Terravek has been certified to ISO/IEC 27001 since 2015. Customers ask what the certificate means, and the honest answer is more interesting than either the marketing version or the cynical version.
The cynical version says a certificate proves only that you can produce documents. This is not quite right, but it is not wrong either — a badly run ISMS certifies successfully if the documents match the practice, even when the practice is mediocre.
What the certificate does prove is that there is a management system: risks are identified, controls are chosen deliberately, exceptions are recorded and approved by someone with the authority to accept the risk, and somebody checks. That is genuinely valuable and it is not free.
The audit cycle is a three-year certification with surveillance audits in years one and two. Ours runs about nine days of auditor time a year, against maybe forty days of internal preparation and a permanent overhead of doing things in a way that is evidenced rather than merely done.
The 2022 transition to the :2022 revision is the next milestone. The control set has been restructured and reduced from 114 to 93 — which is less of a change than it sounds, but the mapping exercise is real work.