No: in the vast majority of cases, ISO 27001 certification is not a prerequisite for answering a security questionnaire. It shortens the demonstration; it does not replace it. Without certification, you answer just as seriously by relying on dated documents and verifiable supporting evidence, as long as you say what you actually do rather than checking what you would like to do.

What ISO 27001 is

ISO/IEC 27001 is the international reference standard for information security management. Published by the International Organization for Standardization (ISO) with the International Electrotechnical Commission (IEC), in its 2022 revised version, it describes how to set up and run an information security management system: an organized framework, not a simple list of technical measures.

In practice, the standard asks you to define a scope, identify the risks to your information, choose measures to reduce them, then check and improve the setup over time. An annex lists security controls grouped by broad themes: organizational, people, physical, technological.

Being “ISO 27001 certified” means an independent, accredited body has audited this system and attested that it meets the standard, for a given scope. It is that last point, the scope, that matters most when a customer assesses you.

An ISO 27001 certificate always states the scope covered. It attests to the conformity of a management system for that precise scope, not the security of the entire company.

Principle of ISO certification

What certification actually changes

When it exists and covers the right scope, certification saves you time on a whole part of the questionnaire. Questions about governance, risk analysis, security policy, or regular review get a single-block answer: “Yes, covered by our ISO 27001 certification, production scope, certificate no. [number], issued on [date].” The customer knows an independent auditor has already verified these items.

But certification does not exempt you from proving everything. Two limits come up every time:

  • the scope is often narrower than people think: a company can be certified for a data center, a subsidiary, or a product line without the specific service bought by the customer being included. An enterprise customer always checks that its service is within the certificate’s scope;
  • some questions fall outside the standard: contractual commitments, the exact location of the data, reversibility, architecture details specific to your product. Certification does not cover them; they have to be answered separately.

In other words, certification is a powerful accelerator on part of the questionnaire, not a free pass on the whole.

Answering solidly without certification

Without certification, the logic is simple: you prove control by control. Each answer rests on three levels of evidence, from weakest to strongest:

  • a dated and signed policy: it shows the intent and the rule, for example an access management policy;
  • an applied procedure: it shows how the rule translates into practice, for example the onboarding and offboarding procedure for staff;
  • a record of execution: it shows that the procedure actually runs, for example an export of the last quarter’s access reviews, a ticket, a log.

An answer that aligns these three levels is worth, to an assessor, as much as a box checked under certification: it is verifiable. An enterprise customer accepts this kind of demonstration very well; what it refuses is the claim with no evidence.

Many items also serve as recognized partial equivalents: a SOC 2 report, a recent penetration test, a policy aligned with a known framework, the baseline measures recommended by ANSSI. None officially replaces a certification, but all of them strengthen an answer by adding external verification.

The principle that holds it all together: say what you actually do, not what you would like to do. A modest but real and provable practice lands better than an unverifiable ideal, which will be caught at the first request for evidence.

When certification becomes necessary

Certification stops being optional in a few specific situations:

  • when the customer explicitly requires it in the contract or its specifications: the question is then no longer whether you can answer another way, but whether you meet the requirement in order to sign;
  • in certain regulated or sensitive markets (finance, healthcare, the public sector, hosting of critical data), where it is often expected by default, sometimes alongside national requirements such as those set by ANSSI;
  • as the size of the contracts and the criticality of the data increase: the more responsibility the customer entrusts to you, the more it expects assurance verified by a third party.

In these cases, certification becomes a commercial investment as much as a technical one. But even there, starting the process is not something you decide the day before a request for proposals: it is a project to plan, not a box to check in a hurry.

The costly mistakes

On this specific topic, three mistakes come up and always cost you:

  • announcing a certification “in progress” as if it were achieved: a customer that asks for the certificate will discover the gap, and trust does not recover. A process underway is mentioned as such, with a realistic timeline;
  • letting a partial scope pass for full coverage: presenting a certificate that covers a different entity or a different service than the one sold is spotted immediately and read as an attempt to deceive;
  • checking “yes” on controls you cannot show: this is the most common and the most round-trip-costly mistake. A “yes” with no evidence will be challenged; repeated, it casts doubt on all the other answers.

The remedy is the same as for the rest of a questionnaire: claim only what you can prove, date each piece of evidence, and clearly distinguish what is in place from what is planned.