What Is ISO 27001?
TL;DR
ISO 27001, formally ISO/IEC 27001, is the international standard for an information security management system. Unlike SOC 2 it produces a genuine certification: an accredited certification body audits the management system and issues a certificate valid for three years, with surveillance audits in the intervening years.
What does ISO 27001 actually certify?
The management system rather than the product. What gets audited is the process by which an organisation identifies information security risks, selects controls to address them, and reviews whether those controls work. A certificate says that process exists and functions, not that a particular feature is secure.
Annex A of the 2022 revision lists 93 controls across four themes: 37 organisational, 8 people, 14 physical and 34 technological. An organisation is not expected to implement all 93. It selects them by risk and records both the selections and the exclusions with justifications in a Statement of Applicability, which is why the scope and that statement tell a reader more than the certificate does.
How does the certification cycle work?
Initial certification runs in two stages, a documentation review followed by a full audit of the system in operation. The certificate that results is valid for three years. Surveillance audits in the intervening years sample controls to confirm the system is still working, and a full recertification audit takes place before the certificate expires.
Versions matter when reading a certificate. Certificates issued against the 2013 edition had to transition to ISO/IEC 27001:2022 by 31 October 2025, so a certificate still citing the older edition is out of date rather than merely old.
Should a vendor review ask for ISO 27001 or SOC 2?
They produce different artefacts and answer slightly different questions. ISO 27001 gives a certificate plus a scope statement and a Statement of Applicability, evidence that a management system is running. SOC 2 gives an auditor opinion on described controls over a period, including any exceptions found. Buyers with a preference usually have it for regional reasons rather than technical ones.
Neither is a statement that a vendor cannot be breached, and neither is a substitute for reading what a vendor says about its own handling of your data. What JaxSuite AI documents on that front is on the security page, phrased as what can be shown rather than in badge names. This entry describes an industry standard in plain language and is not audit or legal advice.
Frequently asked questions
Only what the scope statement says. Scope can be limited to one product, one site or one platform, so a certificate presented without its scope statement cannot be interpreted. Ask for both together.