ISO 27001 certification, and whether you actually need it.
The 2013 edition stopped being current on 31 October 2025, so a certificate issued against it is no longer a valid certificate. The standard today is ISO/IEC 27001:2022 with Amendment 1:2024. We prepare UAE organisations for assessment by an accredited body, and we tell you when certification is the wrong answer.

- 2022 editionPlus Amendment 1:2024
- 93 controlsAnnex A, in four themes
- Deadline passed2013 certificates are not current
- Not a certifierWe prepare, an accredited body audits
Eight things ISO 27001 asks for, and only one of them is a control list.
A scope you have defined deliberately
Scope decides the cost, the effort and the credibility of the certificate. Too narrow and a client reads the certificate, sees it covers one office and not the service they buy, and treats it as worthless. Too broad and you spend a year certifying parts of the business nobody asked about. For most UAE organisations the right scope is the service the customer is actually assessing, plus the infrastructure and people behind it.
A risk assessment that drives everything else
The standard requires a defined, repeatable information security risk assessment and treatment process, and the output of that process is what justifies your control selection. This is the clause auditors probe hardest, because a risk register that was written once to satisfy a consultant and never revisited is visible immediately. It should look like something the business actually uses.
A Statement of Applicability that reasons rather than lists
You do not implement all 93 Annex A controls. You implement the controls your risk assessment identifies as necessary, and you justify any exclusions. The Statement of Applicability is where that reasoning lives, and it is usually the first document an assessor reads. A well-argued exclusion is a sign of a working management system. An unexplained gap is a finding.
Ninety-three Annex A controls across four themes
The 2022 edition reorganised the old 114 controls in 14 domains into 93 controls in four themes: 37 Organizational, 8 People, 14 Physical and 34 Technological. If your existing documentation is still structured around the 2013 domains, it is not wrong in substance but it will make the assessment slower, because the assessor has to map your evidence onto the current structure themselves.
Amendment 1:2024, the climate change clause
Amendment 1 added to clause 4.1 that the organisation shall determine whether climate change is a relevant issue, and added a note to 4.2 acknowledging that interested parties can have climate-related requirements. The 4.2 addition is a note rather than a requirement. In practice this is a short, documented consideration rather than an environmental programme, and certification bodies have been checking for it since 2024.
Evidence that the system is operating, not merely designed
Internal audits, management review, corrective actions, competence records, and evidence that your controls have actually run over a period. This is where organisations that buy a documentation pack come unstuck. The templates satisfy the clauses on paper and produce nothing an assessor can sample, because no activity ever happened behind them.
Assessment by an accredited certification body, not by us
Certification is issued by an accredited certification body following a two-stage audit, and it is maintained through surveillance audits with recertification on a three-year cycle. We prepare you and support you through it. We do not issue certificates, and you should be wary of anyone who offers to both consult and certify, because that is a conflict of interest an accreditation body would not permit.
Reuse against your other UAE obligations
An ISO 27001 management system carries a great deal of the evidence needed for UAE sector requirements, and the reverse is true too. If you already hold national standard alignment, DESC ISR work, or ADHICS controls in Abu Dhabi, a substantial share of your risk, asset, access and incident evidence transfers. We map that first, because paying twice for the same control set is the most common waste in UAE compliance budgets.
If your certificate says 2013, it is not a current certificate.
The transition from ISO/IEC 27001:2013 to the 2022 edition closed on 31 October 2025. That date has passed. This catches UAE organisations more often than it should, usually because the certificate sits in a folder and nobody looks at it between tenders.
- Go and read the edition on your certificate. If it references ISO/IEC 27001:2013, you are not currently certified to the standard, whatever the expiry date on the document says. The practical moment this surfaces is a tender submission or a client due diligence questionnaire, which is the worst possible moment to discover it.
- The work to move is real but usually smaller than people fear. The clauses are largely unchanged. What changes is the Annex A structure, from 114 controls in 14 domains to 93 controls in four themes, so the Statement of Applicability is rebuilt and the evidence is remapped rather than recreated. For an organisation with a genuinely operating management system this is weeks, not months.
- Amendment 1:2024 comes with it. The current standard includes the climate action changes, so a transition done now covers both. If you transitioned early in the window and have not addressed the clause 4.1 climate consideration, that is a small documented gap worth closing before your next surveillance audit.
- If you have let certification lapse entirely, the honest question is whether to resume. Certification costs real money every year, and it is worth it when customers, tenders or regulators ask for it. If nobody has asked you for it in three years, the better answer may be a security programme without the certificate, and we will say so.
Four positions we hold on ISO 27001 work in the UAE.
We will tell you not to certify when that is right
If nobody has asked you for ISO 27001 and your actual need is to answer client security questionnaires credibly, we will say so, and help you do that instead for a fraction of the cost. Certification is an ongoing annual commitment. It is excellent value when it opens doors and a poor use of budget when it opens none.
We prepare, we do not certify, and we say which bodies we work with
We are not a certification body and cannot issue a certificate. We prepare you, run the internal audit, sit with you through stage one and stage two, and manage findings afterwards. Be cautious of any firm offering to both consult and certify: accreditation rules exist precisely to prevent that, and a certificate from an arrangement like that will not survive customer scrutiny.
We build a system your team can actually run
The measure we hold ourselves to is whether your own people can run the management system twelve months after we finish, without calling us. That means documentation sized for your organisation rather than a two-hundred-page pack, risk assessment integrated with how you already make decisions, and internal audit that finds real things.
We stay for the surveillance audits
Certification is a three-year cycle with surveillance audits in between, and the failure mode is a system that decays quietly between visits. We keep the evidence current through the year rather than assembling it in the fortnight before an audit. Priority response applies throughout, P1 within 5 minutes, P2 within 10, P3 within 30.
Six reasons that actually justify the spend.
An enterprise customer has made it a condition
The most common and the most clear-cut. A large client, often a bank, a government entity or a multinational, requires certification from suppliers handling their data. Here the certificate has a direct revenue justification and the scope should be drawn tightly around the service that client buys, rather than around your whole organisation.
A financial services firm in DIFC or ADGM
Regulated firms face supervisory expectations on information security, and while certification is not usually mandated as such, an ISO 27001 management system produces a great deal of the evidence a regulator or an external auditor will ask for. It also answers the outsourcing and third-party questions that come up repeatedly in this sector.
A company bidding for government or semi-government work
Tender requirements in the UAE increasingly reference information security certification, and an expired or 2013-edition certificate has caused real bid disqualifications. If tendering is part of your pipeline, the certificate is best treated as a standing commercial asset that must never lapse, rather than as a project you complete once.
A technology company selling internationally
ISO 27001 is the recognised standard in Europe, the Middle East and much of Asia, and it shortens security review cycles considerably. If your buyers are predominantly American, SOC 2 may serve you better or you may end up needing both. We would rather help you work that out before you commit than watch you certify against the wrong framework.
An organisation already carrying UAE sector obligations
Entities working to ADHICS in Abu Dhabi healthcare, to the national information assurance standard, or to Dubai information security regulation already hold much of the underlying evidence. For them, ISO 27001 is often less additional work than expected, and the resulting management system makes the sector obligations easier to sustain rather than harder.
A growing firm that wants the discipline, not just the badge
A smaller but genuine category: organisations that use certification as a forcing function to build security governance they know they need and would otherwise keep deferring. This works, provided leadership actually wants the discipline. It fails when the objective is the logo and the management system is treated as paperwork.
The certificate, the management system, and the difference.
| Feature | Certified and operating | Certified on paper | Not certified |
|---|---|---|---|
Certificate from an accredited body | |||
Risk assessment the business uses | Sometimes | ||
Statement of Applicability with reasoned exclusions | Generated | ||
Controls with real operating evidence | Varies | ||
Internal audit finding genuine issues | Nominal | ||
Survives a customer deep-dive audit | Not applicable | ||
Evidence reusable for UAE sector requirements | Barely | Varies | |
Surveillance audits are routine, not a scramble | Not applicable | ||
Security actually improved | Marginally | Possibly | |
Annual cost justified | Only if nobody looks | No cost |
The 2013 structure against the current one.
| ISO/IEC 27001:2013 | ISO/IEC 27001:2022 | |
|---|---|---|
| Annex A control count | 114 | 93 |
| Annex A structure | 14 domains | 4 themes |
| Organizational controls | Spread across domains | 37, clauses 5.1 to 5.37 |
| People controls | Spread across domains | 8, clauses 6.1 to 6.8 |
| Physical controls | Spread across domains | 14, clauses 7.1 to 7.14 |
| Technological controls | Spread across domains | 34, clauses 8.1 to 8.34 |
| Climate change consideration | Not present | Required by clause 4.1 via Amendment 1:2024 |
| Statement of Applicability | Required | Required, rebuilt against new structure |
| Management system clauses | Clauses 4 to 10 | Clauses 4 to 10, largely unchanged |
| Currently certifiable | No, transition closed 31 October 2025 | Yes |
Five stages, typically six to twelve months to certificate.
- 1
Decide whether to certify, and define the scope
What is driving the requirement, whether certification is the right response, and if it is, exactly what the certificate should cover. Scope is the single largest cost driver and the hardest thing to change later, so this stage is deliberate rather than quick. We also map what you already hold from other frameworks.
- 2
Gap assessment against the 2022 edition
A clause-by-clause and control-by-control review producing a findings list with effort estimates, so you can see the shape of the programme before committing to it. For organisations transitioning from the 2013 edition this stage is largely a remapping exercise and moves quickly.
- 3
Build the management system
Risk assessment and treatment, Statement of Applicability, policies sized for your organisation, and the control implementation the risk work identified. We build documentation your team will maintain rather than a pack that impresses at handover and is never opened again.
- 4
Operate it, then audit it internally
Controls need to run for a period before they can be sampled, so there is an operating window here that cannot be skipped. During it we run the internal audit and the management review, close findings, and get the evidence into a state where stage two is straightforward.
- 5
Stage one and stage two, then maintain it
We support you through both audit stages with the certification body, manage any nonconformities to closure, and then keep the system running through surveillance audits and recertification. The objective from here is that audits become routine rather than events.
“We were told by another firm that we could be certified in eight weeks using their documentation pack. We went the longer route instead. Eighteen months later a client ran a two-day audit on us and we passed it comfortably, and I am fairly sure the eight-week version would not have survived the first morning.”
What UAE organisations ask about ISO 27001.
Fifteen questions to answer before the first invoice.
Should you certify at all
- Has a specific customer, tender or regulator actually asked for it?If nobody has, the certificate may not be the right spend.
- Would a completed security questionnaire satisfy the same request?Frequently it would, at a fraction of the cost.
- Is the request specifically ISO 27001, or would SOC 2 serve better?Depends heavily on whether your buyers are European or American.
- Can you sustain surveillance audits and annual cost indefinitely?Certification is a recurring commitment, not a project.
- Do you have management commitment beyond signing the budget?Clause 5 is about leadership, and assessors test it directly.
Scope, which drives the cost
- Which service or entity does the customer actually care about?Certify that, plus what supports it.
- How many physical locations are in scope?Sites drive audit days more than headcount does.
- Are cloud platforms and third parties inside or outside the boundary?Ambiguity here produces findings and awkward client questions.
- Does the scope statement read sensibly to a customer?They will read it. A narrow scope can be worse than none.
- Have you chosen an accredited certification body?Accreditation matters. An unaccredited certificate persuades nobody.
Readiness
- Do you have a risk assessment the business actually uses?Not one written once for a consultant.
- Has an internal audit been completed and its findings closed?Required before stage two, and commonly the blocker.
- Has management review happened, with minutes?An assessor will ask to see them.
- Do your controls have three to six months of operating evidence?You cannot sample a control that started last week.
- Have you documented the clause 4.1 climate consideration?Amendment 1:2024, and easy to miss on an early transition.
The pages around this one.
IT audit services in Dubai
The wider audit practice: what an assessment examines, how findings are evidenced, and which type of engagement your situation actually calls for.
ADHICS V2 compliance in Abu Dhabi
The Abu Dhabi healthcare standard, read from the Department of Health source, and how ISO 27001 evidence maps onto its eleven control domains.
NESA compliance in Dubai
The national information assurance regime, and how alignment to one framework reduces the work required for the other.
Start by reading the edition printed on your certificate.
If it says 2013, that is today priority and we can tell you quickly what the route back looks like. If you are not certified at all, the first conversation is about whether you should be, and we are perfectly willing to conclude that you should not.
Related Services
Explore more solutions that work great with this service
CBUAE IT Requirements
Which Rulebook articles actually bind your licence
NIST CSF 2.0 Assessment
Know where you stand, without committing to certification
SOC 2 Readiness UAE
Type II preparation, and when ISO 27001 fits better
Virtual CISO Dubai
Security governance and accountability, not more tools
PCI DSS Compliance UAE
Scope reduction first, then the controls that remain
IT Audit Services Dubai
Assessment, technical test or certification, scoped properly
ADHICS V2 Compliance
The Abu Dhabi healthcare standard, read from the source
NESA / IA Compliance
UAE Information Assurance Standards compliance