Skip to content

ISO 27001: Certification as Competitive Advantage and Security Shield

Information Security Management System implementation and ISO 27001:2022 certification: from gap analysis and Statement of Applicability through the certification audit.

93
Annex A controls in ISO 27001:2022 — we manage all of them
6-12 mo
Typical certification timeline with structured methodology
2022
Current standard version — we also lead transitions from ISO 27001:2013
4.8/5 on Google · 50+ reviews 25+ years experience 5 offices in Spain 500+ clients
Quick assessment

Does this apply to your business?

Have clients, tenders, or international partners requested ISO 27001 certification as a condition of doing business with you?

Have you assessed the gap between your current controls and the 93 Annex A controls of ISO 27001:2022?

Does your company have a formally documented and operational information security risk management system?

Has senior management made the formal documented commitment that the standard requires?

0 of 4 questions answered

Our approach

Our ISO 27001 implementation and certification process

01

Gap analysis and scope definition

We assess the current security posture against ISO 27001:2022 requirements, define the ISMS scope (which assets, processes, and locations are included), and produce a project plan with milestones, resources, and budget.

02

ISMS implementation

We implement the management system: security policy, risk assessment methodology, Statement of Applicability (SoA), selection and implementation of Annex A controls, operational procedures, and the training and awareness programme.

03

Internal audit and management review

We conduct the internal audit prior to certification, identify and close non-conformities, and prepare the management review as required by the standard — ensuring the certification audit is approached without surprises.

04

Certification audit support

We support the team through Stage 1 and Stage 2 of the certification audit, manage responses to auditor findings, and coordinate the resolution of non-conformities within the required timescales.

The challenge

ISO 27001 certification is increasingly demanded by enterprise clients, public tenders, and international partners as a condition of doing business. Yet many companies approach the certification process without a clear methodology, allowing the project to drag on for years and generating disproportionate internal effort. For already-certified organisations, the transition to ISO 27001:2022 adds another layer of complexity — including 11 new controls that must be assessed, implemented, and documented.

Our solution

We lead the ISO 27001 ISMS implementation and certification project from start to finish: from the initial gap analysis through the certification audit. Our team has verified experience in both implementation and audit, enabling us to anticipate certification body criteria and optimise scope to achieve certification in the shortest realistic timeframe.

ISO 27001 is the international standard for Information Security Management Systems (ISMS), published by the International Organization for Standardization and the International Electrotechnical Commission. The current version, ISO/IEC 27001:2022, defines the requirements for establishing, implementing, maintaining, and continually improving an ISMS, including a risk assessment process, a Statement of Applicability, and a set of 93 information security controls organised into four themes (organisational, people, physical, and technological). ISO 27001 certification is granted by accredited third-party certification bodies following a two-stage audit; it is internationally recognised and increasingly required by enterprise customers, public procurement processes, and as evidence of compliance with the security requirements of the GDPR and the NIS2 Directive.

Our ISO 27001 certification team combines verified implementation experience with direct knowledge of the audit criteria applied by the principal certification bodies operating in Spain. We have led certification projects across healthcare, fintech, logistics, professional services, and manufacturing — sectors with very different risk profiles and Annex A control prioritisation.

Why ISO 27001 Has Become a Market Access Requirement

ISO 27001 certification was once a differentiator. For a growing number of sectors and commercial relationships, it is now a threshold requirement. Enterprise procurement frameworks, public tender evaluation criteria, financial services third-party risk assessments, and international partnership agreements increasingly treat ISO 27001 certification as the minimum acceptable evidence of a managed security posture — not as an added value.

The 2022 revision of the standard also aligned ISO 27001 more closely with current threat realities. The 11 new controls added in Annex A — including threat intelligence, cloud service security, web filtering, data masking, and cyber attack preparedness — reflect the environment in which organisations actually operate, not the threat landscape of 2013. Organisations certified under the previous version and still running outdated Annex A implementations are not only non-compliant with the current standard; they have structural security gaps.

The Certification Audit: What Actually Gets Tested

The most common failure mode for ISO 27001 certification projects is the gap between documentation and implementation. Stage 1 of the certification audit reviews whether the ISMS documentation is coherent and complete. Stage 2 tests whether the controls described in that documentation are actually operating in practice. Auditors interview staff, review operational records, and check whether the procedures in place match the procedures on paper.

Our implementation approach bridges this gap deliberately. We do not produce documentation that describes an ideal state and hope the organisation grows into it. We implement controls at the operational level first, then document what actually exists. The Statement of Applicability reflects reality, not aspiration — and that is what certification auditors verify.

Building Towards Broader Regulatory Compliance

ISO 27001 certification provides a strong platform for NIS2 compliance. The standard’s risk-based ISMS framework, Annex A controls, and mandatory management review processes map directly to the Article 21 requirements. The transition overhead from ISO 27001 to NIS2 compliance is substantially lower for certified organisations than for those starting from scratch, particularly in governance documentation and control evidence.

For companies working with our Virtual CISO service, the ISO 27001 ISMS becomes the operational framework for the security governance function: the system from which decisions are made, investments are prioritised, and progress is measured. Certification transforms what might otherwise be an ad hoc security programme into a structured, auditable, and continuously improving management system.

The Statement of Applicability: The Most Important Document

The Statement of Applicability (SoA) is the core document of the ISO 27001 ISMS: it lists all 93 Annex A controls, documents whether each is applicable or excluded, and provides the justification for each decision. Certification auditors scrutinise the SoA in detail. A poorly constructed SoA that excludes controls for convenience rather than legitimate business reasons, or marks controls as implemented when they exist only on paper, is a primary source of certification audit findings. Our implementation methodology constructs the SoA collaboratively with the client’s technical and operational teams, ensuring every decision is documented and defensible.

ISO 27001 in the Supply Chain

For technology suppliers, cloud service providers, and outsourcing partners, ISO 27001 certification is increasingly required by enterprise clients as a condition for contract award and renewal. Supply chain security provisions under NIS2 and DORA are accelerating this trend. If your organisation sells technology or data services to regulated industries — financial services, healthcare, energy, critical infrastructure — ISO 27001 certification is becoming a prerequisite rather than an advantage. The certification process, managed with our team, typically takes between six and twelve months for a mid-sized organisation, depending on existing security maturity.

Maintaining Certification: The Annual Surveillance Audit

ISO 27001 certification is maintained through annual surveillance audits and a full recertification audit every three years. Organisations that let their ISMS documentation or control evidence lapse between surveillance audits typically face significant remediation work before the next audit. Our maintenance programme provides ongoing ISMS support — including internal audit facilitation, management review preparation, and continuous monitoring of Annex A control effectiveness. For organisations also subject to cybersecurity audit requirements under NIS2 or contractual obligations, the annual internal audit process can be coordinated with external regulatory compliance assessments to minimise the total audit burden.

ISO 27001 and GDPR: The Compliance Overlap

The technical and organisational measures required by Article 32 of the GDPR overlap substantially with the information security controls of ISO 27001 Annex A. Organisations with a functioning ISO 27001 ISMS are in a structurally stronger position in GDPR compliance — and in particular in data breach management — because the underlying security infrastructure, incident management procedures, and documentation systems are already in place. The security foundation that ISO 27001 provides eliminates a significant proportion of the technical compliance work, and the integrated management system approach means that compliance gaps are identified and remediated systematically rather than discovered in enforcement proceedings.

The Statement of Applicability: The Most Important Document

The Statement of Applicability (SoA) is the core document of the ISO 27001 ISMS: it lists all 93 Annex A controls, documents whether each is applicable or excluded, and provides the justification for each decision. Certification auditors scrutinise the SoA in detail. A poorly constructed SoA that excludes controls for convenience rather than legitimate business reasons, or marks controls as implemented when they exist only on paper, is a primary source of certification audit findings. Our implementation methodology constructs the SoA collaboratively with the client’s technical and operational teams, ensuring every decision is documented and defensible.

ISO 27001 in the Supply Chain

For technology suppliers, cloud service providers, and outsourcing partners, ISO 27001 certification is increasingly required by enterprise clients as a condition for contract award and renewal. Supply chain security provisions under NIS2 and DORA are accelerating this trend. If your organisation sells technology or data services to regulated industries — financial services, healthcare, energy, critical infrastructure — ISO 27001 certification is becoming a prerequisite rather than an advantage. The certification process, managed with our team, typically takes between six and twelve months for a mid-sized organisation, depending on existing security maturity.

Maintaining Certification: The Annual Surveillance Audit

ISO 27001 certification is maintained through annual surveillance audits and a full recertification audit every three years. Organisations that let their ISMS documentation or control evidence lapse between surveillance audits typically face significant remediation work before the next audit. Our maintenance programme provides ongoing ISMS support — including internal audit facilitation, management review preparation, and continuous monitoring of Annex A control effectiveness. For organisations also subject to cybersecurity audit requirements under NIS2 or contractual obligations, the annual internal audit process can be coordinated with external regulatory compliance assessments to minimise the total audit burden.

ISO 27001 and GDPR: The Compliance Overlap

The technical and organisational measures required by Article 32 of the GDPR overlap substantially with the information security controls of ISO 27001 Annex A. Organisations with a functioning ISO 27001 ISMS are in a structurally stronger position in GDPR compliance — and in particular in data breach management — because the underlying security infrastructure, incident management procedures, and documentation systems are already in place. The security foundation that ISO 27001 provides eliminates a significant proportion of the technical compliance work, and the integrated management system approach means that compliance gaps are identified and remediated systematically rather than discovered in enforcement proceedings.

Track record

Real results from ISO 27001 certification

We had been attempting ISO 27001 with internal resources for two years and arrived at the audit with too many open non-conformities. BMC came in, restructured the project, closed the critical non-conformities in eight weeks, and took us through to certification in the third month. We are now the only supplier in our sector with active ISO 27001 certification — and it has already won us two enterprise contracts.

Helix Healthcare Technologies, S.L.
Chief Technology Officer

Experienced team with local insight and international reach

What you get

What our ISO 27001 service includes

Gap Analysis and Project Plan

Assessment of current security posture against ISO 27001:2022, ISMS scope definition, and a project plan with milestones, resource requirements, and budget.

ISMS Implementation

Security policy, risk assessment, Statement of Applicability, Annex A control selection and implementation, and operational procedures across the defined scope.

Training and Awareness Programme

Project team training, organisation-wide security awareness, and specific training for senior management on their obligations under the standard.

Internal Audit and Non-Conformity Management

Full internal audit prior to certification, non-conformity identification and closure, and management review preparation.

Certification Support and ISMS Maintenance

Stage 1 and Stage 2 audit support, and ongoing ISMS maintenance with annual internal audits and pre-audit readiness assessments.

Guides

Reference guides

Post-Brexit: your British company operating in Spain with the right structure

post-Brexit advisory for UK companies operating in Spain: entity structuring, customs and VAT, work permits for British nationals, UK-Spain tax treaty optimisation and data protection compliance.

View guide

Comprehensive legal services for businesses

Comprehensive legal advisory for businesses: commercial, employment, contracts, regulatory compliance, and dispute resolution. A dedicated legal team to protect your company.

View guide

Buy property in Spain with confidence — and without the horror stories

Buying property in Spain as a non-resident involves legal checks, tax obligations, and title risks that many buyers discover too late. BMC protects your investment from offer to deed.

View guide

The collective agreement that governs your workforce: understand it and negotiate from strength

How collective agreements work in Spain: hierarchy of agreements, company-level vs sector agreements, ultra-actividad, inaplicacion (opt-out), and negotiation strategy for employers after the 2021 labour reform.

View guide

Your commercial lease agreement: get the clauses right before you sign

Expert legal guidance on commercial lease agreements in Spain under the LAU: key clauses, rent reviews, subleasing, termination rights, VAT implications and tenant and landlord protections.

View guide

Corporate lawyer for construction: protect your contracts and your rights

Corporate legal advisory for construction companies and developers in Spain: construction contracts, UTEs, joint ventures, interim valuation disputes, claims for defects, and debt recovery.

View guide
FAQ

Frequently asked questions about ISO 27001 certification in Spain

For a medium-sized company (50-200 employees) starting from a reasonable baseline, the implementation and certification process typically takes 6 to 12 months. The most significant variables are the ISMS scope, the maturity of existing controls, and the availability of internal resources. Our structured methodology and audit experience consistently place clients at the shorter end of that range.
The Statement of Applicability (SoA) is one of the ISMS's key documents. It lists all Annex A controls (93 in the 2022 version) and states for each whether it is applicable and, if applicable, how it is implemented and the justification for its inclusion or exclusion. Certification auditors examine the consistency between the risk assessment, the SoA, and the controls actually implemented in detail — this alignment is where most audit failures occur.
The 2022 version updated Annex A, reducing controls from 114 to 93 and reorganising them into 4 categories (organisational, people, physical, and technological). It introduced 11 new controls including threat intelligence, cloud service security, ICT continuity, and cyber attack preparedness. Organisations certified under ISO 27001:2013 had until October 2025 to transition to the new version.
ISO 27001 certification is issued by certification bodies accredited by ENAC in Spain, or by equivalents in other countries (UKAS in the UK, DAkkS in Germany). The main bodies active in Spain include Bureau Veritas, SGS, Lloyd's Register, DNV, BSI, and TUV. We work with all of them and can recommend the most appropriate for your sector and budget.
ISO 27001 is not formally mandatory under NIS2 or the Spanish National Security Framework (ENS), but certification provides strong evidence of adequate controls and is widely accepted by supervisory authorities as proof of compliance with technical requirements. For ENS, there are specific additional requirements that ISO 27001 does not fully cover. However, ISO 27001 certification is an excellent starting point for both frameworks and substantially reduces the residual compliance gap.
The project requires an internal project owner (not necessarily with prior technical knowledge, but with authority and time allocation) and periodic availability from department heads for risk assessment workshops and procedure reviews. Senior management must make a formal documented commitment — the standard requires this explicitly. We cover the full technical and methodological workload of the project.
ISO 27001 certification requires annual surveillance audits and a full recertification audit every three years. Between audits, the ISMS must remain operational: periodic risk reviews, internal audits, SoA updates when the business or technology changes, and an annual management review. We provide continuous ISMS maintenance services to ensure the certification is sustained without last-minute scrambles before each audit.
Yes. The transition requires updating the risk assessment to align with the new structure, reviewing the SoA against the 11 new controls, updating affected policies and procedures, and operationally integrating the new controls. We perform the transition gap analysis and support the process through to the transition audit with the certification body.
First step

Start with a free diagnostic

Our team of specialists, with deep knowledge of the Spanish and European market, will guide you from day one.

ISO 27001 Certification

Legal

First step

Start with a free diagnostic

Our team of specialists, with deep knowledge of the Spanish and European market, will guide you from day one.

25+
years experience
5
offices in Spain
500+
clients served

Request your diagnostic

We respond within 4 business hours

Or call us directly: +34 910 917 811

Call Contact