When certification opens doors to business
Many large companies and public institutions in the Czech Republic require ISO 27001 from suppliers as a mandatory tender condition. Without certification you do not even enter the selection process. A typical example: a development studio in Brno wanted to work for the banking sector but had no chance of a contract to develop an internal banking system without the certificate. Here certification functions as an entry ticket that pays for itself through new revenue.
When you address real risks, not just paperwork
The standard makes sense when you use it to map where sensitive data lies in the organisation, who has access to it, and what happens in a breach. If you implement an information security management system (ISMS) because the team is growing, more employees work from home, and the loss of a laptop would create a GDPR problem, certification gives you a framework for concrete measures: disk encryption, access control, backups, and an incident response plan. In audits by CIAD, the Czech Institute for AI and Data, companies with this approach retain certification even after external pressure ends.
When it becomes expensive paperwork
Certification loses value when management treats it as a one-off project: they pay a consultant to write policies, pass the certification audit, and then do not look at the documents for years. No staff training, no regular risk assessments, no backup tests. Such an ISMS protects nothing; it only generates annual fees to the certification body (often 150 to 300 thousand CZK annually for a small company) and time spent with auditors. If you have no assigned process owner, a CISO or security manager, with authority and budget, the certificate is just decoration on the wall.
How to decide quickly and without unnecessary costs
First, find out whether key clients or contracts explicitly require the certificate. Second, run an internal gap analysis against Annex A to see what you already have and what is missing. Third, estimate total costs: consulting, internal time, certification audits, and annual surveillance audits. Fourth, compare those costs with the risks: how much would a data breach, a regulator fine, or a lost contract cost? Fifth, decide: full certification, ISMS implementation without a certificate, or ad hoc measures.
What this means
ISO 27001 is an investment in credibility and systematic protection. It pays off when you live it daily, not when you buy it once.
Frequently asked questions
Must every company that processes personal data have ISO 27001?
No, GDPR does not require a specific certification. It requires appropriate technical and organizational measures. ISO 27001 is one possible way to demonstrate compliance, but it is neither the only one nor mandatory.
How much time and money does certification take for a small company of up to 50 people?
Typically 6 to 12 months of preparation and costs of 300 to 800 thousand CZK including consulting and initial audits. Annual maintenance then costs tens of thousands of crowns.
Is it enough to implement ISMS without a certificate?
Yes, for internal needs and GDPR compliance a functioning ISMS without an external certificate is often sufficient. The certificate adds trust with third parties (clients, partners), but does not improve security by itself.
What is the difference between ISO 27001 and TISAX in automotive?
TISAX is a branch specific to the automotive industry, based on ISO 27001 but with additional requirements (prototypes, partner data protection). If you supply to the automotive industry, the client will require TISAX, not pure ISO 27001.