The number of ISO 27001 certificates in circulation nearly doubled in a single year. According to an analysis of the ISO Survey 2024 by HEIC, the number of valid ISO/IEC 27001 certificates worldwide jumped to 96,709 in 2024, up from 48,671 the year before. That kind of growth is good news for information security as a discipline, but it also means the badge on a vendor’s website tells a buyer less than it used to. A logo proves an audit happened once. It doesn’t prove the organization behind it treats security as an ongoing practice rather than an annual event, and that gap is exactly what a serious ISO 27001 audit is supposed to catch.
Part of what’s driving the surge is pressure from two directions at once: regulators writing third-party security requirements directly into law, and buyers who have watched enough vendor breaches to stop taking a logo at face value. Neither pressure goes away once a certificate is issued — both keep applying for as long as the relationship lasts, which is why the interesting question isn’t whether a partner is certified, but what that certification is actually doing day to day.
Growin went through that process itself. In 2025, JOYN Group — the group Growin is part of — achieved ISO/IEC 27001 certification, and the process made clear how much distance can exist between “certified” and “secure.” For CTOs, procurement leads, and anyone evaluating an outsourced or nearshore IT partner, the certificate itself is a starting point for questions, not an answer. Here are six signals that separate an ISO 27001 certification backed by real security operations from one that exists mostly for the sales page.
A real ISMS maps to an active risk register, not a filing cabinet
ISO 27001 requires an information security management system (ISMS), and the ISMS requires a risk register. On paper, every certified organization has one. In practice, the gap between having a risk register and using one is enormous, and it’s exactly the kind of gap the SecurityScorecard 2026 Supply Chain Cybersecurity Trends Report puts numbers on: 78% of organizations admit their internal cybersecurity programs cover less than half of their total vendor ecosystem, even as 90% of the same leaders say they’re confident their business could keep running through a vendor breach.
That confidence isn’t backed by coverage, and it shows up as a widening blind spot exactly where ISO 27001 is supposed to close one. A risk register that only ever grows, never gets pruned, and never assigns a name to each open item isn’t evidence of diligence — it’s evidence that risk management stopped being anyone’s job in particular.

The risk register gets reviewed on a schedule, not just before audit
A working risk register changes throughout the year: new risks get added when the business changes, old ones get closed when controls mature, and ownership is assigned to a named person, not a department. If a vendor’s risk register only gets touched in the weeks before a surveillance audit, that’s a tell. Ask when it was last updated outside of an audit cycle, and who’s accountable for acting on it.
Findings from testing actually change what the team does next
Penetration tests, vulnerability scans, and internal audits are only useful if they produce action. A mature ISO 27001 program can show a closed-loop process: finding, owner, remediation deadline, verification. A vendor that can’t produce that trail — even in summary form — is telling you the ISMS exists to pass audits, not to reduce risk, and that distinction only becomes visible once you ask for specifics instead of accepting a summary slide.
Real audit rights outlast the sales pitch
Every vendor will agree, in a pitch meeting, that you can review their security posture. What matters is whether that right survives into the contract, and whether it extends to the parts of the vendor’s operation you can’t see directly — including the AI tools and subprocessors increasingly woven into delivery. As Sprinto points out in its analysis of AI risk in vendor ecosystems, a vendor may use an AI model from one provider while hosting inference on another provider’s infrastructure entirely, and each of those relationships introduces a subprocessor that standard vendor questionnaires were never built to capture.

Growin’s own delivery teams, for example, increasingly work alongside AI agents in software development, and any serious ISO 27001 program has to extend its risk register and audit scope to cover exactly that kind of tooling, not just the humans on the account team.
The contract specifies what you can inspect and how often
“Right to audit” clauses are common; specific ones are rarer. Look for language that names the cadence (annual, on-notice, post-incident), the scope (which sites, which systems), and what happens if the vendor fails to remediate a finding on schedule. Vague audit rights tend to stay vague in practice, and a clause that only says “reasonable access on reasonable notice” is a clause that hasn’t been tested by anyone yet.
Subcontractors, subprocessors, and AI tools are covered too
An ISO 27001 scope statement should tell you exactly what’s inside the certified boundary. If a vendor’s certified ISMS covers headquarters but not the regional delivery center actually staffed on your account — or the AI coding assistants and automation tools that team uses — the certificate is protecting less of your relationship than it appears to.
Certification means the 2022 Annex A controls, not the 2013 leftovers
ISO/IEC 27001:2022 replaced the 2013 edition, and the transition period for existing certificate holders closed on October 31, 2025. As SGS explained ahead of the deadline, organizations that missed the transition saw their existing certification become invalid, and going forward they’re treated as new applicants subject to a full initial audit rather than a lighter transition review. Anyone still presenting a 2013-era certificate at this point either let their certification lapse or is showing you an out-of-date document.

That operational discipline — closing gaps before deadlines rather than after — is the same discipline Growin has built into how it structures its own services for clients, treating security requirements as part of delivery rather than a separate compliance exercise bolted on afterward.
The October 2025 transition deadline separated current certificates from expired ones
If you’re validating a vendor’s ISO 27001 status, check the certificate’s issue and expiry dates directly with the certification body listed on it, not just the badge on the vendor’s marketing site. A certificate that predates the 2022 revision and has no updated successor is not current, no matter how recent the logo on the vendor’s homepage looks.
The 2022 controls add explicit coverage for cloud and threat intelligence
The 2022 Annex A restructured the control set and added new controls covering areas like cloud security and threat intelligence that the 2013 edition addressed only indirectly. A vendor certified under the current revision has, at minimum, been assessed against controls that map more closely to how modern IT delivery actually works. The additions also formalize expectations around secure configuration management, data masking, and monitoring for suspicious activity — areas earlier revisions addressed only loosely, if at all, and left largely to each certified organization’s discretion.
Security proof shows up in the RFP, not after a breach
Regulators are increasingly writing vendor due diligence into law rather than leaving it to buyer discretion. Under the EU’s Digital Operational Resilience Act, financial entities are required to build ICT third-party risk management into their contracts and monitoring, including key contractual provisions and oversight of critical ICT third-party providers — obligations that entered into application on January 17, 2025, and that flow downstream to any IT partner serving those entities. A vendor that treats ISO 27001 evidence as something to produce reactively, after a client asks or after an incident, is behind where regulated buyers now expect the conversation to start.

This is also where working with a partner that has already been through a structured evaluation like the one CTOs use before signing a nearshore engagement pays off — the questions procurement teams should be asking about security posture overlap heavily with the questions an ISO 27001 audit is designed to answer.
Buyers are asking for ISO 27001 evidence earlier in the process
Security questionnaires used to arrive after a vendor was shortlisted. Increasingly, they’re part of the initial RFP, and a vendor that can answer them from an existing, audited ISMS rather than scrambling to produce documentation is signaling that security isn’t a bolt-on for this particular deal. A vendor that needs weeks to assemble evidence it should already have on hand is telling a buyer something about how the rest of the engagement will run, long before any code gets written.
Third-party involvement is a persistent factor in modern breaches
Vendor relationships are a recurring theme in breach investigations precisely because they extend an organization’s attack surface beyond what its own security team controls directly — which is the entire premise behind writing third-party oversight into regulation rather than leaving it as a best practice. A buyer that only asks about a vendor’s own perimeter, and never about the vendor’s vendors, is leaving exactly the gap this shift in regulation is trying to close.
Certification should line up with sector rules like DORA and NIS2
ISO 27001 is a voluntary international standard, but it increasingly has to coexist with binding regional law. In the EU, the NIS2 Directive requires member states to transpose cybersecurity obligations into national law, and Wavestone’s tracker of that process shows 20 of the 27 EU member states had officially completed transposition as of January 2026, with the rest still moving through draft legislation at different speeds. That unevenness matters for any vendor operating across borders: a partner certified to ISO 27001 in one jurisdiction may still face materially different reporting and registration obligations depending on where its clients and its own operations sit.

For vendors and clients working across Portugal, Belgium, and the wider EU — Growin’s own footprint, for instance — that patchwork means ISO 27001 has to function as a baseline that local regulatory obligations build on top of, not a substitute for tracking them separately.
DORA turns vendor security into a contractual obligation for financial-services clients
If your organization is a financial entity in scope for DORA, your ICT vendors are expected to accept specific contractual terms covering monitoring, audit, and incident cooperation — not just hold a certificate. ISO 27001 certification makes those conversations faster, but it doesn’t replace the paperwork DORA requires.
NIS2 transposition is still uneven across the EU, which raises the bar for cross-border vendors
Because member states are transposing NIS2 on different timelines and with different national specifics, a vendor serving clients in multiple EU countries needs a security program flexible enough to satisfy whichever national implementation applies, not just the strictest reading of the directive itself. Buyers evaluating cross-border partners should ask which national frameworks a vendor already tracks, rather than assuming ISO 27001 alone closes every regional gap.
Certification changes what happens after an incident, not just before one
The real test of an ISMS isn’t the audit; it’s what happens when something goes wrong. The IBM and Ponemon Institute Cost of a Data Breach Report 2026 put the global average cost of a data breach at $4.99 million, a 12% increase over the prior year and a record high, driven largely by detection, escalation, and lost-business costs — the exact costs a tested incident response process is designed to compress.
The same report found that AI-driven attacks, now involved in roughly a quarter of malicious breaches, cost an average of $6 million, about $1 million above the overall average, which is one more reason the AI tooling discussed earlier in this piece belongs inside a vendor’s ISO 27001 scope rather than outside it.

Continuous cloud security posture monitoring is where that gap actually closes — configuration drift and access missteps get flagged in real time instead of surfacing at the next scheduled audit. That distinction is what separates a documented incident response plan from one that has actually been exercised against how these breaches happen in practice, not just written down.
Vendors that can show this kind of continuous monitoring alongside their ISO 27001 certification are demonstrating exactly the operational maturity the standard is meant to represent, and it’s a fair question to ask in any procurement conversation — not everyone claiming the certificate can back it up with evidence that the controls are actually being watched day to day, rather than reviewed once a year.
Breach costs keep climbing, and AI-related incidents cost more
Budgeting for security as a fixed, one-time certification cost misses where the real expense sits: response and recovery when prevention fails. A vendor’s ISO 27001 certification should correlate with a documented, tested incident response plan — not just a policy document that’s never been rehearsed.
A tested ISMS shortens the time between detection and containment
Ask vendors when they last ran a tabletop exercise or simulated an incident, and what changed afterward. An ISO 27001 program that has never been stress-tested outside of an audit is unproven exactly where it matters most, and the difference tends to show up in the first hour of a real incident rather than in the paperwork that follows it.
What this means for choosing a partner
Six months into carrying its own ISO 27001 certification, Growin’s take is straightforward: the certificate is worth exactly as much as the operational discipline behind it, and that discipline is the same thing clients should be evaluating in any IT partner, whether or not that partner is certified yet. None of the six signals above require inside access to a vendor’s systems — they’re all things a buyer can ask about directly, in a call or an RFP response, before a contract is signed rather than after something goes wrong.

If you’re weighing where that kind of scrutiny fits into your own sourcing strategy, it maps onto how Growin structures its work with clients. Teams that need a full engineering function without building one from scratch typically start with Nearshore Software Development, which pairs Portugal-based delivery teams with the same security and reporting standards described above. Organizations that need to fill specific skill gaps rather than stand up a whole team tend to use IT Staff Augmentation instead, bringing in vetted specialists under the same ISMS.
For companies building a long-term presence rather than a project-based engagement, Dedicated Software Team sets up a stable team that operates as an extension of an in-house engineering org, governed by the same ISO 27001 certification. And for organizations further along the AI adoption curve — the ones this article’s audit-rights and incident-response points apply to most directly — Intelligent Automation covers AI and automation projects built under that same security baseline from day one.
Whichever model fits, the underlying question is the same one this article has been circling: not whether a partner has an ISO 27001 certificate, but whether the six signals behind it hold up. Get in touch with Growin to talk through what that looks like for your team and how we can help you grow your business.


