Back to Columns
ISMS & Certification14 min read

What Is an ISMS (ISO/IEC 27001)? A Complete Guide for Healthcare Companies

September 14, 2026

What Is an ISMS (ISO/IEC 27001)? A Complete Guide for Healthcare Companies
Share this article

"Do you hold ISMS certification?" comes up more and more often in dealings with hospitals, pharmaceutical companies, and local governments. In healthcare — PHR, SaMD, clinical trial systems, hospital SaaS — where the information handled is highly sensitive, being able to prove your information security posture to a third party is becoming a precondition for doing business.

Seen from the side considering certification for the first time, though, the standard's requirements are abstract. What must be produced, and to what depth? What does it cost? How long does it take? It is easy to end up holding a quote without the material needed to judge it.

This article gathers what a healthcare company needs in order to decide. Individual topics are split into their own articles, so go deeper wherever you need to.

Disclaimer: This article is general information. The authoritative texts are ISO/IEC 27001 (JIS Q 27001) itself and the publications of the accreditation and certification bodies. Base actual decisions on those.

What Is an ISMS (ISO/IEC 27001)?

An ISMS (Information Security Management System) is the mechanism by which an organisation manages its information assets and continuously maintains their confidentiality, integrity, and availability. The international standard for it is ISO/IEC 27001; the Japanese edition is published as JIS Q 27001.

The key point is that an ISMS is not "installing security products." What the standard requires is a management system — an organisational cycle that keeps turning:

  1. Identify the information security risks that matter to your organisation
  2. Decide which risks to treat, and how
  3. Do what you decided
  4. Check whether you are actually doing it
  5. Improve based on what the check found

The goal is not whether you bought a firewall but being able to explain what your risks are, what you decided to do about them, and whether you operate as decided. Certification is a third-party auditor's confirmation that this mechanism is in place.

Why Healthcare Companies Are Asked for It

Four reasons dominate.

1. It is a condition of trade

Procurement by hospitals, pharmaceutical companies, and local governments increasingly demands evidence of an information security posture. Hospitals in particular carry their own obligations under Japan's three-ministry healthcare guidelines, which forces them to require an equivalent standard of their suppliers. Being excluded for lack of certification does happen.

2. The sensitivity of the data

Patient data, clinical information, PHR, trial data. A breach of any of these can cause irreversible harm to the people involved. Evidence of your controls becomes the basis of trust.

3. Moving beyond person-dependent operations

Early-stage companies often run security on one person's judgement. A structure that stops the moment that person leaves becomes a liability as the business scales. An ISMS shifts it to continuous improvement based on rules (PDCA).

4. It connects to the industry guidelines

Much of what the three-ministry guidelines demand overlaps with ISMS documentation: risk assessment, demarcation of responsibility, supplier management, incident response. Starting from ISMS documents makes industry-specific compliance far more efficient. See Integrating ISMS Documents with the Three-Ministry Guidelines.

The Structure of the Standard

ISO/IEC 27001 divides into two parts. Understanding this first makes everything that follows legible.

The main text (clauses 4–10) — management system requirements

These are the requirements that must be met to certify. Clauses 1–3 cover scope, normative references, and terms, so the practical work sits in clauses 4 through 10.

ClauseContentWhat you produce
4 ContextInternal and external issues, interested parties, ISMS scopeScope definition
5 LeadershipManagement commitment, policy, roles and responsibilitiesSecurity policy, organisation chart
6 PlanningRisk assessment, risk treatment, objectivesRisk assessment table, Statement of Applicability, objectives
7 SupportResources, competence, awareness, communication, documentationTraining plans and records, document control
8 OperationDoing what was plannedOperating rules and records
9 Performance evaluationMonitoring, internal audit, management reviewAudit reports, review minutes
10 ImprovementNonconformity, corrective action, continual improvementCorrective action reports

Each clause is covered in detail starting with ISO/IEC 27001 Clause 4: Context of the Organisation.

Annex A — the 93 controls

The catalogue of controls referenced when deciding risk treatment under clause 6. The 2022 edition organises 93 controls into four themes.

ThemeControlsExamples
Organizational (A.5)37Policies, roles, supplier management, incident management
People (A.6)8Screening, training, disciplinary process, post-employment duties
Physical (A.7)14Physical entry controls, equipment protection, clear desk
Technological (A.8)34Access control, cryptography, logging, vulnerability management, secure development

Crucially, there is no obligation to implement all 93. Based on your risk assessment you decide which controls to adopt and which to exclude, and record the reasoning in the Statement of Applicability (SoA). "This does not apply to us," properly explained, is a valid answer.

See Annex A 2022: 93 Controls Across Four Themes.

The previous (2013) edition had 114 controls in 14 domains. The transition deadline of 31 October 2025 has passed, so new certifications now target the 2022 edition.

Process and Timeline

A first certification typically targets about six months from kick-off, varying with organisation size and how much is already in place.

StageTypical durationMain work
① Objectives and planning~2 weeksScope, structure, annual plan; begin selecting a certification body
② Risk analysis~1 monthAsset inventory, risk assessment, treatment decisions
③ Building the rules~4 monthsPolicy and objectives, procedures, SoA, incident reporting flow
④ Controls and trainingparallel with ③Technical and operational controls, training delivery
⑤ Internal audit and correction~2 weeksInternal audit, correcting nonconformities, management review
⑥ Audit (stage 1 and 2)~1 monthStage 1 (1–2 days) → stage 2 (2–3 days) → certification

Stage ⑤ is the one people miss. Certification requires records of having actually completed one cycle of internal audit and management review. You cannot simply assemble documents and present for audit. Failing to work backwards from this pushes the audit date out.

See ISMS Timeline: What Six Months Actually Looks Like.

The Cost Structure

Costs comprise three different things. When comparing quotes, always check which are included.

ItemWhat it coversHow to think about it
Audit feesPaid to the certification body; set by auditor-days for stages 1 and 2Scales with headcount and scope breadth
Consulting feesDocumentation, project management, training, internal audit supportVaries greatly with scope — "templates only" and "internal audit performed for you" are different products
Internal effortYour team's timeThe most overlooked. Where no dedicated hire is possible, this decides feasibility

Certification is also not a one-off: annual surveillance audits and a recertification audit every three years follow. Compare over three years, not year one alone.

See The Full Cost of ISMS Certification and Preparing for Surveillance Audits.

Choosing Between Certifications

CertificationWhat it protectsWhen it fits
ISMS (ISO/IEC 27001)Information assets generallyPartners demand evidence of security posture. The default for B2B healthcare
Privacy MarkPersonal informationB2C where personal data dominates; strong recognition within Japan
SOC 2Service organisation controlsUS counterparties, overseas SaaS expansion
ISO 27017 / 27018Cloud-specific concernsAdded on top of ISMS, as a cloud provider
ISO 27701Privacy informationAn ISMS extension; useful for demonstrating GDPR alignment

For a B2B healthcare company, ISMS first is the baseline: it is what gets specified as a condition of trade most often, and the others build on top of it.

See ISMS vs Privacy Mark, ISMS vs SOC 2, and When Not to Certify.

Getting Past "We Have Nobody to Assign"

The most common reason certification stalls at smaller healthcare companies is not the difficulty of the standard. It is that nobody can run it alongside their normal job.

RoleResponsibilityCan it be outsourced?
Top managementIntegrating the ISMS, providing resources, owning riskNo — the executive team
ISMS managerOverall construction and operationNo — appointed internally
ISMS officersSupporting operation in each departmentNo — appointed internally
Internal audit managerPlanning and improving audits, documenting resultsYes
Internal auditorsPerforming auditsYes

Because auditors must not audit their own work, internal audit is the hardest part for a small organisation to satisfy in-house. Moving it outside lightens what you need internally considerably.

Healthcare-Specific Concerns

It also helps to know how hospitals evaluate their suppliers: Demarcating Responsibility and Security Check Sheets for Vendors are written from the buyer's side.

Conclusion

  1. An ISMS is not a product purchase but a mechanism for deciding, operating, and checking risk treatment
  2. The standard is two layers: the main text (clauses 4–10) and Annex A (93 controls). There is no duty to implement all 93 — you justify inclusion and exclusion in the SoA
  3. The typical timeline is about six months, and records of one completed internal audit and management review are required
  4. Costs are audit fees, consulting fees, and internal effort. Compare across three years
  5. For B2B healthcare, ISMS is the baseline; Privacy Mark, SOC 2, and 27017 serve different purposes
  6. The main reason certification stalls is lack of a dedicated person — and internal audit can be outsourced

Pottech supports ISMS certification with a focus on healthcare. We supply templates for procedures, registers, and training material, and we lead project management and dealings with the certification body, so your team can concentrate on decisions. We can also serve as your internal audit manager and internal auditors.

See ISMS Certification Support for scope and pricing, or contact us to discuss your situation.

References and Sources

Note: interpretation of requirements and controls, and the handling of accreditation and certification, are governed by the standard itself and the publications of the accreditation and certification bodies. Cost ranges vary substantially with organisation size, scope, and certification body.

Share this article

Related Articles

ISMS & Certification

Reading the 37 Organizational Controls

The 37 organizational controls of Annex A.5, grouped into eight clusters rather than translated one by one: policy and governance, assets and classification, access policy, suppliers and cloud, threat intelligence, incident management, continuity, and compliance. What each cluster is asking for, and what you end up producing.

September 14, 2026
ISMS & Certification

Annex A 2022: 93 Controls Across Four Themes

A map of the 93 Annex A controls in ISO/IEC 27001:2022 across four themes — 37 organizational, 8 people, 14 physical, 34 technological. Why there is no duty to implement all 93, how inclusion and exclusion are justified in the Statement of Applicability, what the attributes are for, and the order a healthcare company should work in.

September 14, 2026
ISMS & Certification

Reading the 8 People Controls

The 8 people controls of Annex A.6, grouped into entry, employment, exit, where people work, and reporting culture. How they connect to existing employment rules, how to handle segregation of duties when the team is too small for it, and how far to go on remote working — written for healthcare companies.

September 14, 2026
ISMS & Certification

Reading the 14 Physical Controls

The 14 physical controls of Annex A.7 in five clusters, with a concrete treatment of what a fully remote, cloud-only organisation can exclude and what must be reassigned to home-working rules and supplier management — data centres, media and disposal, and equipment off premises.

September 14, 2026
AI Karte

Explore AI Karte

An AI-native EHR connecting reception, documentation, accounting, claims, and analytics into one cycle.

View the product page

ISMS Certification Support as an Option

From scope design and documentation to training, internal audit, and dealing with the certification body. Pottech supports healthcare companies through ISO/IEC 27001 certification end to end.