Don’t panic, and don’t go quiet. Most customers asking for ISO 27001 will accept a committed certification date plus evidence of the security you run today — they rarely need the certificate this week. Reply promptly, ask exactly what they need, send what you have, and commit to a date you can defend.
The email landed this week and it reads like a demand: “Please confirm your ISO 27001 certification status.” Before you spend a weekend pricing consultants, work out what’s actually being asked — because “ISO 27001” in a customer email means different things depending on who sent it and why.
| What the email says | What they usually need |
|---|---|
| “Are you ISO 27001 certified?” | A yes/no for a procurement checklist. A committed certification date plus current evidence often satisfies it. |
| “Please complete the attached security questionnaire” | Honest answers about the controls you run today. The certificate is one question among dozens — see what to do when a questionnaire is blocking a deal. |
| “Certification is required under our supplier policy” | A firm requirement — but ask whether “certified” or “certified within an agreed period” is the contractual test. Many supplier policies allow the latter. |
| “Our security team would like to review your controls” | A conversation, not a certificate. Evidence of logging, monitoring, access control and incident handling, presented by someone who can answer questions. |
The pattern across all four: the customer’s security or procurement team needs to close a risk question about you. A certificate closes it fastest, but it’s rarely the only thing that closes it. Audit-ready evidence and a committed date close it too — this quarter, not next year.
The deal stalls on silence, not on the missing certificate. Reply within days, not weeks, and cover four things.
Acknowledge and ask. Confirm you’ve received the request and ask precisely what they need to progress: certificate, questionnaire, evidence pack, or a call with their security team. You’ll often find the bar is lower than the email implied.
State what’s true today. List the security you actually run — access controls, logging, backups, vulnerability management, incident response — plainly and without inflation. Don’t claim “compliance”. Claim what exists.
Commit to a date you can defend. “We are working toward ISO 27001 certification, with Stage 2 scheduled for the June quarter” holds a deal open. A date you miss reopens the risk question with interest, so scope it properly first — what certification costs and how long it takes are both knowable before you reply.
Offer their security team a direct line. A supplier who says “here’s our security lead, ask anything” reads as lower risk than one who sends a polished PDF and goes quiet.
You don’t need the full picture to reply to the customer, but you need enough to commit to a date honestly.
ISO 27001:2022 certifies an information security management system. Annex A lists 93 controls across four themes — organisational, people, physical, technological — and the standard is risk-based: you assess all 93 and document which apply to you in a Statement of Applicability. Certification itself is a two-stage audit by an accredited certification body: Stage 1 reviews your documentation, Stage 2 tests evidence and interviews your people. After that, surveillance audits run annually and full recertification every three years — so the date you give your customer is the start of an obligation, not the end of a project.
The two questions every buyer asks next — what it costs and how long it takes — each have their own page: the real cost of ISO 27001 in Australia and the certification timeline. Read both before you put a date in writing.
The instinct is to treat the email as a compliance problem and disappear to solve it. So the founder buys a platform subscription, gets handed a 90-item control checklist, and goes dark on the customer for six weeks while trying to staff it. “The compliance tool handed me a to-do list I can’t staff” is how that reads from the inside. From the customer’s side it reads worse: an unanswered risk question, and a supplier who might be hiding something.
Treat it as a sales problem with a compliance workstream inside it. The reply keeps the deal alive; the certification plan makes the reply true. Do them in that order.
Tools hand you a to-do list. We do the list — and run the security behind it. When a customer request lands, we scope what your certification actually takes, give you a date you can put in writing, and build the ISMS with the governance and evidence kept live — while the logging, monitoring and vulnerability management your auditor will test runs on our platform underneath. We’re ISO 27001:2022 certified ourselves. The certificate is issued by an accredited certification body, not by us; our job is making sure you walk into that audit ready.
Does the customer need our certificate before they'll sign?
Usually not. Most procurement and security teams are assessing risk, and will hold a deal open on a committed certification date plus evidence of the controls you run now. Ask them directly — ‘certified before signature’ is rarer than the email makes it sound.
Can we tell the customer we're 'ISO 27001 compliant' without being certified?
No. ‘Compliant’ or ‘aligned’ without a certificate is a claim you can’t back, and a security team will ask for the certificate number. Say what’s true: which controls you run today, and the date you’ve committed to certification.
Who actually issues the ISO 27001 certificate?
An accredited certification body, through a Stage 1 documentation review and a Stage 2 audit of evidence and interviews. Consultants and providers — Secure60 included — prepare you for that audit; they don’t issue the certificate.
We have SOC 2. Does that answer an ISO 27001 request?
Sometimes. SOC 2 is a US-market attestation report and ISO 27001 is the international certification, and they cover similar ground. Some customers accept one for the other; others won’t. Ask yours. Secure60 focuses on ISO 27001 — see SOC 2 vs ISO 27001 for Australian companies.
What should we send while we're not yet certified?
Whatever is real: your security policies, an outline of how you handle access, logging, vulnerabilities and incidents, and your certification plan with a date. Evidence of running controls carries more weight than a promise of future ones.
What does certification cost and how long does it take?
At Australian market rates, budget across implementation, a platform and the audit — the full breakdown is in our cost guide. Timeline depends on your starting point; see how long certification takes.