ISO/IEC 27001 is the international reference standard for an Information Security Management System (ISMS). Increasingly required by customers, in tenders, by cyber insurers, or for access to certain export markets, SYAGA supports you from the gap assessment through to preparation for the certification audit.
ISO 27001 is not a general legal obligation, but it is becoming an unavoidable commercial prerequisite
ISO/IEC 27001 remains a voluntary approach. It is nonetheless increasingly required in tenders, by large customers, by some cyber insurers, or as a prerequisite for access to certain export markets.
The majority of SMEs and mid-sized companies have not undertaken any structured approach to an Information Security Management System. The topic is perceived as complex, technical, and lengthy.
Classic certification engagements tie up your teams for several months and represent a substantial investment, often out of reach for an SME.
Tying up the CIO or the security manager for months to build an ISMS is not viable in an SME where everyone already wears several hats.
A structured approach in 3 phases, based on the same methodology already proven by SYAGA on PSSI-Express
Scoping interview with management and the IT security manager, followed by a systematic assessment of each of the 93 security controls in Annex A (2022 edition), spread across the 4 themes: organizational, people, physical, and technological. Delivery of a factual gap report.
Drafting or updating the security policy (ISMS), the Statement of Applicability (SoA) justifying the application or exclusion of each of the 93 controls, and a prioritized remediation plan to close the gaps identified in phase 1.
Follow-up on the implementation of the remediation plan, documentary review, and preparation of your team for the audit carried out by an independent accredited certification body. SYAGA prepares you for the audit; the certification itself is issued by that third-party body.
The core documents of the ISO 27001 certification file
Factual assessment of your compliance level against the standard.
Central normative document of the ISO 27001 certification file.
The governance document required by clauses 4 to 10 of the standard.
The roadmap to close the identified gaps.
Documents directly applicable by your teams.
All documents in formats you can evolve.
The ISO 27001 ISMS naturally overlaps with several frameworks
Central framework: clauses 4 to 10 (management requirements) and Annex A (93 security controls spread across 4 themes).
The cyber risk management measures required by the NIS2 directive largely overlap with the Annex A controls of ISO 27001. An ISO 27001 ISMS makes NIS2 compliance easier for entities in scope.
The measures in the IT hygiene guide published by ANSSI (the French national cybersecurity agency) overlap significantly with the Annex A controls of ISO 27001. Correspondence documented in the remediation plan.
The appropriate technical and organizational measures required by Article 32 of the GDPR rely on the same good practices as Annex A of ISO 27001 (access control, encryption, incident management).
Every ISO 27001 engagement is scoped according to your perimeter and current maturity level. Always a personalized quote.
Initial snapshot of your gaps
From gap assessment to audit preparation
After certification or on an ongoing basis
What ISO/IEC 27001 really says, explained simply. Each point links to its official source (ISO, AFNOR, COFRAC, ANSSI), updated on 17/07/2026.
ISO/IEC 27001 is a recognized method for identifying the threats to your data, managing the risks, and putting the right protections in place, so that your information stays confidential, available and reliable. It is not software - it is an organization to put in place within the company.
Source: AFNOR CertificationUnlike other approaches (such as the security accreditation imposed on certain State systems), ISO 27001 is optional: it is a certifying standard, not a general regulatory obligation. You choose it to reassure customers, partners and insurers.
Source: ANSSI (method sheet)Never the company itself, nor a consultant: only an independent, accredited certification body can issue it (COFRAC is the sole French accreditation body, created in 1994). The certificate obtained is valid for 3 years.
Source: COFRACPreliminary assessment (optional), preparation, document review, on-site audit to verify what is really in place, issuance of the certificate (3 years), then a surveillance visit every year and a full renewal audit after 3 years. Nothing is set in stone once and for all.
Source: AFNOR CertificationAccording to an AFNOR study of certified companies: 89% observed fewer security incidents, 83% have stronger internal security processes, and 88% retained customers who might otherwise have left without the certification.
Source: AFNOR study, 2019It is the most widely used information security standard in the world, according to ISO itself. And the accreditation that oversees certification bodies (such as COFRAC in France) is recognized internationally through agreements between countries, which makes it easier to access markets in Europe and beyond.
Source: ISO (JTC1/SC27 committee)You don't need to be a multinational or a tech company. Here, backed by official sources, is who can (and sometimes must) take an interest.
The certification is aimed at "all organizations, companies and public bodies, of any size and in any sector, holding data, whether physical or digital". AFNOR itself states that it is not aimed "solely at data hosting providers, start-ups, multinationals or IT companies": accounting firm, garage, association, town hall, clinic... if you hold data, you are in scope.
Source: AFNOR Certification (17/07/2026)The official ANSSI method sheet (May 2025) confirms it in black and white: for ISO/IEC 27001, the "Obligation" box is ticked "Optional". By contrast, security accreditation (the genuinely mandatory regime) applies only to the information systems of the French State and regulated operators (OIV/OSE). Two different worlds: don't confuse the two - if a provider tells you ISO 27001 is a legal obligation, that is not accurate.
Source: ANSSI, method sheet v1.0 (May 2025)The European NIS2 text (which is mandatory) explicitly cites the ISO/IEC 27000 family of standards, which includes ISO 27001, as a reference for good practice on the cybersecurity measures to put in place. The European Commission asks Member States to "promote the use of relevant European and international standards". In practice: ISO 27001 becomes the most recognized way to prove NIS2 compliance to a regulator.
Source: EUR-Lex, Directive (EU) 2022/2555, recitals 79-80According to the European Commission, NIS2 covers 18 critical sectors: energy, transport, health, finance, water management, digital infrastructure (already covered under NIS1), plus now public electronic communications, social networks, waste management, manufacturing of critical products, postal and courier services, public administration, and the space sector. The size rule: "medium and large entities" in these sectors will have to take cyber risk management measures and report significant incidents.
Source: European Commission, digital-strategy.ec.europa.euThe official European definition (Recommendation 2003/361/EC) sets precise thresholds. A company crosses the "medium-sized" threshold (and enters the likely scope of NIS2) as soon as it exceeds one of these benchmarks:
| Category | Headcount | Turnover |
|---|---|---|
| Micro-enterprise | fewer than 10 | €2 M or less |
| Small enterprise | fewer than 50 | €10 M or less |
| Medium-sized enterprise | fewer than 250 | €50 M or less |
On 20 January 2026, the European Commission proposed a targeted amendment to ease compliance for 28,700 companies, including 6,200 micro and small enterprises. Proof that the topic no longer concerns only large groups: modest-sized organizations find themselves, through their customers or their sector, having to meet the same requirements.
Source: European Commission, digital-strategy.ec.europa.eu (20/01/2026)No need for unnecessary panic here, just the official figures. What the law really says about fines, who enforces them, and why ISO 27001 remains your best protection against them.
This is the most reassuring point: not being ISO 27001 certified does not, in itself, lead to any fine. The standard is optional (the official ANSSI method sheet confirms it: "Obligation box ticked Optional"). An optional standard logically has no legal sanction mechanism attached to its absence.
Source: ANSSI, method sheet v1.0 (May 2025)If your activity falls within the scope of the European NIS2 directive (which is mandatory), the fines are spelled out in black and white by the European Commission: up to EUR 10,000,000 or 2% of worldwide turnover for the preceding financial year for an "essential" entity (whichever amount is higher), and up to EUR 7,000,000 or 1.4% of worldwide turnover for an "important" entity. It is precisely to avoid this risk that ISO 27001 is recommended as proof of compliance.
Source: European Commission, official NIS2 FAQThese are not automatic or flat-rate fines. The competent authority must take into account "the nature, gravity and duration of the infringement, the damage caused or losses incurred, [and] the intentional or negligent character of the infringement". A company acting in good faith that quickly corrects an incident is not treated the same as a negligent, repeat offender.
Source: European Commission, official NIS2 FAQEach Member State designates its own competent authority to enforce NIS2. In France, it is ANSSI (the French national cybersecurity agency) that is responsible for implementation and enforcement. In March 2026 it made available a national framework (ReCyF, non-mandatory) to help companies find their way around and compare their existing approaches, including ISO 27001.
Source: cyber.gouv.fr (ANSSI)The competent authorities also have non-financial tools available: binding instructions, orders to implement the recommendations of a security audit, or orders to bring security measures into compliance. The directive also provides for provisions on the liability of persons holding senior management positions. A fine is generally not the first response to a breach.
Source: European Commission, official NIS2 FAQMember States had until 17 October 2024 to transpose NIS2 into national law. As of the time of writing, no official source has published any real case with a sanction amount actually applied in France or the EU: the figures above are maximum legal ceilings, not average amounts observed in practice. We will update this page as soon as an official case is published.
Source: European Commission, digital-strategy.ec.europa.euWhich dates really matter? What is already mandatory, what is already running, and what's coming. Backed by official sources, understood in 2 minutes, updated on 18/07/2026.
There used to be a 2013 version, now superseded. The official ANSSI method sheet (May 2025) confirms it in black and white in its comparison table: "Latest version: ISO 27001 version 2022". This version covers the organizational, physical and technological domains of the scope to be certified. In practice: any new certification, or any renewal, is now carried out against this version.
Source: ANSSI, method sheet v1.0 (May 2025)The European NIS2 directive entered into force in January 2023, but the date that matters for companies is 17 October 2024: the deadline by which each Member State had to transpose the text into national law. Since that date, NIS2 has applied in practice, and it precisely cites the ISO/IEC 27000 family of standards (which includes ISO 27001) as a reference for good practice for complying with it.
Source: European Commission, digital-strategy.ec.europa.euThe day after the NIS2 transposition deadline, the old NIS1 directive (from 2016) was officially repealed. There is now a single reference text in Europe for the regulatory cybersecurity of critical sectors: no more doubt about which framework applies.
Source: European Commission, digital-strategy.ec.europa.euOnce issued by an accredited body, the ISO 27001 certificate is valid for 3 years. But it is not set in stone: AFNOR Certification schedules a surveillance visit every year, then a full renewal audit at the 3-year mark. ANSSI confirms exactly the same mechanism in its May 2025 sheet: 3-year duration, annual management review and follow-up audit. Two different official sources, the same timeline.
Source: AFNOR Certification, ANSSI (May 2025)On 20 January 2026 the European Commission proposed a targeted amendment to simplify compliance for 28,700 companies, including 6,200 micro and small enterprises. As of that date, this is a proposal, not yet an adopted text: the regulatory timeline around ISO 27001 could therefore still shift in the coming months, without changing the value of the standard itself.
Source: European Commission, digital-strategy.ec.europa.eu (20/01/2026)For the information systems of the State and regulated operators, ANSSI has its own procedure, security accreditation, currently at version 2.1 (2025), which also has a maximum duration of 3 years and a recommended annual system review. This is not the same process as ISO 27001 (optional), but both move at the same 3-year rhythm, which makes life easier for those who have to manage both at once.
Source: ANSSI, method sheet v1.0 (May 2025)Contact us for a personalized quote based on your scope and current maturity level.
Free: your score + your gaps. The detailed report and the attestation: 499 EUR excl. VAT, only if you decide to.
contact@syaga.eu