1. Home
  2. Blog

ISO 27001 consulting: where should an SMB start?

Blog post 4 min read

This article is also available in: TürkçeDeutsch

ISO 27001 consulting: where should an SMB start?

An ISO 27001 certificate is not a software licence. ISO/IEC 27001:2022 is a standard that asks you to manage information security in a regular way.

When a customer or a tender asks "do you have an ISO 27001 certificate?", what they are asking you to buy is not a software licence. ISO/IEC 27001:2022 is a standard that asks you to manage information security in a regular way.

As of September 2026, this is the current edition. It stands in the ISO catalogue as a published standard; the 2013 edition has been withdrawn. A small amendment from 2024, ISO/IEC 27001:2022/Amd 1:2024, asks whether climate change is a relevant issue for the organisation. That amendment does not replace the 2022 edition. No newer year-edition has been published either.

What an ISMS is, and what it is not

The structure the standard sets up is an information security management system, ISMS for short. You write the scope, assess the risks, choose the measures and review them at set intervals. Being audited once and putting the folder back on the shelf is not this system.

ISO 27001 is not a product either. Buying a firewall, backup software or protection against malware does not meet the standard. Those tools can be useful. The standard asks which one you chose, why, and whether you actually operate it.

Getting a certificate is not compulsory either. Some companies set the system up only to put their house in order. Others want a certificate to show a customer or a tender. Those are two separate decisions.

What does the company actually do?

The work splits into four parts:

  1. Scope: which site, which system and which information is inside this work.
  2. Risk assessment: where a loss of confidentiality, integrity or availability would stop the business.
  3. Statement of Applicability: a reasoned list of the controls you selected and the ones you did not. Contracts often use this English name.
  4. Policies and daily work: short rules that are actually followed, such as access, backup, and who is called when an incident happens.

Annex A is a menu of controls. In the 2022 edition, 93 controls are grouped into four themes: organizational, people, physical and technological. You do not have to apply all of them. A control that does not fit your risk is left out, and the reason is written in the Statement of Applicability. You can also add a measure that is not on the list. The menu does not replace your list.

Annex A is not a list you tick from top to bottom. It is a menu you choose from according to your risk.

Who issues the certificate?

The certificate is issued by a certification body whose authority is recognised by an independent accreditation body. The consultant is not that organisation. Consulting helps you make the scope clear, write down the risk and put the remaining work in order. A consultant cannot issue the certificate.

Doğa Network provides ISO 27001 consulting. We do not certify you, and we do not take the place of the certification body. The decision to seek a certificate stays with you. For most small teams, a calmer sequence is to build the system first and leave the certificate date until the other party actually asks.

Who is it for?

If a contract or a tender asks for an information security management system, or for ISO 27001 by name, scattered notes become a hard answer. An ISMS answers that question under one roof.

There is also an overlap with personal data. Turkish Law No. 6698 on the Protection of Personal Data (KVKK) treats the protection of personal data as a separate legal obligation. ISO 27001 builds a system for managing information security. Personal data can be part of that information, which is why the two subjects sit side by side. One does not replace the other. This article is not legal advice. For your obligations under the KVKK, ask your own legal adviser.

Where should you start?

Four questions are enough, before any certificate calendar:

  1. Which information and which systems should really be in scope?
  2. Is the other party asking for a certificate, or asking whether you manage security?
  3. Where do access, backup and the incident record sit today, and with whom?
  4. Who owns this work, and who looks after it when that person is away?

If the answers do not fit on a short page, the scope is not clear yet. Starting there wastes less time than filling in ready-made policy texts.

How can Doğa Network help?

Our team can help you clarify the scope, carry out the risk assessment and prepare the Statement of Applicability. We do not take the place of the certification body. Call us on +90 850 888 3642 or email hi@doga.network.

#ISO 27001#ISMS#SMB#information security#ISO/IEC 27001:2022
Newsletter

Hear about critical vulnerabilities first.

Get our security advisories, practical guides and announcements by email. A few emails a month, no advertising.

Which topics would you like to hear about?