The question comes early in almost every engagement. Do we have to certify? This chapter gives an answer, but first another answer to a more important question, why the standard is useful even for those who never intend to obtain a certificate. Certification is evidence pointing outwards. The management system is what makes a difference inwards, and the two do not have to travel together.
The chapter opens with why ISO 27001 has become the common reference and then gives an overview of the 2022 version, with its split between requirements and controls. After that comes the central comparison, how the requirements of the standard meet the requirement areas of the Cybersecurity Act and where they do not overlap. The standard is not named in the legal text, but in practice it covers most of what the law asks for, which makes it the shortest route forward for most organisations. The national methodological guidance is treated as the Swedish guidance it is, with its own structure and its own vocabulary, and with the advantage of being free of charge. One section describes the work of building a management system in broad strokes, which is then taken all the way in chapter 13 on building a management system. The question of certification gets its own section with an honest picture of the cost and a review of when it actually pays off. Then comes the integrated management system, how information security shares a structure with quality and environment, along with the competences the standard does not cover and which therefore have to be sourced elsewhere. The chapter closes with the shift from compliance to resilience.
The relevance lies in the fact that many organisations now face a choice between building something of their own against the legal text or leaning on an established structure. The former tends to cost more, since every question has to be answered from scratch, every reviewer is met with a new vocabulary and every customer enquiry requires its own explanation.
This page shows what the chapter covers and why the standard works as the hub. The mapping, the guidance and the practicalities of certification are in chapter 11 of the book.
A management system is not a document. It is how the organisation thinks when nobody is watching.
Key insights
- ISO 27001 is not named in the Cybersecurity Act, but in practice it covers most of what the law requires.
- A management system is a way of working, not a collection of documents. The difference only shows during an incident.
- Certification is market evidence rather than a compliance requirement, and the need is decided by who is asking.
- The national methodological guidance gives the Swedish reading and is free, which makes it a natural starting point.
- The standard does not cover everything. A number of competences sit outside it and have to be sourced elsewhere.
Tools that belong to this chapter
The templates and interactive tools are in the Toolbox, free of charge.
Control mapping
Appendix B, ISO 27001 control by control against the requirements of the Cybersecurity Act.
System tools
Platforms for management systems, GRC and continuous compliance.
Read on
Next step
Where does your organisation stand?
The self-assessment gives you a maturity profile against the ten requirement areas of the Cybersecurity Act in a few minutes, right on screen.