why it arrives with a date attached. The mechanics of how that obligation travels down a supply chain are in NIS2 supply chain security and vendor risk, and the relationship between the certificate and the directive is in NIS2, certification standards and ISO 27001.

The technical reality: a certified quality system proves process, not defence

Here is the part worth saying plainly to anyone who has run a certified management system for a decade.

Your quality certificate proves that you can define a process, follow it, audit it, and correct it when it drifts. That competence is real and it is transferable. It does not tell you whether an administrator account belonging to someone who left in March still works, whether an internet-facing service is behind on patches, whether your backups have ever been restored, or whether a supplier still has network access under a contract that ended last year.

ISO 27001 will ask you to declare that these things are managed. It will not, on its own, tell you whether they are true this week. That is the gap between an audited system and a defensible one, and it is the reason the certificate and the security posture have to be built as one exercise rather than two. The fuller argument is in certified is not secure, and the practical route for a company with no security team is in ISO 27001 without a security team.

If you want the gap measured against your existing system rather than estimated, an independent security audit starts from what you already have certified, and the ISO 27001 service page sets out what the rest of the route looks like.

Daniel Grigorovich

Daniel Grigorovich · Founder

I believe that no business should suffer from "compliance checklists" or navigating vague regulatory text. While I still stand by the principle that all software products should be reliable and secure, I want to give companies a way to overcome the challenges faced when implementing these requirements.