Cost, timeline, risk assessment, required documents, and how ISMS compares with the Privacy Mark, explained in the order an IT company actually works through them.
ISMS (ISO/IEC 27001) vs the Japanese Privacy Mark: scope of protection, certification boundary, cost, timeline and audit cycle, and which fits a B2B IT company.
ISO 27001 certification typically costs JPY 1.5M-7M in year one and JPY 400K-2M a year to maintain. See the breakdown by company size and 5 ways to cut it.
ISO 27001 (ISMS) certification in eight steps from kickoff to registration, why it usually takes 6 to 12 months, and what Stage 1 and Stage 2 audits check.
All 93 Annex A controls of ISO/IEC 27001:2022 by theme: 37 organizational, 8 people, 14 physical, 34 technological, plus the 11 new controls and SoA use.
ISO/IEC 27001 documents in two layers: the documented information the standard explicitly requires, and the policies teams build around Annex A controls.