Elamilanga Consulting

§27001 / Information Security Management

Proof that your business actually protects the data it holds — not just a POPIA policy on a shelf.

ISO/IEC 27001 is the closest thing to a universal language for ‘we take information security seriously’. For South African businesses juggling POPIA, client due-diligence questionnaires and cyber-insurance requirements at the same time, it’s usually the most efficient way to answer all three at once.

§01 / The Definition

What is ISO 27001, in one honest paragraph?

ISO/IEC 27001:2022 is the international standard for an Information Security Management System (ISMS) — a documented, risk-based way of protecting the confidentiality, integrity and availability of the information your business holds, whether that’s customer records, financial data or intellectual property. At its core sits a risk assessment: you identify what could go wrong, decide which of the standard’s Annex A controls (things like access control, encryption, supplier security and incident management) actually apply to you, and document that decision in a Statement of Applicability.

It’s worth being precise about what ISO 27001 is not: it’s not a POPIA compliance certificate, and there’s no such thing as one. What it is, is a management system that covers a large overlap of the operational work POPIA also demands — access controls, breach procedures, supplier due diligence, staff training — which is exactly why so many South African businesses tackle both at the same time rather than as two unrelated projects.

§02 / Who Actually Needs It

Who in South Africa actually needs an ISO 27001 certificate?

Anywhere sensitive data changes hands at scale, ISO 27001 tends to show up on the requirements list. Fintechs and financial services firms lead the pack, followed closely by BPOs and call centres handling other companies’ customer data, healthcare providers, law firms, and e-commerce platforms processing payment information. If your sales process regularly hits a security questionnaire from an enterprise client’s procurement or legal team, that questionnaire is very often scored against ISO 27001’s control set whether it says so explicitly or not.

Fintech & Financial ServicesBPO & Call CentresHealthcareLegal & Professional ServicesE-commerce & ICT

A useful, verifiable example: Omnisient, a Cape Town-based privacy-preserving data-collaboration platform serving fintech and financial-inclusion use cases, announced its ISO/IEC 27001:2022 certification in November 2024 — a good illustration of exactly the kind of South African tech business for which this certificate is now table stakes when handling other companies’ consumer data. We reference it here because it’s public record, not because they’re a client of ours; if you want to see what certification looks like for one of our own clients, our Industries page is the place to start.

Information security engineer monitoring servers for ISO 27001 ISMS in South Africa
§03 / ISO 27001 vs POPIA

How this actually lines up against POPIA

POPIA is South African law, administered by the Information Regulator, and it applies to you regardless of any certificate. ISO 27001 is voluntary. But in practice, a meaningful share of what POPIA requires — a documented record of what personal information you hold and why, access controls around it, a breach-response procedure, staff awareness training, oversight of third-party processors — maps directly onto ISO 27001’s Annex A controls and risk-assessment process. Businesses that build their ISMS properly usually find their POPIA compliance work gets meaningfully easier alongside it, rather than needing to be run as a second, separate project.

None of that removes your obligation to appoint an Information Officer or handle data-subject requests under POPIA specifically — those stay your responsibility either way. What ISO 27001 gives you is the audited, internationally recognised evidence that the security half of that promise is real.

§04 / The Path To Certification

The path from ‘we should probably get certified’ to certificate in hand

ISO 27001 projects live or die on the risk assessment. Get the scope and the Statement of Applicability right early, and everything else — policies, controls, evidence — follows logically. Rush that step, and you end up building controls for risks that don’t really apply to you while missing ones that do.

  1. 1
    Scope & asset inventory

    Defining exactly what information, systems and locations the ISMS covers — get this wrong and everything downstream is harder.

  2. 2
    Risk assessment & Statement of Applicability

    Identifying what could go wrong and which Annex A controls genuinely apply to your business.

  3. 3
    Policy & control implementation

    Building the access controls, procedures and documentation the risk assessment calls for — see our Policy Development service.

  4. 4
    Staff training & awareness

    Security is a people problem as much as a technical one — auditors check whether staff actually know the procedures.

  5. 5
    Internal audit & management review

    Testing the ISMS against the standard before an external auditor does.

  6. 6
    Stage 1 & Stage 2 audits

    Documentation review, followed 6–8 weeks later by a full operational audit from a SANAS-accredited certification body.

  7. 7
    Certification decision

    Certificate issued, valid for three years subject to annual surveillance audits.

Total time from kickoff to certificate is typically six weeks to four months once the ISMS has actually been running for a few months first — certification bodies generally want to see the system operating in practice, not just documented, before Stage 2. Insist on a SANAS-accredited certification body; it’s the only version of the certificate enterprise clients and cyber insurers will fully trust.

§05 / After Certification

The audit doesn’t stop once you’re certified

Like every ISO management standard, your ISO 27001 certificate runs on a three-year cycle. What’s specific to information security is how the two annual surveillance audits are structured: certification bodies typically rotate which Annex A controls they sample between Surveillance Audit 1 and Surveillance Audit 2, so SA1 might focus on access control, incident management and supplier security, while SA2 looks at physical security, business continuity and cryptography. A handful of areas — internal audit, management review, risk assessment, and any previous findings — get checked at every visit regardless.

At the end of year three, the recertification audit is a genuinely deeper exercise, closer in scope to your original Stage 2 audit than to a surveillance visit. The best preparation for all of it is simply running the ISMS consistently in between audits, rather than trying to reconstruct a year of evidence the week before an auditor arrives.

§06 / Questions People Actually Ask

ISO 27001 — the questions we get asked before anything else

01Is ISO 27001 required by POPIA?+

No — POPIA doesn’t name ISO 27001 or any other certificate as mandatory. But a large share of the operational work POPIA requires (access control, breach procedures, supplier oversight, staff training) overlaps with ISO 27001’s Annex A controls, so most businesses find it more efficient to build one system that satisfies both rather than treating them as separate compliance projects.

02How does ISO 27001 actually help with POPIA compliance?+

It gives you a structured risk-assessment process and a documented set of controls that cover much of what POPIA expects operationally — but you still need to separately appoint an Information Officer and handle data-subject access requests under POPIA specifically, since those obligations exist regardless of certification.

03What’s the difference between ISO 27001 and SOC 2?+

ISO 27001 is a certification against an international standard, assessed by an accredited certification body, valid for three years with annual surveillance. SOC 2 is an attestation report (not a certificate) produced by an auditor, usually renewed annually, and more commonly requested by US enterprise clients. South African businesses selling internationally sometimes end up needing both.

04How much does ISO 27001 cost for a small South African business?+

It varies by scope, number of systems and locations, and how mature your existing security practices are. As with our other ISO services, we scope this properly on a call rather than quoting blind — request a quote and we’ll give you a real number.

05How long does ISO 27001 certification take?+

Typically six weeks to four months for the certification audit itself, but certification bodies generally expect to see your ISMS operating for at least a few months beforehand — so the realistic total project timeline is usually four to nine months from a standing start.

06How often do I need to renew ISO 27001?+

Every three years, with two annual surveillance audits in between that each sample a rotating subset of your Annex A controls, followed by a fuller recertification audit before the three years expire.

07Do small tech companies and startups really need ISO 27001?+

Increasingly, yes — particularly if you’re selling to enterprise clients, banks, or handling any volume of consumer financial or health data. It’s common for a single large client’s due-diligence process to be the trigger that makes certification worth doing.

Next Step

Ready to talk about your Information Security Management System?

Book an obligation-free consultation and we’ll tell you honestly what your business actually needs.