BSI

United States

Service types
  • Auditor
  • ISO 27001
Industries served
  • SaaS
  • Technology

Standards, certification, and assessment services

BSI offers ISO 27001 certification assessment and training. Compare the proposed ISMS scope, audit stages, assigned team, follow-up work, and continuing review costs for your organization.

Source checked September 23, 2026 · View official source

Company sizes served
  • early-stage
  • mid-market
  • enterprise

Documented services

BSI's ISO 27001 page describes assessment through a two-stage audit and discusses training and optional gap analysis. Confirm services available for your location and the legal entity responsible for issuing the certificate.

Engagement considerations

Bring a service boundary covering your organization, locations, systems, interfaces, and customer expectations. Ask how that boundary affects the audit plan, assigned staff, and required records. Separate implementation or training from the certification assessment.

Request an example audit plan and findings-response process with client details removed. Discuss how the body communicates prerequisites for each stage and what happens when evidence or corrective work is incomplete. Establish the expected certification decision process rather than relying on a target issue date alone.

Questions to verify in a consultation

  • Which entity issues the certificate and where can relevant accreditation be verified?
  • Which scope, sites, and audit methods are included?
  • Who performs the work and what access is required?
  • How are findings and follow-up reviews handled?
  • Which surveillance, recertification, travel, and change fees apply?

Scope to confirm

Compare preparation, initial assessment, optional services, follow-up work, and the continuing audit cycle separately. Ask how certificate status and scope can be checked after issuance. Public service descriptions do not establish accreditation for your particular engagement or guarantee a certification outcome.

Plan ISO 27001 certification · Explore ISO 27001 resources · Plan evidence collection

Buying content reviewed October 1, 2026. Public sources; no firsthand service evaluation.