More and more contracts require the supplier to hold ISO 27001 certification: those of public authorities, those of large clients that pass their cybersecurity obligations down their supply chain, and those of any organisation that processes third-party data. At CEDESA we have been through that process and we maintain the certification alongside certification under Spain’s National Security Framework (Esquema Nacional de Seguridad, ENS), ISO 9001 and ISO 56001, so we know the route from the inside. This guide explains, step by step, how to implement the standard in a Spanish company: what it requires, how much real work it involves, how certification works and how it fits with the ENS. If what you want is to understand what an external supplier’s certificate guarantees, we have a separate guide on what ISO 27001 certifies in a software supplier.
What is ISO/IEC 27001 and what does it require?
ISO/IEC 27001 is the international standard that specifies the requirements for an information security management system (ISMS): the set of policies, processes, roles and controls with which an organisation protects the confidentiality, integrity and availability of its information. The current version dates from 2022; the transition period from the 2013 version ended on 31 October 2025, so today every certificate is issued and audited against the 2022 standard.
The standard has two parts:
- The management system requirements (clauses 4 to 10): context of the organisation, leadership, planning, support, operation, performance evaluation and improvement. These are mandatory and cannot be excluded.
- Annex A, with 93 reference controls grouped into four themes: organisational (37), people (8), physical (14) and technological (34). Implementing all of them is not mandatory: the organisation decides which ones apply on the basis of its risk analysis and justifies the decision in the statement of applicability. ISO/IEC 27002 explains how to implement each control.
The underlying idea is that security is managed like any other business process: risks are identified, decisions are taken on what to do about them, controls are implemented, their effectiveness is measured and improvements are made. The certificate attests that this cycle exists and works, not that the company is invulnerable.
Who needs it in Spain
It is not required by law, but in practice the demand for it comes from:
- Public authorities, in many tender specifications, as a technical capacity criterion or as a requirement for the successful bidder, often together with ENS certification. We explain this in the guide on how to prepare technical specifications for software with ENS requirements.
- Large clients, which pass the security requirements of their own supply chain on to their suppliers; the NIS2 Directive, Directive (EU) 2022/2555, reinforces that trend in the essential and important sectors.
- Companies that process third parties’ personal data: a certified ISMS is a recognised way of demonstrating the technical and organisational measures required by Article 32 of the GDPR.
- Software and cloud service companies, for which certification has become a basic commercial requirement.
Implementation step by step
Step 1. Define the scope and the context
The scope defines which part of the organisation, which processes, which sites and which systems the ISMS covers. Too narrow a scope produces a certificate that is no use for the contracts you want to win; too broad a scope multiplies the work. It is best to align it with what clients are going to ask for: at CEDESA the scope covers all the systems we develop and our clients’ data, because that is what public authorities and client companies want to see. This is also the stage at which the interested parties (clients, regulators, employees, suppliers) and the applicable legal and contractual requirements are identified.
Step 2. Senior management commitment and the security policy
The standard requires senior management to lead the system: to approve the information security policy, assign roles and responsibilities and provide resources. Without that commitment the project turns into a paper exercise for the IT department and will not pass the certification audit, which includes interviews with senior management.
Step 3. Asset inventory and risk analysis
The information assets (systems, data, people, premises, suppliers) are inventoried and a risk analysis methodology is defined: identifying threats and vulnerabilities, assessing likelihood and impact, and setting acceptance criteria. In Spain it is common to rely on MAGERIT (the Spanish government’s own risk analysis methodology), which also makes it easier to align with the ENS. The result is a prioritised risk register and a treatment plan: which risks are mitigated with controls, which are transferred, which are avoided and which are accepted.
Step 4. Statement of applicability and treatment plan
The statement of applicability goes through the 93 Annex A controls and states, for each one, whether it applies, why and how it is implemented, or why it is excluded. It is the document the auditor will use as a map. The risk treatment plan sets owners, deadlines and resources for implementing the controls that are missing.
Step 5. Implement the controls and the documentation
This is the longest stage. It covers organisational controls (policies, supplier management, information classification, incident management, continuity), people controls (recruitment, awareness, confidentiality agreements, disciplinary process), physical controls (perimeters, access control, protection of equipment) and technological controls (identity and privilege management, encryption, backups, event logging, vulnerability management, secure development, cloud security). The documentation should be what the system needs in order to work, not a lever arch file for the auditor; the standard requires specific documented information, but not any particular volume.
Step 6. Training and awareness
All staff within the scope must know the policy, their responsibilities and what to do in the event of an incident. The audit checks this by interviewing employees at different levels, not only the security officer.
Step 7. Measure, audit internally and carry out the management review
Before certification, at least one full cycle must have been completed: indicators defined and measured, an internal audit carried out by someone independent of the area being audited, and a management review with its decisions recorded. Any nonconformities found are dealt with through documented corrective actions. Without evidence of this cycle, the certification audit cannot conclude that the system is operating.
Step 8. Certification
Certification is issued by an accredited certification body; in Spain, accreditation is granted by ENAC (Spain’s national accreditation body), and it is worth checking that the body you choose is accredited specifically for ISO/IEC 27001. The process has two stages: the stage 1 audit reviews the documentation and readiness; the stage 2 audit verifies in practice that the controls are implemented and working. Any major nonconformities must be closed before the certificate is issued. The certificate is valid for three years, with annual surveillance audits and a renewal audit at the end of the cycle.
ISO 27001 and the ENS: how they relate
In Spain the question comes up in every public sector project: is ISO 27001 enough, or is ENS certification needed as well? They are different things, and complementary:
- ISO 27001 is a voluntary international standard that certifies a management system. It sets the method, not the specific measures: each organisation chooses its controls on the basis of its risks.
- The National Security Framework, governed by Royal Decree 311/2022 (Real Decreto 311/2022), is a piece of Spanish legislation that is mandatory for the information systems of public authorities and of the suppliers that provide services to them. It sets a catalogue of specific measures according to the category of the system (basic, medium or high) and is certified by accredited bodies, under the supervision of the National Cryptologic Centre (CCN).
A well-built ISMS makes ENS conformity much easier, because the risk analysis, incident management, supplier management and a good part of the technological controls are common to both; the CCN publishes guides that map one framework onto the other. But one certificate does not replace the other: to contract with the public sector you need ENS certification, and ISO 27001 is asked for in addition, as evidence of maturity. At CEDESA we maintain both certifications, together with ISO 9001 and ISO 56001, and we explain what changes with the size of the supplier in our comparison of large integrator or mid-sized company.
Common implementation mistakes
- Buying a pack of templates and filling them in. The auditor spots in the first interview that the policies are not being applied. The documentation must describe what the company actually does.
- Leaving everything to IT. ISO 27001 is a management system for the whole organisation; HR, purchasing, senior management and operations all have controls of their own.
- A risk analysis that drives nothing. If the statement of applicability does not follow from the risk analysis, the system is not coherent and the auditor will say so.
- Choosing the wrong scope. Certifying only a secondary system for the sake of having the badge ends in contracts that require a scope the company does not have.
- Reaching certification without a completed cycle. Without an internal audit and a management review backed by evidence, there is no certificate.
- Forgetting about maintenance. The annual surveillance audits require the system to stay alive: indicators kept up to date, risks reviewed, incidents managed.
Frequently asked questions about implementing ISO 27001
How long does it take to implement ISO 27001?
It depends on the size of the organisation, the scope and the starting level of maturity. A small company whose processes are already in good order can complete the implementation and achieve certification in under a year; a complex organisation, or one starting from scratch, needs longer. What cannot be shortened is the minimum operating cycle before the audit: measured indicators, an internal audit and a management review.
Is it mandatory to implement all 93 Annex A controls?
No. The Annex A controls are a reference set. The organisation decides which ones apply on the basis of its risk analysis and justifies both the inclusions and the exclusions in the statement of applicability. What is mandatory are the requirements in clauses 4 to 10 of the standard.
Is ISO 27001 of any use for contracting with the Spanish public sector?
It helps and is often required, but it is no substitute for the National Security Framework, which is mandatory for suppliers of information systems to public authorities under Royal Decree 311/2022. The usual approach in tender specifications is to require ENS certification and to give credit for ISO 27001 as well.
Who can issue ISO 27001 certification in Spain?
Any certification body accredited for that standard. In Spain accreditation is granted by ENAC; bodies accredited by the accreditation bodies of other countries that have signed the international recognition agreements are also accepted. It is worth checking in the accreditation body’s register that the certification body is accredited specifically for ISO/IEC 27001.
What is the difference between the 2013 and 2022 versions of ISO 27001?
The 2022 version reorganised Annex A: it went from 114 controls in 14 domains to 93 controls in 4 themes, added new controls on threat intelligence, cloud security, ICT continuity, web filtering, secure coding and others, and made slight adjustments to the management system clauses. Since 31 October 2025, only certification against the 2022 version has been valid.
Conclusion
Implementing ISO 27001 in a Spanish company is an organisational project before it is a technology one: defining the scope properly, analysing the risks, choosing and justifying the controls, training staff and completing a full cycle of measurement and improvement before the audit. For anyone who works with the public sector, the natural route is to build the ISMS so that it serves for the ENS as well. If you need a software supplier that has already travelled that road and develops with security built in from the design stage, we at CEDESA will be glad to help; write to us via our contact page.