Who should read this: a company that has just passed its ISO 27001 audit, or is about to, and wants to know what it has actually bought.
Start with the fair part. A certificate is not theatre. It means an accredited third party sampled your management system and found it operating. It opens doors, it shortens security reviews, and it is often the difference between being eligible for a contract and not. None of what follows is an argument against getting one.
It is an argument about what it measures, because a lot of companies quietly believe the certificate answers a question it was never designed to answer.
What the standard actually requires
ISO 27001 is a management system standard. It requires you to determine your context, assess risk, select controls, implement them, check that they work, and improve. Annex A is a reference set of 93 controls you choose from and justify.
Read that again, because the important word is select. The standard does not tell you what good looks like for any given control. It tells you to decide, document the decision, and be able to show the control operates. The grouping in the Annex A controls grouped for real work separates the ones where recording is genuinely the work from the ones where recording is the easy half.
That design is deliberate and it is what makes the standard usable across a bank and a twelve-person software company. It is also precisely where the gap lives.
Four controls, and what satisfies them
The clearest way to show this is to take the operational controls and ask what the minimum passing implementation looks like.
A.8.8, management of technical vulnerabilities. You need a process to obtain information about vulnerabilities, evaluate exposure, and take action. A monthly scan, a report, and a documented process satisfies it. The report can contain critical findings that have been open for nine months. The control asked for a process and got one.
A.8.15, logging. Produce, store and protect logs of activities. Logs written to a disk with retention set satisfies it. Nobody has to look at them. Nobody has to be able to answer a question with them.
A.8.16, monitoring activities. Networks, systems and applications monitored for anomalous behaviour. This is the widest gap on the list, because the control can be met with a documented procedure and a nominated responsibility while nothing in the estate is actually watching in a way that would raise an alert at two in the morning.
A.8.13, information backup. Backups maintained and tested. A backup job that runs and a test recorded once satisfies it. Whether a full restore has ever been timed against your actual recovery objective is a separate question the control does not force.
None of this is a criticism of auditors. An auditor’s job is to sample whether the control you declared operates as you described it. It is not to form a judgement about whether your security is good. There is no clause that asks them to.
The four questions a certificate does not answer
Put plainly, and these are the questions a customer actually cares about even when their questionnaire asks something else:
- Would you notice? If someone was in your environment right now, is there anything that would tell you, and how long would it take.
- How long do known problems stay open? Not whether you scan, but what your median time to remediate a critical finding is.
- Can you actually recover? Not whether backups run, but whether a restore has been timed end to end against the recovery objective you promised somebody.
- Is the account that left still able to get in? Not whether you have a leaver process, but whether it caught the tokens, the SaaS logins, the registrar and the billing portal.
A certificate can be entirely genuine while all four answers are bad. That is not a loophole, it is the scope of the instrument.
Why the gap widens rather than closes
Two forces make this worse over time, and both are structural rather than anyone’s fault.
Certification rewards stability, security rewards change. The cheapest way to keep a certificate is to keep the system as it was described. The cheapest way to stay secure is to keep changing it as the estate changes. Those pull in opposite directions between audits.
The consultant model ends at the certificate. An engagement scoped to certification stops when the certificate issues. The gap list produced by the gap analysis was priced. Closing the technical half of it usually was not, which is the recurring budget failure described in what ISO 27001 actually costs an SME.
There is also a version of this that arrives as a customer question rather than an incident. A prospect’s security team asks what your mean time to detect is, and the certificate does not contain the answer. The same happens under NIS2, where the obligation is measures appropriate to the risk, assessed on what happened rather than on what was certified.
What closing it actually looks like
Not more auditing. The audit is not the constraint.
Make the operational controls testable rather than reviewable. Restore a backup and time it. Pick a leaver at random and hunt for live credentials. Take one finding from the scanner and follow it to closure with a date. Write those into the internal audit programme so they happen on a schedule, which is the practical version of the point in internal audit and management review.
Attach a clock to findings, not just an owner. A vulnerability with an owner and no deadline is a vulnerability. The number that matters is how long criticals stay open, and almost nobody in this size band measures it.
Let the tooling produce the evidence. Detection, vulnerability management, cloud posture and backup verification all generate records as a by-product. Run them and the evidence problem solves itself, which is the argument in evidence that assembles itself. Run them and you also get the actual security, which is the point.
That is the reason our platform carries both halves in one place: the control set and the gap list on one side, the detection and exposure management that closes the technical gaps on the other, landing in the same evidence record. A gap list you cannot close is a document. The independent audit exists to tell you which of your gaps are documentation and which are technical, before you spend on either.
The honest summary
Get the certificate. It is worth having, it opens doors, and the discipline of building an ISMS is genuinely useful even before it is certified. The full picture of doing that without a security team is in ISO 27001 for a company without a security team.
Then answer the four questions above separately, because the certificate does not, and because those are the questions that decide whether the thing the certificate describes was ever true.