FillTrust

How to answer

Do you hold ISO 27001 certification?

One of the few questions where the answer is usually no, and where no is a perfectly good answer.

A model answerAnswered “no” from your documents

No. We are not currently ISO 27001 certified. We hold a SOC 2 Type II report covering [Security and Availability], which is available under NDA and addresses the same control areas.

Square brackets are yours to fill in. FillTrust grades an answer like this answered “no” from your documents when your documents support it.

Answered from
Your certificate if you hold one, and your SOC 2 report if you hold that instead.
Evidence to attach
The certificate itself, which is a public document and can be shared without an NDA. The Statement of Applicability is sometimes requested and usually goes under NDA.
Where it is asked
CAIQ v4.0 · A&A-02SIG LiteISO 27001

Most companies under about fifty people do not hold ISO 27001, and reviewers know that. What they are checking is whether you know your own position and whether you have something else.

There is no partial state. "ISO 27001 aligned", "compliant", "working toward" and "implementing the framework" are all ways of not saying no, and they are read that way. The one useful version is a fact with a date: "not certified; we are in the process, with the Stage 1 audit scheduled for Q2" is worth saying because it is checkable. Everything else is worse than the plain answer.

Scope decides a yes. If you are certified, the reviewer's next question is the scope statement on the certificate: which legal entity, which locations, which services. A group certificate covering a parent company's headquarters does not cover a product built by a subsidiary, and answering yes on that basis is the kind of finding that ends a procurement conversation rather than continuing it.

A no is much better with a companion. SOC 2 Type II is the usual alternative and, for a North American buyer, often the preferred one. Naming it in the same breath turns "no" into "no, and here is the equivalent assurance". If you have neither, the honest structure is still the same: no, and here is what we do have, which might be a completed CAIQ, a pen test summary and a documented policy set.

The two are not interchangeable, and saying so helps. ISO 27001 certifies that a management system exists and is audited against a standard. SOC 2 attests that specific controls operated over a period. Reviewers who ask for one will often accept the other, and briefly naming the difference is the kind of answer that makes the rest of your questionnaire more credible.

This question grades as a confident no for most teams, which is a completed row, not a gap. The row that actually needs attention is the one after it, asking what you have instead.

How this one goes wrong

Specific to this question, not general advice.

  • Saying you are "ISO 27001 compliant". There is no such status. You are certified or you are not, and the phrase reads to an auditor as an attempt to sound like both.
  • Answering yes when the certificate covers a different legal entity or a scope that excludes the product being assessed. Scope is the first thing a reviewer checks.
  • Treating a no as a problem to be talked around. A clear no with what you do have instead is a finished answer.

There are another two hundred of these in the file.

FillTrust drafts every one from your own documents and shows the passage behind each answer, including the ones it refuses to answer.

Or write this answer down once and publish it on a Trust Center of your own, which costs nothing.