Phone: 0 (552) 380 25 25  |  Weekdays 10:00–18:00 · Technical support 24/7

🇹🇷 TR

Digital Bridge Blog

Cyber Security & Compliance

ISO 27001 Certification for SMEs: What the Standard Requires, the Steps to Certification and the Link to KVKK

ISO 27001 certification for SMEs explained: the ISMS, the 93 Annex A controls, eight steps to certification and the KVKK link. Start your gap analysis today.

9 min read  · Digital Bridge Engineering Team
ISO 27001 Certification for SMEs: What the Standard Requires, the Steps to Certification and the Link to KVKK

ISO 27001 (ISO/IEC 27001) is the international standard for managing information security through a risk-based, auditable information security management system (ISMS). For SMEs, ISO 27001 certification means identifying your risks, selecting and implementing suitable controls and improving them continually; an independent certification body then audits the system and, if it is satisfied, issues a certificate valid for three years.

How the ISO 27001 question lands on your desk

Most SMEs do not discover ISO 27001 by choice. It arrives as a line in a large customer's supplier security questionnaire — "Do you hold ISO 27001 certification?" — as a requirement in a tender specification, or as a request from a European buyer to document your security measures alongside a data processing agreement. At that point the company usually has an antivirus licence, a few firewall rules and scattered passwords, but no written framework holding it all together.

That is exactly the question ISO 27001 answers: how do we make information security depend on a system rather than on individuals? The standard does not prescribe any particular product or technology. It asks you to identify your risks, record which control you apply to each and why, and prove that it works.

The cost of staying uncertified and unstructured

The spread of the standard tells you what customers now expect from suppliers. According to the ISO Survey 2024, there were 96,709 valid ISO/IEC 27001 certificates worldwide, covering 179,877 sites. If competitors in your supply chain hold the certificate and all you can offer is "we take security seriously", you can lose points at the bidding stage.

The real cost, however, shows up during an incident. According to ENISA Threat Landscape 2025, ransomware accounted for 81.1% of cybercrime activity targeting EU organisations, and vulnerability exploitation, at 21.3%, remained one of the main routes of initial access. Patch management, backups and access control are precisely the areas ISO 27001 turns into a system.

According to Verizon's 2026 Data Breach Investigations Report, breaches involving a third party rose 60% to reach 48% of all breaches.

That figure explains why customers scrutinise supplier security. In the EU, entities covered by the NIS2 Directive must send an early warning within 24 hours of becoming aware of a significant incident and an incident notification within 72 hours (European Commission NIS2 FAQs). Türkiye is not directly subject to NIS2, but a Turkish supplier serving European customers often finds those obligations passed down through contracts. We list the concrete clauses in NIS2 requirements for suppliers.

How ISO 27001 is structured: clauses and Annex A controls

The current edition is ISO/IEC 27001:2022; the transition period from the 2013 edition ended in October 2025. The standard has two parts:

  • Clauses 4–10 (management system requirements): organisational context and scope, leadership, risk assessment and the risk treatment plan, resources and awareness, operation, performance evaluation (internal audit and management review) and improvement. These clauses are mandatory and cannot be excluded.
  • Annex A (the control set): 93 controls grouped into four themes. Which controls apply is decided through risk assessment and recorded, with justification, in the Statement of Applicability.
Annex A themeControlsExamples
Organisational37Security policies, asset inventory, supplier relationships, incident management, business continuity
People8Pre-employment screening, awareness training, leaver process, remote working
Physical14Secure areas, physical entry control, equipment protection, clear desk
Technological34Access rights, authentication, malware protection, backup, logging, secure development

The table shows that the standard is not only about the server room. Supplier contracts, closing a leaver's access and who enters the building are all within scope of the audit. We explain what the authentication controls mean in practice in multi-factor authentication for business, and how physical entry control applies to critical areas in data centre access control.

The ISO 27001 certification process in eight steps

For a company of SME size, a realistic roadmap looks like this:

  1. Define the scope. The whole company, only the software development unit, or one specific service? A narrow, clear scope speeds up the first certification; make sure the service your customer cares about is inside it.
  2. Build the asset inventory. Information assets (customer data, source code, contracts), systems, devices, suppliers and their owners. If you already have a personal data inventory, start from there.
  3. Carry out a risk assessment. For each asset, score threats, vulnerabilities, likelihood and impact. The method can be simple, but it must be consistent and repeatable.
  4. Prepare the risk treatment plan and Statement of Applicability. Record which risks you will reduce, accept or transfer, and which Annex A controls you have chosen and why.
  5. Implement the controls. Policies, access rights, MFA, backups and restore tests, logging, supplier assessment, awareness training. A control that produces no evidence counts for nothing at audit.
  6. Run an internal audit and management review. Audit the system yourselves, close the findings and minute the top management review.
  7. Undergo the certification audit. An accredited certification body first reviews your documentation (Stage 1) and then assesses implementation on site (Stage 2). In Türkiye, check the body's accreditation through TÜRKAK, the national accreditation agency, or another recognised accreditation body.
  8. Maintain it. The certificate is valid for three years, with surveillance audits in between and recertification at the end of the third year.

A common mistake is treating certification as a documentation project. Auditors look for evidence rather than policy binders: the record of your last backup restore test, the date a leaver's accounts were closed, how the findings from your last penetration test were resolved. To turn backups into hard evidence, see our guide to backup restore testing.

ISO 27001 and KVKK: not the same thing, but pointing the same way

Article 12 of KVKK, Türkiye's personal data protection law, requires data controllers to take "all necessary technical and administrative measures" to ensure an appropriate level of security and prevent unlawful processing of or access to personal data. ISO 27001 is a strong way to put those measures in place systematically and document them. However, an ISO 27001 certificate does not equal KVKK compliance. Duties such as privacy notices, lawful bases for processing, a data retention and disposal policy and breach notification must be met separately; we explain how to run both workstreams together in KVKK compliance steps.

ISO 27001 certification for SMEs: is it necessary?

There is no general legal requirement; the decision is commercial and risk-based. Broadly, the certificate becomes a real advantage or a hard requirement when you provide software, cloud or data processing services to corporate or overseas customers, when tenders ask for an ISMS, or when customer data sits in your systems. If none of these applies, it makes sense to use ISO 27001 as a framework and put the basic controls in place before pursuing certification. Our SME cyber security checklist is a good first pass.

Ask the same question when you choose a software or IT supplier: does their certificate's scope cover the service you are buying? We list the other points to check in choosing a software company. If the supplier processes your data abroad, a certificate alone is not enough; build the KVKK rules on cross-border data transfer into the contract as well.

How Digital Bridge helps you prepare for ISO 27001

We do not certify organisations; that is the job of independent, accredited bodies. We work on the other side, making a significant share of the controls an auditor will look at genuinely work and producing the evidence for them:

  • Finding and closing technical vulnerabilities. Through our cyber security consultancy, we carry out penetration testing and vulnerability scanning against a scope agreed in writing. We rank the findings by risk, report a remediation step for each and, if you wish, retest after the fixes. That report and the closure records are evidence that technical vulnerability management is working.
  • Awareness training. Phishing simulations, social engineering examples and an incident reporting procedure give Annex A's people controls real substance.
  • Inventory and the KVKK side. Our data protection compliance work covers a gap analysis, the personal data inventory, access logging, a permission matrix and a breach response plan. That inventory gives the ISMS asset inventory a solid starting point. For data ownership and approval workflows for access requests we draw on our data governance and quality work. We explain the principles for organising file sharing permissions in our guide to file sharing permissions.
  • Prioritisation and roadmap. We tie security investments, alongside your other technology projects, into a digital transformation consultancy roadmap that shows which step to take in which order.

For physical security controls, our own product SmartPass produces the kind of evidence auditors ask for: who may enter which zone is defined in plain-language rules, every change is written to an audit trail with its old and new value, and the auditor role sees records read-only. For email and files, Smart360 provides department-based permissions and closes a leaver's access in a single action.

Next step

Your first step needs no certificate: collect the security questionnaires and tender requirements you received from customers in the past six months and mark the questions you could not answer. That list largely defines your scope and priorities. Then get in touch and we will run the gap analysis with you. For more guides, visit our Cyber Security & Compliance hub.

Let us look at your case

Tell us about your process; after a needs analysis we send a written proposal with scope, phases and cost.

Request a Quote +90 552 380 25 25
Questions we hear most often

Frequently Asked Questions

Is ISO 27001 certification mandatory?

In Türkiye there is no general legal requirement for private companies to hold it. Certification usually comes up because of customer demands, tender conditions or contracts with overseas buyers, and firms serving the public sector or critical infrastructure may face additional security requirements. Even when it is not mandatory, using the standard as a framework makes security work orderly and auditable.

How long is an ISO 27001 certificate valid?

The certificate is valid for three years. During that period the certification body checks that the system is still working through surveillance audits, usually held once a year. At the end of the third year a recertification audit takes place. If a surveillance audit finds a major nonconformity that is not corrected, the certificate can be suspended, so the system has to live in day-to-day operations.

Does ISO 27001 certification make us KVKK compliant?

Not on its own. ISO 27001 systematically covers many of the technical and administrative security measures that KVKK requires. However, duties such as privacy notices, lawful bases for processing, explicit consent, the retention and disposal policy, VERBIS registration and breach notification must be handled separately. The most efficient approach is to run both workstreams on the same inventory.

Who issues ISO 27001 certificates?

Certificates are issued by accredited certification bodies, not by consultancies. The body first reviews your documentation (Stage 1) and then assesses on site how the controls actually work (Stage 2). Before requesting quotes, verify the body's ISO 27001 accreditation through TÜRKAK, Türkiye's national accreditation agency, or another recognised accreditation body. Also check that the certificate's scope statement names the service your customer is asking about.

What does ISO 27001 certification cost depend on?

The main cost drivers are the breadth of the scope, the number of employees and locations within it, the maturity of your existing controls and how much outside preparation support you use. The certification body's audit time is also largely calculated from scope and headcount. Starting with a narrow, clear scope therefore reduces both audit time and the internal preparation workload, and a gap analysis is the first step towards a realistic budget.

What is the difference between ISO 27001 and ISO 27002?

ISO 27001 is the requirements standard you are certified against: it defines what the management system must do and contains the Annex A control list. ISO 27002 is a guidance standard explaining how to implement those controls, and you cannot be certified to it. Drawing on ISO 27002 when designing controls makes it easier to understand what an auditor will expect.

Can a small company get ISO 27001 certified?

Yes. The standard scales with risk rather than company size, so a small firm can have shorter policies and simpler processes. What matters is a clear scope, a consistent risk assessment and evidence for every control. Starting with a scope limited to one service or unit makes the first certification far more manageable.

Have a different question? Ask Us

Talk to an Engineer

Tell us what you need to solve. We'll come back with a written proposal.