Back to Columns
ISMS & Certification11 min read

The Benefits and Drawbacks of ISMS Certification

September 14, 2026

The Benefits and Drawbacks of ISMS Certification
Share this article

A proposal that lists only the upside of ISO/IEC 27001 certification rarely survives an internal review. What management wants to know is not just how much better things get, but what the company will be carrying every year once the certificate is on the wall.

An ISMS is not the kind of initiative that ends when it is achieved. A surveillance audit follows every year, a recertification audit every three, and throughout it all you must keep running internal audits and management reviews. Start without understanding that structure — "a client asked for it" — and operations tend to stall in year two, leaving nothing but the certificate.

This article sets out the benefits and the drawbacks at the level of detail an internal review actually asks about, and then goes further: when not certifying, or deferring it, is the right answer. For the standard itself, see What Is an ISMS (ISO/IEC 27001)? A Complete Guide for Healthcare Companies.

Disclaimer: This article is general information. The authoritative texts are ISO/IEC 27001 (JIS Q 27001) itself and the publications of the accreditation and certification bodies. Base actual decisions on those.

What Certification Actually Buys You

It helps to separate the effects into three: external, internal, and what happens after an incident.

1. Market access — staying on the shortlist

The most legible benefit. Procurement by hospitals, pharmaceutical companies, and local governments increasingly requires third-party evidence of information security. Because hospitals themselves must satisfy Japan's three-ministry healthcare guidelines, they are structurally pushed to demand an equivalent standard of their suppliers.

Note the direction of the effect: certification works less as "we win because we have it" and more as "we are not eliminated because we lack it." Once it appears in an RFP's mandatory requirements, the conversation is over. If you want to quantify the value, count the deals lost — or never offered — for want of a certificate.

See When ISMS Becomes a Condition of Trade.

2. Internal control — from individuals to rules

The under-appreciated benefit. Building an ISMS forces decisions nobody had made:

  • Who may access which information — and who revokes it when they leave
  • Which data may leave the company, and under what conditions
  • What must be verified about a supplier before contracting
  • Who must be told, within how many minutes, when an incident occurs
  • How long logs are retained, and for what purpose

Every growing organisation needs these answers eventually. What an ISMS supplies is an externally imposed deadline and a template for producing them. A company that has been saying "we should write a security policy" for three years will often write the whole set in three months once an audit date exists.

3. The ability to explain yourself

Security incidents happen regardless of controls. What gets asked afterwards is not only "why did this happen" but "was there a framework in place beforehand?"

Whether you can produce risk assessment records, policies, training attendance, an incident response procedure, and a recent internal audit report changes your position materially — whether the contract is terminated or continues under an agreed remediation plan. An ISMS is, in part, a machine for accumulating that evidence during peacetime.

Type of benefitWho it acts onWhen it becomes visible
Market accessCustomers' procurement teamsImmediately, at RFP time
Internal controlYour own staff and managementDuring the build itself
Explaining yourselfClients, regulators, usersOnly when an incident occurs

The third is invisible in normal times. That is why reviews call it unmeasurable — but unmeasurable and worthless are not the same thing.

The Burden, Stated Honestly

First-year internal effort

Consulting does not reduce your work to zero. At minimum, the following cannot be delegated:

  • Deciding scope — which businesses, sites, and information are covered
  • Inventorying information assets: only you know where your data lives
  • Deciding which risks to accept
  • Getting every employee through training
  • Management review by the executive team

The heavy parts, in practice, are the asset inventory and chasing each department for confirmation. These are cross-functional, so they stall when the project owner lacks authority. Most delayed certifications are delayed not by the standard's difficulty but by unanswered internal requests.

Recurring fees and audits

Costs run on a three-year cycle.

YearAuditMain internal work
1Stage 1 (documentation) + Stage 2 (on-site)Full build, internal audit, management review
2Surveillance auditRisk assessment update, internal audit, review
3Surveillance auditAs above
4Recertification auditAs above, plus scope and policy review

Internal audit and management review are required every year. A common failure mode is a company that ran year one with external help and then tried to run year two alone. Budget the three-year total and name the person who will run it. See The Full Cost of ISMS Certification and Preparing for Surveillance Audits.

Decisions get slower

Worth conceding openly. Running an ISMS inserts process at points like these:

  • Adopting a new SaaS now requires a supplier assessment
  • Changing how data is handled in a new line of business requires updating the risk assessment
  • Temporarily widening someone's privileges requires a record

For a speed-oriented organisation this is friction. But most of that friction is the price of not ending up in a state nobody can explain later. It can be reduced at design time — keep approval flows light, define an exception procedure. Writing rules so strict that nobody follows them is far more dangerous.

The Real Risk Is Hollowing Out

The genuine drawback is neither cost nor effort. It is holding a certificate while the practice behind it has stopped — a state that can be worse than having no certificate at all, because you are representing to clients that a framework exists when it does not.

Warning signWhat is really happening
Records are assembled in the month before the auditDocumentation is detached from daily operation
The risk assessment has not changed since year oneRisk perception has not tracked the business
Internal audits find zero issues every yearThe audit has become a ritual confirming "no problems"
Training is a video and an attendance logYou are managing completion rates, not understanding
Staff do not know the rules the procedures stateProcedures were written against an imagined operation

The remedy is simple in principle: write procedures that describe reality. Recording what you actually do, and using the risk assessment to state explicitly which risks you accept, holds up better in both audit and practice than an aspirational document nobody follows. See Adapting Policy Templates to Your Company and Running an Internal Audit.

When Not to Certify — or to Wait

"You should get certified" is not a universal conclusion. In the following cases, there is a good chance you do not need to start now.

1. No client is asking, and no deal in the next 12 months requires it

The core benefit is as a condition of trade. Certifying ahead of demand front-loads cost and effort. It can be more rational to raise your actual security posture first and start the certification once the requirement is visible. See Choosing Not to Certify: Certification vs. Security Questionnaires.

2. What is being asked for concerns personal data specifically

If you are B2C, personal data dominates, and what clients or users want is evidence of personal information protection, the Privacy Mark may fit the purpose better. See ISMS vs Privacy Mark.

3. A US counterparty is asking for SOC 2

Overseas SaaS deals often call for a SOC 2 report rather than ISO certification. The two are different instruments. See ISMS vs SOC 2.

4. The product direction may change materially within six months

Scope and risk assessment are tied to the shape of the business. Fixing scope just before a pivot means rebuilding it right after certification. That said, policy, training, and access management are foundations that survive a pivot. Build those without rushing the certificate, in a form that scope can later be layered onto.

5. The executive team cannot be involved

The standard explicitly requires top management involvement. Approving the policy, providing resources, and conducting the management review cannot be delegated away. Where leadership cannot go beyond "we left it to the team," the build may progress but the system will hollow out. Aligning the start date with a period when leadership can engage usually finishes faster.

Conversely, any of these argues for proceeding:

  • Business with hospitals, pharma, or government is core, or soon will be
  • Headcount is growing and security judgement is concentrated in one person
  • Suppliers and sub-suppliers are multiplying beyond what you can explain
  • Due diligence for fundraising or M&A is likely to probe your framework

Benefits and Drawbacks Side by Side

DimensionBenefitDrawback / caveat
Sales and procurementMeets procurement requirements; you stay shortlistedCertification alone does not generate revenue
Internal controlAccess, outsourcing, and data egress rules become explicitMore process; decisions carry friction
PeopleLess person-dependence; handover becomes possibleSomeone must run it, or year two collapses
Incident responseEvidence for accountability accumulates in advanceInvisible in normal times; hard to justify in a review
CostConcentrated in year one, tapering afterwardsAudit and maintenance fees recur indefinitely
Industry complianceReusable as the base for three-ministry guideline workISMS alone may not satisfy sector-specific demands

That last row matters for healthcare. ISO/IEC 27001 is a general framework and does not by itself cover every requirement specific to medical information. See Integrating ISMS Documents with the Three-Ministry Guidelines and, for what hospitals themselves face, The Three-Ministry Two-Guideline Framework.

Conclusion

  1. The benefits are market access, internal control, and post-incident accountability. Market access works as a condition for not being eliminated, not for being chosen
  2. The burden is not only year one: annual surveillance audits, internal audits, and management reviews continue. Budget three years and name an owner
  3. The biggest risk is not cost but hollowing out — a certificate without the practice can be worse than no certificate
  4. The best defence is to describe reality in your procedures and state accepted risks explicitly, rather than documenting an ideal
  5. Where no client requires it, where the Privacy Mark or another scheme fits better, where the business is still shifting, or where leadership cannot engage, deferring is a rational decision
  6. The choice is not binary: build the foundations before the requirement arrives, and layer scope on when it does

Pottech supports ISO/IEC 27001 certification with a focus on healthcare. We are happy to be involved from the "should we even do this" stage, and our templates for procedures, registers, and training plus full project management let companies proceed without a dedicated internal hire. We can also act as your internal audit manager and internal auditors.

See ISMS Certification Support for scope and pricing, or contact us — including to discuss whether you need certification at all.

References and Sources

Note: interpretation of requirements and the handling of accreditation and certification are governed by the standard itself and the publications of the accreditation and certification bodies. Audit frequency, cost, and operational load vary with organisation size, scope, and certification body, and schemes change over time.

Share this article

Related Articles

ISMS & Certification

Reading the 37 Organizational Controls

The 37 organizational controls of Annex A.5, grouped into eight clusters rather than translated one by one: policy and governance, assets and classification, access policy, suppliers and cloud, threat intelligence, incident management, continuity, and compliance. What each cluster is asking for, and what you end up producing.

September 14, 2026
ISMS & Certification

Annex A 2022: 93 Controls Across Four Themes

A map of the 93 Annex A controls in ISO/IEC 27001:2022 across four themes — 37 organizational, 8 people, 14 physical, 34 technological. Why there is no duty to implement all 93, how inclusion and exclusion are justified in the Statement of Applicability, what the attributes are for, and the order a healthcare company should work in.

September 14, 2026
ISMS & Certification

Reading the 8 People Controls

The 8 people controls of Annex A.6, grouped into entry, employment, exit, where people work, and reporting culture. How they connect to existing employment rules, how to handle segregation of duties when the team is too small for it, and how far to go on remote working — written for healthcare companies.

September 14, 2026
ISMS & Certification

Reading the 14 Physical Controls

The 14 physical controls of Annex A.7 in five clusters, with a concrete treatment of what a fully remote, cloud-only organisation can exclude and what must be reassigned to home-working rules and supplier management — data centres, media and disposal, and equipment off premises.

September 14, 2026
AI Karte

Explore AI Karte

An AI-native EHR connecting reception, documentation, accounting, claims, and analytics into one cycle.

View the product page

ISMS Certification Support as an Option

From scope design and documentation to training, internal audit, and dealing with the certification body. Pottech supports healthcare companies through ISO/IEC 27001 certification end to end.