IT, SaaS & software development
Software development, SaaS products, outsourcing & BPO, data analytics, AI services
The certificate proves your data is protected and your risks are under control. That's what's expected in tenders, when exporting services, and during audits by foreign partners. Built on Annex SL — the shared structure of ISO standards — so it integrates with ISO 27701 (personal data), ISO 22301 (business continuity) and ISO 9001.
Who it's for
Software development, SaaS products, outsourcing & BPO, data analytics, AI services
Banks, payment services, insurers, microfinance, processing, fintech startups
Universities, research centers, R&D labs, EdTech platforms
Machinery, mining & metals, oil & gas, energy, ICS/SCADA and OT infrastructure
Telecom operators, data centers, billing systems, cloud and hosting providers
Four common situations when a business needs ISO 27001. We tailor the plan to your goal.
When you need international recognition, we help you obtain the certificate through IAF-accredited bodies. They're listed in the IAF MLA register, which spans the EU, the US, the UAE, China and the EAEU — status can be verified online in 2 minutes.
Countries recognize the certificate via IAF MLA
97
Number of partner certification bodies
15
Certificate validity period
3 years
We call, identify your need, lock in the deadline and calculate an exact price
We sign an NDA before kickoff and the contract, then assign an expert to your project
50 or 25% at kickoffInformation security policy, risk assessment and Annex A controls tailored to your processes
We train two in-house ISMS auditors and clear nonconformities before the certification body steps in
The certification body auditor: Stage 1 (documents) + Stage 2 (processes)
Your certificate is in hand, with the apostille and English translation done
50 or 25% on issuanceA 15-minute intro call. We pin down the task, deadline and industry. Then we send a quote with a price range and timeline
We sign an NDA before kickoff and a fixed-price contract. We assign a dedicated expert and agree on a roadmap with milestone dates
50 or 25% at kickoffWe prepare the document package: information security policy, risk assessment and treatment, a Statement of Applicability (SoA) and Annex A controls. We tailor it to your processes — no boilerplate templates
We train two of your in-house ISMS auditors — the people who will maintain the system after issuance. We run a preliminary check and close out nonconformities before the certification body's auditor arrives
The certification body auditor reviews in 2 stages: Stage 1 — documentation remotely, Stage 2 — processes on site or via Zoom. We support you through both stages
You receive the certificate in Russian and English. The apostille and translation into the destination country's language are done. You can submit a tender bid right away or show it to a partner
50 or 25% on issuanceAnswer 5 questions — see the approximate cost of consulting and certification in dollars and tenge. It's a guide: the final amount depends on your organization. We'll give you the exact price after a short call.
1 / 6
Your estimate is ready. Our manager will get in touch and send a step-by-step breakdown.
Consulting — preparation for certification
≈ $1 600
~890 000 ₸
Certification — audit and issuance
≈ $3 000
~1 670 000 ₸
Certificate issuance time
45–60 days
This is an approximate cost at the current EUR rate. The final amount may differ for your organization — it depends on headcount, industry, the number of sites and other factors. We'll give you the exact price and timeline after a short call.
An IAF-accredited certificate — for exports and international tenders, recognized in 97 countries. Without IAF — for local needs, faster and more affordable.
The cost and timeline are spelled out in the contract. Billing in KZT, USD or EUR — your choice.
You start with a partial prepayment; the final payment is due after you receive the certificate. Not a full prepayment, and not an annual subscription.
We take on the ISMS documentation, risk work and audit prep — we lift that burden off you. And we train your team with two internal auditors: after the project it maintains the system on its own. NDA before kickoff.
We run Stage 1 and Stage 2 remotely, in Russian and English. No auditor travel and no logistical delays — a bridge between your team in the CIS and a client in the EU or US.
On average a standard project runs 50–75 business days and includes: developing the ISMS document package (information security policy, risk assessment, statement of applicability and Annex A controls), implementation, submission to the body, a two-stage certification audit and receiving the certificate. For large companies (over 1000 staff, multiple sites) timelines are calculated individually. For a tight deadline there are options to fast-track the project.
With IAF accreditation — yes, in all IAF MLA countries: the EU, USA, UAE, China, the EAEU — that's 97 countries. The body's accreditation status can be verified online in 2 minutes.
Without IAF — for other purposes and internal corporate requirements. Such a certificate has no international recognition, but it's cheaper and faster. We match the body to your goal.
For a foreign client we run documentation and the audit in Russian and English.
These are three different standards. ISO/IEC 27001 was created by the international organization ISO and the IEC technical committee — today it's the core standard for managing information security in organizations. Government bodies take the international standard as a basis and issue national versions: ST RK — the Kazakhstani one, GOST R ISO/IEC — the Russian one. They're 95% identical, differing only in certain terms.
So if you operate in more than one country, it's more advantageous to get an internationally recognized certificate with IAF accreditation — in most cases it covers your needs in the available markets. The exceptions are national-security projects or work with information assets critical to the state.
The certificate itself is voluntary — the law doesn't require it. Kazakhstan's personal data law obliges the operator to ensure data security: localization in Kazakhstan, incident notification, access control, encryption.
ISO 27001 and its extension ISO 27701 are a recognized way to show clients and the regulator that controls are in place and that you exercise due diligence.
ISO 27001 is the information security management system (ISMS) as a whole. ISO 27701 is an extension on top of 27001 specifically for personal data protection (privacy). They're often implemented together.
SOC 2 is a separate report, more often requested by US clients. It's a different framework: ISO 27001 is an internationally recognized certificate. We'll tell you exactly what your client requires and won't substitute one for the other.
No. The transition period from ISO/IEC 27001:2013 to the 2022 edition ended on 31 October 2025 — certificates to the 2013 version are invalid after that date.
If you still hold one, we'll move you to the current 2022 edition: we'll update the documentation to the new Annex A (93 controls) and pass a transition audit.
The certificate is issued for 3 years and includes 3 audits: the initial certification audit (after which you receive the certificate), the first surveillance audit (months 9–12) and the second surveillance audit (months 21–24). Costs fall into two parts: obtaining the certificate and maintaining it over three years.
1. Obtaining the certificate (if you don't have an ISMS yet):
Developing the documentation. Two paths.
— In-house: hiring a specialist (≈€200), a workspace (≈€500), salary (€500–1 000/mo), buying standards and regulations (up to €200), training (≈€500). Timeline ≥ 6 months. Total €4 400–7 000 over six months, before taxes.
— Bring in expertise: the price depends on the certification scope, company size and the consultant's experience. From €500 (usually templates) to €7 000 (a full project). Timeline 3–4 months.
The certification audit. The cost depends on the organization's size, geography, certification scope and the body's fee, plus auditor expenses (audit days, transport, per diem). From €2 000 to €12 000 for an internationally accredited body.
If you wish, you can run a preliminary documentation review or a trial audit on site to minimize risks and check readiness with no consequences.
If nonconformities are found during the audit, extra costs depend on severity: ≈€200 for a minor one, up to €2 000 for a major one + a possible re-audit.
2. Maintaining the certificate (per year):
— Surveillance audit: ≈70% of the initial audit cost (€1 400–8 400) + auditor expenses.
— Maintaining the ISMS: the salary of the responsible specialist — €6 000–12 000 for 12 months, before taxes.
— Staff training: about €500 per employee per year.
— Risk reassessment and security testing: varies widely with the infrastructure.
From experience: if the documents aren't maintained during the year, many nonconformities pile up at the surveillance audit — and if they aren't resolved, the certificate is suspended. It's also worth acting on the areas for improvement the auditor points out — this significantly improves the auditor's opinion of the organization.
Estimate it for your own company in the calculator on this page in 45 seconds. We send the exact quote within 24 hours after a short call — the price is fixed in tenge in the contract, part at the start, the rest after you receive the certificate.
Every certificate has a unique number and is verified in the certification body's register — most often a public database available without registration.
For IAF-accredited ones there's an additional check in the international IAF CertSearch database and confirmation of the body's own status on iaf.nu. That's enough for foreign partners and qualifying for tenders abroad.
Some bodies issue certificates on unique numbered letterheads, which also helps build confidence in the certificate's authenticity
It depends on the tender spec. On goszakup.gov.kz and samruk.kz, IT procurement often requires ISO/IEC 27001 specifically, sometimes also ISO 27701 (personal data) or ISO 22301 (business continuity).
They all integrate with 27001 through Annex SL — one audit for several standards, a shared documentation package. Send us the spec — within an hour we'll tell you which set covers the requirements.
For a tight deadline we issue a preliminary letter on the certification status — it's attached to the tender application to pass qualification.
The full certificate is issued in parallel, usually by the time the contract is signed. This hybrid scenario is standard for tenders with a tight deadline; we've done it many times.
Most clients don't keep a dedicated information security specialist on staff; instead they spread ISMS responsibility across several employees. We prepare all the ISMS documentation (information security policy, risk assessment, statement of applicability, procedures) and train two of your internal auditors. There's no need to hire a separate employee — it saves on payroll.
Over three years the certification body runs 2 surveillance audits — in months 9–12 and 21–24 from the issue date.
Between audits the company maintains the ISMS on its own: updating documents, reassessing risks, resolving nonconformities, training staff. If the documents aren't maintained, the surveillance audit reveals issues — and if they aren't resolved, the certificate is suspended.
In the 3rd year — recertification under the full program. You can switch certification bodies without losing your track record — that's normal practice.
A quote within 24 hours after a short call — free and with no obligation. We tailor information security certification to your goal: client requirements, IT tenders in Kazakhstan and the CIS, exports and due diligence. We work in Russian and English and sign an NDA.
A manager will get in touch within one business day and confirm the scope.
A manager will get in touch within one business day, clarify your task and send a commercial proposal within 24 hours.