ISO/IEC 27001:2022

ISO 27001, implemented and managed

ISO 27001 certifies a management system, not a product. We set the scope, build the ISMS, keep it running and prepare the evidence an independent accredited certification body will ask for. The certificate is theirs to issue, not ours.

Updated 25 September 2026

93
Controls in Annex A
4
Themes in Annex A
3
Years per cycle

Voluntary, and increasingly expected

Almost no Dutch law requires ISO 27001. The Cyberbeveiligingswet does not name the standard and neither does NIS2. There is one exception: for essential entities in the government sector, the Cyberbeveiligingsregeling sector overheid does make NEN-EN-ISO/IEC 27001:2023 mandatory. For every other organisation the demand comes from customers, from tenders and from the board. That makes it a commercial judgement rather than a legal one, and it is the cleanest way to order your evidence.

01

Customers and tenders ask for it

An accredited certificate with a current Statement of Applicability is the one artefact most Dutch procurement teams accept without running an audit of their own. Without it, you answer the same question at every bid.

02

You sit inside someone else's supply chain

Under the duty of care in article 21(3)(d) of the Cyberbeveiligingswet, every essential and important entity has to manage the security of its suppliers. An accredited certificate is the evidence your customers accept fastest for that.

03

The board wants something it can rely on

Clause 9 requires monitoring, internal audit and a management review at planned intervals. That gives directors a recurring, evidenced account of how information security is actually performing, rather than an opinion.

04

A head start on NIS2

The Cyberbeveiligingswet and supplier assessments ask for overlapping evidence of the same controls. One scoped ISMS serves both, with the obligations each adds on top handled deliberately.

93 controls in four themes

Annex A is a normative reference set, not a checklist to implement in full. Clause 6.1.3 requires you to compare your own selection against it, and to justify every inclusion and every exclusion in the Statement of Applicability. The number of controls per theme says nothing about the amount of work: your scope determines that, not the standard.

A.537

Organizational controls

Governance, policy, roles, asset inventory, supplier relationships, incident management, legal and regulatory obligations, and independent review. The largest theme, and the one auditors spend most of their time on.

controls

  • A.5.1 Policies for information security
  • A.5.19 Information security in supplier relationships
  • A.5.24 Incident management planning and preparation
A.68

People controls

Screening, terms of employment, awareness and training, the disciplinary process, responsibilities after a change of role, confidentiality agreements, remote working and event reporting. Eight controls, all about people.

controls

  • A.6.1 Screening
  • A.6.3 Awareness, education and training
  • A.6.7 Remote working
A.714

Physical controls

Security perimeters, physical entry, secure rooms and facilities, physical monitoring, protection against physical and environmental threats, assets off premises, storage media, supporting utilities and secure disposal. For an organisation without its own server room this is usually the smallest part of the Statement of Applicability.

controls

  • A.7.1 Physical security perimeters
  • A.7.4 Physical security monitoring
  • A.7.11 Supporting utilities
A.834

Technological controls

Endpoints, privileged access, authentication, protection against malware, vulnerability and configuration management, backup, logging, monitoring, cryptography, secure coding and change management.

controls

  • A.8.5 Secure authentication
  • A.8.8 Management of technical vulnerabilities
  • A.8.16 Monitoring activities

Four phases, one management system

We build the management system and prepare for certification. The certification decision rests with an independent, accredited certification body, which cannot be us and should not be. How long this takes depends on the scope and on what is already in place. For an organisation of fifty to two hundred people with a working management system, allow indicatively six months to a year to certificate. That is not a commitment: the ISMS must demonstrably have operated before Stage 1, and the body sets its own schedule and reaches its own verdict.

01

Analysis

Scope, gap analysis and the risk assessment method. Scope is the decision that sets the cost, because audit time under ISO/IEC 27006-1:2024 is calculated on the number of people working inside it.

  • ISMS scope and boundaries
  • Gap analysis against clauses 4 to 10
  • Risk assessment methodology
02

Implementation

Building the ISMS: policy, objectives, risk treatment, the Statement of Applicability and the controls you have determined necessary. Selected on risk, because every control you include is evidence you produce at every audit.

  • Statement of Applicability
  • Risk treatment plan
  • Control implementation and documentation
03

Verification

An internal audit and a management review must have been carried out and recorded before Stage 1. The internal audit is done by a colleague who had no part in building the system, or by your own ISO 9001 internal auditor. The management review belongs to your top management; we supply the clause 9.3.2 inputs.

  • Internal audit programme
  • Management review
  • Stage 1 and Stage 2 preparation
04

Management

The certificate opens a three-year cycle: surveillance audits in years one and two, recertification in year three. Each samples a different part of the system, so the ISMS has to keep running between visits.

  • Surveillance audit preparation
  • Continual improvement and corrective action
  • Recertification in year three
05by the certification body, not by us

Certification

An RvA-accredited body carries out Stage 1 (documentation and readiness) and then Stage 2 (operation, through sampling and interviews). A major nonconformity must be closed before the certificate is issued; that happens weeks after Stage 2, following a decision by someone who was not on the audit team. We have no influence on that verdict. We do help you choose a body and budget the audit days, which under ISO/IEC 27006-1 are calculated on the number of people within the scope.

What an auditor will ask to see

ISO/IEC 27001:2022 names the documented information you are required to hold. Missing any of it is a finding. We produce these as working documents, kept current between audits rather than assembled in the month before one.

  • Scope of the ISMS (clause 4.3)
  • Information security policy (clause 5.2)
  • Risk assessment process (clause 6.1.2)
  • Risk treatment process (clause 6.1.3)
  • Statement of Applicability (clause 6.1.3 d)
  • Risk treatment plan (clauses 6.1.3 e and 8.3)
  • Information security objectives (clause 6.2)
  • Evidence of competence (clause 7.2)
  • Internal audit programme and results (clause 9.2.2)
  • Results of management reviews (clause 9.3.3)
  • Evidence that processes were carried out as planned (clause 8.1)
  • Results of the risk assessment (clause 8.2)
  • Results of the risk treatment (clause 8.3)
  • Results of monitoring and measurement (clause 9.1)
  • Nature of nonconformities, actions taken and their results (clause 10.2)

What is known about you outside your network, every day

An audit is a snapshot. Both frameworks ask for more than that: NIS2 requires policies to assess the effectiveness of measures, and ISO 27001 makes threat intelligence a control in its own right. That is why we continuously search the dark web, criminal chat channels, ransomware leak sites, paste sites and public code repositories for what has surfaced about your organisation.

What is watched

Leaked credentials
Passwords and session cookies of your staff harvested by infostealer malware and traded in criminal channels, validated against your identity provider.
Leak sites and criminal forums
Mentions of your organisation, your domains and your suppliers on ransomware leak sites, in dark web forums and in criminal chat channels.
Secrets in public code
API keys, tokens and passwords that ended up by accident in public repositories, package registries or container images.
Lookalike domains
Newly registered domains that resemble yours, and previously flagged domains that suddenly become active.
Exposure in the supply chain
Known suppliers appearing in ransomware data leaks, as continuous evidence for the supplier assessment.

What we do with it

Our monitoring collects and alerts in near real time. We assess every alert, rate its severity and turn it into the action the framework requires: a password reset, revoking sessions, a notification within the deadline or a correction in the file. Every finding and every follow-up is recorded with a date, so the effectiveness review is not a once-a-year exercise but is substantiated continuously.

Where it lands in the framework

  • NIS2Art. 21(2)(a), (b), (d) and (f)

    Risk analysis, incident handling, supply chain security and the assessment of the effectiveness of measures.

  • ISO 27001Annex A 5.7, 5.19 to 5.22 and 8.16

    Threat intelligence, supplier relationships and monitoring activities.

What it is not

This monitoring is not a security operations centre. It looks at what has leaked about you outside your network, not at the traffic inside it. Detection in your own environment and incident response are a separate agreement.

NIS2 and ISO 27001 compared

Two frameworks that are regularly confused. One is law, the other a standard you choose. This table sets out what each one is, who it binds, and what it asks you to be able to demonstrate.

  • What it is

    NIS2
    EU directive, implemented in Dutch law as the Cyberbeveiligingswet (Cbw).
    ISO 27001
    A standard for an information security management system, an ISMS.
  • Who it applies to

    NIS2
    Essential and important entities in 18 sectors. More than 8,000 Dutch organisations.
    ISO 27001
    Any organisation, of any type or size, that chooses to adopt it.
  • Mandatory or voluntary

    NIS2
    Mandatory. Registration, duty of care and incident reporting, all from day one.
    ISO 27001
    Voluntary. One exception: essential entities in the government sector must apply it.
  • Applies since

    NIS2
    15 August 2026, when the Cyberbeveiligingswet entered into force.
    ISO 27001
    Current edition published 25 October 2022, with a climate amendment added in 2024.
  • Supervisor or issuing body

    NIS2
    Sector inspectorates: RDI, ILT, DNB, AFM, IGJ, NVWA. The NCSC runs the reporting portal.
    ISO 27001
    An accredited certification body, in the Netherlands accredited by the RvA.
  • What you must be able to show

    NIS2
    Ten duty of care elements, lettered a to j, and a management system on a PDCA cycle.
    ISO 27001
    A documented ISMS: scope, risk method, Statement of Applicability, audit and review records.
  • Consequence of non-compliance

    NIS2
    Essential entities: up to EUR 10 million or 2% of group turnover, whichever is higher.
    ISO 27001
    No fine. The certificate is suspended or withdrawn, which customers and tenders notice.
  • Certification available

    NIS2
    No. There is no NIS2 certificate and the Cbw does not require one.
    ISO 27001
    Yes, by an accredited certification body.

Position as at September 2026. The Cyberbeveiligingswet entered into force on 15 August 2026 and the sector thresholds that define a reportable incident are still being completed in ministerial regulations. Determining which framework applies to your organisation remains your own legal responsibility, and this table is a summary rather than advice.

Where a certificate stops

A certified ISMS carries a substantial share of what the Cyberbeveiligingswet asks for. It does not carry all of it, and no certificate makes an organisation legally compliant with the Act. We add what is missing on purpose rather than assume it away.

Compare frameworks

What clients ask us

No, ISO 27001 is a voluntary standard. No Dutch law requires it, and the Cyberbeveiligingswet does not name it. There is one exception: for essential entities in the public administration sector, water boards excepted, the Cyberbeveiligingsregeling sector overheid makes NEN-EN-ISO/IEC 27001:2023 mandatory. For everyone else the demand comes from clients, tenders and the board.

Start with a scope estimate

Tell us your sector, your size and what has been asked of you. Within 24 hours you receive a written first view of what an ISO 27001 scope would look like for your organisation, and where NIS2 obligations sit alongside it.