ISO/IEC 27001
ISO/IEC 27001 (Information Security Management System)
The international standard for an Information Security Management System (ISMS) — certification that demonstrates an organisation's maturity in IT security.
What is ISO/IEC 27001?
ISO/IEC 27001 is an international standard from the International Organization for Standardization (ISO) and the International Electrotechnical Commission (IEC) that defines the requirements for an Information Security Management System (ISMS). The current version ISO/IEC 27001:2022 contains 93 security controls in Annex A, organised into 4 themes (organisational, people, physical, technological).
ISO 27001 certification is voluntary, but in B2B it is becoming a de facto requirement — most enterprise customers require it when selecting a SaaS vendor. The certification process consists of:
- Gap analysis against the standard’s requirements
- ISMS implementation — policies, procedures, controls
- Internal audit
- Certification audit by an accredited body (e.g. Bureau Veritas, TÜV SÜD, BSI)
- Re-certification every 3 years, surveillance audit every year
Key areas of Annex A 2022:
- A.5 Organisational controls — policies, roles, suppliers
- A.6 People controls — screening, discipline
- A.7 Physical controls — access to buildings, data centres
- A.8 Technological controls — cryptography, logging, access management
When it applies
ISO 27001 is relevant for:
- SaaS providers — customers require it
- Financial institutions and fintech
- Public sector — mandatory for certain projects
- Healthcare and critical infrastructure
See the Security page.
Related terms
- GDPR — ISO 27001 significantly supports GDPR compliance. See /en/glossary/gdpr.
- RBAC — a technical control from Annex A. See /en/glossary/rbac.
- SSO — a common technological control. See /en/glossary/sso.
In Modulario
Modulario implements ISO 27001 controls in its cloud operations — encryption of data at rest and in transit, RBAC, audit logging, incident response process. Details on certifications and sub-processors are at /en/security.
Modulario as a SaaS vendor provides customers with SOC 2 and ISO 27001 reporting to facilitate compliance audits. Customers receive a sub-processor list, penetration test results, and security incident documentation — all available in the customer portal.
Other relevant certifications include ISO/IEC 27701 (extension for personal data protection), ISO 9001 (quality), and TISAX (automotive). Modern SaaS companies often hold multiple certifications to succeed in enterprise and public sector B2B sales.
Related terms
GDPR
The EU regulation on personal data protection in force since 25 May 2018 — defines the rights of data subjects and the obligations of controllers.
AI Act
The first comprehensive EU regulation governing the development, deployment and use of artificial intelligence — a risk-based approach with four levels.
RBAC
An authorisation model in which permissions are assigned through roles rather than to individual users — simpler management and auditability.
SSO
An authentication mechanism that allows a user to log in once and gain access to multiple applications without repeatedly entering a password.
ReBAC
An authorisation model based on relationships between objects — access is derived from which teams and projects a user belongs to.
Implementing ISO/IEC 27001 in your company?
Modulario covers most B2B processes modularly — deploy only what you need now and grow gradually. Book a free consultation.
Book a consultation