Международная сертификация в Казахстане
Kazakhstan
+7 717 297 22 39
sales department
Международная сертификация в Казахстане
+7 717 297 22 39
Sales department · Free consultation
language versions of the website

Get an ISO/IEC 27001 certificate for your organization

to win contracts
to meet client requirements
for tenders and public procurement
personal data protection
IAF MLA – 97 COUNTRIES
FLEXIBLE PRICING
DOCUMENTS IN RUSSIAN AND ENGLISH
INTERNATIONAL ISO/IEC 27001:2022 CERTIFICATION · INFORMATION SECURITY
We prepare your organization for the standard’s requirements and develop the full set of documents. The certificate is recognized in 97 countries through the IAF MLA. We work with clients from Kazakhstan, Uzbekistan, Armenia, Azerbaijan and beyond.
We sign an NDA
We sign it before we get access to your systems and data.
Payment in KZT, USD, EUR
Final payment after you receive the certificate.
Certificate with apostille
We take care of the ISMS documents, risk assessment and audit preparation.
50/50 payment
25/50/25 payment
Final payment after you receive the certificate
Certificates & audits
Loading…
Updates automatically
Clients & partners

Trusted by

Standard

ISO/IEC 27001 — the certificate without which a client won't trust you with their data

The certificate proves your data is protected and your risks are under control. That's what's expected in tenders, when exporting services, and during audits by foreign partners. Built on Annex SL — the shared structure of ISO standards — so it integrates with ISO 27701 (personal data), ISO 22301 (business continuity) and ISO 9001.

  • 2022 current edition of the standard
  • 93 Annex A controls — we implement them for your risks
  • 3 years validity, with a surveillance audit every year

Who it's for

Fintech, banks & insurance

Banks, payment services, insurers, microfinance, processing, fintech startups

Financial metrics on a screen

Industry & energy

Machinery, mining & metals, oil & gas, energy, ICS/SCADA and OT infrastructure

Industrial manufacturing

Telecom & data centers

Telecom operators, data centers, billing systems, cloud and hosting providers

Server racks in a data center

What's your case?

Four common situations when a business needs ISO 27001. We tailor the plan to your goal.

Client

Does a client demand assurance about your data?

A major client or partner won't hand over the project or sign the contract until you prove your information security with an ISO 27001 certificate. The deal stalls until you have the document.

What we can offer
  1. 1We build the ISMS and prepare you for certification to the standard's requirements — we handle the documents for you
  2. 2An IAF-accredited certificate if your partner verifies authenticity in the register — recognized in 97 countries
  3. 3A preliminary status letter — show it to the client before the certificate itself is issued
This is my case
Tender

An IT tender that requires ISO 27001?

goszakup.gov.kz, samruk.kz and corporate IT specs increasingly include ISO/IEC 27001 in the qualification. No certificate — you're out. The deadline is hard, with no second chances.

What we can offer
  1. 1There's a fast-track option to get the certificate in time for the tender deadline
  2. 2The certificate is verifiable in the body's register and in IAF CertSearch — the client won't doubt its authenticity
  3. 3Certificates to the 2013 version are invalid from October 2025 — we'll move you to the current 2022 edition
This is my case
Data

Do you handle personal data?

Kazakhstan's personal data law requires protecting client data: localization in Kazakhstan, incident notification, access control. ISO 27001 and 27701 show your controls are in place.

What we can offer
  1. 1ISO 27001 + ISO 27701 (the personal-data extension) — a framework to demonstrate due diligence
  2. 2We help you set up the processes: logging, incident response, access control
  3. 3The certificate is voluntary, but it removes questions from clients and the regulator about data protection
This is my case
Export

Exporting, or a client from the EU or US?

A foreign client or investor runs due diligence and requires an internationally recognized information-security certificate. We run the project in Russian and English.

What we can offer
  1. 1An IAF-accredited certificate — recognized in 97 countries via IAF MLA, verifiable in the register
  2. 2We run documentation and the audit in Russian and English — a bridge between your team in the CIS and the client in the West
  3. 3We help our clients obtain SOC 2
This is my case

An ISO/IEC 27001 certificate recognized in tenders and abroad

When you need international recognition, we help you obtain the certificate through IAF-accredited bodies. They're listed in the IAF MLA register, which spans the EU, the US, the UAE, China and the EAEU — status can be verified online in 2 minutes.

International Accreditation Forum International Accreditation Service Italian Accreditation Body Egyptian Accreditation Council United Accreditation Foundation ANSI National Accreditation Board Czech Accreditation Institute Slovak National Accreditation Service

Countries recognize the certificate via IAF MLA

97

Number of partner certification bodies

15

Certificate validity period

3 years

ISO 27001 certification timeline: from request to certificate in 6 steps

  1. 1

    Request and quote within 24 hours

    We call, identify your need, lock in the deadline and calculate an exact price

  2. 2

    NDA, contract and kickoff

    We sign an NDA before kickoff and the contract, then assign an expert to your project

    50 or 25% at kickoff
  3. 3

    ISMS development

    Information security policy, risk assessment and Annex A controls tailored to your processes

  4. 4

    Training and internal audit

    We train two in-house ISMS auditors and clear nonconformities before the certification body steps in

  1. 5

    Certification audit

    The certification body auditor: Stage 1 (documents) + Stage 2 (processes)

  2. 6

    Certificate issuance

    Your certificate is in hand, with the apostille and English translation done

    50 or 25% on issuance
  1. 1

    Request and quote within 24 hours

    A 15-minute intro call. We pin down the task, deadline and industry. Then we send a quote with a price range and timeline

  2. 2

    NDA, contract and kickoff

    We sign an NDA before kickoff and a fixed-price contract. We assign a dedicated expert and agree on a roadmap with milestone dates

    50 or 25% at kickoff
  3. 3

    ISMS development

    We prepare the document package: information security policy, risk assessment and treatment, a Statement of Applicability (SoA) and Annex A controls. We tailor it to your processes — no boilerplate templates

  4. 4

    Training and internal audit

    We train two of your in-house ISMS auditors — the people who will maintain the system after issuance. We run a preliminary check and close out nonconformities before the certification body's auditor arrives

  5. 5

    Certification audit

    The certification body auditor reviews in 2 stages: Stage 1 — documentation remotely, Stage 2 — processes on site or via Zoom. We support you through both stages

  6. 6

    Certificate issuance

    You receive the certificate in Russian and English. The apostille and translation into the destination country's language are done. You can submit a tender bid right away or show it to a partner

    50 or 25% on issuance

Estimate your budget

Answer 5 questions — see the approximate cost of consulting and certification in dollars and tenge. It's a guide: the final amount depends on your organization. We'll give you the exact price after a short call.

1 / 6

Company size

What's your headcount?

Country

Where is your business registered?

Affects certificate recognition and cost.

Target market

Where do you plan to sell your products or services?

The market where you work with clients.

ISO certificates

Which ISO certificates do you already have?

You can pick several. If you have none yet — choose "None".

Industry

What's your industry?

Doesn't affect the price — helps us assign a manager with industry experience.

Contact details

Where should we send your estimate?

Our manager will send the cost, timeline and a step-by-step breakdown.

Why companies order ISO 27001 certification from us

Matched to your needs

An IAF-accredited certificate — for exports and international tenders, recognized in 97 countries. Without IAF — for local needs, faster and more affordable.

Fixed price

The cost and timeline are spelled out in the contract. Billing in KZT, USD or EUR — your choice.

Pay in installments

You start with a partial prepayment; the final payment is due after you receive the certificate. Not a full prepayment, and not an annual subscription.

We do it for you — and with your team

We take on the ISMS documentation, risk work and audit prep — we lift that burden off you. And we train your team with two internal auditors: after the project it maintains the system on its own. NDA before kickoff.

Remote audit

We run Stage 1 and Stage 2 remotely, in Russian and English. No auditor travel and no logistical delays — a bridge between your team in the CIS and a client in the EU or US.

Frequently asked questions about ISO 27001 certification

How long does ISO 27001 certification really take?

On average a standard project runs 50–75 business days and includes: developing the ISMS document package (information security policy, risk assessment, statement of applicability and Annex A controls), implementation, submission to the body, a two-stage certification audit and receiving the certificate. For large companies (over 1000 staff, multiple sites) timelines are calculated individually. For a tight deadline there are options to fast-track the project.

Is an ISO 27001 certificate recognized abroad?

With IAF accreditation — yes, in all IAF MLA countries: the EU, USA, UAE, China, the EAEU — that's 97 countries. The body's accreditation status can be verified online in 2 minutes.

Without IAF — for other purposes and internal corporate requirements. Such a certificate has no international recognition, but it's cheaper and faster. We match the body to your goal.

For a foreign client we run documentation and the audit in Russian and English.

How does ISO/IEC 27001 differ from ST RK and GOST R ISO/IEC 27001?

These are three different standards. ISO/IEC 27001 was created by the international organization ISO and the IEC technical committee — today it's the core standard for managing information security in organizations. Government bodies take the international standard as a basis and issue national versions: ST RK — the Kazakhstani one, GOST R ISO/IEC — the Russian one. They're 95% identical, differing only in certain terms.

So if you operate in more than one country, it's more advantageous to get an internationally recognized certificate with IAF accreditation — in most cases it covers your needs in the available markets. The exceptions are national-security projects or work with information assets critical to the state.

Is ISO 27001 mandatory under Kazakhstan's personal data law?

The certificate itself is voluntary — the law doesn't require it. Kazakhstan's personal data law obliges the operator to ensure data security: localization in Kazakhstan, incident notification, access control, encryption.

ISO 27001 and its extension ISO 27701 are a recognized way to show clients and the regulator that controls are in place and that you exercise due diligence.

How does ISO 27001 differ from ISO 27701? And do we need SOC 2?

ISO 27001 is the information security management system (ISMS) as a whole. ISO 27701 is an extension on top of 27001 specifically for personal data protection (privacy). They're often implemented together.

SOC 2 is a separate report, more often requested by US clients. It's a different framework: ISO 27001 is an internationally recognized certificate. We'll tell you exactly what your client requires and won't substitute one for the other.

We have a certificate to the 2013 version — is it still valid?

No. The transition period from ISO/IEC 27001:2013 to the 2022 edition ended on 31 October 2025 — certificates to the 2013 version are invalid after that date.

If you still hold one, we'll move you to the current 2022 edition: we'll update the documentation to the new Annex A (93 controls) and pass a transition audit.

How much does ISO 27001 certification cost?

The certificate is issued for 3 years and includes 3 audits: the initial certification audit (after which you receive the certificate), the first surveillance audit (months 9–12) and the second surveillance audit (months 21–24). Costs fall into two parts: obtaining the certificate and maintaining it over three years.

1. Obtaining the certificate (if you don't have an ISMS yet):

Developing the documentation. Two paths.

In-house: hiring a specialist (≈€200), a workspace (≈€500), salary (€500–1 000/mo), buying standards and regulations (up to €200), training (≈€500). Timeline ≥ 6 months. Total €4 400–7 000 over six months, before taxes.

Bring in expertise: the price depends on the certification scope, company size and the consultant's experience. From €500 (usually templates) to €7 000 (a full project). Timeline 3–4 months.

The certification audit. The cost depends on the organization's size, geography, certification scope and the body's fee, plus auditor expenses (audit days, transport, per diem). From €2 000 to €12 000 for an internationally accredited body.

If you wish, you can run a preliminary documentation review or a trial audit on site to minimize risks and check readiness with no consequences.

If nonconformities are found during the audit, extra costs depend on severity: ≈€200 for a minor one, up to €2 000 for a major one + a possible re-audit.

2. Maintaining the certificate (per year):

Surveillance audit: ≈70% of the initial audit cost (€1 400–8 400) + auditor expenses.

Maintaining the ISMS: the salary of the responsible specialist — €6 000–12 000 for 12 months, before taxes.

Staff training: about €500 per employee per year.

Risk reassessment and security testing: varies widely with the infrastructure.

From experience: if the documents aren't maintained during the year, many nonconformities pile up at the surveillance audit — and if they aren't resolved, the certificate is suspended. It's also worth acting on the areas for improvement the auditor points out — this significantly improves the auditor's opinion of the organization.

Estimate it for your own company in the calculator on this page in 45 seconds. We send the exact quote within 24 hours after a short call — the price is fixed in tenge in the contract, part at the start, the rest after you receive the certificate.

How will a partner or client verify authenticity?

Every certificate has a unique number and is verified in the certification body's register — most often a public database available without registration.

For IAF-accredited ones there's an additional check in the international IAF CertSearch database and confirmation of the body's own status on iaf.nu. That's enough for foreign partners and qualifying for tenders abroad.

Some bodies issue certificates on unique numbered letterheads, which also helps build confidence in the certificate's authenticity

Is ISO 27001 alone enough for a tender?

It depends on the tender spec. On goszakup.gov.kz and samruk.kz, IT procurement often requires ISO/IEC 27001 specifically, sometimes also ISO 27701 (personal data) or ISO 22301 (business continuity).

They all integrate with 27001 through Annex SL — one audit for several standards, a shared documentation package. Send us the spec — within an hour we'll tell you which set covers the requirements.

The tender is in 1–2 weeks — can we make it?

For a tight deadline we issue a preliminary letter on the certification status — it's attached to the tender application to pass qualification.

The full certificate is issued in parallel, usually by the time the contract is signed. This hybrid scenario is standard for tenders with a tight deadline; we've done it many times.

What if we don't have an information security specialist?

Most clients don't keep a dedicated information security specialist on staff; instead they spread ISMS responsibility across several employees. We prepare all the ISMS documentation (information security policy, risk assessment, statement of applicability, procedures) and train two of your internal auditors. There's no need to hire a separate employee — it saves on payroll.

The certificate is valid for 3 years — what happens during that time?

Over three years the certification body runs 2 surveillance audits — in months 9–12 and 21–24 from the issue date.

Between audits the company maintains the ISMS on its own: updating documents, reassessing risks, resolving nonconformities, training staff. If the documents aren't maintained, the surveillance audit reveals issues — and if they aren't resolved, the certificate is suspended.

In the 3rd year — recertification under the full program. You can switch certification bodies without losing your track record — that's normal practice.

Get in touch

We’re ready to tell you more about ISO 27001

A quote within 24 hours after a short call — free and with no obligation. We tailor information security certification to your goal: client requirements, IT tenders in Kazakhstan and the CIS, exports and due diligence. We work in Russian and English and sign an NDA.

Company number

+7 (717) 297-22-39

Find us on messengers

Request a quote within 24 hours

A manager will get in touch within one business day and confirm the scope.