ISO/IEC 27001 has become a commercial requirement. It is not an auditor who asks for it: it is the large client that is about to hire you, or the tender you want to bid for. That is, almost always, the honest reason for getting certified.
What it is and what it is not
It is not a list of technical measures you install. It is a management system: a way of identifying what information you hold, what risks it runs, what you do about it and how you check that it is still being done. The technical side is a consequence, not the starting point.
What it involves in practice
- Defining the scope: which part of the company gets certified. Starting with everything is usually a mistake.
- Un risk assessment that is real, not copied off a template.
- Policies and procedures that are actually going to be followed. The ones that are not get spotted at the very first audit.
- Implementing the controls that come out of the assessment: access, backups, event logging, supplier management, training.
- Internal audit, management review and a certification audit with an accredited body.
- And afterwards: annual surveillance audits. A management system left in a drawer collapses on its own.
ISO 27001, ENS and NIS2: how they relate
- ISO 27001 is voluntary and works as a commercial argument in any sector.
- ENS (the Spanish ENS scheme, Esquema Nacional de Seguridad) is mandatory in order to work with the Spanish public sector.
- NIS2 is the European directive, and it reaches more companies than it seems: many are caught by it because they supply another company that is in scope.
They share a good deal of the work. If you know you are going to need two of them, it is worth planning them together from the start instead of doing the same job twice.
The useful question is not “should I get certified?” but “how much business am I losing by not being certified?”. With that number, the decision makes itself.



