ISO 27001
The global standard for information security, earned.
ISO 27001 is the world's most recognized information security certification. Johanson Group guides you through every phase — initial certification (stage 1 & 2), surveillance audit, and recertification or even continuing where you are now without starting over. A dedicated team of experts is there at every step.
Market leaders choose Johanson Group:
























Experienced Practitioners
Our audit team brings decades of combined experience across security and compliance frameworks — seasoned practitioners, not junior staff learning on your engagement.
Platform Experts
Former GRC platform experts on staff. We audit inside your existing tools — no manual exports, no spreadsheets.
Our Staff
Every audit is managed and conducted by experienced, qualified professionals with real operational knowledge of the standards being assessed.
Expert Network
Tap into our trusted ecosystem of MSP and vCISO partners to strengthen your full security posture — not just your audit.
Relevant services
Find the right ISO 27001 service for where you are.
Whether you're pursuing certification for the first time, coming out of a missed transition, or maintaining an existing certificate, every engagement is scoped to your situation.
Stage 1 Audit - Documentation Review
This audit confirms that a management system and its supporting documentation are in place and are ready for certification. It focuses on the Clauses of the standard and required documentation, validating the system and noting areas that may be considered nonconformities. Identifying these areas in the Stage 1 audit gives your team the opportunity to resolve them cleanly before the certification audit (Stage 2).
Stage 2 Audit - Certification Audit
During the Stage 2 audit, auditors focus on the controls you've included for certification. The review covers the processes behind each control, their alignment with the requirements of the standard, and the operational evidence showing the control has been managed as required. This is your opportunity to demonstrate that you operate the way your policies and procedures say you do. Through interviews, evidence review, and process observation, the audit is conducted in a natural, cooperative manner. Successful completion results in ISO 27001:2022 certification.
Readiness Assessment
Optional assessment against mandatory certification requirements related to ISO/IEC 27001:2022. We provide an opportunity for your team to undergo a mock audit as they learn about requirements, expectations, and areas for improvement.
Internal Audit
We have a list of companies that have demonstrated quality in services and align with our expectations for customer care. The internal audit will help comply with the internal audit requirement from an independent and objective third party. They can point out gaps and potential problems before seeking certification by examining policies, procedures, risk assessment framework, statement of applicability, and control implementation. Results written to allow documented evidence and provide guidance for working with auditors.
Annual Surveillance Audit
Your certification is valid for 3 years and requires a review during each 12-month period. The first surveillance audit is completed prior to your first anniversary of registration. Each surveillance audit will review any changes and updates to the management system. It will also include a portion of the Controls in scope of certification to confirm continued compliance and maintenance of the ISMS. We coordinate the full surveillance process to help you keep your certificate in good standing.
Recertification
The recertification audit combines elements of a Stage 2 audit and a surveillance audit. We review changes to your management system as well as all applicable controls to re-issue your ISO 27001 certification for another three-year cycle. Our focus is on ensuring your certification doesn't lapse, while giving the fairest and fullest representation of the maturity your program has achieved.
Already certified to ISO 27001? We can help.
If you’re certified with ISO 27001 (or another ISO standard) and wondering how to certify multiple management systems, we can help to reduce the resources needed by certifying under an integrated management system. Common Clauses and Controls can be audited together during the same audit. We can also help transfer your certification at any time during the certification cycle.
Additional Services
SOC 2
The standard trust report for technology companies. Demonstrates that your security, availability, confidentiality, processing integrity, privacy and data handling controls meet rigorous AICPA standards.
For: SaaS, cloud, and software companies selling to enterprise buyers
ISO 27017/18
Security controls tailored specifically to cloud service providers and cloud customers — going beyond ISO 27001 to address cloud-unique risks and responsibilities.The internationally recognized information security management standard. Required by enterprise and government buyers globally — and a strong differentiator in competitive deals.
For: Cloud providers, IaaS, PaaS, and SaaS platforms
ISO 42001
The world's first AI management system standard - helping organizations demonstrate responsible, ethical, and secure use of artificial intelligence to enterprise buyers and regulators.The privacy standard for cloud processors handling personal data — demonstrates to customers and regulators that PII is managed responsibly in your cloud environment.
For: AI companies, ML platforms, and enterprises deploying AI systems
.avif)
"Johanson Group has performed all of our SOC audits professionally, communicated well during the engagement, and delivered the reports within the expected time frames."

"The auditors we worked with were focused, friendly, and professional. We've spoken to many companies in this area before deciding for Johanson Group."
.png)
"They set clear expectations around the audit process and were very flexible working around our schedules. Johanson Group was a true partner. Very flexible and communicative throughout our audit process.""
.png)
"The coordination from their account management to the actual auditors and then the final follow-up on the operational and finance side was very well coordinated and seamless. It's very easy to work with them, and they create a lot of predictability in achieving our desired business outcomes."

"The communication has been great, and we have a very good portal to manage our data on, which altogether works out best for us. We appreciate everything they offer as part of our audit process."

"I truly appreciate Johanson Group's affordable pricing, which was a significant factor in my decision to transition from another provider. Overall, my experience with Johanson Group has been positive, as evidenced by my willingness to rate them a perfect 10 for recommendations."
.avif)
"Johanson Group has performed all of our SOC audits professionally, communicated well during the engagement, and delivered the reports within the expected time frames."

"The auditors we worked with were focused, friendly, and professional. We've spoken to many companies in this area before deciding for Johanson Group."
.png)
"They set clear expectations around the audit process and were very flexible working around our schedules. Johanson Group was a true partner. Very flexible and communicative throughout our audit process.""
.png)
"The coordination from their account management to the actual auditors and then the final follow-up on the operational and finance side was very well coordinated and seamless. It's very easy to work with them, and they create a lot of predictability in achieving our desired business outcomes."

"The communication has been great, and we have a very good portal to manage our data on, which altogether works out best for us. We appreciate everything they offer as part of our audit process."

"I truly appreciate Johanson Group's affordable pricing, which was a significant factor in my decision to transition from another provider. Overall, my experience with Johanson Group has been positive, as evidenced by my willingness to rate them a perfect 10 for recommendations."
.avif)
"Johanson Group has performed all of our SOC audits professionally, communicated well during the engagement, and delivered the reports within the expected time frames."

"The auditors we worked with were focused, friendly, and professional. We've spoken to many companies in this area before deciding for Johanson Group."
.png)
"They set clear expectations around the audit process and were very flexible working around our schedules. Johanson Group was a true partner. Very flexible and communicative throughout our audit process.""
.png)
"The coordination from their account management to the actual auditors and then the final follow-up on the operational and finance side was very well coordinated and seamless. It's very easy to work with them, and they create a lot of predictability in achieving our desired business outcomes."

"The communication has been great, and we have a very good portal to manage our data on, which altogether works out best for us. We appreciate everything they offer as part of our audit process."

"I truly appreciate Johanson Group's affordable pricing, which was a significant factor in my decision to transition from another provider. Overall, my experience with Johanson Group has been positive, as evidenced by my willingness to rate them a perfect 10 for recommendations."
.avif)
"Johanson Group has performed all of our SOC audits professionally, communicated well during the engagement, and delivered the reports within the expected time frames."

"The auditors we worked with were focused, friendly, and professional. We've spoken to many companies in this area before deciding for Johanson Group."
.png)
"They set clear expectations around the audit process and were very flexible working around our schedules. Johanson Group was a true partner. Very flexible and communicative throughout our audit process.""
.png)
"The coordination from their account management to the actual auditors and then the final follow-up on the operational and finance side was very well coordinated and seamless. It's very easy to work with them, and they create a lot of predictability in achieving our desired business outcomes."

"The communication has been great, and we have a very good portal to manage our data on, which altogether works out best for us. We appreciate everything they offer as part of our audit process."

"I truly appreciate Johanson Group's affordable pricing, which was a significant factor in my decision to transition from another provider. Overall, my experience with Johanson Group has been positive, as evidenced by my willingness to rate them a perfect 10 for recommendations."
Frequently asked questions
Your answer not here? Feel free to contact us for more information.
ISO/IEC 27001 is the internationally recognized standard for Information Security Management Systems (ISMS). It's published by the International Organization for Standardization and specifies requirements for establishing, implementing, maintaining, and continuously improving a systematic approach to managing information security risks. You likely need it if enterprise clients are requiring it during vendor onboarding, if you're selling into European or APAC markets, if government or defense contracts require it, or if you want to demonstrate security maturity to investors and partners with a globally recognized credential.
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat. Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur.
The time required to achieve ISO 27001 certification depends largely on an organization's readiness for certification. Once an organization is ready, the certification process typically includes a Stage 1 Audit followed by a Stage 2 Audit. Audit duration is determined by factors such as organizational size, number of locations, and the complexity of the certification scope.
We can provide an estimated certification timeline after reviewing your organization's scope and certification requirements.
The Statement of Applicability (SoA) is one of the most important documents in an ISO 27001 engagement. It lists all 93 Annex A controls from ISO 27001:2022, documents which controls are applicable to your organization, whether each is implemented, and the justification for including or excluding each one.
Auditors use the SoA as a primary reference during Stage 1 and Stage 2. A poorly constructed SoA is one of the most common reasons Stage 1 audits identify issues. We build and review your SoA as part of every pre-certification engagement.
The ISO 27001:2022 update restructured Annex A from 114 controls across 14 control objectives to 93 controls across 4 themes: Organizational, People, Physical, and Technological. It added 11 new controls including threat intelligence, information security for cloud services, data masking, data leakage prevention, web filtering, and secure coding. 57 controls were merged, 23 renamed, 35 remained the same, and 1 was split.
The 2022 version also introduced 5 control attributes for better categorization and aligns more closely with ISO/IEC 27002:2022 and other modern management system standards.
The cost of ISO 27001 certification depends on factors such as organizational size, number of personnel, locations within scope, and the complexity of the activities covered by the ISMS. Audit duration is determined in accordance with established certification requirements and directly influences certification costs.
We provide customized quotations based on your organization's specific certification scope and requirements. Contact us to discuss your needs and receive a proposal.
ISO 27001 certification is valid for three years, but it requires annual surveillance audits in years 1 and 2 to confirm continued compliance and ongoing ISMS improvement. Surveillance audits are lighter than the initial certification audit — they focus on specific areas of the ISMS rather than a full review. In year 3, a full recertification audit renews the certificate for another three-year cycle. Johanson Group manages your full surveillance program so these annual touchpoints are predictable and low-burden for your team.
Yes. ISO 27001 can be applied to organizations with fully remote, hybrid, or office-based workforces. The organization must demonstrate that information security risks associated with remote work are appropriately identified and controlled. Many modern SaaS and technology companies achieve certification while operating entirely remotely.
Yes. Organizations may determine that certain Annex A controls are not applicable based on their scope, activities, technology, and risk assessment results. Any excluded controls must be justified and documented in the Statement of Applicability (SoA). Exclusions cannot be used to avoid addressing relevant risks.
Certified organizations are responsible for notifying Johanson Group of significant changes that may affect their certified management system or certification scope. Examples include:
* Changes to the organization's legal name
* Changes to the organization's registered or certified address
* Addition or closure of locations within the certification scope
* Significant changes to the scope of certification
* Mergers, acquisitions, or ownership changes
* Significant organizational restructuring
* Major changes to products, services, or activities covered by the certification
* Significant changes affecting the effectiveness of the management system
Organizations should communicate these changes as soon as possible so that Johanson Group can determine whether additional review activities, audits, or updates to certification records are required.
Organizations must notify Johanson Group whenever significant changes occur that could affect the certified management system or the scope of certification. Examples include changes to the organization's name, addresses, locations, scope, ownership, or key business activities.
Early notification allows Johanson Group to assess the impact of the change and determine whether additional review activities, special audits, or certificate updates are necessary. Delaying notification may affect the organization's ability to maintain accurate certification records.



.png)
.jpg)
.avif)

