

ISO/IEC 27001 is the international benchmark standard for an information security management system (ISMS). Through ISO 27001 certification, your organisation demonstrates that it protects its own information, as well as that of its customers, on the basis of clearly defined policies, procedures and controls, whilst managing security risks in a structured manner. SRAC, a RENAR-accredited certification body (certificate no. SM 004), offers ISO 27001 assessment and certification services that are recognised both nationally and internationally.
Before embarking on the implementation and certification process, many organisations wonder what ISO 27001 is and what, exactly, an information security management system entails. ISO/IEC 27001 is the international standard that sets out the requirements for establishing, implementing, maintaining and continuously improving an information security management system, applicable to any organisation that processes or stores information, regardless of its field of activity.
The ISO 27001 standard is based on three properties that define information security: confidentiality (the property of information not being accessible to or disclosed to unauthorised entities), integrity (the property of information being accurate and complete) and availability (the property of information to be accessible and usable on demand by an authorised entity). In practice, ISO 27001 helps organisations to identify security risks, assess them and manage them, thereby demonstrating to stakeholders that sensitive data is protected.
Certification is currently carried out in accordance with ISO/IEC 27001:2022, the third edition of the standard, published in October 2022. In Romania, this has been adopted as SR EN ISO/IEC 27001:2023, the European version transposed at national level. ISO/IEC 27001:2022 retains the high-level structure (Harmonised Structure) common to management standards, which facilitates integration with other systems, such as the ISO 9001 quality management system.
The main change in the ISO/IEC 27001:2022 standard concerns Annex A: the number of security controls has been reduced from 114 to 93 and reorganised into four categories – organisational, personnel, physical and technological. Eleven new controls have also been introduced, focusing on current threats (cyber security, cloud services, data protection). The transition period from ISO/IEC 27001:2013 ended on 31 October 2025; consequently, only certificates issued in accordance with the 2022 edition are currently valid, and organisations seeking certification now do so directly against ISO/IEC 27001:2022.
The requirements of ISO 27001 are set out in clauses 4–10 of the standard and define the framework for a functional information security management system:
The controls used to manage information security risks are selected from Annex A of the standard, depending on the risks identified and the specific characteristics of the organisation.
The implementation and certification of an information security management system bring tangible benefits to any organisation:
From a legal perspective, ISO 27001 certification is not, in general, mandatory. In practice, however, it is increasingly becoming a requirement. Article 32 of the GDPR requires appropriate technical and organisational measures for the security of personal data – this aspect is addressed in ISO 27001 and elaborated on in detail in ISO 27701. Added to these are the requirements of public tenders and procurement, contracts with large clients or those in regulated sectors, and supply chains where suppliers must demonstrate a high level of information security. Thus, although it is not explicitly required by law in most cases, ISO 27001 certification is often a prerequisite for securing contracts and accessing new markets.
The ISO 27001 certification process with SRAC is clear and predictable. Once the information security management system has been implemented, SRAC’s auditors carry out a conformity assessment. SRAC provides ISO 27001 certification for organisations in Romania across all sectors.
SRAC is accredited by RENAR – the national accreditation body (certificate no. SM 004) – to certify information security management systems in accordance with the reference standard SR EN ISO/IEC 27001:2023.
The SRAC certificate is internationally recognised thanks to its RENAR accreditation – a signatory to the international IAF-MLA agreement and its partnership with IQNET (The International Certification Network).
Organisations certified by SRAC receive both the SRAC certificate and the IQNET certificate at no extra cost. This reassures customers and business partners that the audits have been carried out to the highest standards of impartiality and professionalism, and also facilitates access to foreign markets.
Join the leading companies and institutions in Romania that have chosen the SRAC brand: over 10,000 certified organizations / over 25,000 certificates issued in 30 years. From top brands to major public institutions, leading companies have chosen our services.
Choose the leader in certification—Get certified with SRAC!










Vrei să afli prețul pentru certificarea ISO/IEC 27001 sau alte detalii?
Request an offer and you will receive a response as soon as possible.
Courses
Are you interested in courses in the upcoming period?
Check the current month's calendar
or go to the training page.