ISO 27001

4.9
Based on 100+ G2 reviews

The global standard for information security, earned.

ISO 27001 is the world's most recognized information security certification. Johanson Group guides you through every phase — initial certification (stage 1 & 2), surveillance audit, and recertification or even continuing where you are now without starting over. A dedicated team of experts is there at every step.

Market leaders choose Johanson Group:

Experienced Practitioners

Our audit team brings decades of combined experience across security and compliance frameworks — seasoned practitioners, not junior staff learning on your engagement.

Platform Experts

Former GRC platform experts on staff. We audit inside your existing tools — no manual exports, no spreadsheets.

Our Staff

Every audit is managed and conducted by experienced, qualified professionals with real operational knowledge of the standards being assessed.

Expert Network

Tap into our trusted ecosystem of MSP and vCISO partners to strengthen your full security posture — not just your audit.

Relevant services

Find the right ISO 27001 service for where you are.

Whether you're pursuing certification for the first time, coming out of a missed transition, or maintaining an existing certificate, every engagement is scoped to your situation.

Already certified to ISO 27001? We can help.

If you’re certified with ISO 27001 (or another ISO standard) and wondering how to certify multiple management systems, we can help to reduce the resources needed by certifying under an integrated management system. Common Clauses and Controls can be audited together during the same audit. We can also help transfer your certification at any time during the certification cycle.

Additional Services

SOC & ATTESTATION

SOC 2

Audit Timeline: 4-8 weeks*

The standard trust report for technology companies. Demonstrates that your security, availability, confidentiality, processing integrity, privacy and data handling controls meet rigorous AICPA standards.

For: SaaS, cloud, and software companies selling to enterprise buyers

ISO Standards

ISO 27017/18

Security controls tailored specifically to cloud service providers and cloud customers — going beyond ISO 27001 to address cloud-unique risks and responsibilities.The internationally recognized information security management standard. Required by enterprise and government buyers globally — and a strong differentiator in competitive deals.

For: Cloud providers, IaaS, PaaS, and SaaS platforms

ISO standards

ISO 42001

The world's first AI management system standard - helping organizations demonstrate responsible, ethical, and secure use of artificial intelligence to enterprise buyers and regulators.The privacy standard for cloud processors handling personal data — demonstrates to customers and regulators that PII is managed responsibly in your cloud environment.

For: AI companies, ML platforms, and enterprises deploying AI systems

Customer Success Stories

Cryptocurrency Exchange

Bitkub Exchange Becomes Thailand's First Digital Asset Exchange to Achieve SOC 2 Type II

Thailand's leading digital asset exchange became the country's first to earn SOC 2 Type II — validating security across all five Trust Services Criteria.

6 weeks
Biotech Company

Scisco Genetics Secures Data with SOC 2 Compliance

Seattle-based Scisco Genetics Inc. is a leader in genetic analysis, offering fast and accurate high resolution genotyping of complex immune regions.

4.9
Based on 100+ G2 reviews

Don't just take our word for it.

"Johanson Group has performed all of our SOC audits professionally, communicated well during the engagement, and delivered the reports within the expected time frames."

David Patrick
Director of Security and Compliance

"The auditors we worked with were focused, friendly, and professional. We've spoken to many companies in this area before deciding for Johanson Group."

Björn Schwenzer
COO, WunderGraph

"They set clear expectations around the audit process and were very flexible working around our schedules. Johanson Group was a true partner. Very flexible and communicative throughout our audit process.""

Daryl Pinkal
CTO, Clozd

"The coordination from their account management to the actual auditors and then the final follow-up on the operational and finance side was very well coordinated and seamless. It's very easy to work with them, and they create a lot of predictability in achieving our desired business outcomes."

Ram Ganesan
Co-Founder, Kaboom AI

"The communication has been great, and we have a very good portal to manage our data on, which altogether works out best for us. We appreciate everything they offer as part of our audit process."

Chintan Shukla
Founder & CEO, Infotech Houston Health

"I truly appreciate Johanson Group's affordable pricing, which was a significant factor in my decision to transition from another provider. Overall, my experience with Johanson Group has been positive, as evidenced by my willingness to rate them a perfect 10 for recommendations."

Sheryl Briggs
CEO, Classapps

"Johanson Group has performed all of our SOC audits professionally, communicated well during the engagement, and delivered the reports within the expected time frames."

David Patrick
Director of Security and Compliance

"The auditors we worked with were focused, friendly, and professional. We've spoken to many companies in this area before deciding for Johanson Group."

Björn Schwenzer
COO, WunderGraph

"They set clear expectations around the audit process and were very flexible working around our schedules. Johanson Group was a true partner. Very flexible and communicative throughout our audit process.""

Daryl Pinkal
CTO, Clozd

"The coordination from their account management to the actual auditors and then the final follow-up on the operational and finance side was very well coordinated and seamless. It's very easy to work with them, and they create a lot of predictability in achieving our desired business outcomes."

Ram Ganesan
Co-Founder, Kaboom AI

"The communication has been great, and we have a very good portal to manage our data on, which altogether works out best for us. We appreciate everything they offer as part of our audit process."

Chintan Shukla
Founder & CEO, Infotech Houston Health

"I truly appreciate Johanson Group's affordable pricing, which was a significant factor in my decision to transition from another provider. Overall, my experience with Johanson Group has been positive, as evidenced by my willingness to rate them a perfect 10 for recommendations."

Sheryl Briggs
CEO, Classapps

"Johanson Group has performed all of our SOC audits professionally, communicated well during the engagement, and delivered the reports within the expected time frames."

David Patrick
Director of Security and Compliance

"The auditors we worked with were focused, friendly, and professional. We've spoken to many companies in this area before deciding for Johanson Group."

Björn Schwenzer
COO, WunderGraph

"They set clear expectations around the audit process and were very flexible working around our schedules. Johanson Group was a true partner. Very flexible and communicative throughout our audit process.""

Daryl Pinkal
CTO, Clozd

"The coordination from their account management to the actual auditors and then the final follow-up on the operational and finance side was very well coordinated and seamless. It's very easy to work with them, and they create a lot of predictability in achieving our desired business outcomes."

Ram Ganesan
Co-Founder, Kaboom AI

"The communication has been great, and we have a very good portal to manage our data on, which altogether works out best for us. We appreciate everything they offer as part of our audit process."

Chintan Shukla
Founder & CEO, Infotech Houston Health

"I truly appreciate Johanson Group's affordable pricing, which was a significant factor in my decision to transition from another provider. Overall, my experience with Johanson Group has been positive, as evidenced by my willingness to rate them a perfect 10 for recommendations."

Sheryl Briggs
CEO, Classapps

Frequently asked questions

Your answer not here? Feel free to contact us for more information.

ISO/IEC 27001 is the internationally recognized standard for Information Security Management Systems (ISMS). It's published by the International Organization for Standardization and specifies requirements for establishing, implementing, maintaining, and continuously improving a systematic approach to managing information security risks. You likely need it if enterprise clients are requiring it during vendor onboarding, if you're selling into European or APAC markets, if government or defense contracts require it, or if you want to demonstrate security maturity to investors and partners with a globally recognized credential.

Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat. Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur.

The time required to achieve ISO 27001 certification depends largely on an organization's readiness for certification. Once an organization is ready, the certification process typically includes a Stage 1 Audit followed by a Stage 2 Audit. Audit duration is determined by factors such as organizational size, number of locations, and the complexity of the certification scope.

We can provide an estimated certification timeline after reviewing your organization's scope and certification requirements.

The Statement of Applicability (SoA) is one of the most important documents in an ISO 27001 engagement. It lists all 93 Annex A controls from ISO 27001:2022, documents which controls are applicable to your organization, whether each is implemented, and the justification for including or excluding each one.

Auditors use the SoA as a primary reference during Stage 1 and Stage 2. A poorly constructed SoA is one of the most common reasons Stage 1 audits identify issues. We build and review your SoA as part of every pre-certification engagement.

The ISO 27001:2022 update restructured Annex A from 114 controls across 14 control objectives to 93 controls across 4 themes: Organizational, People, Physical, and Technological. It added 11 new controls including threat intelligence, information security for cloud services, data masking, data leakage prevention, web filtering, and secure coding. 57 controls were merged, 23 renamed, 35 remained the same, and 1 was split.

The 2022 version also introduced 5 control attributes for better categorization and aligns more closely with ISO/IEC 27002:2022 and other modern management system standards.

The cost of ISO 27001 certification depends on factors such as organizational size, number of personnel, locations within scope, and the complexity of the activities covered by the ISMS. Audit duration is determined in accordance with established certification requirements and directly influences certification costs.


We provide customized quotations based on your organization's specific certification scope and requirements. Contact us to discuss your needs and receive a proposal.

ISO 27001 certification is valid for three years, but it requires annual surveillance audits in years 1 and 2 to confirm continued compliance and ongoing ISMS improvement. Surveillance audits are lighter than the initial certification audit — they focus on specific areas of the ISMS rather than a full review. In year 3, a full recertification audit renews the certificate for another three-year cycle. Johanson Group manages your full surveillance program so these annual touchpoints are predictable and low-burden for your team.

Yes. ISO 27001 can be applied to organizations with fully remote, hybrid, or office-based workforces. The organization must demonstrate that information security risks associated with remote work are appropriately identified and controlled. Many modern SaaS and technology companies achieve certification while operating entirely remotely.

Yes. Organizations may determine that certain Annex A controls are not applicable based on their scope, activities, technology, and risk assessment results. Any excluded controls must be justified and documented in the Statement of Applicability (SoA). Exclusions cannot be used to avoid addressing relevant risks.

Certified organizations are responsible for notifying Johanson Group of significant changes that may affect their certified management system or certification scope. Examples include:

* Changes to the organization's legal name
* Changes to the organization's registered or certified address
* Addition or closure of locations within the certification scope
* Significant changes to the scope of certification
* Mergers, acquisitions, or ownership changes
* Significant organizational restructuring
* Major changes to products, services, or activities covered by the certification
* Significant changes affecting the effectiveness of the management system

Organizations should communicate these changes as soon as possible so that Johanson Group can determine whether additional review activities, audits, or updates to certification records are required.

Organizations must notify Johanson Group whenever significant changes occur that could affect the certified management system or the scope of certification. Examples include changes to the organization's name, addresses, locations, scope, ownership, or key business activities.


Early notification allows Johanson Group to assess the impact of the change and determine whether additional review activities, special audits, or certificate updates are necessary. Delaying notification may affect the organization's ability to maintain accurate certification records.

Johanson Group LLP is responsible for and will retain authority for its decision relating to certification, including the granting, refusing, maintaining, renewing, suspending, restoring, or withdrawing of certification. The client is responsible for maintaining compliance with ISO/IEC 27001 requirements during the period of certification. Following the confirmation of the successful remediation of necessary corrective actions, the findings and recommendations made in the audit report will be reviewed and considered for certification will be conducted. If the organization’s ISMS is approved for certification, Johanson Group LLP will issue an ISO/IEC 27001 certification / or scope of certification, which is valid for three years from the issuance date and subject to the successful completion of annual surveillance audits. Based on the results of surveillance audits or other circumstances, Johanson Group LLP holds the right to suspend, withdraw, or reduce the scope of the certification. Refusal of certification could occur due to the client’s non-compliance with a number of factors including Johanson Group LLP’s terms and agreements. Detailed information and documentation outlining terms and conditions will be provided upon completion of the certification process. All decisions will be communicated to the organization in writing detailing the grounds for refusal of certification. When a client’s certification is suspended, refused, or withdrawn the client must cease the use of the certification mark or any promotional material that advertises the fact that the client is certified.

Surveillance audits are conducted annually and are required in order to help ensure the certified organization is able to maintain its compliance with the standard. As part of this process, limited testing and an onsite review will be conducted to determine the impact of any significant changes since the original certification and that the initial certification scope remains valid.

Before the certificate expires, arrangements for recertification are planned. Recertification activities include a full audit of the ISMS.

If during the 3-year certification cycle there are changes in the scope of the certification or changes to requirements, this will be discussed with the Johanson Group LLP certification team.

Information about a particular certified client shall not be disclosed to a third party without the written consent of the certified client except as required in ISO/IEC 17021.

Johanson Group LLP is committed to maintaining professionalism in our organization and our clients. As such Johanson Group LLP is impartial, intellectually honest, and free of conflicts of interest. This policy helps ensure commitments to independence, impartiality, and objectivity of its management systems certification activities.


Our stated impartiality policy clearly identifies and assesses all relationships that may result in a conflict of interest or may pose a threat to impartiality. The policy helps ensure that our personnel are, and will remain, impartial in our certification activities.


Johanson Group LLP will not provide advisory or management systems consulting services to assist in the design, selection, or implementation of controls or internal audit services used to meet the ISO/IEC 27001 requirements. This requirement does not prevent Johanson Group LLP from performing ISO/IEC 27001 pre-audit assessment services.

Item descriptionJohanson Group LLP maintains a Client Directory containing the current status of all client certifications.

Clients can appeal an application, certification, or other decisions taken by Johanson Group LLP. The appeal must be submitted by requesting and completing an appeals document which will be provided by Johanson Group LLP via email. Acknowledgment of receipt of the appeal will be conveyed by Johanson Group LLP and the client will be notified of the status of the appeal. Johanson Group LLP personnel involved in the certification activity will not be involved in the matter of the appeal.

Johanson Group LLP will ensure the investigation, and decision on an appeal submitted does not result in any discriminatory action taken against the client and will give formal notice to the appellant at the end of the process.


Once a decision has been made regarding the appeal, no counterclaims can be made by either party to change the decision unless additional supporting documentation is provided. Johanson Group LLP will consider the results of historical cases when similar appeals are received. If an appeal is successful and certification is insured or reinstated, claims cannot be made against Johanson Group LLP for reimbursement of costs associated with the withholding, suspension, or withdrawal notification.


To file a confidential appeal, please send an email to complaints@johansonllp.com with “ISO/IEC 27001 Appeal” in the subject line.

Johanson Group LLP shall acknowledge the receipt of any complaint and will provide the client with the progress of its resolution. The decision, formally communicated at the end of the complaint-handling process, will be communicated by individuals not previously involved in the subject or the complaint.

Prior to disclosing any complaints against Johanson Group LLP or its clients, both parties will collectively discuss such matters unless disclosure is required by law.
To file a confidential complaint, please send an email to complaints@johansonllp.com with “ISO/IEC 27001 Complaint” in the subject line.

Johanson Group LLP clients are responsible for maintaining the certified ISMS. If the client fails to complete the surveillance audits or recertification activities or fails to remediate major non-conformities within the specified time frame, Johanson Group LLP will initiate certification suspension procedures.

Suspension status will be communicated to the client, and the client will have six months from the audit to remediate the issues, after which certification may be restored. If remediation is not completed, Johanson Group LLP will determine if certification should be withdrawn, or the scope of certification reduced. The client should contact Johanson Group LLP upon reduction or expansion of the ISMS scope to initiate the scope review process.

If a client fails to maintain compliance with certification conditions, Johanson Group LLP reserves the right to suspend certification. During a suspension period, certification is invalid, and these periods are reflected in the status field within our client directory.

Rules for the use of the Johanson Group name and logo are documented within the terms and conditions section of our client agreement and within documentation given to clients upon successful certification. We closely monitor the use of our name and logo to ensure compliance with standards governing us as a certification body. Complaints against Johanson Group or our clients are not made public unless required by law. Certified clients may use our certification mark subject to the following conditions:


The certification mark may be used on correspondence, advertising, and promotional material in conjunction with the certified client’s name, and shall not be used in connection with services, activities, or locations not covered by the scope of certification;


The certification mark shall not be used on a product nor product packaging nor in any other way that may be interpreted as denoting product conformity;
The certification mark shall not be altered, including both style and colors;
Upon termination of certification, the certified client shall immediately discontinue the use of the mark. Use of the marks is not to be reinitiated unless certification is fully reinstated.