SRAC Logo
hero-certificate
iso icon

ISO/IEC 27001 Certification - Information security management system

ISO/IEC 27001 is the international benchmark standard for an information security management system (ISMS). Through ISO 27001 certification, your organisation demonstrates that it protects its own information, as well as that of its customers, on the basis of clearly defined policies, procedures and controls, whilst managing security risks in a structured manner. SRAC, a RENAR-accredited certification body (certificate no. SM 004), offers ISO 27001 assessment and certification services that are recognised both nationally and internationally.

Inquiry Form

Do you want to know the certification costs?

Fill in the online form and you will receive our response as soon as possible.

We look forward to having you among SRAC's clients!

Choose
Choose
* required fields

You will receive a response as soon as possible.

What is the ISO 27001 standard?

Before embarking on the implementation and certification process, many organisations wonder what ISO 27001 is and what, exactly, an information security management system entails. ISO/IEC 27001 is the international standard that sets out the requirements for establishing, implementing, maintaining and continuously improving an information security management system, applicable to any organisation that processes or stores information, regardless of its field of activity.

The ISO 27001 standard is based on three properties that define information security: confidentiality (the property of information not being accessible to or disclosed to unauthorised entities), integrity (the property of information being accurate and complete) and availability (the property of information to be accessible and usable on demand by an authorised entity). In practice, ISO 27001 helps organisations to identify security risks, assess them and manage them, thereby demonstrating to stakeholders that sensitive data is protected.

 

ISO/IEC 27001:2022 – current edition

Certification is currently carried out in accordance with ISO/IEC 27001:2022, the third edition of the standard, published in October 2022. In Romania, this has been adopted as SR EN ISO/IEC 27001:2023, the European version transposed at national level. ISO/IEC 27001:2022 retains the high-level structure (Harmonised Structure) common to management standards, which facilitates integration with other systems, such as the ISO 9001 quality management system.

 

What has changed compared with ISO/IEC 27001:2013

The main change in the ISO/IEC 27001:2022 standard concerns Annex A: the number of security controls has been reduced from 114 to 93 and reorganised into four categories – organisational, personnel, physical and technological. Eleven new controls have also been introduced, focusing on current threats (cyber security, cloud services, data protection). The transition period from ISO/IEC 27001:2013 ended on 31 October 2025; consequently, only certificates issued in accordance with the 2022 edition are currently valid, and organisations seeking certification now do so directly against ISO/IEC 27001:2022.

 

The requirements of the ISO 27001 standard

The requirements of ISO 27001 are set out in clauses 4–10 of the standard and define the framework for a functional information security management system:

  • the organisation’s context and the identification of stakeholders;
  • leadership and management commitment, information security policy;
  • assessing and addressing information security risks;
  • setting security objectives and planning how to achieve them;
  • resources, skills, awareness and documented information;
  • implementing security controls and drawing up the Statement of Applicability;
  • performance assessment through monitoring, internal audits and management analysis;
  • continuous improvement, through the resolution of non-conformities and corrective actions.

The controls used to manage information security risks are selected from Annex A of the standard, depending on the risks identified and the specific characteristics of the organisation.

 

The benefits of implementing and obtaining ISO 27001 certification

The implementation and certification of an information security management system bring tangible benefits to any organisation:

  • to instil credibility and confidence in customers, employees, contractual partners and owners that the company’s information and IT systems are protected;
  • proof, for the authorities, that the laws and regulations in force are being complied with, including the requirements relating to the protection of personal data;
  • a business continuity and incident recovery plan appropriate to the organisation;
  • increasing productivity by reducing operational risks and improving the availability of IT systems;
  • strategic differentiation from the competition, both in public procurement procedures and in commercial contracts involving access to sensitive data or state secrets;
  • reducing the likelihood and impact of security incidents, such as cyber-attacks, fraud or data breaches.

 

Is ISO 27001 certification compulsory?

 

From a legal perspective, ISO 27001 certification is not, in general, mandatory. In practice, however, it is increasingly becoming a requirement. Article 32 of the GDPR requires appropriate technical and organisational measures for the security of personal data – this aspect is addressed in ISO 27001 and elaborated on in detail in ISO 27701. Added to these are the requirements of public tenders and procurement, contracts with large clients or those in regulated sectors, and supply chains where suppliers must demonstrate a high level of information security. Thus, although it is not explicitly required by law in most cases, ISO 27001 certification is often a prerequisite for securing contracts and accessing new markets.

 

How can you obtain ISO 27001 certification with SRAC?

The ISO 27001 certification process with SRAC is clear and predictable. Once the information security management system has been implemented, SRAC’s auditors carry out a conformity assessment. SRAC provides ISO 27001 certification for organisations in Romania across all sectors.

 

The stages of ISO 27001 certification and auditing

  1. Auditul ISO 27001 de certificare, include umătoarele etape:
  • analiza documentelor sistemului de management (inclusiv a Declarației de aplicabilitate).
  • etapa 1 in care se evaluează condițiile specifice locației clientului; analizarea stadiului SMSI al solicitantului şi a înţelegerii de către acesta a cerinţelor standardului; evaluarea nivelului de implementare a SMSI etc.
  • etapa 2 în care se determină eficacitatea sistemului de management pentru a asigura faptul că organizația, pe baza evaluarii riscului, a implementat controale aplicabile și a atins obiectivele stabilite de securitatea informațiilor; confirmarea că organizaţia client aderă la politicile, obiectivele şi procedurile proprii și că SMSI este conform cu toate cerinţele standardului ISO/IEC 27001.
  1. Tratarea eventualelor neconformități și implementarea acțiunilor corective.
  2. Emiterea certificatului ISO 27001, valabil 3 an, cu condiția realizării auditurilor anuale de supraveghere.
  3. Auditul de recertificare (reînnoirea certificării), pentru prelungirea valabilității certificatului pentru un nou ciclu de 3 ani.

 

Why SRAC: RENAR accreditation and international recognition by IQNET and IAF

SRAC is accredited by RENAR – the national accreditation body (certificate no. SM 004) – to certify information security management systems in accordance with the reference standard SR EN ISO/IEC 27001:2023.

The SRAC certificate is internationally recognised thanks to its RENAR accreditation – a signatory to the international IAF-MLA agreement and its partnership with IQNET (The International Certification Network).

Organisations certified by SRAC receive both the SRAC certificate and the IQNET certificate at no extra cost. This reassures customers and business partners that the audits have been carried out to the highest standards of impartiality and professionalism, and also facilitates access to foreign markets.

 

Join the leading companies and institutions in Romania that have chosen the SRAC brand: over 10,000 certified organizations / over 25,000 certificates issued in 30 years. From top brands to major public institutions, leading companies have chosen our services.

Choose the leader in certification—Get certified with SRAC!

Portfolio

BITDEFENDER logo
BITDEFENDER
ENDAVA logo
ENDAVA
EUROWEB logo
EUROWEB
INTRAROM logo
INTRAROM
KPMG logo
KPMG
M247 EUROPE logo
M247 EUROPE
NEXTGEN logo
NEXTGEN
NXDATA logo
NXDATA
ROEL logo
ROEL
ROMSYM DATA logo
ROMSYM DATA

 

Frequently Asked Questions about ISO 27001 certification

What does ISO 27001 certification mean?
How much does ISO 27001 certification cost?
How long does it take to obtain ISO 27001 certification?
How long is the ISO 27001 certificate valid for?
Under what accreditation does SRAC issue the ISO 27001 certificate?
Are ISO/IEC 27001:2013 certificates still valid?
Is ISO 27001 certification mandatory?
Can ISO 27001 certification be integrated with other standards?
What is the current situation regarding ISO 27001 certification in Romania and globally?

Vrei să afli prețul pentru certificarea ISO/IEC 27001 sau alte detalii?

Request an offer and you will receive a response as soon as possible.

Courses

Are you interested in courses in the upcoming period?

Check the current month's calendar

or go to the training page.