ISO 27001 is an international standard for managing information security. Large customers sometimes ask whether you are certified, or send a questionnaire built around its controls. Certification is a significant undertaking, and most small suppliers do not hold it. The good news is that you can usually answer the questions honestly by describing the controls and practices you do have.
This guide explains what ISO 27001 questions are really checking and how to answer whether or not you are certified.
Draft your answers free →Certification versus the underlying controls
Two different things get bundled together. ISO 27001 certification is a formal audit by an accredited body that confirms you run an information security management system. The controls it references (in an annex often called Annex A) are practical security measures: access control, encryption, supplier management, incident response, and so on. A customer questionnaire usually asks about those controls, and only sometimes requires the certificate itself.
So if you are not certified, do not stop there. Describe the equivalent controls you have in place.
How to answer "Are you ISO 27001 certified?"
Answer honestly. If you are certified, give the certificate number and scope. If you are working towards it, say so with a rough timeframe. If you are not, say that and pivot to the controls you do operate. For example: "We are not ISO 27001 certified. We follow equivalent practices including enforced MFA, encryption, least-privilege access, regular backups, and a documented incident response process."
The control areas customers ask about
ISO 27001-style questionnaires tend to probe these themes, all of which a small business can speak to:
- Information security policies and who owns them.
- Access control and multi-factor authentication.
- Encryption of data in transit and at rest.
- Supplier and sub-processor management.
- Operations security: backups, logging, malware protection, and patching.
- Incident management: detecting, logging, and responding to security events.
- Business continuity: how you keep running and recover after disruption.
- People security: identity and right-to-work checks where appropriate, and staff awareness.
Will they accept an answer without the certificate?
Often yes, especially from a small supplier. Many customers care more that you operate sound controls than that you hold a specific badge. A clear, honest description of equivalent controls, plus Cyber Essentials if you have it, is frequently enough. Where a customer strictly requires ISO 27001, they will usually say so, and you can weigh whether certification is worth pursuing for that relationship.
Do not over-claim
It can be tempting to answer yes to everything in an ISO-shaped form. Resist it. Claiming a control you do not have is the one thing that can genuinely damage a customer relationship if it later matters. Say what you do, flag what you do not, and note any plans. Buyers respect that.
A faster way to answer
Tickbox drafts an answer to each question in your own words, grounded in the frameworks it covers and in any policies you upload, and shows what each answer draws on. It does not issue or imply certification of any kind. You review and send, and your first few answers are free.
Example answers
These are illustrative drafts. Tickbox writes answers like these in your own words, grounded in your policies and the relevant framework.
Frequently asked questions
Can I answer an ISO 27001 questionnaire without being certified?
Yes. Most questions ask about specific controls, which you can describe honestly. Only where a customer strictly requires the certificate itself do you need to hold it.
Is Cyber Essentials the same as ISO 27001?
No. Cyber Essentials is a focused UK baseline of technical controls and is quick and inexpensive. ISO 27001 is a broader international standard covering a full information security management system, and certification is a larger undertaking.
Should a small business get ISO 27001 certified?
Only if customers repeatedly require it, as it is a significant investment of time and money. Many small suppliers win business by describing strong controls and holding Cyber Essentials instead.
More guides
Answer your questionnaire in minutes
Drop it in and Tickbox drafts every answer for you to review. Your first few are free.
Try it free