"Do you hold ISMS certification?" comes up more and more often in dealings with hospitals, pharmaceutical companies, and local governments. In healthcare — PHR, SaMD, clinical trial systems, hospital SaaS — where the information handled is highly sensitive, being able to prove your information security posture to a third party is becoming a precondition for doing business.
Seen from the side considering certification for the first time, though, the standard's requirements are abstract. What must be produced, and to what depth? What does it cost? How long does it take? It is easy to end up holding a quote without the material needed to judge it.
This article gathers what a healthcare company needs in order to decide. Individual topics are split into their own articles, so go deeper wherever you need to.
Disclaimer: This article is general information. The authoritative texts are ISO/IEC 27001 (JIS Q 27001) itself and the publications of the accreditation and certification bodies. Base actual decisions on those.
What Is an ISMS (ISO/IEC 27001)?
An ISMS (Information Security Management System) is the mechanism by which an organisation manages its information assets and continuously maintains their confidentiality, integrity, and availability. The international standard for it is ISO/IEC 27001; the Japanese edition is published as JIS Q 27001.
The key point is that an ISMS is not "installing security products." What the standard requires is a management system — an organisational cycle that keeps turning:
- Identify the information security risks that matter to your organisation
- Decide which risks to treat, and how
- Do what you decided
- Check whether you are actually doing it
- Improve based on what the check found
The goal is not whether you bought a firewall but being able to explain what your risks are, what you decided to do about them, and whether you operate as decided. Certification is a third-party auditor's confirmation that this mechanism is in place.
Why Healthcare Companies Are Asked for It
Four reasons dominate.
1. It is a condition of trade
Procurement by hospitals, pharmaceutical companies, and local governments increasingly demands evidence of an information security posture. Hospitals in particular carry their own obligations under Japan's three-ministry healthcare guidelines, which forces them to require an equivalent standard of their suppliers. Being excluded for lack of certification does happen.
2. The sensitivity of the data
Patient data, clinical information, PHR, trial data. A breach of any of these can cause irreversible harm to the people involved. Evidence of your controls becomes the basis of trust.
3. Moving beyond person-dependent operations
Early-stage companies often run security on one person's judgement. A structure that stops the moment that person leaves becomes a liability as the business scales. An ISMS shifts it to continuous improvement based on rules (PDCA).
4. It connects to the industry guidelines
Much of what the three-ministry guidelines demand overlaps with ISMS documentation: risk assessment, demarcation of responsibility, supplier management, incident response. Starting from ISMS documents makes industry-specific compliance far more efficient. See Integrating ISMS Documents with the Three-Ministry Guidelines.
The Structure of the Standard
ISO/IEC 27001 divides into two parts. Understanding this first makes everything that follows legible.
The main text (clauses 4–10) — management system requirements
These are the requirements that must be met to certify. Clauses 1–3 cover scope, normative references, and terms, so the practical work sits in clauses 4 through 10.
| Clause | Content | What you produce |
|---|---|---|
| 4 Context | Internal and external issues, interested parties, ISMS scope | Scope definition |
| 5 Leadership | Management commitment, policy, roles and responsibilities | Security policy, organisation chart |
| 6 Planning | Risk assessment, risk treatment, objectives | Risk assessment table, Statement of Applicability, objectives |
| 7 Support | Resources, competence, awareness, communication, documentation | Training plans and records, document control |
| 8 Operation | Doing what was planned | Operating rules and records |
| 9 Performance evaluation | Monitoring, internal audit, management review | Audit reports, review minutes |
| 10 Improvement | Nonconformity, corrective action, continual improvement | Corrective action reports |
Each clause is covered in detail starting with ISO/IEC 27001 Clause 4: Context of the Organisation.
Annex A — the 93 controls
The catalogue of controls referenced when deciding risk treatment under clause 6. The 2022 edition organises 93 controls into four themes.
| Theme | Controls | Examples |
|---|---|---|
| Organizational (A.5) | 37 | Policies, roles, supplier management, incident management |
| People (A.6) | 8 | Screening, training, disciplinary process, post-employment duties |
| Physical (A.7) | 14 | Physical entry controls, equipment protection, clear desk |
| Technological (A.8) | 34 | Access control, cryptography, logging, vulnerability management, secure development |
Crucially, there is no obligation to implement all 93. Based on your risk assessment you decide which controls to adopt and which to exclude, and record the reasoning in the Statement of Applicability (SoA). "This does not apply to us," properly explained, is a valid answer.
See Annex A 2022: 93 Controls Across Four Themes.
The previous (2013) edition had 114 controls in 14 domains. The transition deadline of 31 October 2025 has passed, so new certifications now target the 2022 edition.
Process and Timeline
A first certification typically targets about six months from kick-off, varying with organisation size and how much is already in place.
| Stage | Typical duration | Main work |
|---|---|---|
| ① Objectives and planning | ~2 weeks | Scope, structure, annual plan; begin selecting a certification body |
| ② Risk analysis | ~1 month | Asset inventory, risk assessment, treatment decisions |
| ③ Building the rules | ~4 months | Policy and objectives, procedures, SoA, incident reporting flow |
| ④ Controls and training | parallel with ③ | Technical and operational controls, training delivery |
| ⑤ Internal audit and correction | ~2 weeks | Internal audit, correcting nonconformities, management review |
| ⑥ Audit (stage 1 and 2) | ~1 month | Stage 1 (1–2 days) → stage 2 (2–3 days) → certification |
Stage ⑤ is the one people miss. Certification requires records of having actually completed one cycle of internal audit and management review. You cannot simply assemble documents and present for audit. Failing to work backwards from this pushes the audit date out.
See ISMS Timeline: What Six Months Actually Looks Like.
The Cost Structure
Costs comprise three different things. When comparing quotes, always check which are included.
| Item | What it covers | How to think about it |
|---|---|---|
| Audit fees | Paid to the certification body; set by auditor-days for stages 1 and 2 | Scales with headcount and scope breadth |
| Consulting fees | Documentation, project management, training, internal audit support | Varies greatly with scope — "templates only" and "internal audit performed for you" are different products |
| Internal effort | Your team's time | The most overlooked. Where no dedicated hire is possible, this decides feasibility |
Certification is also not a one-off: annual surveillance audits and a recertification audit every three years follow. Compare over three years, not year one alone.
See The Full Cost of ISMS Certification and Preparing for Surveillance Audits.
Choosing Between Certifications
| Certification | What it protects | When it fits |
|---|---|---|
| ISMS (ISO/IEC 27001) | Information assets generally | Partners demand evidence of security posture. The default for B2B healthcare |
| Privacy Mark | Personal information | B2C where personal data dominates; strong recognition within Japan |
| SOC 2 | Service organisation controls | US counterparties, overseas SaaS expansion |
| ISO 27017 / 27018 | Cloud-specific concerns | Added on top of ISMS, as a cloud provider |
| ISO 27701 | Privacy information | An ISMS extension; useful for demonstrating GDPR alignment |
For a B2B healthcare company, ISMS first is the baseline: it is what gets specified as a condition of trade most often, and the others build on top of it.
See ISMS vs Privacy Mark, ISMS vs SOC 2, and When Not to Certify.
Getting Past "We Have Nobody to Assign"
The most common reason certification stalls at smaller healthcare companies is not the difficulty of the standard. It is that nobody can run it alongside their normal job.
| Role | Responsibility | Can it be outsourced? |
|---|---|---|
| Top management | Integrating the ISMS, providing resources, owning risk | No — the executive team |
| ISMS manager | Overall construction and operation | No — appointed internally |
| ISMS officers | Supporting operation in each department | No — appointed internally |
| Internal audit manager | Planning and improving audits, documenting results | Yes |
| Internal auditors | Performing audits | Yes |
Because auditors must not audit their own work, internal audit is the hardest part for a small organisation to satisfy in-house. Moving it outside lightens what you need internally considerably.
Healthcare-Specific Concerns
- How to include handling of medical information in scope (Scope Design for Healthcare Companies)
- PHR operators need the personal information law relationship settled first (ISMS for PHR Operators)
- SaMD means running ISMS and QMS (ISO 13485) together (SaMD, ISMS and QMS)
- Clinical trial systems raise alignment with the ER/ES guidance (ISMS for Clinical Trial Systems)
- Healthcare SaaS turns on multi-tenant risk assessment (ISMS for Healthcare SaaS)
It also helps to know how hospitals evaluate their suppliers: Demarcating Responsibility and Security Check Sheets for Vendors are written from the buyer's side.
Conclusion
- An ISMS is not a product purchase but a mechanism for deciding, operating, and checking risk treatment
- The standard is two layers: the main text (clauses 4–10) and Annex A (93 controls). There is no duty to implement all 93 — you justify inclusion and exclusion in the SoA
- The typical timeline is about six months, and records of one completed internal audit and management review are required
- Costs are audit fees, consulting fees, and internal effort. Compare across three years
- For B2B healthcare, ISMS is the baseline; Privacy Mark, SOC 2, and 27017 serve different purposes
- The main reason certification stalls is lack of a dedicated person — and internal audit can be outsourced
Pottech supports ISMS certification with a focus on healthcare. We supply templates for procedures, registers, and training material, and we lead project management and dealings with the certification body, so your team can concentrate on decisions. We can also serve as your internal audit manager and internal auditors.
See ISMS Certification Support for scope and pricing, or contact us to discuss your situation.
References and Sources
- Information Management System Accreditation Center (ISMS-AC)
- On the transition to ISO/IEC 27001:2022 | ISMS-AC
- ISO/IEC 27001 Information security management systems | ISO
- Guidelines for the Safe Management of Medical Information Systems | MHLW
Note: interpretation of requirements and controls, and the handling of accreditation and certification, are governed by the standard itself and the publications of the accreditation and certification bodies. Cost ranges vary substantially with organisation size, scope, and certification body.