SaaS · Compliance

ISO 27001 for SaaS — A Field Guide

ISO 27001 certifies that you run a real, risk-driven security management system — not that you ticked a list of controls. Understanding that distinction is half the battle.

John Kihiu12 min read

ISO 27001 is the international standard for information security management, and it is frequently misunderstood as a checklist of controls to implement. It is not. It certifies that you operate an information security management system (ISMS) — a living, risk-driven process for managing security. The controls matter, but the system that decides and maintains them is what is actually certified.

It's a system, not a checklist

The core of ISO 27001 is the ISMS: an ongoing management process that identifies your information-security risks, decides how to treat them, implements controls, and continuously reviews and improves. The standard's well-known Annex A controls are a menu you select from based on your risks — not a mandatory list to blanket-implement. This is why "which controls do we need" is the wrong opening question; the risk assessment answers it.

Risk assessment drives everything

The risk assessment is the engine. You identify your information assets, the threats to them, and the impact if those threats materialise, then decide how to treat each risk — mitigate it with a control, accept it, transfer it, or avoid it. The controls you implement flow from this assessment, which is what makes an ISO 27001 program specific to your business rather than a generic template. Skimp on the risk assessment and the whole system rests on nothing.

What certification takes

  1. Scope the ISMS — define what parts of the business and which assets are covered.
  2. Assess risks and decide treatments; document the controls you will apply.
  3. Implement the controls and the management processes, and run them long enough to produce evidence.
  4. Internal audit and management review — prove the system works, not just that it exists.
  5. External certification audit — a Stage 1 review of documentation, then a Stage 2 audit of operation.

Certification is not a one-off. It requires surveillance audits to maintain and a full recertification periodically, because the standard is about ongoing management, not a moment-in-time snapshot. Budget for the standard being a continuous commitment, not a project with an end date.

The evidence is that it operates over time

Auditors do not just check that a policy exists — they check that it is followed and produces records. A control you wrote down but never operated fails the audit. Build the ISMS far enough ahead of the audit that it has actually run and generated evidence, because ISO 27001 certifies a working system, not a binder of good intentions.

ISO 27001 for SaaS certifies a risk-driven information security management system: a risk assessment that selects your controls, the controls operating in practice, and internal review proving it all works — validated by an external audit and maintained continuously. Approach it as building a real, ongoing security process rather than passing a checklist, and both the certification and the security it represents follow.

John Kihiu
Acumatica ERP Developer · Laravel Engineer

Independent software engineer in Nairobi specialising in Acumatica customisations, Laravel backends, and tax fiscalisation integrations across East and Southern Africa.