ISO 27001 (ISO/IEC 27001) is the international standard for managing information security through a risk-based, auditable information security management system (ISMS). For SMEs, ISO 27001 certification means identifying your risks, selecting and implementing suitable controls and improving them continually; an independent certification body then audits the system and, if it is satisfied, issues a certificate valid for three years.
How the ISO 27001 question lands on your desk
Most SMEs do not discover ISO 27001 by choice. It arrives as a line in a large customer's supplier security questionnaire — "Do you hold ISO 27001 certification?" — as a requirement in a tender specification, or as a request from a European buyer to document your security measures alongside a data processing agreement. At that point the company usually has an antivirus licence, a few firewall rules and scattered passwords, but no written framework holding it all together.
That is exactly the question ISO 27001 answers: how do we make information security depend on a system rather than on individuals? The standard does not prescribe any particular product or technology. It asks you to identify your risks, record which control you apply to each and why, and prove that it works.
The cost of staying uncertified and unstructured
The spread of the standard tells you what customers now expect from suppliers. According to the ISO Survey 2024, there were 96,709 valid ISO/IEC 27001 certificates worldwide, covering 179,877 sites. If competitors in your supply chain hold the certificate and all you can offer is "we take security seriously", you can lose points at the bidding stage.
The real cost, however, shows up during an incident. According to ENISA Threat Landscape 2025, ransomware accounted for 81.1% of cybercrime activity targeting EU organisations, and vulnerability exploitation, at 21.3%, remained one of the main routes of initial access. Patch management, backups and access control are precisely the areas ISO 27001 turns into a system.
According to Verizon's 2026 Data Breach Investigations Report, breaches involving a third party rose 60% to reach 48% of all breaches.
That figure explains why customers scrutinise supplier security. In the EU, entities covered by the NIS2 Directive must send an early warning within 24 hours of becoming aware of a significant incident and an incident notification within 72 hours (European Commission NIS2 FAQs). Türkiye is not directly subject to NIS2, but a Turkish supplier serving European customers often finds those obligations passed down through contracts. We list the concrete clauses in NIS2 requirements for suppliers.
How ISO 27001 is structured: clauses and Annex A controls
The current edition is ISO/IEC 27001:2022; the transition period from the 2013 edition ended in October 2025. The standard has two parts:
- Clauses 4–10 (management system requirements): organisational context and scope, leadership, risk assessment and the risk treatment plan, resources and awareness, operation, performance evaluation (internal audit and management review) and improvement. These clauses are mandatory and cannot be excluded.
- Annex A (the control set): 93 controls grouped into four themes. Which controls apply is decided through risk assessment and recorded, with justification, in the Statement of Applicability.
| Annex A theme | Controls | Examples |
|---|---|---|
| Organisational | 37 | Security policies, asset inventory, supplier relationships, incident management, business continuity |
| People | 8 | Pre-employment screening, awareness training, leaver process, remote working |
| Physical | 14 | Secure areas, physical entry control, equipment protection, clear desk |
| Technological | 34 | Access rights, authentication, malware protection, backup, logging, secure development |
The table shows that the standard is not only about the server room. Supplier contracts, closing a leaver's access and who enters the building are all within scope of the audit. We explain what the authentication controls mean in practice in multi-factor authentication for business, and how physical entry control applies to critical areas in data centre access control.
The ISO 27001 certification process in eight steps
For a company of SME size, a realistic roadmap looks like this:
- Define the scope. The whole company, only the software development unit, or one specific service? A narrow, clear scope speeds up the first certification; make sure the service your customer cares about is inside it.
- Build the asset inventory. Information assets (customer data, source code, contracts), systems, devices, suppliers and their owners. If you already have a personal data inventory, start from there.
- Carry out a risk assessment. For each asset, score threats, vulnerabilities, likelihood and impact. The method can be simple, but it must be consistent and repeatable.
- Prepare the risk treatment plan and Statement of Applicability. Record which risks you will reduce, accept or transfer, and which Annex A controls you have chosen and why.
- Implement the controls. Policies, access rights, MFA, backups and restore tests, logging, supplier assessment, awareness training. A control that produces no evidence counts for nothing at audit.
- Run an internal audit and management review. Audit the system yourselves, close the findings and minute the top management review.
- Undergo the certification audit. An accredited certification body first reviews your documentation (Stage 1) and then assesses implementation on site (Stage 2). In Türkiye, check the body's accreditation through TÜRKAK, the national accreditation agency, or another recognised accreditation body.
- Maintain it. The certificate is valid for three years, with surveillance audits in between and recertification at the end of the third year.
A common mistake is treating certification as a documentation project. Auditors look for evidence rather than policy binders: the record of your last backup restore test, the date a leaver's accounts were closed, how the findings from your last penetration test were resolved. To turn backups into hard evidence, see our guide to backup restore testing.
ISO 27001 and KVKK: not the same thing, but pointing the same way
Article 12 of KVKK, Türkiye's personal data protection law, requires data controllers to take "all necessary technical and administrative measures" to ensure an appropriate level of security and prevent unlawful processing of or access to personal data. ISO 27001 is a strong way to put those measures in place systematically and document them. However, an ISO 27001 certificate does not equal KVKK compliance. Duties such as privacy notices, lawful bases for processing, a data retention and disposal policy and breach notification must be met separately; we explain how to run both workstreams together in KVKK compliance steps.
ISO 27001 certification for SMEs: is it necessary?
There is no general legal requirement; the decision is commercial and risk-based. Broadly, the certificate becomes a real advantage or a hard requirement when you provide software, cloud or data processing services to corporate or overseas customers, when tenders ask for an ISMS, or when customer data sits in your systems. If none of these applies, it makes sense to use ISO 27001 as a framework and put the basic controls in place before pursuing certification. Our SME cyber security checklist is a good first pass.
Ask the same question when you choose a software or IT supplier: does their certificate's scope cover the service you are buying? We list the other points to check in choosing a software company. If the supplier processes your data abroad, a certificate alone is not enough; build the KVKK rules on cross-border data transfer into the contract as well.
How Digital Bridge helps you prepare for ISO 27001
We do not certify organisations; that is the job of independent, accredited bodies. We work on the other side, making a significant share of the controls an auditor will look at genuinely work and producing the evidence for them:
- Finding and closing technical vulnerabilities. Through our cyber security consultancy, we carry out penetration testing and vulnerability scanning against a scope agreed in writing. We rank the findings by risk, report a remediation step for each and, if you wish, retest after the fixes. That report and the closure records are evidence that technical vulnerability management is working.
- Awareness training. Phishing simulations, social engineering examples and an incident reporting procedure give Annex A's people controls real substance.
- Inventory and the KVKK side. Our data protection compliance work covers a gap analysis, the personal data inventory, access logging, a permission matrix and a breach response plan. That inventory gives the ISMS asset inventory a solid starting point. For data ownership and approval workflows for access requests we draw on our data governance and quality work. We explain the principles for organising file sharing permissions in our guide to file sharing permissions.
- Prioritisation and roadmap. We tie security investments, alongside your other technology projects, into a digital transformation consultancy roadmap that shows which step to take in which order.
For physical security controls, our own product SmartPass produces the kind of evidence auditors ask for: who may enter which zone is defined in plain-language rules, every change is written to an audit trail with its old and new value, and the auditor role sees records read-only. For email and files, Smart360 provides department-based permissions and closes a leaver's access in a single action.
Next step
Your first step needs no certificate: collect the security questionnaires and tender requirements you received from customers in the past six months and mark the questions you could not answer. That list largely defines your scope and priorities. Then get in touch and we will run the gap analysis with you. For more guides, visit our Cyber Security & Compliance hub.