For mid-sized companies, the question of ISO 27001 rarely comes from their own auditor. It comes from the customer: as a supplier questionnaire, as a tender criterion, as a contract clause. And it has come up more often since the new BSI act took effect – because the BSIG 2025 (in force since December 6, 2025) requires regulated entities to pass security requirements down their supply chain. What the legislator demands of the large players lands as an evidence question with their suppliers – that is, with many mid-sized companies that have never needed a certificate before.
The good news: no one has to jump from zero to certification. The dependable path is a staircase – and the first step is considerably lower than many assume.
What ISO 27001 means in concrete terms today
Since October 31, 2025, the transition period for the old version has expired: ISO/IEC 27001:2022 is the only valid basis for certification. The current edition is 2022 including Amendment 1:2024 – a minor addition that adds the “Climate Action” aspect at two points in the text but changes nothing about the security framework itself.
At the core of the standard is an information security management system (ISMS): defined responsibilities, risk assessment, control management, continuous improvement. Annex A of the 2022 version comprises 93 controls in four thematic groups:
- Organizational: 37 controls – policies, roles, supplier relationships, incident management.
- People: 8 controls – from onboarding to awareness.
- Physical: 14 controls – access, sites, equipment.
- Technological: 34 controls – from access control through backup to logging.
The structure is aligned with ISO 27002:2022, which serves as an implementation guide. A certificate is valid for three years, with annual surveillance audits and a subsequent recertification. In Germany, certification bodies are accredited by the DAkkS – a criterion you should watch for when making your selection.
The staircase: four steps instead of one leap
Step 1: Determine your position – the CyberRisikoCheck
For smaller companies there is an official entry point below ISO 27001: the CyberRisikoCheck per DIN SPEC 27076, which the BSI helped develop. It is aimed at companies with fewer than 50 employees and is deliberately kept lean: a one- to two-hour interview, 27 requirements across six thematic areas, and at the end a results report with a score and prioritized recommendations – including pointers to possible funding. The BSI maintains a list of qualified service providers permitted to carry out the check. For specific funding programs, it is worth consulting the federal government’s funding database; the terms differ by state and program.
For companies above this size, a structured gap analysis against Annex A achieves the same thing: it shows where you stand – before you plan where you want to go. That this sober look is necessary is shown in passing by the BSI-Lagebericht 2025: on average, SMEs met roughly 56 percent of the baseline requirements of the CyberRisikoCheck – while their self-assessment was predominantly positive (our analysis of the situation report). The gap between self-image and finding is the real reason to begin with a measurement.
Step 2: Close the basics
Nearly every initial analysis produces the same priorities: multi-factor authentication across the board, demonstrably recoverable backups, consistent patch management. These measures reduce real risk immediately – regardless of whether an auditor ever visits. Anyone who skips them and goes straight to writing documents for an ISMS builds a facade instead of a foundation.
Step 3: An ISMS with a clean scope
Only now does the actual ISMS project begin: define the scope, assess risks, select or exclude controls from Annex A with justification, document processes and – crucially – live them. Scope is the biggest lever here: a deliberately drawn scope, for example around the systems and sites that actually affect your customers, keeps the project manageable. On the effort involved, honesty is in order: an ISMS does not emerge as a side project; it ties up management attention and internal capacity over an extended period. It can only be quantified seriously after the gap analysis – blanket project durations from sales brochures do not help with planning.
Step 4: Certify when there is a reason
The certificate itself is the last step – and it pays off when a customer, a tender, or a regulatory framework demands the formal proof. A lived ISMS without a certificate is valuable; a certificate without a lived ISMS is exposed at the surveillance audit at the latest. Anyone who has taken steps one through three seriously turns the certification audit into a plannable conclusion rather than a feat of strength.
The second path: IT-Grundschutz – and what is coming in 2026/2027
Alongside native ISO certification, Germany has the BSI path: the “ISO 27001 certificate on the basis of IT-Grundschutz” demonstrates ISO conformity via the BSI methodology. It is common above all where public authorities or authority-adjacent clients explicitly require it.
Here it is worth looking ahead: the BSI is modernizing its methodology under the name IT-Grundschutz++. The pilot phase runs from April 1 to September 30, 2026, publication is announced for October 27, 2026 at it-sa, and the new approach is expected to be certifiable from January 1, 2027. The existing IT-Grundschutz remains valid in parallel. In practice this means: anyone starting today starts on a secure foundation – and should keep the transition in view during multi-year planning.
Conclusion: start small, but start
For mid-sized companies, ISO 27001 is neither an end in itself nor black magic – but also not a project to hand to an intern with a document template. The realistic path leads via an honest assessment of where you stand, closed-out basics, and a deliberately drawn scope to the certificate when the market demands it. Each step has its own value: less risk, better answers to customer questionnaires, dependable compliance evidence – and the certainty that your self-image of your own security holds up to scrutiny.
How sector7 supports you
As an owner-led firm, we accompany mid-sized companies at every step of this staircase: from determining where you stand, through implementing the baseline measures, to compliance consulting on ISO 27001, NIS-2, DORA, and TISAX. The technical side – from certified network and security expertise (Juniper, Cisco, HPE, F5, Fortinet, Palo Alto Networks), through our Veeam backup practice, to automated 24/7 monitoring via our NOC – we deliver ourselves. On request at plannable flat monthly rates, so the path to an ISMS stays budgetable.
This article is a professional assessment and does not replace legal advice in individual cases.
Sources
- https://www.iso.org/standard/88435.html
- https://www.sgs.com/en/news/2025/09/last-chance-to-transition-to-iso-iec-27001-2022-and-next-steps-if-you-miss-the-deadline
- https://www.dataguard.com/iso-27001/annex-a/
- https://www.dakks.de
- https://www.bsi.bund.de/DE/Themen/Unternehmen-und-Organisationen/Informationen-und-Empfehlungen/KMU/CyberRisikoCheck/CyberRisikoCheck_node.html
- https://medien.bsi.bund.de/lagebericht/de/it-sicherheit-fuer-kmus/
- https://www.bsi.bund.de/DE/Themen/Unternehmen-und-Organisationen/Standards-und-Zertifizierung/IT-Grundschutz/it-grundschutz_node.html
- https://www.bsi.bund.de/DE/Themen/Unternehmen-und-Organisationen/Standards-und-Zertifizierung/Grundschutz-in-der-Informationssicherheit/Grundschutz-Plus-Plus/grundschutz-plus-plus_node.html
- https://www.foerderdatenbank.de