Guides

ISO 27001 guides & explainers

Practical, source-backed guides to ISO 27001 costs, timelines, certification-body selection, and certification prep — written for the person who has to get it done.

Certification bodies

How to Choose an ISO 27001 Certification Body: 8 Questions to Ask

The vetting checklist we recommend: accreditation verification, audit teams, audit-day math, fees, and the red flags that signal a bad fit.

September 2026
Fundamentals

ISO 27001 Stage 1 vs Stage 2 Audits: What's Actually Different

Documentation review vs effectiveness testing: what each stage checks, how long each takes, and what sinks companies at each stage.

September 2026
Comparisons

ISO 27001 vs SOC 2: Which One Do Your Customers Actually Need?

Certificate vs attestation report, international vs US expectations, and the combined program that covers both — sequenced honestly.

September 2026
Costs

How ISO 27001 Audit Fees Are Actually Calculated (Audit Days Explained)

ISO/IEC 27006 tables, day rates, and why two CBs quote different fees for the same company — plus how to sanity-check any quote.

September 2026
Accreditation

Accredited vs Non-Accredited ISO 27001 Certificates: The Expensive Mistake

Why the cheaper certificate costs more in the end: procurement rejection, what accreditation actually checks, and how to verify a CB.

September 2026
Fundamentals

ISO 27001:2022 Annex A: The 93 Controls, Grouped for Humans

The 2022 version's four control themes — organizational, people, physical, technological — and the 11 new controls that trip up 2013 holdouts.

September 2026

Reading is step one. Quotes are step two.

When you're ready, get scoped quotes from accredited certification bodies matched to your company.

Get a free quote