ISO 27001 Certification
At Noordbeek we have been certifying since 2005. Accredited by the Dutch Council for Accreditation under registration number C663. What that means in plain language. Our certificate is recognised worldwide and your client cannot dismiss it. No small print. No surprises afterwards. Short lines of communication and a fixed point of contact.
Call us directly on +31 71 341 69 11 or request a tailored quote.
Why ISO 27001 certification is suddenly appearing everywhere
A few years ago still a nice-to-have. Now it appears in practically every serious tender above two hundred thousand euros. Healthcare requires it through NEN 7510. The Dutch central government through DigiD assessments. Banks through their supplier policies. And since NIS2 a whole group of medium-sized businesses has been added that never had to deal with it before.
What we see most often? Companies that start too late. Someone calls in a panic. A tender is on the table. The certificate is missing. The deadline is ticking. At that point you are not going to certify in three months. At that point you simply lose the contract.
Or maybe this sounds familiar to you:
A major client suddenly asks for an ISO 27001 certificate. Otherwise the contract will not go through. You already have a lot in order. Policies. Procedures. A GDPR mapping. But whether that is enough for the standard? No idea. You requested three quotes and the prices range from 4,000 to 18,000 euros. What is going on here? Everyone says something different about what you need as a minimum.
We help you with exactly that. Not vaguely. Not in general terms. Very concretely.
What exactly is ISO 27001? Without the jargon
ISO 27001 is the international standard for information security. Full name? ISO/IEC 27001:2022. The European version is NEN-EN-ISO/IEC 27001:2023 + A1:2024. That A1 from 2024 is new and adds climate risks. Think: overheated server rooms. Water damage in a basement where your backups are stored. The kind of things nobody thinks about until something goes wrong.
The standard essentially says this. You set up an ISMS, which stands for Information Security Management System. You identify what can go wrong with your data. You do something about it. And you check whether it works. Sounds straightforward. In practice there is a bit more to it.
With your certificate you prove two things at once:
You know what can go wrong with data belonging to clients, employees and partners. You do something about it. And you keep it up. Not an annual ritual but a living system.
What is the difference between ISO 27001 and ISO 27002?
This comes up more often than you would think. People confusing ISO 27001 and ISO 27002. A quick breakdown:
ISO 27001 is the standard you actually certify against. ISO 27002 is a kind of accompanying handbook that explains how to implement the measures from Annex A of 27001 in practice. You cannot certify against 27002.
Simple rule of thumb. 27001 says what. 27002 says how.
Who can realistically get ISO 27001 certification?
Honest answer. Any organisation that regularly works with other people's data. Our clients range from 5 employees to well over 5,000. The main sectors we certify for:
IT companies and SaaS providers Financial service providers and accounting firms Healthcare institutions, almost always combined with NEN 7510 Municipalities, government ministries and executive agencies Consultancies and advisors Logistics and industry
For small and medium-sized businesses it often turns out to be easier than they expected. We regularly see organisations of 12 to 30 people achieve certification because an important client asked for it. Not because they suddenly want to show off about information security. Very pragmatic.
Who is it less suitable for? Sole traders without staff. Companies that process zero client data. And organisations so unstable that an ISMS changes faster than you can document it. We say that honestly in the intake. We do not send anyone in at the deep end without reason.
What does an ISO 27001 certificate actually get you?
Not the standard marketing talk. We mention what our clients literally tell us after their certification.
Nights where you sleep better. A ransomware attack can cost up to 1.5 million euros per incident. Certification costs a fraction of that. Do the maths yourself.
GDPR that suddenly falls into place. A large part of what data protection authorities require from you is already covered by ISO 27001. Two birds with one stone.
NIS2 that clicks into place. Many clients get ISO 27001 to comply with NIS2. The directive does not explicitly prescribe it but covers 80 to 90 percent of the requirements. Considerably cheaper than two separate processes.
A certificate recognised everywhere. Through RvA accreditation our logo is on your certificate and it is valid in 70-plus countries. No complications with international clients.
ISO 27001 certification process in 5 steps
We work predictably. No unexpected invoices. No vague follow-up steps. Here is the route:
Step 1 - Intake No obligation. We go through what you want to certify, which is the scope, how many people you have and what your organisation looks like. Based on that we draw up a quote. This conversation usually takes about an hour. Sometimes three quarters of an hour if you are well prepared.
Step 2 - Audit phase 1 Document review. An auditor reads your policies, procedures, risk analysis and statement of applicability. He comes back with a report. It states what you still need to do before you are ready for phase 2.
Step 3 - Audit phase 2 The practice. The auditor comes to your office or works remotely. He talks to people. Reviews systems. Checks whether the practice matches what you have written down. The question is always: does it actually happen the way you claim?
Step 4 - Certification committee Three senior auditors assess the report independently. So an auditor can never decide alone that you receive a certificate. That keeps the quality high and the value of our logo intact.
Step 5 - The certificate Valid for three years. Followed by recertification. In between, an annual lighter surveillance audit. Not to bother you. But to establish that the system is still alive.
ISO 27001: do it yourself or outsource?
A question we get every week. Our answer. The implementation you can partly do yourself. The certification never.
Many organisations set up the ISMS themselves. With an internal project manager or an IT coordinator who studies the standard in their spare time. For the risk analysis and gap assessment they bring in a consultant. We conduct the certification audit.
Important to know. A certification body is never allowed to both advise and certify you. Otherwise you are your own examiner. So we only certify. For advice we refer you elsewhere or work together with independent consultants.
Why choose Noordbeek?
We are deliberately not a huge firm. No client who sees a different name at the table every year. No audits via a foreign hub. What we are:
RvA accreditation C663. Internationally recognised. Verifiable. No "well that is a different body". Auditors with sector experience. Our SaaS auditor worked in software for years. The healthcare auditor knows NEN 7510 inside and out. No junior with a checklist. Independent certification committee. Three senior auditors per file. One person can never decide alone. Fixed point of contact. You speak to a real person. No call centre. No ticket system. Clear quotes. You know the amount upfront. No "we will invoice the rest after scope determination".
Frequently asked questions about ISO 27001 certification
How long does an ISO 27001 certification process take in practice?
Count on three to six months from the intake if you already have a reasonable foundation in place. Have nothing? Then you are looking at closer to six to nine months of preparation before an audit makes sense. A good gap analysis upfront genuinely saves you time. We regularly see clients who in that preparation phase do 30 to 40 percent more than strictly necessary because they are double-checking everything just to be sure. That is not needed. That is what we are here for.
What does ISO 27001 certification cost for a small or medium-sized business?
Costs are largely determined by your number of FTEs and the scope of your certification. Not by our own discretion but by ISO 27006. That is the guideline all accredited certification bodies must comply with. For a small or medium-sized organisation of around 30 FTEs you are looking at 4,500 to 8,000 euros for the first certification. On top of that a lower annual amount for the surveillance audits. For an exact figure tailored to your situation, request a quote.
Is ISO 27001 mandatory for my company?
Legally not for most companies. In practice yes if you work for banks, healthcare bodies, government or large multinationals. Since NIS2 a whole group of medium-sized businesses has been added. Quick test. Have you seen a tender in the past twelve months where ISO 27001 was a requirement? Then it is practically mandatory for you too.
ISO 27001 for NIS2: does it cover everything?
Not entirely but close. NIS2 does not prescribe a specific standard. The directive does require a structured approach to information security. ISO 27001 covers 80 to 90 percent of the NIS2 requirements. For the rest you need to arrange something specific around incident reporting to the government and specific supply chain risks. Many clients therefore choose ISO 27001 as a base and build the NIS2-specific elements on top of it.
Can I switch from another certification body?
Yes and it is less hassle than you think. We take over your current certification at no extra cost. You do not go back to square one. You keep your certificate and your surveillance cycle. Only our accreditation is on it from that point forward. Clients switch for various reasons. Poor availability at their current body. Auditors without sector experience. Vague invoices afterwards. Or simply more peace of mind.
What is the difference between ISO 27001 and NEN 7510?
ISO 27001 is the general standard for information security. NEN 7510 is the Dutch healthcare variant. It has additional requirements around patient data and the Dutch law on supplementary provisions for processing personal data in healthcare, known as the Wabvpz. Do you work in healthcare? Then you almost always certify for both. We handle that in a combined process. That saves you time and costs.
How long is an ISO 27001 certificate valid?
Three years. Followed by recertification. In between, an annual surveillance audit. That surveillance audit is a lighter version. Not the entire standard all over again. Spot checks on critical components. Do you lose the certificate if you do not pass an audit? Not immediately. You first get a period to resolve the shortcomings.
What if we do not pass the first audit?
No drama. You receive a list of shortcomings, also called non-conformities. You are given time to resolve them. Then a follow-up check takes place. You only pay for the extra hours. Not an entirely new audit. What we see in practice. Organisations that prepare seriously pass in one go. Almost without exception.
Request a tailored quote
