Skip to content

IT EN

ISO 27001 certification: information security

We take companies in Switzerland, Italy and international markets through to ISO 27001 certification, from the first review to the body's audit.

What ISO 27001 is

It is the international standard for information security management systems (ISMS). The version in force, and the one on which certification is granted, is ISO/IEC 27001:2022.

It is not just an IT matter: it is about how a company protects information — digital and otherwise — from unauthorised access, loss and tampering, through clear rules, defined responsibilities and documented controls.

The principle is simple: assess the risk first, then choose the controls. You do not apply all of them, only those the risk justifies. It is a system cut to fit, not off the peg — which is also why generic consulting will not do.

Who needs it, and why

  • Companies handling sensitive or critical data — customer, health, financial, industrial — that have to show it is protected.
  • Software and digital service providers that need to reassure clients about the security of the data entrusted to them.
  • Companies bidding for tenders where certification is an entry requirement or a scoring factor, increasingly so in digital and IT supply.
  • Companies wanting to cut the risk of attacks, data breaches and operational downtime.
  • Companies working across Switzerland and Italy that want one system to cover what both the GDPR and the Swiss FADP expect.

Is it mandatory? Not by law, but it becomes necessary in practice as soon as a client, a tender or a supply chain calls for it — and that is happening more and more often.

ISO 27001 is not the same thing as personal data protection, but it is the organisational tool that helps demonstrate the adequate security measures required both by the GDPR (for clients in Italy and the European Union) and by the Swiss FADP.

Article 32 of the GDPR calls for appropriate technical and organisational measures to secure processing; the FADP imposes comparable duties. A well-built 27001 system documents precisely those measures: who has access to what, how data is protected, which controls are live, who is accountable.

For a company operating on both sides of the border the gain is tangible: one system covers what the two regimes expect, instead of chasing them separately.

GDPR (EU / Italy)FADP (Switzerland)ISO 27001
NatureRegulation (law)LawVoluntary standard
SubjectPersonal dataPersonal dataInformation security
ScopeNatural personsNatural personsAll company information
CertificationNoNoYes, voluntary

Risk assessment: the heart of the standard

This is the most important step and the most technical: it is where you decide which controls are genuinely needed and which would only be dead weight. A tick-box approach applies everything indiscriminately and breeds pointless bureaucracy; a risk-based approach protects where protection is needed, without weighing the company down. It is the part where competence tells — and where the auditor looks hardest.

The version in force: ISO 27001:2022

Certification is currently granted against ISO/IEC 27001:2022, which updated and reorganised the security controls of the previous edition. Anyone certifying now starts straight away on the updated structure; those certified against the old version completed the transition at their usual surveillance or renewal audits.

The path, step by step

  1. Initial review — the free preliminary assessment: where you stand, what you already have, what is missing.
  2. Planning — the scope of the system, objectives, responsibilities.
  3. Information risk assessment — the step that drives everything else.
  4. Selection of controls and Statement of Applicability — the measures that fit the case are defined and the choice is documented.
  5. Building the management system — policies, procedures, access management, physical and technical controls.
  6. Training the staff — security is made by people, not by technology alone.
  7. Internal audit — the dress rehearsal, done properly.
  8. Certification audit — the assessment by the independent third-party body.
  9. Maintenance — annual surveillance, renewal on a three-year cycle.

How the cost breaks down

There are two items and they stay separate: our consulting fee and the fee of the certification body, an independent third party. The variables are size, how complex the information system is, the number of sites, and whether a system is already in place or you are starting from scratch. We discuss it openly at the first contact, on your case rather than off a generic price list.

Why BS & Partners

  • Ten years in business, 117 projects, work in 9 countries.
  • Real software expertise: we build applications, so we come at information security from the inside rather than from a checklist. On a standard as technical as this one, that is an advantage few ISO consultants around here can offer.
  • The firm and the way we work: the BS & Partners profile.

If artificial intelligence is also on your radar, the natural next step is ISO 42001: anyone who already holds 27001 starts ahead.

Frequently asked questions

Is ISO 27001 mandatory?

No, it is not required by law. It is, however, demanded by a growing number of clients and tenders, especially in digital and IT supply. It becomes necessary in practice as soon as a client makes it a condition.

What is the difference between ISO 27001 and the GDPR or the Swiss FADP?

The GDPR and the FADP are personal data protection laws. ISO 27001 is a voluntary, certifiable standard on information security: it does not replace the law, but it is the organisational tool that helps demonstrate the adequate security measures both require. The laws say what to do; ISO 27001 says how to do it in a structured, auditable way.

Is ISO 27001 only for IT companies?

No. It is about how a company protects information, digital and otherwise: contracts, client data, know-how, paper documents, credentials. It matters to anyone handling valuable or critical information.

Does it integrate with ISO 9001 or ISO 42001?

Yes. It shares the common management system structure with ISO 9001, so integration is straightforward. The link with ISO 42001 on artificial intelligence is closer still, because AI governance and data security overlap heavily: anyone who already holds 27001 starts ahead. An integrated system avoids duplication.

The firm in numbers

  • 10 years in business
  • 117 projects completed
  • 9 countries we have worked in

Want to know how exposed you are?

The preliminary assessment is free: we look at how you handle data today and what it takes to reach ISO 27001.

Request a free preliminary assessment

Or write to direzione@bs-partners.ch or call +41 76 731 16 99.