forumNew topic

A large enterprise client is demanding an ISO 27001 certificate from us, what exactly is this and is it really necessary?

SSena Y***Member
Job title
Front office accounting
Sector
Healthcare services
Organization type
chain store
Joined
May 2023
Message
205
#1

We are a 9-person software agency based in Barcelona, developing custom e-commerce integrations and microservices architectures for fintech and retail. We were negotiating an annual software development and maintenance contract worth 120,000 euros with a major retail chain operating across Spain. Yesterday, their procurement team sent over a vendor security questionnaire asking whether we hold an ISO 27001 certification, and if not, by when we plan to obtain it.

When we told them we don't have the certificate, they stated that this standard is an internal requirement for all external vendors accessing customer data and building integrations, and that otherwise the contract cannot be approved. Internally, we do use two-factor authentication, encrypted databases, and version control, but we have never been through a formal audit process like this before.

What exactly is ISO 27001, and is it strictly about technical server infrastructure? Is getting certified feasible for a small team of 9, how long does it take, and what would it cost? Is there an interim solution we could propose to the client without losing this deal?

KKader K***MemberCommunity member
Joined
Apr 2024
Message
393
Most Helpful#2

Short answer: ISO 27001 is the international framework for establishing an Information Security Management System (ISMS) to secure a company's information assets. It doesn't just cover technical or server security; it encompasses all company operations, from human resources and physical office security to business continuity and contract management.

Basically, the standard requires you to set up the following: 1) A risk assessment methodology identifying all company information assets and potential threats, 2) Access control matrices, password policies, and data classification rules, 3) Secure coding practices and incident response plans. In other words, it's not just putting a firewall on a server; it's documenting and auditing every single step, from how an employee's access is revoked upon leaving the company to how external drives are disposed of.

Getting certified is definitely feasible for a 9-person software agency, and it actually wraps up much faster than in large corporate environments. The process usually takes between 4 to 6 months. In the Spanish market, the cost for an accredited certification body's initial three-year audit cycle runs around 4,000 to 7,000 euros; if you hire an independent consultant to guide the process, that will add another 5,000 to 8,000 euros in consulting fees.

To avoid losing the sale immediately, you can approach the client with this proposal: provide a management commitment letter stating you have kicked off certification prep, alongside your consulting agreement and a roadmap detailing the audit timeline. When corporate procurement teams see that the process has officially started and will be completed within 6 months, they can often sign off by adding a conditional approval clause to the contract.

Edit: asked below, I wrote the answer in the second message.

MMurat Ç***Expert
Job title
Project manager
Sector
Accounting & advisory
Organization type
medium-sized business
Joined
Oct 2022
Message
246
#3

Whatever you do, don't just cut the conversation short with "we don't have this certificate." A lot of big enterprises will grant provisional approval if you tell them, "We've initiated our ISO 27001 compliance project with a target audit date in 6 months," and back it up with your current baseline security policies.

TTuğçe K***New memberCommunity member
Joined
Sep 2026
Message
310
#4

In the latest ISO/IEC 27001:2022 revision, the Annex A controls were streamlined down to 93 items. As a software agency, what will concern you most are the secure software development lifecycle (SDLC), source code repository access logs, test data anonymization, and separating production from development environments.

KKader U***Member
Job title
Store associate
Sector
Media and publishing
Organization type
family business
Joined
Jun 2024
Message
86
#5

We got certified last year with an 11-person team in Madrid. We paid 5,000 euros to an external consultant and 3,500 euros to the accredited audit firm for the first year. The whole thing took 5 months. It might look pricey, but for a 120,000 euro annual contract, that investment definitely pays for itself.

NNeslihan E***Member
Job title
Board member
Sector
Security services
Organization type
8-person team
Joined
Apr 2025
Message
35

Doki · Corporate website · 2023

#6

If you're doing this just for a single client think twice imo. This isn't a piece of paper you get once and hang on the wall; there's a surveillance audit every year and you have to pay for it. Constantly keeping records and filling out risk forms seriously slows down the dev workflow in a 9-person shop.

AAytenNew member
Job title
Home cooking
Organization type
8-person team
Joined
Nov 2024
Message
28
#7

Looking at hundreds of pages of standard clauses is pretty intimidating at first. But once you dive in, you realize it's mostly about formalizing procedures that any software team taking its work seriously is already doing informally anyway.

MMustafa Ç***Member
Job title
Clinic manager
Sector
Glass
Organization type
two-branch business
Joined
Oct 2022
Message
49
#8

What exact data will you be accessing in the client's system? If you are only running code on their servers and not hosting client data in your own office, you might be able to narrow down the audit scope and cut both the timeline and costs in half.

MMert E***MemberCommunity member
Joined
Sep 2024
Message
28
#9

we went through the exact same thing with a telecom client, patched up our vulnerabilities, handed over a third-party pentest report, and bought ourselves 6 months and definitely dont walk away from the deal just yet.

ZZehra K***MemberCommunity member
Joined
Mar 2025
Message
86
#10

In the Spanish market, enterprises and public entities treat ISO 27001 as a mandatory baseline for vendor security. Achieving this certification is a strategic move that will provide a competitive advantage in your future enterprise sales pipelines.

DDoruk A***Member
Job title
General coordinator
Sector
Automotive aftermarket
Organization type
20-person company
Joined
Oct 2022
Message
18

Doki · Penetration test · 2024

#11

Let me share what happened to me; it might be useful. I mean when we decide without measuring, we always end up in the same place.

If I were you Id go this route.

CCansu K***Member
Job title
Logistics planning
Sector
Printing
Organization type
sole proprietorship
Joined
Sep 2023
Message
1

Doki · Backup setup · 2023

#12

I partly agree, partly disagree. Any unwritten clause becomes a point of disagreement later, as both sides remember it differently.

Good luck with that.

RRecep Y***Member
Job title
Data entry clerk
Sector
Jewelry
Organization type
workshop
Joined
May 2025
Message
3
#13

Just a heads-up. If the notification path is long notifications don't arrive; missing notifications mean delayed incident detection.

Good luck with that.

SSerkan U***Member
Job title
Site Manager
Sector
Education
Organization type
medium-sized business
Joined
May 2025
Message
312
#14

I'm writing this so you don't make the same mistake. An automated scan report is not the same as a penetration test.

Just leaving this note, it might be useful.

AAleynaNew member
Job title
Social media specialist
Joined
Sep 2024
Message
48
#15

to get into the details: If the notification path is long notifications don't arrive; missing notifications mean delayed incident detection.

solutions that work at a small scale collapse when you grow; I learned this late but just leaving this note it might be useful.

LLeyla Ö***MemberCommunity member
Joined
Feb 2025
Message
38
#16

Same here. The biggest time-waster for us was not knowing who had the final say.

If you get three different answers on a topic, the question was asked wrong.

RRamazan T***MemberCommunity member
Joined
Sep 2023
Message
262
#17

We need to make a distinction here. Mistakes made on the what is ISO 27001 side are usually reversible but expensive.

If you post the result here, it will help others too.

PPolat G***Member
Job title
Chief Technology Officer
Sector
Printing
Organization type
8-person team
Joined
Aug 2023
Message
275
#18

Timely topic.

CCem I***MemberCommunity member
Joined
Sep 2025
Message
4
#19

Looking at it as a process, the picture changes. Don't rely on a single measure; go layer by layer.

Correct me if I'm wrong.

HHüseyin U***Member
Job title
Content Editor
Sector
Tourism
Organization type
early-stage startup
Joined
Jun 2023
Message
107
#20

It's rare to find an explanation this clear... Your time to detect an issue directly determines its cost.

Proven by experience.

Reply