What is ISO 27001, and why do customers ask about it?

ISO 27001 is an international standard that describes how to set up the kind of security system I explained on the previous page. Many businesses get asked about it by their customers, even when they are not obliged to do anything themselves. This page explains what the standard is and why the question comes up.

← Cybersecurity in plain language

A standard is a shared agreement

A standard is a document in which experts from around the world set out how to do something well. ISO 27001 does that for information security.

When they hear ISO 27001, many business owners think of a long list of rules someone else came up with. That is not how the standard works. It describes how you set up the system: starting from what is at stake for you, making agreements, following up and adjusting. It does come with a list of possible measures. You go through that list and record which ones you take, which ones you do not, and why.

Enough, and not too much

Because the standard starts from your own business, a transport company with ten employees ends up with different measures from a software company with eighty.

That is exactly why it works. You do enough to have the security your business needs, but not too much either. Businesses that start without a framework often go wrong in one of two directions: they do too little, or they spend a lot of money on measures that deliver little.

Too littleLess than your business needs
EnoughThe security your business needs
Too muchLots of money, measures that deliver little
Two ways to go wrong, one to aim for

Even businesses outside NIS2 get the question

NIS2 is a European law on cybersecurity. It applies to organisations that keep society and the economy running, in sectors such as energy, transport and healthcare, and to a number of other sectors. Many businesses do not fall under it themselves.

Yet they still get the question.

An organisation that falls under NIS2 also has to manage the security of its suppliers. So it looks at who has access to its systems, who processes its data and who could bring its operations to a halt. And it asks those parties which measures they have taken. If you do not fall under NIS2 yourself, there is a real chance that at least one of your customers does.

1Your customerFalls under NIS2
2Checks suppliersAccess, data, operations
3Asks youWhich measures have you taken?
When one of your customers falls under NIS2

You can answer that question by filling in a (long) questionnaire every time. Or you can point to a system that follows a recognised standard. If you have your system checked by an independent, officially accredited organisation, you receive an ISO 27001 certificate. That is not mandatory, but it is the proof customers recognise most quickly, in Belgium and abroad.

In Belgium, an organisation that falls under NIS2 itself can demonstrate its measures through ISO 27001 or through CyFun, the Belgian framework of the Centre for Cybersecurity Belgium.

Next: Who decides on cybersecurity?