STANDARD ISO/IEC 27001:2022 - ISMS

Prepare your ISO 27001 certification
without losing 6 months

ISO/IEC 27001 is the international reference standard for an Information Security Management System (ISMS). Increasingly required by customers, in tenders, by cyber insurers, or for access to certain export markets, SYAGA supports you from the gap assessment through to preparation for the certification audit.

93
Annex A controls (2022 ed.)
4
Security themes
7
Management clauses (4 to 10)
1
Statement of Applicability delivered

Context

ISO 27001 is not a general legal obligation, but it is becoming an unavoidable commercial prerequisite

📋

A voluntary certification, but increasingly requested

ISO/IEC 27001 remains a voluntary approach. It is nonetheless increasingly required in tenders, by large customers, by some cyber insurers, or as a prerequisite for access to certain export markets.

🔒

Few SMEs have formalized their ISMS

The majority of SMEs and mid-sized companies have not undertaken any structured approach to an Information Security Management System. The topic is perceived as complex, technical, and lengthy.

💰

Long and costly engagements

Classic certification engagements tie up your teams for several months and represent a substantial investment, often out of reach for an SME.

Your IT teams are already overloaded

Tying up the CIO or the security manager for months to build an ISMS is not viable in an SME where everyone already wears several hats.

The ISO27001-Express method

A structured approach in 3 phases, based on the same methodology already proven by SYAGA on PSSI-Express

1
Phase 1 - Gap Assessment

Assessment of the 93 Annex A controls

Scoping interview with management and the IT security manager, followed by a systematic assessment of each of the 93 security controls in Annex A (2022 edition), spread across the 4 themes: organizational, people, physical, and technological. Delivery of a factual gap report.

2
Phase 2 - ISMS documentation

Security policy, Statement of Applicability, and remediation plan

Drafting or updating the security policy (ISMS), the Statement of Applicability (SoA) justifying the application or exclusion of each of the 93 controls, and a prioritized remediation plan to close the gaps identified in phase 1.

3
Phase 3 - Support toward certification

Preparation for the audit by the certification body

Follow-up on the implementation of the remediation plan, documentary review, and preparation of your team for the audit carried out by an independent accredited certification body. SYAGA prepares you for the audit; the certification itself is issued by that third-party body.

What you receive

The core documents of the ISO 27001 certification file

📊

Gap Assessment Report

Factual assessment of your compliance level against the standard.

  • Assessment of the 93 Annex A controls
  • Status per control: compliant / partial / non-compliant
  • Summary by theme (organizational, people, physical, technological)
  • Factual findings, without value judgment
🔐

Statement of Applicability (SoA)

Central normative document of the ISO 27001 certification file.

  • Applicable/excluded status for each of the 93 controls
  • Justification for each exclusion
  • Reference to the ISMS documents
  • Ready to be presented to the certification body
📝

Security policy (ISMS)

The governance document required by clauses 4 to 10 of the standard.

  • Scope and context of the ISMS
  • Security roles and responsibilities
  • Risk management process
  • Continual improvement cycle (PDCA)
🎯

Prioritized remediation plan

The roadmap to close the identified gaps.

  • Actions ranked by priority
  • Organizational and technical measures
  • Progress tracking
  • Progressive preparation for the audit
📄

Operational procedures

Documents directly applicable by your teams.

  • Security incident management
  • Access and identity management
  • Change management
  • IT usage policy
💻

Editable files

All documents in formats you can evolve.

  • Standalone HTML (openable in any browser)
  • High-quality PDF (A4 print)
  • Editable DOCX (Microsoft Word)
  • Updated at each annual review

A shareable documentation base

The ISO 27001 ISMS naturally overlaps with several frameworks

ISO

ISO/IEC 27001:2022

Central framework: clauses 4 to 10 (management requirements) and Annex A (93 security controls spread across 4 themes).

N2

Bridge with NIS2

The cyber risk management measures required by the NIS2 directive largely overlap with the Annex A controls of ISO 27001. An ISO 27001 ISMS makes NIS2 compliance easier for entities in scope.

AN

ANSSI Guide - IT hygiene (France)

The measures in the IT hygiene guide published by ANSSI (the French national cybersecurity agency) overlap significantly with the Annex A controls of ISO 27001. Correspondence documented in the remediation plan.

RG

GDPR (Art. 32)

The appropriate technical and organizational measures required by Article 32 of the GDPR rely on the same good practices as Annex A of ISO 27001 (access control, encryption, incident management).

Offers tailored to your context

Every ISO 27001 engagement is scoped according to your perimeter and current maturity level. Always a personalized quote.

Gap Assessment

Initial snapshot of your gaps

On request
based on scope and headcount
  • Assessment of the 93 Annex A controls
  • Factual findings report
  • Summary by security theme
  • Presentation to management
  • HTML + PDF + DOCX formats
Request a quote

Annual maintenance

After certification or on an ongoing basis

On request
based on scope and headcount
  • Annual ISMS review
  • SoA update
  • Remediation plan update
  • Preparation for surveillance audits
Request a quote

Frequently asked questions

What is the ISO/IEC 27001 standard?
ISO/IEC 27001 is the international reference standard for establishing an Information Security Management System (ISMS). In its 2022 edition, it is structured into clauses 4 to 10 (management requirements: context, leadership, planning, support, operation, evaluation, improvement) and an Annex A of 93 security controls spread across 4 themes: organizational, people, physical, and technological.
Is ISO 27001 mandatory for my company?
No, ISO 27001 is a voluntary certification, unlike regulatory texts such as NIS2. However, it is increasingly required de facto: tenders, requirements from large customers, cyber insurance conditions, or access to certain export markets. It is more a strategic choice than a general legal obligation.
Does SYAGA issue the certification?
No. ISO 27001 certification is issued exclusively by an independent accredited certification body, following an external audit. SYAGA supports you in the preparation (gap assessment, ISMS documentation, remediation plan, preparing your teams), but does not itself issue the certificate.
What is the Statement of Applicability (SoA)?
The SoA is a mandatory normative document of the certification file. It lists each of the 93 Annex A controls and states whether it is applied or excluded, with the corresponding justification. It is one of the most closely scrutinized documents during the certification audit.
How much time do I need to commit my teams?
Most of the work (assessment, documentation drafting, remediation plan) is carried out by our auditors. Your teams are mainly involved during the initial scoping interview and the review meetings. The total duration of a certification journey depends heavily on your scope and starting maturity; it is estimated case by case in the quote.
What makes SYAGA qualified to support me?
SYAGA Consulting has been carrying out information system security audits since 2009. Our auditors work with clients of various sizes across several sectors. The gap assessment and document generation methodology used for ISO27001-Express relies on the same engine already used in our other compliance engagements (PSSI-Express).

Regulatory watch - official sources

What ISO/IEC 27001 really says, explained simply. Each point links to its official source (ISO, AFNOR, COFRAC, ANSSI), updated on 17/07/2026.

What is it, concretely?

ISO/IEC 27001 is a recognized method for identifying the threats to your data, managing the risks, and putting the right protections in place, so that your information stays confidential, available and reliable. It is not software - it is an organization to put in place within the company.

Source: AFNOR Certification

It's a choice, not a law

Unlike other approaches (such as the security accreditation imposed on certain State systems), ISO 27001 is optional: it is a certifying standard, not a general regulatory obligation. You choose it to reassure customers, partners and insurers.

Source: ANSSI (method sheet)

Who issues the certificate?

Never the company itself, nor a consultant: only an independent, accredited certification body can issue it (COFRAC is the sole French accreditation body, created in 1994). The certificate obtained is valid for 3 years.

Source: COFRAC

The journey, in 6 steps

Preliminary assessment (optional), preparation, document review, on-site audit to verify what is really in place, issuance of the certificate (3 years), then a surveillance visit every year and a full renewal audit after 3 years. Nothing is set in stone once and for all.

Source: AFNOR Certification

Does it really pay off?

According to an AFNOR study of certified companies: 89% observed fewer security incidents, 83% have stronger internal security processes, and 88% retained customers who might otherwise have left without the certification.

Source: AFNOR study, 2019

Recognized everywhere, not just in France

It is the most widely used information security standard in the world, according to ISO itself. And the accreditation that oversees certification bodies (such as COFRAC in France) is recognized internationally through agreements between countries, which makes it easier to access markets in Europe and beyond.

Source: ISO (JTC1/SC27 committee)

Who is really concerned by ISO 27001?

You don't need to be a multinational or a tech company. Here, backed by official sources, is who can (and sometimes must) take an interest.

Everyone, regardless of size or sector

The certification is aimed at "all organizations, companies and public bodies, of any size and in any sector, holding data, whether physical or digital". AFNOR itself states that it is not aimed "solely at data hosting providers, start-ups, multinationals or IT companies": accounting firm, garage, association, town hall, clinic... if you hold data, you are in scope.

Source: AFNOR Certification (17/07/2026)

A choice, never an obligation as such

The official ANSSI method sheet (May 2025) confirms it in black and white: for ISO/IEC 27001, the "Obligation" box is ticked "Optional". By contrast, security accreditation (the genuinely mandatory regime) applies only to the information systems of the French State and regulated operators (OIV/OSE). Two different worlds: don't confuse the two - if a provider tells you ISO 27001 is a legal obligation, that is not accurate.

Source: ANSSI, method sheet v1.0 (May 2025)

The real trigger: the European NIS2 directive

The European NIS2 text (which is mandatory) explicitly cites the ISO/IEC 27000 family of standards, which includes ISO 27001, as a reference for good practice on the cybersecurity measures to put in place. The European Commission asks Member States to "promote the use of relevant European and international standards". In practice: ISO 27001 becomes the most recognized way to prove NIS2 compliance to a regulator.

Source: EUR-Lex, Directive (EU) 2022/2555, recitals 79-80

NIS2 in practice: 18 sectors, from 50 employees

According to the European Commission, NIS2 covers 18 critical sectors: energy, transport, health, finance, water management, digital infrastructure (already covered under NIS1), plus now public electronic communications, social networks, waste management, manufacturing of critical products, postal and courier services, public administration, and the space sector. The size rule: "medium and large entities" in these sectors will have to take cyber risk management measures and report significant incidents.

Source: European Commission, digital-strategy.ec.europa.eu

What exactly does "medium-sized company" mean?

The official European definition (Recommendation 2003/361/EC) sets precise thresholds. A company crosses the "medium-sized" threshold (and enters the likely scope of NIS2) as soon as it exceeds one of these benchmarks:

Category Headcount Turnover
Micro-enterprise fewer than 10 €2 M or less
Small enterprise fewer than 50 €10 M or less
Medium-sized enterprise fewer than 250 €50 M or less
Source: European Commission, SME definition

The scope is widening, including for small organizations

On 20 January 2026, the European Commission proposed a targeted amendment to ease compliance for 28,700 companies, including 6,200 micro and small enterprises. Proof that the topic no longer concerns only large groups: modest-sized organizations find themselves, through their customers or their sector, having to meet the same requirements.

Source: European Commission, digital-strategy.ec.europa.eu (20/01/2026)

Sanctions: what you really need to worry about

No need for unnecessary panic here, just the official figures. What the law really says about fines, who enforces them, and why ISO 27001 remains your best protection against them.

ISO 27001 itself imposes no sanctions

This is the most reassuring point: not being ISO 27001 certified does not, in itself, lead to any fine. The standard is optional (the official ANSSI method sheet confirms it: "Obligation box ticked Optional"). An optional standard logically has no legal sanction mechanism attached to its absence.

Source: ANSSI, method sheet v1.0 (May 2025)

The real financial risk: NIS2 fines

If your activity falls within the scope of the European NIS2 directive (which is mandatory), the fines are spelled out in black and white by the European Commission: up to EUR 10,000,000 or 2% of worldwide turnover for the preceding financial year for an "essential" entity (whichever amount is higher), and up to EUR 7,000,000 or 1.4% of worldwide turnover for an "important" entity. It is precisely to avoid this risk that ISO 27001 is recommended as proof of compliance.

Source: European Commission, official NIS2 FAQ

Who decides the amount?

These are not automatic or flat-rate fines. The competent authority must take into account "the nature, gravity and duration of the infringement, the damage caused or losses incurred, [and] the intentional or negligent character of the infringement". A company acting in good faith that quickly corrects an incident is not treated the same as a negligent, repeat offender.

Source: European Commission, official NIS2 FAQ

In France, ANSSI is the enforcer

Each Member State designates its own competent authority to enforce NIS2. In France, it is ANSSI (the French national cybersecurity agency) that is responsible for implementation and enforcement. In March 2026 it made available a national framework (ReCyF, non-mandatory) to help companies find their way around and compare their existing approaches, including ISO 27001.

Source: cyber.gouv.fr (ANSSI)

Before the fine, corrective measures

The competent authorities also have non-financial tools available: binding instructions, orders to implement the recommendations of a security audit, or orders to bring security measures into compliance. The directive also provides for provisions on the liability of persons holding senior management positions. A fine is generally not the first response to a breach.

Source: European Commission, official NIS2 FAQ

No published figures to date

Member States had until 17 October 2024 to transpose NIS2 into national law. As of the time of writing, no official source has published any real case with a sanction amount actually applied in France or the EU: the figures above are maximum legal ceilings, not average amounts observed in practice. We will update this page as soon as an official case is published.

Source: European Commission, digital-strategy.ec.europa.eu

The ISO 27001 timeline, made simple

Which dates really matter? What is already mandatory, what is already running, and what's coming. Backed by official sources, understood in 2 minutes, updated on 18/07/2026.

2022 In force

Today's reference version: ISO/IEC 27001:2022

There used to be a 2013 version, now superseded. The official ANSSI method sheet (May 2025) confirms it in black and white in its comparison table: "Latest version: ISO 27001 version 2022". This version covers the organizational, physical and technological domains of the scope to be certified. In practice: any new certification, or any renewal, is now carried out against this version.

Source: ANSSI, method sheet v1.0 (May 2025)
17 Oct. 2024 In force

The real starting point: NIS2 transposed across the EU

The European NIS2 directive entered into force in January 2023, but the date that matters for companies is 17 October 2024: the deadline by which each Member State had to transpose the text into national law. Since that date, NIS2 has applied in practice, and it precisely cites the ISO/IEC 27000 family of standards (which includes ISO 27001) as a reference for good practice for complying with it.

Source: European Commission, digital-strategy.ec.europa.eu
18 Oct. 2024 In force

The old NIS1 directive has retired

The day after the NIS2 transposition deadline, the old NIS1 directive (from 2016) was officially repealed. There is now a single reference text in Europe for the regulatory cybersecurity of critical sectors: no more doubt about which framework applies.

Source: European Commission, digital-strategy.ec.europa.eu
Ongoing 3-year cycle

Once certified, the rhythm never stops

Once issued by an accredited body, the ISO 27001 certificate is valid for 3 years. But it is not set in stone: AFNOR Certification schedules a surveillance visit every year, then a full renewal audit at the 3-year mark. ANSSI confirms exactly the same mechanism in its May 2025 sheet: 3-year duration, annual management review and follow-up audit. Two different official sources, the same timeline.

Source: AFNOR Certification, ANSSI (May 2025)
20 Jan. 2026 Upcoming

What's still changing: an easing of NIS2 under review

On 20 January 2026 the European Commission proposed a targeted amendment to simplify compliance for 28,700 companies, including 6,200 micro and small enterprises. As of that date, this is a proposal, not yet an adopted text: the regulatory timeline around ISO 27001 could therefore still shift in the coming months, without changing the value of the standard itself.

Source: European Commission, digital-strategy.ec.europa.eu (20/01/2026)
2025 In force

On the French side: a parallel timeline for State systems

For the information systems of the State and regulated operators, ANSSI has its own procedure, security accreditation, currently at version 2.1 (2025), which also has a maximum duration of 3 years and a recommended annual system review. This is not the same process as ISO 27001 (optional), but both move at the same 3-year rhythm, which makes life easier for those who have to manage both at once.

Source: ANSSI, method sheet v1.0 (May 2025)
SYAGA supports you in preparing your ISMS and your certification file. ISO/IEC 27001 certification itself is issued by an independent accredited certification body, not affiliated with SYAGA. This content is a support tool and does not constitute legal advice.

Ready to structure your ISO 27001 journey?

Contact us for a personalized quote based on your scope and current maturity level.

Start my free diagnostic

Free: your score + your gaps. The detailed report and the attestation: 499 EUR excl. VAT, only if you decide to.

contact@syaga.eu