ISO 27001

In short
ISO 27001 is the international standard for an information security management system. What gets certified is not the technology but the procedure: that a business knows its risks, has decided on measures against them, checks whether those measures work, and handles deviations traceably. A firewall cannot hold a certificate. The organisation behind it can.
What actually gets examined
The core is a loop: identify risks, choose measures, apply them, measure, correct. An auditor therefore asks «do you have X» less often than «how do you know X is working, and what did you do the last time it wasn't».
The annex lists measures as a menu, not a mandatory programme. Which of them apply follows from your own risk assessment — and that is precisely the part you cannot buy in.
The mistake we see most
Reading the certificate as proof of security. It is proof of traceability. A certified business can show how it reached its decisions; that does not rule out an incident, but it makes the handling of one auditable.
The second mistake is the direction of travel. Plenty of companies start with the certificate and then go looking for the benefit. It works the other way round. The usual genuine trigger is a tender or a large customer asking for it — at which point it is a market-access question and pays for itself.
The Swiss context
Certification is not mandatory for ordinary Swiss SMEs. The statutory duty sits in the FADP and is phrased more generally: appropriate technical and organisational measures (Art. 8 FADP, SR 235.1), plus notification to the FDPIC of data-security breaches posing a high risk (Art. 24 FADP).
Separately, a 24-hour reporting duty for cyberattacks has applied since 1 April 2025 — but expressly only to operators of critical infrastructure, not to SMEs generally. Conflate the two and you end up building a compliance programme that does not apply to you.
How we handle it
We build the groundwork so a later certification does not start from zero: documented access, traceable changes, restores that have actually been tested. Framework under IT security.
Whether certification makes sense is not decided by headcount. It is decided by whether anyone is asking for it.
Related terms
A term in your quote that nobody explained?
In a strategy call we translate the offer in front of you — even when it did not come from us.