What ISO 27001 actually requires
Unlike PCI DSS, which prescribes specific technical configurations, ISO 27001 is a management framework. The core of ISO 27001 is the implementation of an Information Security Management System (ISMS).
The ISMS
A systematic approach to managing sensitive company information. It encompasses people, processes, and IT systems, applying a risk management process to ensure confidentiality, integrity, and availability.
Risk Assessment
You must formally identify risks to your information assets, evaluate their potential impact, and decide how to treat them (mitigate, accept, transfer, or avoid).
Statement of Applicability (SoA)
A crucial document that lists the 93 controls from Annex A, stating which ones you have implemented to mitigate your identified risks and justifying any exclusions.
Annex A controls relevant to fintechs
The 2022 update of ISO 27001 consolidated the controls into four themes. For engineering teams, the Technological controls are where the heavy lifting occurs.
- A.8.8 Management of technical vulnerabilities: Requires ongoing vulnerability assessments and patch management.
- A.8.25 Secure development lifecycle: Security must be integrated into your CI/CD pipeline.
- A.8.28 Secure coding: Developers must be trained in secure coding principles to prevent OWASP Top 10 vulnerabilities.
- A.8.29 Security testing in development and acceptance: This mandates regular, independent penetration testing of your applications before they go live.
Evidence to collect before the audit
Map each control to an owner, policy, operating record, and review date. Keep access reviews, joiner and leaver records, risk decisions, supplier checks, incident records, backup tests, change approvals, vulnerability records, and remediation evidence in one controlled location.
A penetration test supports the technical control set. It does not create an information security management system or grant certification. The certification body judges the management system, risk process, control selection, and evidence that those controls operate.
Use this decision rule
Choose ISO 27001 when customers or partners require a documented security program. Choose a focused security test when the immediate question is whether a product control can be bypassed. Run both workstreams when certification and product assurance share the same deadline.
ISO 27001 requires independent penetration testing. We provide reports that auditors accept.
Get an ISO 27001 Pentest QuoteThe certification process
Certification is granted by an accredited external body (like BSI or SGS in Nigeria) following a two-stage audit.
Stage 1: Documentation Review
The auditor reviews your ISMS documentation, policies, and SoA to ensure they meet the standard's requirements. This is a "desktop" audit.
Stage 2: Certification Audit
The auditor verifies that your organization is actually following the documented procedures. They will interview staff, review logs, and check evidence like recent pentest reports.
Surveillance Audits
After certification, you undergo annual surveillance audits to ensure the ISMS is maintained, leading to a recertification audit in year three.
Relationship to CBN requirements
The CBN Risk-Based Cybersecurity Framework draws heavily from ISO 27001 principles. If your fintech successfully implements an ISO 27001 ISMS, you will inherently meet the vast majority of the governance and risk management requirements mandated by the CBN. The primary addition will be the specific CBN reporting timelines and the CSAT submission.
Winning Enterprise Deals
An ISO 27001 certificate and a current security test summary can support vendor review. Buyers still decide which questionnaires, evidence, and contract controls they require.
Related reading
Blog: Fintech Security Audit Timing
Guides: CBN Compliance Guide · Security Before Fundraising
Services: Secure Architecture Review
Frequently asked questions
Is ISO 27001 required for Nigerian fintechs?
It is not explicitly mandated by the CBN for basic operations, but the CBN Risk-Based Cybersecurity Framework is heavily modeled on ISO 27001. Commercially, it is often required to secure enterprise B2B contracts or integrate with commercial banks.
Should we get ISO 27001 or SOC 2?
ISO 27001 is globally recognized and often preferred in Europe, Asia, and Africa. SOC 2 is heavily preferred in the US market. Many Nigerian fintechs targeting local enterprise clients or European partners prioritize ISO 27001.
How long does ISO 27001 certification take?
For a growing fintech, building the ISMS and passing both Stage 1 and Stage 2 audits typically takes between 6 and 12 months, depending on the current state of your security controls.