ISO 27001 Certification
DigiTrust is happy to help your organisation achieve your ISO 27001 certification and is the expert on information security in the Netherlands. Assessing your information security management system is our core business. We have our own team of auditors, who look closely at the context of your organisation.
- Accredited for ISO 27001 by the RvA (C618)
- Your audit starts when it suits your organisation.
- Personal guidance throughout the certification process.
- Sharp prices
More than 500 organisations have already gone before you.
![Certification process - DigiTrust - ISO 27001 Certification - NEN 7510 Certification - ISO 9001 certification - ISO 14001 Certification](https://www.digitrust.nl/wp-content/uploads/2022/05/IMG_4921-scaled-1-2048x1536.jpeg)
ISO 27001:2022 and the ISO27001:2023
ISO27001:2023 version
Yes you read correctly, there is a 2022 AND a 2023 version. How about that?
The ISO/IEC 27001:2022 standard was published in October 2022. This is a global - international standard. To prevent international standards conflict with European standards, the European Committee for Standardisation (CEN) must first approve those international standards. On 23 July 2023, CEN approved the international 2022 version, without modifications, for Europe. NEN accepted this version for the Netherlands and published it in August 2023, making the following versions available:
- NEN-EN-ISO/IEC 27001:2023 en
- NEN-EN-ISO/IEC 27001:2023 and
So these are the European - Dutch versions.
The international / global version is and will therefore remain: ISO/IEC 27001:2022.
If you want to certify, you need to specify whether you want to be certified for the European-Dutch version or international. Do you want to buy the ISO 27001 standard, then look here.
New name ISO 27001 certification
The new version of the ISO27001 standard has also been renamed. The full name is now: Information security, cybersecurity and privacy protection - Information security management system
Adjustment HLS
In chapters 4 to 10 (HLS), some minor changes have been made. These include H4 stakeholder analysis, H6.3 Managing changes to your ISMS, H8 operational planning, H9 internal audit and the Management Review and finally H10 where the 10.1 and 10.2 topics have been reversed. These are minor changes that you can implement quite easily in your ISMS.
Adjustment Annex A
The current ISO 27001:2013 contained 114 measures divided into 14 chapters. The ISO 27001:2022 standard has been reduced to four chapters, many of whose measures have been merged:
- Annex 5 (organisation-specific control measures)
- Annex 6 (human-centred management measures)
- Annex 7 (physical security management measures)
- Annex 8 (technical management measures)
There are now a total of 96 management measures, of which 11 are new.
From ISO 27001:2013 to ISO 27001:2023
For already certified organisations, the transition from ISO 27001:2013 to ISO 27001:2023 will have to take place within 3 years and you will also have to comply with the new version within 3 years. The deadline depends on the date of birth of your certificate. The DigiTrust back office can assess your situation and determine with you when your deadline is. Of course, you may also switch to the new standard earlier. This transition is done via a Transition Audit.
If you are going to start a new initial certification with DigiTrust, we may perform it on this new version of the standard from 01/02/23.
From 30 April 2024, we are no longer allowed to certify on ISO27001:2013. From this date, we will only be allowed to perform certifications on the new version of the standard.
Transition audit if you are already certified with us
According to the applicable guidelines, DigiTrust must schedule the appropriate audit time with you before conducting the transition audit.
In case of a separate transition audit or combined with a control audit, 1 additional day will be charged. If the transition audit is combined with a HER certification then 0.5 will be charged for the additional transition audit.
During this audit, we review some topics to assess whether you are really ready to transfer your current certificate to one against the ISO27001:2023 version.
What are we going to assess?
- GAP analysis performed
- Risk analysis and treatment plan
- VVT adaptation
- Internal audit
- Management review
NEN 7510 or ISO 27001?
If you have a NEN7510 certification then it will remain on the current version. After all, no new version of this standard is available yet. If you have both ISO27001 and NEN7510 certification, you can already switch to the new standard with your current ISO27001 certification. This will create a situation of 'old and new' mixed up in your ISMS.
The administrator/owner of this standard is the NEN. Because a new version of ISO 27001 has been released, the NEN standards committee is currently working on a new version of NEN7510 as well. This is only expected to be finalised and published during 2024.
Do you have any questions about this or about ISO certification 27001 at all? Then please take contact with us.
Proudly certified by DigiTrust
![Certification process - DigiTrust - Topicus](https://www.digitrust.nl/wp-content/uploads/2021/08/topicus-logo-2020-oblong-rgb-dark1-300x100.png)
![Certification process - DigiTrust - Pink](https://www.digitrust.nl/wp-content/uploads/2022/11/Pink-logo-300x150.png)
![Certification process - DigiTrust - Stedin](https://www.digitrust.nl/wp-content/uploads/2022/09/Stedin-logo-300x135.png)
![Certification process - DigiTrust - ISO Group](https://www.digitrust.nl/wp-content/uploads/2022/12/ISO_Groep_Logo_rgb-300x159.png)
![Certification process - DigiTrust - Enexis](https://www.digitrust.nl/wp-content/uploads/2021/08/enexis-300x113.png)
![Certification process - DigiTrust - Spie](https://www.digitrust.nl/wp-content/uploads/2023/08/Logo-Spie-Transparant-300x146.png)
![full-colour](https://www.digitrust.nl/wp-content/uploads/2022/12/full-color-300x60.png)
![Certification process - DigiTrust - Meander](https://www.digitrust.nl/wp-content/uploads/2021/08/meander.png)
![Certification process - DigiTrust - Antoni van Leeuwenhoek](https://www.digitrust.nl/wp-content/uploads/2022/11/logo-NL-Antoni-van-Leeuwenhoek_grootformaat_jpeg-9x6-1-300x200.jpg)
![Certification process - DigiTrust - Ipse de Bruggen](https://www.digitrust.nl/wp-content/uploads/2021/08/ipse-de-bruggen-300x300.jpeg)
![logo-zl-concern[1]](https://www.digitrust.nl/wp-content/uploads/2025/02/logo-zl-concern1-300x90.jpg)
![Certification process - DigiTrust - Province of Brabant](https://www.digitrust.nl/wp-content/uploads/2021/08/Logo-Provincie-brabant-1530x852-1-300x167.png)
![Certification process - DigiTrust - Hosted](https://www.digitrust.nl/wp-content/uploads/2021/08/hosted-xl-logo-300x144.jpeg)
![Certification process - DigiTrust - Cab Holland](https://www.digitrust.nl/wp-content/uploads/2022/12/download-300x145.png)
![Certification process - DigiTrust - GGD GZ](https://www.digitrust.nl/wp-content/uploads/2021/08/ggdgz-square-logo-1.png)
![certification-trail-digitrust-hoeflake](https://www.digitrust.nl/wp-content/uploads/2023/05/Hoeflake-logo-300x130.png)
![Certification process - DigiTrust - eXperIT](https://www.digitrust.nl/wp-content/uploads/2021/11/logoeXperIT-300x96.png)
![download](https://www.digitrust.nl/wp-content/uploads/2024/02/download.png)
![Certification process - DigiTrust - Bizzcon](https://www.digitrust.nl/wp-content/uploads/2021/10/Bizzcon-Logo-4-color-2448-x-1580-300x194.png)
![Certification process - DigiTrust - Qii](https://www.digitrust.nl/wp-content/uploads/2021/08/qii-logo.png)
![logo_tcc_thecomputercompany-2](https://www.digitrust.nl/wp-content/uploads/2021/06/logo_tcc_thecomputercompany-2-300x153.png)
![Certification process - DigiTrust - Infozorg](https://www.digitrust.nl/wp-content/uploads/2021/08/250x132-infozorg-logo-a.jpeg)
![Certification process - DigiTrust - Hihaho](https://www.digitrust.nl/wp-content/uploads/2022/12/hihaho-logo-300x200.jpg)
![Certification route - DigiTrust - ITON](https://www.digitrust.nl/wp-content/uploads/2021/08/Logo-ITON-300x159.jpeg)
![gp_logo_ms-v3](https://www.digitrust.nl/wp-content/uploads/2022/03/GP_LOGO_MS-V3-272x300.png)
![Certification process - DigiTrust - Province of Gelderland](https://www.digitrust.nl/wp-content/uploads/2023/05/PG-logo-zw-750x268px-300x107.jpg)
![Certification process - DigiTrust - Indicia](https://www.digitrust.nl/wp-content/uploads/2021/08/logo_indicia_payoff_zwart-300x170.png)
![Certification process - DigiTrust - Nitea](https://www.digitrust.nl/wp-content/uploads/2022/09/nitea-300x212.png)
![Certification process - DigiTrust - The People Group](https://www.digitrust.nl/wp-content/uploads/2021/08/TPG-300x158.png)
![Certification process - DigiTrust - informens](https://www.digitrust.nl/wp-content/uploads/2022/09/logo_informens.png)
![Certification process - DigiTrust - ip4sure](https://www.digitrust.nl/wp-content/uploads/2021/08/ip4sure_transparant_web-300x102.png)
![Certification process - DigiTrust - Softmedia](https://www.digitrust.nl/wp-content/uploads/2022/09/softmedia-logo.png)
![schermafbeelding-2021-04-14-om-17-04-54](https://www.digitrust.nl/wp-content/uploads/2022/08/Schermafbeelding-2021-04-14-om-17.04.54-2-300x97.png)
![Xinno ISO27001 certification - certification process](https://www.digitrust.nl/wp-content/uploads/2022/08/qJ7UVvdH_400x400-300x300.png)
![spaarne-gasthuis-300x152-e1481635004909](https://www.digitrust.nl/wp-content/uploads/2023/12/Spaarne-Gasthuis-300x152-e1481635004909.png)
![linkit-1](https://www.digitrust.nl/wp-content/uploads/2021/08/linkit-1-300x225.jpeg)
![Certification process - DigiTrust - Iwink](https://www.digitrust.nl/wp-content/uploads/2021/08/iwink-300x152.png)
![Certification process - DigiTrust - Constant-IT](https://www.digitrust.nl/wp-content/uploads/2021/04/Logo-Constant-IT-met-tekst-e1519732342794-300x58.jpeg)
![cab-holland](https://www.digitrust.nl/wp-content/uploads/2022/12/cab-holland-300x81.png)
![cybercloud logo](https://www.digitrust.nl/wp-content/uploads/2023/01/Cybercloud-logo-300x158.jpg)
![bit logo](https://www.digitrust.nl/wp-content/uploads/2023/01/BIT-logo-300x142.jpg)
![Certification process - DigiTrust - ARROW](https://www.digitrust.nl/wp-content/uploads/2023/02/2016-02-02-ARROW-Logo-CMYK-300x71.webp)
![Certification process - DigiTrust - Rijnmond Doctors](https://www.digitrust.nl/wp-content/uploads/2023/02/logo-300x169.jpeg)
![logo_line_no_background](https://www.digitrust.nl/wp-content/uploads/2023/02/Logo_line_no_background-300x50.png)
![Certification process - DigiTrust - ARCHIE](https://www.digitrust.nl/wp-content/uploads/2023/03/ARCHIE-LOGO-_-AUBERGINE-tbv-Digitrust-300x69.png)
![rgb_full-color_black8x](https://www.digitrust.nl/wp-content/uploads/2023/03/rgb_full-color_black@8x-300x93.png)
![dionar background](https://www.digitrust.nl/wp-content/uploads/2023/04/Dionar-achtergrond-300x116.png)
![schermafbeelding-2023-04-22-150754](https://www.digitrust.nl/wp-content/uploads/2023/04/Schermafbeelding-2023-04-22-150754-300x98.jpg)
![logo](https://www.digitrust.nl/wp-content/uploads/2023/05/logo.jpg)
![logo_tt_2021_screen](https://www.digitrust.nl/wp-content/uploads/2023/06/Logo_TT_2021_scherm-300x81.jpg)
![Certification process - DigiTrust - Calibre](https://www.digitrust.nl/wp-content/uploads/2023/07/Kaliber-logo_zwart-300x243.png)
![schermafbeelding-2023-08-31-212010](https://www.digitrust.nl/wp-content/uploads/2023/08/Schermafbeelding-2023-08-31-212010-300x190.jpg)
![Certification process - DigiTrust - Vival Care Group](https://www.digitrust.nl/wp-content/uploads/2023/08/logo.jpg)
![Certification process - DigiTrust - Ten](https://www.digitrust.nl/wp-content/uploads/2023/10/tien-logo-1024x408-1-300x120.png)
![20211103-314335541-wza-logo](https://www.digitrust.nl/wp-content/uploads/2024/02/20211103-314335541-wza-logo-300x46.png)
![schermafbeelding-2024-02-13-194425](https://www.digitrust.nl/wp-content/uploads/2024/02/Schermafbeelding-2024-02-13-194425-300x115.png)
![treant_logo2022_rgb_green-plane_pos](https://www.digitrust.nl/wp-content/uploads/2024/02/Treant_Logo2022_rgb_Groen-Vlak_pos-300x80.jpg)
![logo-1500px](https://www.digitrust.nl/wp-content/uploads/2024/05/Logo-1500px-1-300x126.jpg)
![catharina_hospital_logo-small](https://www.digitrust.nl/wp-content/uploads/2024/05/Catharina_Ziekenhuis_logo-small-300x82.jpg)
![EyeOn logo black](https://www.digitrust.nl/wp-content/uploads/2024/06/EyeOn-logo-zwart-300x96.png)
![logo](https://www.digitrust.nl/wp-content/uploads/2024/07/logo-300x86.png)
![DCSolutions logo](https://www.digitrust.nl/wp-content/uploads/2024/08/DCSolutions-logo-300x90.jpg)
![cmyk-Logo Cura Mare [top]](https://www.digitrust.nl/wp-content/uploads/2024/09/RGB-Logo-CuraMare-300x45.jpg)
![logo_karmacii](https://www.digitrust.nl/wp-content/uploads/2024/10/logo_karmacii.png)
![logo](https://www.digitrust.nl/wp-content/uploads/2024/10/logo-300x94.png)
![smc_logo-01](https://www.digitrust.nl/wp-content/uploads/2024/10/smc_logo-01.webp)
![Sollie-Logo-Grey-Orange-payoff](https://www.digitrust.nl/wp-content/uploads/2025/01/Sollie-Logo-GrijsOranje-payoff-300x113.png)
![Frontis-Corporate-Logo](https://www.digitrust.nl/wp-content/uploads/2025/02/Frontis-Corporate-Logo-300x300.png)
or call one of our specialists
The standards explained
What is ISO 27001?
ISO 27001 is a globally recognised standard in the field of information security. As an organisation, you therefore need to have your information security in order. A data breach not only has financial consequences for your organisation, but also affects your reputation.
In the ISO 27001 standard all information security requirements are laid down. With certification against this standard, you demonstrate that you have a working information security management system. Moreover, certification is a requirement in many tenders.
Why is ISO 27001 certification important?
If, as an organisation, you do not secure your business data the data of your customers, suppliers or stakeholders, the consequences can be dire. For instance, a hack or data breach could cause this sensitive information to be out in the open with all the consequences.
With an ISO 27001 certification, you ensure that the set of measures, processes and procedures in place to minimise a data breach or unwanted access to important information such as personal data, intellectual property, business-sensitive information or information of customers and relations is in place. This provides confidence for others to do business with your company.
The steps explained
How can you achieve ISO 27001 certification as a company?
You can purchase the ISO 27001 standard through the NEN. To obtain certification, there is first a ISO 27001 audit needed. This is where DigiTrust can help you. Our certification process has a number of logical steps.
During the Pre-audit, we check whether you are ready for certification. What is the status of the management system? Are there any issues that may not be in order? Together with you, DigiTrust can determine which topics should be covered during this pre-audit. We also determine the duration together. Usually this is between 2 and 4 days for a good picture of the management system and all control measures. After each pre-audit, DigiTrust provides you with a clear audit report, detailing where you may not yet be working in accordance with the ISO 27001 standard requirements.
Tip; this is a frequently chosen option. It really gets you started in the process and immediately gives you a good idea of where you stand as an organisation.
Initial certification
DigiTrust tests whether the system works and functions according to the requirements from ISO 27001. This assessment also includes the review of all operations at your office as well as at the implementation site. The initial certification consists of 2 parts. The phase 1 and phase 2 audit.
During the phase 1 audit, we take an outline look at your management system (ISMS) and whether you are really ready for the phase 2 audit. We will also create the audit plan together for the phase 2. Who do we need when.
During the phase 2 audit, we test the ISMS and all management measures.
Phase 1
During the phase 1 audit, we take an outline look at your management system (ISMS) and whether you are really ready for the phase 2 audit. We will also create the audit plan together for the phase 2. Who do we need when.
Phase 2
During the ISO 27001 phase 2 audit, we test the ISMS and all control measures.
Issue certificate
In case of a positive assessment, the auditor will nominate the organisation for certification. The certification manager will do a quality check on the file. If everything is in order, you will receive the ISO 27001 certification.
Control 1
During the term of the ISO certification 27001 certificate, which is typically three years, DigiTrust will conduct an annual surveillance audit. During a surveillance audit, we will take a sample on the various standard elements. In case of a positive assessment, the ongoing certificate will be continued.
Control 2
DigiTrust will visit about three months before the certificate expires for the reassessment. This assessment is of the same scope as the one at step 2 and should ensure that if the result is positive, the certificate is renewed for another three years.
What is the investment for ISO 27001 certification?
Curious about the investment of an ISO 27001 certification and how they are structured? The basis of the audit time and therefore the cost starts with the number of FTE working within the scope of certification, the number of full-time equivalents. It then looks at the complexity of the IT landscape and your organisation in general. Which products/services and processes play a role within your scope of certification? Questions that come into play here are:
- What (critical) sectors do you work in?
- Do you develop software?
- Do you have your own server or do you store data in the cloud?
These factors determine, among others, the complexity of the information security management system and determine the final number of audit days and thus the costs involved in obtaining ISO 27001 certification. To get a good idea of this, we will always send you our intake form.
We try to keep the cost of ISO 27001 certification as low as possible through a competitive daily rate. Meanwhile, you can count on senior auditors with in-depth expertise and broad experience in the ICT, healthcare and government sectors.
At DigiTrust, you can expect;
- Sharp daily rates
- Own auditors, we do not work with hired auditors
- Quick response to all your questions
- Direct contact with the back office and auditors
- Quick quote, usually within a few days
- We can often schedule your audit at short notice
Questions about ISO 27001 certification or curious about the possibilities?
Our specialists will be happy to tell you more about it. Call us at 088-224 56 00, please email us at sales@digitrust.nl or use our online contact form. We will be happy to visit you for a no-obligation introduction.
More than 300 organisations have already gone before you.
- Read more about this certification:
- ISO 27001 certification
- ISO 27001 Standard
- ISO 27001 Checklist
- Download ISO 27001 PDF
- ISO 27001 Audit
- Information security
- Certification path
- Other certifications