+ 1-510-330-1361
Most SaaS companies encounter ISO 27001 the same way. A large enterprise prospect requests it during a security review, the deal stalls, and leadership starts paying attention. Founders and CTOs almost universally describe the same moment: a specific contract, not a strategic decision, is what moved certification from a future plan to an active project.
MG Environmental Consulting works with SaaS companies, technology businesses, and data-driven organizations pursuing ISO 27001 certification. This guide covers what the standard actually requires, what is different for cloud-native businesses, and what getting certified realistically involves from start to finish.
The ISO Survey 2024, developed with the International Accreditation Forum, reported 96,709 valid ISO 27001 certificates worldwide at year-end 2024, up from 48,671 the prior year and covering 179,877 registered sites globally. New certificate volume grew more than 24 percent year over year. Expanding cybersecurity regulations, particularly the EU NIS2 Directive and GDPR enforcement activity, are driving much of that growth alongside enterprise procurement teams treating certification as a baseline supplier condition.
Enterprise procurement teams, particularly in European markets and in regulated industries like financial services and healthcare, now treat ISO 27001 the way they treat GDPR compliance: as a non-negotiable. Their security teams don’t want to review detailed questionnaires for every new SaaS vendor. A current ISO 27001 certificate from an accredited certification body tells them that a third-party auditor has already verified your controls against an internationally recognized standard. That saves their team time and gives your sales process real traction.
The regulatory pressure is also building. In the EU, NIS2 references ISO 27001 as a relevant standard for Article 21 risk management obligations. SaaS companies supplying regulated sectors, including energy, healthcare, finance, and public administration, face increasing scrutiny around information security governance. In the US, enterprise organizations working toward CMMC or FedRAMP compliance often prefer ISO 27001 certified suppliers because the control overlap simplifies their own compliance workload.
ISO 27001:2022 is the current version, published by the International Organization for Standardization. It specifies what an Information Security Management System (ISMS) needs to include and how it needs to function. An ISMS is a governance framework, not a software tool. It covers policies, documented processes, risk management practices, security controls, and the monitoring activities that demonstrate the system is working. Before beginning certification, SaaS companies should understand the requirements outlined in ISO 27001 Clauses, which explains the scope of the standard and its applicability to organizations seeking to establish, implement, maintain, and continually improve an Information Security Management System (ISMS).
The ISMS is what you’re building when you implement ISO 27001. It documents what information assets you need to protect, what risks could affect those assets, what controls you’ve chosen to address those risks, and how you’re monitoring whether those controls actually work. The standard doesn’t hand you a fixed list of security controls and tell you to implement all of them. It requires you to conduct a risk assessment, identify which risks are relevant to your organization, select controls that address those risks, and document your reasoning in a Statement of Applicability.
The mandatory requirements live in Clauses 4 through 10. These cover your organizational context and stakeholder requirements, leadership commitment and accountability, risk-based planning, resource and competence management, operational security controls, performance evaluation through internal audits and management reviews, and corrective action processes.
Annex A contains 93 security controls organized across four themes: organizational controls, people controls, physical controls, and technological controls. You don’t implement all 93. You select the ones relevant to your identified risks, document which ones you’ve excluded, and explain why. Auditors pay close attention to both what you’ve included and what you’ve decided to leave out.
The 2022 revision of ISO 27001 introduced controls that specifically address cloud-hosted, software-as-a-service environments. SaaS companies aren’t implementing the same standard as a traditional corporate IT department, even if the clause numbers look the same.
Most SaaS companies run on AWS, Azure, or Google Cloud. The cloud provider handles physical security, network hardware, and hypervisor isolation. You own everything above that: identity and access management configurations, encryption settings, VPC architecture, application-layer security, and access controls over customer data. Annex A control A.5.23, added specifically in the 2022 revision, addresses information security for cloud service use. You need documented processes for selecting cloud providers, defining security requirements for those providers, and managing provider transitions.
When multiple customers share your infrastructure, preventing one tenant from accessing another tenant’s data is a critical security obligation, not just a good engineering practice. ISO 27001’s risk assessment process forces you to model this threat explicitly and document the controls that address it. The relevant Annex A controls include A.8.3 on information access restriction, A.8.5 on privileged access management, and A.8.24 on cryptography. Multi-tenant data isolation is consistently one of the first areas auditors examine in SaaS certification audits.
In a software company, your engineers are your largest security surface. They have access to production systems, they push code that handles customer data, and in fast-moving teams, access controls can drift without anyone noticing. The 2022 revision added A.8.25 on secure development lifecycle, requiring documented policies around secure coding standards, code review, security testing, and change management. Control A.8.28 covers secure coding practices, A.8.29 covers security testing in development and acceptance, and A.8.33 addresses the risk of production data being used in development environments.
Scope is the first real decision in an ISO 27001 implementation and probably the most consequential one for how long certification takes and what it costs. Organizations that scope too broadly in their first certification cycle spend more time, pay higher audit fees, and take longer to get the certificate.
For most SaaS companies, a practical ISMS scope includes the product and its cloud infrastructure, the cloud accounts that process customer data, the engineering, DevOps, and security teams, the CI/CD pipeline and deployment tooling, and any third-party services that access customer data. What you typically exclude in a first cycle are internal HR systems unrelated to the product, corporate IT assets with no connection to product infrastructure, and back-office functions with no access to customer data. You can expand the scope in later recertification cycles once the core system is stable.
SaaS companies frequently ask whether they need ISO 27001, SOC 2, or both. The geography of your customer base is the deciding factor. SOC 2 Type II reports dominate in North America. ISO 27001 is what European enterprise buyers recognize and request. If you’re selling into both markets, you’ll probably need both at some point. The good news is that the control overlap between the two frameworks is significant, so organizations that have completed one have a real head start on the other.
The structural difference matters too. ISO 27001 produces a publicly verifiable certificate. SOC 2 produces a confidential audit report shared only with specific parties under NDA. Both require ongoing effort: ISO 27001 through annual surveillance audits and a three-year recertification cycle, SOC 2 through annual Type II engagements. An experienced ISO 27001 and SOC 2 consultant can help organizations maintain compliance, prepare for audits, and streamline ongoing security governance requirements.
Start by mapping your current security practices against ISO 27001:2022 clause by clause. The gap analysis tells you what exists, what’s missing, and what’s documented but not actually followed. Right after the gap analysis, run a formal risk assessment. This doesn’t have to be a complex exercise, but it does need to be systematic and documented. You’re identifying information assets, modeling threats and vulnerabilities, assessing likelihood and impact, and deciding which risks need treatment.
Based on your risk assessment, select the Annex A controls and any additional controls that address your identified risks. Build out the policies, procedures, and technical configurations that implement them. The Statement of Applicability, required by Clause 6.1.3, is a document that lists every Annex A control, states whether you’ve applied it, and explains why you’ve excluded any that don’t apply. This document is one of the first things auditors review.
Before the external certification audit, run a full internal audit of your ISMS. Use auditors who are independent from the areas they’re reviewing. Document findings formally, close them through corrective actions, and then hold a management review meeting where leadership goes through ISMS performance data: audit results, security incidents, risk treatment status, and progress against security objectives. The outputs of that meeting need to be recorded.
Accredited certification bodies conduct the external audit in two stages. Stage 1 reviews your documented ISMS for conformance and assesses whether you’re ready for the on-site audit. Stage 2 verifies that what’s documented is actually implemented and generates objective evidence. A certificate is issued for three years, with surveillance audits in years one and two.
For a SaaS company of 20 to 100 people with a focused ISMS scope, certification typically takes four to six months using compliance automation tooling, or nine to twelve months going manually. Total first-year costs including gap analysis, control implementation, and the Stage 1 and Stage 2 certification audit typically run between $25,000 and $60,000 USD, depending on company size, scope, and which certification body you use. The biggest single variable is whether you use tooling that automates evidence collection from your cloud environment.
"The organizations that get through Stage 2 cleanly are almost always the ones that built their ISMS around how they actually operate, not around what they thought the auditor wanted to see. A risk assessment that reflects real threats, controls that people actually follow, a Statement of Applicability that someone actually wrote. That's what audit-ready looks like."
— Puneet Gupta, ISO Consultant, MG Environmental Consulting
Scoping too broadly in the first certification cycle is the most expensive mistake we see regularly. Trying to bring your entire business into scope in year one, including HR, finance, and corporate IT, adds months to the timeline and thousands to the audit fee. Start with the product and the teams that build and operate it.
Writing policies that describe the security posture you want rather than the one you actually have is closely related. If your access control policy says all production access requires multi-factor authentication but several engineers still authenticate with just a password, your documentation and your reality don’t match. Auditors find this. More practically, it’s a genuine security gap regardless of whether an auditor ever sees it.
Treating the risk assessment as a one-time exercise is a problem that surfaces at surveillance audits. ISO 27001 requires risk assessments to be revisited when significant changes occur in your environment, including new product features, new cloud services, or shifts in your threat landscape. A risk register that hasn’t been updated since the initial certification is a finding waiting to happen.
“We used MG's services for ISO 27001 certification. Highly recommend them as they are thoroughly professional, knowledgeable and always have client first approach.”
— Diane Smith
MG Environmental Consulting works with SaaS companies, technology businesses, and data-driven organizations through every stage of ISO 27001 certification. Our work covers gap assessments, ISMS documentation, internal auditor training, and audit preparation, whether the organization is pursuing certification for the first time or maintaining an existing one. We work with clients across California and nationally.
To speak with a consultant, call (510) 332-1321.