What is ISO 27001? The Complete Guide for Swiss Companies

What is ISO 27001?

ISO 27001 is the internationally recognised standard for Information Security Management Systems (ISMS). Developed by the International Organisation for Standardisation (ISO) together with the International Electrotechnical Commission (IEC), it defines how organisations should systematically protect their information.

The standard specifies the requirements an organisation must meet to identify, assess, and treat information security risks. An ISO 27001 certification means that an independent auditor has confirmed that the organisation meets these requirements.

Why Does ISO 27001 Matter?

In an increasingly digital world, information is one of the most valuable assets a company has. Data breaches, cyberattacks, and privacy violations can cause enormous financial and reputational damage.

ISO 27001 helps organisations to:

  • Systematically identify and reduce security risks
  • Build trust with customers, partners, and investors
  • Meet legal and regulatory requirements — including Switzerland’s nFADP
  • Use compliance as a competitive advantage and win new deals

For Swiss IT companies, ISO 27001 is increasingly non-optional — many large enterprises and public institutions require it from their suppliers as a prerequisite for doing business.

ISO 27001:2022 — The Current and Only Valid Version

The current version is ISO 27001:2022, published in October 2022. Important: the transition period for the old version (ISO 27001:2013) expired on 31 October 2025. The 2013 version is now officially retired and invalid. Every new certification and every existing certificate must today conform strictly to the 2022 standard.

The key updates in ISO 27001:2022:

  • The number of controls was reduced from 114 to 93 and restructured
  • 11 completely new controls were added — including Threat Intelligence, Cloud Security, and Data Leakage Prevention. Particularly relevant for Swiss SaaS companies managing customer data in the cloud.
  • The focus on cybersecurity and data privacy was significantly strengthened

What Are the 93 Controls?

ISO 27001:2022 contains 93 controls divided into four categories:

  • Organisational controls (37) — policies, roles, responsibilities
  • People controls (8) — training, awareness, background checks
  • Physical controls (14) — access controls, device security
  • Technological controls (34) — encryption, network security, monitoring

Not all controls need to be implemented — organisations conduct a risk assessment and select the relevant controls based on their specific risk profile.

How Does ISO 27001 Certification Work?

The certification process typically involves the following steps:

  1. Gap analysis — Where does the organisation stand today compared to the requirements?
  2. Risk assessment — What information security risks exist?
  3. Treatment plan — Which controls will be implemented?
  4. Implementation — Roll out policies, processes, and technical measures
  5. Internal audit — Review of implementation before the external audit
  6. External audit (Stage 1) — Documentation review by an accredited auditor
  7. External audit (Stage 2) — Verification of actual implementation
  8. Certification — Issuance of the ISO 27001 certificate (valid for 3 years)

How Long Does ISO 27001 Certification Take?

For a Swiss SME with 10-100 employees, the process typically takes between 3 and 12 months, depending on:

  • The size and complexity of the organisation
  • The current maturity level of information security
  • Available internal resources
  • The chosen certification body

How Much Does ISO 27001 Certification Cost in Switzerland?

This is one of the most common questions — and the answer surprises many Swiss SMEs:

  • External ISO 27001 consulting: CHF 30,000–80,000 for a typical SME project
  • Internal personnel costs: 100–300 hours of effort for internal staff
  • Certification audit: CHF 5,000–15,000 depending on the certification body and company size
  • Annual surveillance audits: CHF 2,000–6,000 per year

The good news: with the right platform and preparation, consulting costs can be significantly reduced. Normapulse automates the bulk of this process — gap analysis, risk register, task management, and documentation — substantially reducing the time and cost burden for Swiss SMEs.

ISO 27001 and the Swiss Federal Act on Data Protection (nFADP)

For Swiss companies, ISO 27001 is particularly relevant in the context of the revised Federal Act on Data Protection (nFADP), which has been in force since September 2023. Many ISO 27001 requirements align directly with nFADP requirements — an ISO 27001 certification therefore also significantly supports nFADP compliance.

Additionally, Swiss companies and their clients place great importance on data sovereignty. ISO 27001 combined with Swiss data hosting — for example on Swiss cloud infrastructure — is today a powerful competitive differentiator against international competitors.

Is ISO 27001 Right for Your Organisation?

ISO 27001 is particularly recommended for:

  • IT service providers and SaaS companies
  • Companies that handle sensitive customer data
  • Companies operating in regulated industries
  • Companies looking to win large enterprises or public institutions as clients

If your clients or potential clients are asking for proof of your security posture — or if you are losing tenders because you cannot show a certificate — ISO 27001 is the right next step.

Conclusion

ISO 27001 is far more than a compliance checkbox. It is a strategic tool that helps Swiss IT companies build trust, reduce risk, and turn compliance into a competitive advantage.

Traditional ISO 27001 consulting costs CHF 30,000–80,000 and requires hundreds of hours of manual work. Normapulse automates this process — from gap analysis to audit-ready documentation — so Swiss SMEs can achieve certification faster, cheaper, and with far less effort.

Discover more from Normapulse — AI-native Compliance Operating System

Subscribe now to keep reading and get access to the full archive.

Continue reading