Certifying a scope that does not answer the buyer’s question
A certificate whose scope excludes the platform the customer is actually buying will be read, noticed, and raised in the security review.
ISO/IEC 27001 is the international standard for information security management systems. It requires an organisation to assess its security risks systematically, select and implement controls against them, and operate a governance cycle — policy, internal audit, management review, continual improvement — that keeps those controls current. Certification is granted by an accredited body on a three-year cycle.
For a digital health company the honest question is whether ISO 27001 or a medical device QMS comes first, and the answer is usually driven by who is asking. Enterprise and hospital procurement asks for 27001; a notified body does not.
The two systems share a great deal of machinery — document control, internal audit, management review, corrective action — and running them as one integrated management system rather than two parallel ones saves a substantial amount of duplicated effort.
Scope is the decision that determines cost. A tightly and defensibly drawn scope certifies faster and cheaper than an organisation-wide one, provided it genuinely covers the systems that handle customer data. And 27001 is a management-system certification: it is not a statement that any particular product is secure.
A certificate whose scope excludes the platform the customer is actually buying will be read, noticed, and raised in the security review.
Two document control systems, two audit programmes and two management reviews for one company is a self-inflicted cost. Integrate from the start.
It is a strong foundation for the Article 32 security obligation and nothing more. Lawful basis, data subject rights, international transfers and impact assessments all sit outside it.
It depends entirely on who is asking. A notified body will not ask for ISO 27001; enterprise and hospital procurement routinely will. If both apply, run them as one integrated management system — document control, internal audit, management review and corrective action are shared machinery, and duplicating them is a self-inflicted cost.
Three to six months for a tightly drawn scope, longer for an organisation-wide one. The audit is in two stages, and Stage 2 requires evidence the ISMS has actually operated — a completed internal audit, a management review, and risk treatment records. Scope is the single biggest determinant of both cost and duration.
No. It is a strong foundation for the Article 32 security-of-processing obligation and nothing more. Lawful basis, Article 9 conditions for health data, data subject rights, international transfers, and impact assessments all sit entirely outside it and need their own analysis.
Working out how ISO 27001 applies to what you are building is usually the first conversation.
Get in touch →