ISO 27001 is the international standard for information security management systems (ISMS). Certification requires an organization to implement a systematic approach to managing sensitive information and to have that implementation verified by an accredited certification body.
ISO 27001 certification covers Annex A controls across 14 domains, from access control to supplier relationships. Unlike SOC 2, which is US-centric, ISO 27001 is internationally recognized and commonly required for vendors operating in Europe, the UK, and APAC. Certificates are valid for three years with annual surveillance audits.
Which vendors hold ISO 27001?
Search the TrustVendor vendor graph to see current certification status, evidence age, and expiry runway across all your vendors.
Common questions about ISO 27001
Which vendors hold ISO 27001 certification?
Search the TrustVendor vendor graph to see which vendors in your portfolio hold current ISO 27001 certification, when it was last verified, and how long until it expires. Certifications are tracked continuously and alerts fire when evidence ages past its half-life.
How often does ISO 27001 certification need to be renewed?
Renewal frequency depends on the framework. SOC 2 Type II reports typically cover a 12-month audit period and should be requested annually. ISO 27001 certificates are valid for three years with annual surveillance audits. FedRAMP authorizations require annual assessment. TrustVendor tracks expiry dates and alerts you 90, 60, and 30 days before lapse.
Can I verify a vendor's ISO 27001 report myself?
For certifications that produce a published artifact (ISO 27001 certificate, FedRAMP Marketplace listing), you can verify directly with the certifying body. For SOC 2, the report is issued by the auditing CPA firm and should be shared directly by the vendor under NDA. TrustVendor stores a sha256-hashed snapshot of every artifact it processes — you can verify the hash client-side using standard tooling.