Who is ISO 27001 relevant to?
ISO/IEC 27001:2022 can be used by organisations of different sizes and in different sectors. A customer request, tender or need for systematic risk management may prompt its adoption. Certification and applying the standard are separate choices. See the official ISO explanation.
When a customer asks for evidence, first record what they require, for which service and within which scope. A supplier’s certificate does not automatically cover your own processes. An ISO 27001 certificate also does not mean that all privacy or sector-specific obligations have been met.
What steps are involved?
- Scope and starting point: define services, locations, systems and the parties involved. Conduct a gap analysis and appoint a project owner.
- Risks and decisions: assess information security risks, plan their treatment and justify which controls apply.
- Implementation: adapt policies, allocate tasks, train staff and put controls into practice.
- Checking: gather evidence, carry out internal audits and a management review, and follow up nonconformities.
- Certification and ongoing management: have the system independently assessed, then keep risks, evidence and improvement actions up to date.
Read the detailed ISO 27001 roadmap for the outputs at each stage. Agree the external audit procedure and schedule with the chosen body.
Which documents and evidence should you prepare?
Use one overview covering scope, information security policy, risk assessment, treatment plan, Statement of Applicability, responsibilities and improvement actions. Include the internal audit and management review.
A document describes the arrangement; evidence shows what happens. Examples include a completed access review, a recovery test, a supplier assessment and the follow-up of an incident. Link evidence to its owner, date and relevant control. The ISO 27001 checklist helps you prepare; it does not replace the standard itself.
Three ways DCA can help
Choose support that fits your starting point. We agree the scope, allocation of responsibilities and deliverables in advance. Your management remains responsible for decisions, risks and implementation within the organisation.
Implementation: from your starting point to an effective ISMS
DCA helps with scope, gap analysis, risk assessment, the treatment plan and adapting policies and documents. We map responsibilities and support preparation for assessment. This helps you work towards an established management system with tasks, owners, decisions and evidence.
What you do: provide process knowledge and existing documentation, establish scope and risk decisions, allocate resources and implement agreed controls. The division of responsibilities determines which work DCA takes on.
Explore the implementation support or read how VORM organised risks, responsibilities and documentation with DCA.
Internal audit: assess, report and follow up
We agree the audit objective, scope, assessment criteria, roles and reporting arrangements in advance. You provide relevant documents, previous findings and evidence, and ensure the people involved are available. A Compliance Officer examines the documentation, speaks to those involved and assesses whether arrangements and controls are demonstrably implemented.
What you receive: a report with findings and areas for improvement, in the Compliance Tool or as a standalone report, as agreed. You appoint owners, implement improvements and record evidence of follow-up. We agree what support DCA will provide.
Even when DCA has been involved in implementation, a Compliance Officer assesses the agreed subject without approving their own work. We record the division of responsibilities in advance to safeguard objectivity and impartiality. The internal audit does not provide a certificate; for certification, the certification body makes the external certification decision independently. Read more about our audit approach.
Compliance Tool: maintain oversight between audits
The Compliance Tool brings requirements, risks, controls, tasks, documents and evidence together. You record responsibilities and deadlines, schedule audits and follow up findings and improvement actions. This makes it clear who needs to do what and where the supporting evidence is held.
What DCA provides: the software and the agreed support for its use. What you do: keep information current, assess risks, carry out tasks and substantiate improvements. The Tool organises the work; decisions and implementation remain with your organisation. Software or support alone is not a certificate.
Explore the features of the Compliance Tool or see them in a demo.
Our own ISO 27001 certification
The information security management system of De Compliance Afdeling is certified to ISO/IEC 27001:2022 by EIK Certificering, under RvA accreditation C669.
Certificate EIK417.01 states a validity period of 30 December 2025 to 30 December 2028. It covers our management system within the stated scope for software development and compliance consultancy.
For our own information security, this means that the management system has been independently assessed against the standard’s requirements. Certification concerns how we organise, assess and improve information security; it does not guarantee that incidents will never occur.
Download our ISO 27001 certificate (PDF, in Dutch) · Check DCA in the EIK register
EIK is the accredited certification body. This does not make DCA an accredited organisation, the Compliance Tool is not certified as a standalone product and our customers are not automatically certified. View the full certificate details and scope.
View our certification and registrations in the Trust Center →
Costs, internal time and planning
Distinguish between software, support, internal time, any technical measures and the independent external audit. Implementation support starts at 4 hours per week at €120 per hour: an average of €2,080 per month, excluding VAT. The software licence and external certification costs are separate. View current prices and calculate the division of work.
There is no fixed number of internal hours or guaranteed lead time. Allocate time for the project owner, management, IT, HR and relevant process owners. Scope, existing controls, missing evidence and auditor availability determine the schedule. Turn the initial discussion into a work plan with tasks, owners and review points.
From preparation to a practical decision
Just getting started? The Compliance Scan helps you discuss your starting point and priorities. Also explore the cost breakdown for ISO 27001 certification. If you work with healthcare information, also assess the applicability of NEN 7510.
Frequently asked questions about ISO 27001
Is DCA itself ISO 27001 certified?+
Yes. The information security management system of De Compliance Afdeling is certified to ISO/IEC 27001:2022 by EIK Certificering, under RvA accreditation C669. Certificate EIK417.01 states a validity period from 30 December 2025 to 30 December 2028. EIK is the accredited body; this does not make DCA an accredited organisation.
Where can I check the certificate?+
View our certificate (PDF, in Dutch) for its number, scope and dates, and check the DCA entry in the EIK certification register. EIK’s accreditation and scope are listed in the RvA register under C669.
What does DCA’s certification scope cover?+
Our certificate states the following scope, translated from Dutch: “The development, delivery, maintenance and support of software development and consultancy for compliance matters.” The certificate covers the information security management system within that scope.
What does our certification mean for the Compliance Tool?+
Development, delivery, maintenance and support within the stated scope fall under our certified management system. This does not certify the Compliance Tool as a standalone product. Using the Tool does not automatically certify your organisation.
How do implementation, internal auditing and external certification differ?+
Implementation establishes the management system. An internal audit assesses, within the agreed scope, how the system and controls work and what improvements are needed. For accredited certification, a certification body accredited for that purpose assesses your management system and makes the certification decision independently. The internal audit and implementation support do not themselves result in a certificate.
Can DCA also issue certificates itself?+
Alongside software, implementation support and internal audits, DCA describes a separate offering of certification without accreditation. This differs both from a certificate issued to you by an accredited certification body and from DCA’s own certificate issued by EIK under accreditation. Agree in advance what evidence your client requires.
Does ISO 27001 certification mean an organisation is secure?+
A certificate covers the assessed management system and its stated scope. It does not guarantee that incidents will never occur. Ongoing monitoring and improvement are part of the approach.
How much does our organisation need to do itself?+
You remain responsible for management decisions, process knowledge and implementing agreed controls. During the initial discussion, we agree task by task what you will do and what DCA will handle.
Official sources
Sources consulted on 19 September 2026. Use the current standard or scheme requirements for implementation.
