A proposal that lists only the upside of ISO/IEC 27001 certification rarely survives an internal review. What management wants to know is not just how much better things get, but what the company will be carrying every year once the certificate is on the wall.
An ISMS is not the kind of initiative that ends when it is achieved. A surveillance audit follows every year, a recertification audit every three, and throughout it all you must keep running internal audits and management reviews. Start without understanding that structure — "a client asked for it" — and operations tend to stall in year two, leaving nothing but the certificate.
This article sets out the benefits and the drawbacks at the level of detail an internal review actually asks about, and then goes further: when not certifying, or deferring it, is the right answer. For the standard itself, see What Is an ISMS (ISO/IEC 27001)? A Complete Guide for Healthcare Companies.
Disclaimer: This article is general information. The authoritative texts are ISO/IEC 27001 (JIS Q 27001) itself and the publications of the accreditation and certification bodies. Base actual decisions on those.
What Certification Actually Buys You
It helps to separate the effects into three: external, internal, and what happens after an incident.
1. Market access — staying on the shortlist
The most legible benefit. Procurement by hospitals, pharmaceutical companies, and local governments increasingly requires third-party evidence of information security. Because hospitals themselves must satisfy Japan's three-ministry healthcare guidelines, they are structurally pushed to demand an equivalent standard of their suppliers.
Note the direction of the effect: certification works less as "we win because we have it" and more as "we are not eliminated because we lack it." Once it appears in an RFP's mandatory requirements, the conversation is over. If you want to quantify the value, count the deals lost — or never offered — for want of a certificate.
See When ISMS Becomes a Condition of Trade.
2. Internal control — from individuals to rules
The under-appreciated benefit. Building an ISMS forces decisions nobody had made:
- Who may access which information — and who revokes it when they leave
- Which data may leave the company, and under what conditions
- What must be verified about a supplier before contracting
- Who must be told, within how many minutes, when an incident occurs
- How long logs are retained, and for what purpose
Every growing organisation needs these answers eventually. What an ISMS supplies is an externally imposed deadline and a template for producing them. A company that has been saying "we should write a security policy" for three years will often write the whole set in three months once an audit date exists.
3. The ability to explain yourself
Security incidents happen regardless of controls. What gets asked afterwards is not only "why did this happen" but "was there a framework in place beforehand?"
Whether you can produce risk assessment records, policies, training attendance, an incident response procedure, and a recent internal audit report changes your position materially — whether the contract is terminated or continues under an agreed remediation plan. An ISMS is, in part, a machine for accumulating that evidence during peacetime.
| Type of benefit | Who it acts on | When it becomes visible |
|---|---|---|
| Market access | Customers' procurement teams | Immediately, at RFP time |
| Internal control | Your own staff and management | During the build itself |
| Explaining yourself | Clients, regulators, users | Only when an incident occurs |
The third is invisible in normal times. That is why reviews call it unmeasurable — but unmeasurable and worthless are not the same thing.
The Burden, Stated Honestly
First-year internal effort
Consulting does not reduce your work to zero. At minimum, the following cannot be delegated:
- Deciding scope — which businesses, sites, and information are covered
- Inventorying information assets: only you know where your data lives
- Deciding which risks to accept
- Getting every employee through training
- Management review by the executive team
The heavy parts, in practice, are the asset inventory and chasing each department for confirmation. These are cross-functional, so they stall when the project owner lacks authority. Most delayed certifications are delayed not by the standard's difficulty but by unanswered internal requests.
Recurring fees and audits
Costs run on a three-year cycle.
| Year | Audit | Main internal work |
|---|---|---|
| 1 | Stage 1 (documentation) + Stage 2 (on-site) | Full build, internal audit, management review |
| 2 | Surveillance audit | Risk assessment update, internal audit, review |
| 3 | Surveillance audit | As above |
| 4 | Recertification audit | As above, plus scope and policy review |
Internal audit and management review are required every year. A common failure mode is a company that ran year one with external help and then tried to run year two alone. Budget the three-year total and name the person who will run it. See The Full Cost of ISMS Certification and Preparing for Surveillance Audits.
Decisions get slower
Worth conceding openly. Running an ISMS inserts process at points like these:
- Adopting a new SaaS now requires a supplier assessment
- Changing how data is handled in a new line of business requires updating the risk assessment
- Temporarily widening someone's privileges requires a record
For a speed-oriented organisation this is friction. But most of that friction is the price of not ending up in a state nobody can explain later. It can be reduced at design time — keep approval flows light, define an exception procedure. Writing rules so strict that nobody follows them is far more dangerous.
The Real Risk Is Hollowing Out
The genuine drawback is neither cost nor effort. It is holding a certificate while the practice behind it has stopped — a state that can be worse than having no certificate at all, because you are representing to clients that a framework exists when it does not.
| Warning sign | What is really happening |
|---|---|
| Records are assembled in the month before the audit | Documentation is detached from daily operation |
| The risk assessment has not changed since year one | Risk perception has not tracked the business |
| Internal audits find zero issues every year | The audit has become a ritual confirming "no problems" |
| Training is a video and an attendance log | You are managing completion rates, not understanding |
| Staff do not know the rules the procedures state | Procedures were written against an imagined operation |
The remedy is simple in principle: write procedures that describe reality. Recording what you actually do, and using the risk assessment to state explicitly which risks you accept, holds up better in both audit and practice than an aspirational document nobody follows. See Adapting Policy Templates to Your Company and Running an Internal Audit.
When Not to Certify — or to Wait
"You should get certified" is not a universal conclusion. In the following cases, there is a good chance you do not need to start now.
1. No client is asking, and no deal in the next 12 months requires it
The core benefit is as a condition of trade. Certifying ahead of demand front-loads cost and effort. It can be more rational to raise your actual security posture first and start the certification once the requirement is visible. See Choosing Not to Certify: Certification vs. Security Questionnaires.
2. What is being asked for concerns personal data specifically
If you are B2C, personal data dominates, and what clients or users want is evidence of personal information protection, the Privacy Mark may fit the purpose better. See ISMS vs Privacy Mark.
3. A US counterparty is asking for SOC 2
Overseas SaaS deals often call for a SOC 2 report rather than ISO certification. The two are different instruments. See ISMS vs SOC 2.
4. The product direction may change materially within six months
Scope and risk assessment are tied to the shape of the business. Fixing scope just before a pivot means rebuilding it right after certification. That said, policy, training, and access management are foundations that survive a pivot. Build those without rushing the certificate, in a form that scope can later be layered onto.
5. The executive team cannot be involved
The standard explicitly requires top management involvement. Approving the policy, providing resources, and conducting the management review cannot be delegated away. Where leadership cannot go beyond "we left it to the team," the build may progress but the system will hollow out. Aligning the start date with a period when leadership can engage usually finishes faster.
Conversely, any of these argues for proceeding:
- Business with hospitals, pharma, or government is core, or soon will be
- Headcount is growing and security judgement is concentrated in one person
- Suppliers and sub-suppliers are multiplying beyond what you can explain
- Due diligence for fundraising or M&A is likely to probe your framework
Benefits and Drawbacks Side by Side
| Dimension | Benefit | Drawback / caveat |
|---|---|---|
| Sales and procurement | Meets procurement requirements; you stay shortlisted | Certification alone does not generate revenue |
| Internal control | Access, outsourcing, and data egress rules become explicit | More process; decisions carry friction |
| People | Less person-dependence; handover becomes possible | Someone must run it, or year two collapses |
| Incident response | Evidence for accountability accumulates in advance | Invisible in normal times; hard to justify in a review |
| Cost | Concentrated in year one, tapering afterwards | Audit and maintenance fees recur indefinitely |
| Industry compliance | Reusable as the base for three-ministry guideline work | ISMS alone may not satisfy sector-specific demands |
That last row matters for healthcare. ISO/IEC 27001 is a general framework and does not by itself cover every requirement specific to medical information. See Integrating ISMS Documents with the Three-Ministry Guidelines and, for what hospitals themselves face, The Three-Ministry Two-Guideline Framework.
Conclusion
- The benefits are market access, internal control, and post-incident accountability. Market access works as a condition for not being eliminated, not for being chosen
- The burden is not only year one: annual surveillance audits, internal audits, and management reviews continue. Budget three years and name an owner
- The biggest risk is not cost but hollowing out — a certificate without the practice can be worse than no certificate
- The best defence is to describe reality in your procedures and state accepted risks explicitly, rather than documenting an ideal
- Where no client requires it, where the Privacy Mark or another scheme fits better, where the business is still shifting, or where leadership cannot engage, deferring is a rational decision
- The choice is not binary: build the foundations before the requirement arrives, and layer scope on when it does
Pottech supports ISO/IEC 27001 certification with a focus on healthcare. We are happy to be involved from the "should we even do this" stage, and our templates for procedures, registers, and training plus full project management let companies proceed without a dedicated internal hire. We can also act as your internal audit manager and internal auditors.
See ISMS Certification Support for scope and pricing, or contact us — including to discuss whether you need certification at all.
References and Sources
- Information Management System Accreditation Center (ISMS-AC)
- ISO/IEC 27001 Information security management systems | ISO
- Guidelines for the Safe Management of Medical Information Systems | MHLW
- Information Security | Information-technology Promotion Agency (IPA)
Note: interpretation of requirements and the handling of accreditation and certification are governed by the standard itself and the publications of the accreditation and certification bodies. Audit frequency, cost, and operational load vary with organisation size, scope, and certification body, and schemes change over time.