What to provide
If a vendor you’re assessing is ISO 27001 certified, the recommended evidence package is:- Provide the vendor’s current ISO 27001 certificate and Statement of Applicability (SoA).
- If the certificate’s issuance or re-issuance date is more than one year old, evidence of the vendor’s latest successful surveillance audit.
Why an ISO 27001 certificate alone isn’t enough
ISO 27001 is a leading international standard for information security management. When a vendor is certified, an independent certification body has confirmed that it operates an Information Security Management System (ISMS) that meets the standard. That is meaningful, but the certificate alone may not provide all the information needed to complete a security assessment. Additional documentation helps confirm what the certification covers, which security controls are applicable, and whether the certification continues to be maintained.What the certificate does — and doesn’t — tell you
Think of the certificate as a badge. It confirms that a certified ISMS exists. It does not describe which security controls are applicable within the vendor’s ISMS, whether the certified scope covers the service you use, or whether the certification continues to be maintained. Supporting documentation provides that context.What documents may be required
When a vendor is ISO 27001 certified, obtain the following:ISO 27001 Certificate
The certificate confirms the vendor’s certification and identifies the scope covered by the certified ISMS.Statement of Applicability (SoA)
The SoA identifies the security controls the vendor has determined are applicable to its ISMS, as well as controls that have been excluded and the justification for those exclusions. It provides additional visibility into the security control coverage behind the certification.Surveillance Audit Evidence, when applicable
ISO 27001 certification operates on a three-year certification cycle, with surveillance audits conducted in between. If the certificate’s issuance or re-issuance date is more than one year old, obtaining evidence of a successful surveillance audit is recommended to confirm the certification continues to be maintained. A surveillance audit report is also accepted in place of a current SoA when the vendor is mid-cycle.ISO 27001 by the numbers
- The 2022 revision defines 93 Annex A controls across four themes — organizational, people, physical, and technological. The SoA must address all 93 (each marked applicable or excluded, with justification) and is a mandatory part of certification under clause 6.1.3, which is why it is a reasonable request.
- A certificate reflects a point in time. The annual surveillance audit is what keeps it valid between the three-yearly recertifications, which is why “current and maintained” matters as much as “certified.”