Tickbox Draft your answers free
Guide

ISO 27001 questionnaire: how to answer when you are not certified

A customer is asking ISO 27001 questions but you are not certified? You can still answer well. Here is what the questions are getting at and how to respond honestly.

Last updated: July 2026

ISO 27001 is an international standard for managing information security. Large customers sometimes ask whether you are certified, or send a questionnaire built around its controls. Certification is a significant undertaking, and most small suppliers do not hold it. The good news is that you can usually answer the questions honestly by describing the controls and practices you do have.

This guide explains what ISO 27001 questions are really checking and how to answer whether or not you are certified.

Draft your answers free →

Certification versus the underlying controls

Two different things get bundled together. ISO 27001 certification is a formal audit by an accredited body that confirms you run an information security management system. The controls it references (in an annex often called Annex A) are practical security measures: access control, encryption, supplier management, incident response, and so on. A customer questionnaire usually asks about those controls, and only sometimes requires the certificate itself.

So if you are not certified, do not stop there. Describe the equivalent controls you have in place.

How to answer "Are you ISO 27001 certified?"

Answer honestly. If you are certified, give the certificate number and scope. If you are working towards it, say so with a rough timeframe. If you are not, say that and pivot to the controls you do operate. For example: "We are not ISO 27001 certified. We follow equivalent practices including enforced MFA, encryption, least-privilege access, regular backups, and a documented incident response process."

The control areas customers ask about

ISO 27001-style questionnaires tend to probe these themes, all of which a small business can speak to:

Will they accept an answer without the certificate?

Often yes, especially from a small supplier. Many customers care more that you operate sound controls than that you hold a specific badge. A clear, honest description of equivalent controls, plus Cyber Essentials if you have it, is frequently enough. Where a customer strictly requires ISO 27001, they will usually say so, and you can weigh whether certification is worth pursuing for that relationship.

Do not over-claim

It can be tempting to answer yes to everything in an ISO-shaped form. Resist it. Claiming a control you do not have is the one thing that can genuinely damage a customer relationship if it later matters. Say what you do, flag what you do not, and note any plans. Buyers respect that.

A faster way to answer

Tickbox drafts an answer to each question in your own words, grounded in the frameworks it covers and in any policies you upload, and shows what each answer draws on. It does not issue or imply certification of any kind. You review and send, and your first few answers are free.

Example answers

Are you certified to ISO 27001?
We are not currently certified to ISO 27001. We operate equivalent controls, including enforced multi-factor authentication, encryption in transit and at rest, least-privilege access, regular tested backups, and a documented incident response process.
Do you have an information security policy?
Yes. We maintain an information security policy covering access control, acceptable use, data handling, and incident response. It is owned by the person responsible for security in our business and reviewed periodically.
How do you manage information security risks?
We identify the main risks to the information we hold, put proportionate controls in place, and review them periodically and when something significant changes. Where we find a gap, we agree an action and a timeframe to address it.
How do you manage security incidents?
We log suspected incidents as soon as they are identified, assess the impact, contain and resolve the issue, and notify affected customers and, where personal data is involved and required, the ICO within 72 hours. We review incidents afterwards to prevent recurrence.
How do you ensure business continuity?
Our key systems run on reputable cloud services with built-in resilience, our data is backed up and recoverable, and we have a plan for continuing to operate and communicate with customers during a disruption.

These are illustrative drafts. Tickbox writes answers like these in your own words, grounded in your policies and the relevant framework.

Frequently asked questions

Can I answer an ISO 27001 questionnaire without being certified?

Yes. Most questions ask about specific controls, which you can describe honestly. Only where a customer strictly requires the certificate itself do you need to hold it.

Is Cyber Essentials the same as ISO 27001?

No. Cyber Essentials is a focused UK baseline of technical controls and is quick and inexpensive. ISO 27001 is a broader international standard covering a full information security management system, and certification is a larger undertaking.

Should a small business get ISO 27001 certified?

Only if customers repeatedly require it, as it is a significant investment of time and money. Many small suppliers win business by describing strong controls and holding Cyber Essentials instead.

More guides

Answer your questionnaire in minutes

Drop it in and Tickbox drafts every answer for you to review. Your first few are free.

Try it free