Business inquiry
Home · Compliance · ISO 27001
ISO certification · ISO 27001

Bond prepares ISO 27001 certification in Iraq and Kurdistan.

The information security management system. It sets who may reach which data, how risk is assessed and treated, and how an incident is handled, and it is the certificate banks, telecom operators and UN agencies ask a supplier for.

ISO 27001 Information security management systems · Information security

At a glance
Published
October 2022. ISO/IEC 27001:2022 is the current edition. Amendment 1 of February 2024 added the climate action wording to clauses 4.1 and 4.2.
Structure
Annex SL high level structure. 10 clauses, and clauses 4 to 10 carry the auditable requirements. Annex A adds 93 controls in four themes.
Certifiable
Yes. The company is certified for a defined scope of systems, services and sites. There is no certificate for a product or a person under this standard.
Certificate validity
3 years from the date the body issues it.
Surveillance
One audit by the certification body every year, and a recertification audit in year three.
Audit days, 10 to 50 people
About 5 to 9 auditor days for stage 1 and stage 2 together. The time is calculated from the ISO/IEC 27006 table rather than the IAF MD 5 quality table, because the scope and the number of systems move it. The certification body sets the final number.
Accredited bodies active in Iraq
Bureau Veritas has an Erbil office. SGS and TUV operate in Iraq. KQC in Erbil is accredited by IQAS, and IQAS is not an IAF MLA member.
Who certifies
An independent accredited certification body issues the certificate.
Language of the system
We write the policies and procedures in Arabic, Kurdish or English. Asset registers, access reviews and incident logs are usually kept in English because the tools are in English.

What ISO 27001 is

ISO/IEC 27001:2022 is the international standard for an information security management system. It asks a company to list what it holds and what it runs, assess the risk to that information, decide which controls it applies, and record what happens when something goes wrong. It applies to a defined scope of systems, services and sites. The certification body issues the certificate to the company.

What the standard requires

  1. Clauses 1 to 3 cover scope, normative references and terms. Clauses 4 to 10 are the requirements an auditor checks, and Annex A lists the 93 controls.
  2. Clause 4, context. List the parties that matter, then fix the scope of the security system by site, service, system and type of data.
  3. Clause 5, leadership. Management signs the information security policy and names who owns risk, who approves access and who runs incident response.
  4. Clause 6, planning. Run the risk assessment, write the risk treatment plan, and produce the Statement of Applicability that accepts or excludes each of the 93 Annex A controls with a written reason.
  5. Clause 7, support. Competence records for the IT and security roles, awareness training for every employee, and version control over the documented information.
  6. Clause 8, operation. Carry out the risk treatment plan, keep the risk assessment current, and control the changes and the suppliers that touch the scope.
  7. Clause 9, performance evaluation. Measure the security objectives, run internal audits against every clause and every applied control, and hold a management review.
  8. Clause 10, improvement. Log every nonconformity and every security incident, find the cause, correct it, and show the correction worked.
  9. Annex A, 93 controls in four themes: 37 organisational, 8 people, 14 physical and 34 technological. The auditor samples the controls the Statement of Applicability declares in use.

Who needs ISO 27001 in Iraq and Kurdistan

IT and managed service providersA bank or a telecom operator will not hand over access to a system without a security certificate and a named person who owns incident response.
Banks, payment and fintech companiesVendor reviews check access control, change control and incident records before a company is allowed near cardholder or account data.
Telecom operators and their contractorsZain Iraq, Asiacell and Korek Telecom assess suppliers who touch network, billing or subscriber data before the contract is signed.
Hospitals and medical groupsPatient records sit in systems that are shared with insurers and laboratories, and every one of those links is a risk point.
Oil and gas contractors handling operator dataOperators in Kurdistan and Basra share drilling, production and commercial data with contractors and ask how it is stored and who can read it.
Software and outsourcing companies selling abroadBuyers in the Gulf and Europe ask for the certificate and the Statement of Applicability before they place a first order.
Government IT suppliersMinistry and KRG tenders for systems, hosting and support carry a security section that has to be answered with documents.
NGOs and UN implementing partnersGrant agreements carry data protection clauses covering beneficiary records, and the agency can ask to see the controls.

The buyers that ask for ISO 27001

Buyer or listWhat they ask for
Central Bank of Iraq licensed payment companiesElectronic payment providers licensed by the Central Bank of Iraq run vendor security reviews. A supplier holding transaction or customer data is asked for ISO/IEC 27001 and for the list of applied controls.
Telecom operatorsZain Iraq, Asiacell and Korek Telecom prequalify suppliers who reach network, billing or subscriber systems, and the security certificate is part of that file.
UN agencies through UNGMungm.org. One free registration covers UNDP, UNICEF, WFP, UNHCR, IOM and FAO. Contracts that involve beneficiary data carry data protection clauses in English.
KRG Approved Suppliers Centerasc.gov.krd. Annual registration. Certificates must come from a recognised conformity body to clear the quality criteria.
Federal Ministry of PlanningContractor classification and the federal unified electronic tendering platform. We confirm the current instruction before filing. IT packages carry a security section.
Kurdistan and Basra operatorsDNO, Genel Energy, Gulf Keystone, HKN and Basrah Gas Company ask IT and communications suppliers how operator data is stored, backed up and deleted.
Gulf buyersBuyers in the UAE, Saudi Arabia and Qatar ask for ISO/IEC 27001 next to local rules such as the Saudi National Cybersecurity Authority Essential Cybersecurity Controls.
Foreign parent companies and lendersThey require a certificate from a body accredited under an IAF member, such as Bureau Veritas, SGS or TUV, before a system is connected to theirs.

Two tracks, you choose one

Certificate track

5 days

A company that has to answer a security clause in a bank, telecom or IT tender before the deadline, or register on the KRG ASC with a recognised certificate. We prepare the compliance system in five working days. The certification body then issues the certificate, and its calendar sits outside those five days.

Steps
  1. We read the tender or the vendor questionnaire and confirm the scope, the standard and the body the buyer accepts.
  2. We build the asset register and run the risk assessment with the IT owner and the department heads on the first of the five working days.
  3. We write the risk treatment plan and the Statement of Applicability covering all 93 Annex A controls.
  4. We write the document set inside those five days: policy, procedures, access rules, incident procedure and supplier controls.
  5. We train the IT team and the process owners in half day sessions on the records they have to keep.
  6. We run the first internal audit and the management review in the same five days, then close the findings.
  7. We book the certification body, prepare the site, attend stage 1 and stage 2, and answer the findings with your team.
Deliverables
  • The compliance system, prepared in five working days
  • Scope statement covering sites, systems, services and data
  • Asset register and risk assessment with rated risks
  • Risk treatment plan and Statement of Applicability for all 93 controls
  • Information security policy and supporting procedures
  • Access control records and supplier security clauses
  • Internal audit report and management review minutes
  • Corrective action records for every finding
  • A three year surveillance and renewal calendar

Implementation track

6 to 14 weeks

A company that will be audited on its records by a bank, a telecom operator or a foreign partner, and needs the controls running in daily work.

Steps
  1. We analyse what the company does and what its buyers and tenders require, then send a proposal.
  2. We build the asset register with the people who run each system and rate the risks with them.
  3. We agree the risk treatment plan with management and write the Statement of Applicability control by control.
  4. We write the documentation in Arabic, Kurdish or English and set up the logs the staff will actually fill in.
  5. We train every department, run the awareness sessions, and hand the records to the control owners.
  6. We let the system run live for three to four weeks so the certification body sees real access reviews, change records and incident logs.
  7. We run the internal audit programme and the management review, then prepare the site and attend stage 1 and stage 2.
Deliverables
  • Asset register and risk assessment built with the system owners
  • Risk treatment plan and Statement of Applicability for all 93 controls
  • Full documented system in the working language
  • Access review, change and backup records
  • Incident log and tested incident response procedure
  • Supplier security assessments and contract clauses
  • Internal audit programme, reports and management review minutes
  • A three year surveillance and renewal calendar we run with you

The certification body issues the certificate.

The implementation track, week by week

PhaseWeeksWhat happens
Scope and buyer requirementsWeeks 1 to 2We confirm which sites, systems, services and data the certificate covers, and which body the buyer accepts. Nothing is written before this is fixed.
Asset register and risk assessmentWeeks 2 to 4We list every system, database, device and supplier in scope, then rate the risk to each one with the people who run it.
Treatment plan and Statement of ApplicabilityWeeks 3 to 6We agree which of the 93 Annex A controls apply, write the reason for every inclusion and exclusion, and set the treatment plan with owners and dates.
Documentation and controlsWeeks 4 to 9Policy, procedures, access rules, backup and change control, supplier clauses and the incident procedure, written in Arabic, Kurdish or English.
Training and awarenessWeeks 7 to 9A session per department on the records that department owns, a technical session for the IT team, and a session for management on the review.
Records running liveWeeks 8 to 11The controls run in daily operations for three to four weeks so there are real access reviews, change records and incident entries for the auditor to sample.
Internal audit and management reviewWeeks 11 to 12We audit every clause and every applied control, log the findings, and hold the management review with the owner.
Certification auditWeeks 12 to 14The accredited body runs stage 1 on the documents and the Statement of Applicability, then stage 2 on site. We prepare the site, attend both, and answer the findings.

What we do, what you do

We do

  • Confirm which scope, which standard and which certification body the buyer accepts, before any work starts.
  • Build the asset register and run the risk assessment with your system owners.
  • Write the risk treatment plan and the Statement of Applicability covering all 93 Annex A controls.
  • Write the whole documented system in the language the company works in.
  • Train the IT team, the control owners and management on the records they have to keep.
  • Run the first internal audit against every clause and every applied control, and chair the management review.
  • Select certification bodies, collect their quotes, and book the audit dates.
  • Prepare the site, attend stage 1 and stage 2, answer the auditor, and write the corrective actions for every finding.
  • Keep the surveillance and recertification dates in a calendar and prepare the company for each audit.

You do

  • Name one management representative and one IT owner who can each give about four hours a week.
  • Give us the network diagram, the system list, the supplier contracts and any security records you already keep.
  • Release each control owner for a half day of training and a half day for the internal audit.
  • Approve the risk treatment decisions, which takes the owner or general manager about two hours per review round.
  • Have the owner or general manager attend the management review, which takes about two hours.
  • Keep the access reviews, change records and incident log filled in during the live period so the auditor sees real evidence.
  • Pay the certification body directly, or through us at cost with the receipts.
  • Have the owner or general manager present at the opening and closing meetings of the certification audit.

What moves the price

The proposal names the scope, the deliverables and the dates before work starts.

ISO 27001 questions we are asked

We prepare the compliance system in five working days on the certificate track. The implementation track runs six to fourteen weeks. The certification body then issues the certificate on its own calendar. Bureau Veritas, SGS, TUV and KQC in Erbil each set their own audit dates.

The proposal names the scope, the deliverables and the dates before work starts.

A certificate from a body accredited by IQAS, for example KQC in Erbil, is valid in Iraq and accepted for KRG lists. IQAS is not a member of the IAF Multilateral Recognition Arrangement. Banks, telecom operators, UN agencies and foreign buyers normally require a body accredited under an IAF member, such as Bureau Veritas, SGS or TUV. We confirm which one the buyer accepts before any body is booked.

Electronic payment companies licensed by the Central Bank of Iraq ask their suppliers for it. Zain Iraq, Asiacell and Korek Telecom prequalify contractors who reach network, billing or subscriber systems. UN agencies contracting through ungm.org attach data protection clauses. KRG ASC registration at asc.gov.krd runs every year and asks for certificates from a recognised conformity body. IT companies bidding to banks and telecom operators in Baghdad and Erbil are usually asked for ISO 9001, ISO/IEC 27001 and ISO/IEC 20000-1 together.

Three years from the date of issue. The certification body runs a surveillance audit each year and a recertification audit in year three. We keep those dates in a calendar and prepare the company for each one. If a surveillance audit is missed the body can suspend the certificate, and a suspended certificate will not pass a list renewal at the KRG ASC or a bank's annual vendor review.

Annex A was rebuilt. The 2013 edition had 114 controls in 14 clauses. The 2022 edition has 93 controls in four themes, including 11 new ones such as threat intelligence, cloud services and data leakage prevention. The transition period for the 2013 edition closed on 31 October 2025, so every new certificate issued in Erbil or Baghdad is against the 2022 edition.

Yes. We work anywhere in Iraq, in Basra, Baghdad, Kirkuk, Erbil, Sulaymaniyah and Duhok, and in the Gulf. The office is in Erbil and the team travels to the site.

Business inquiry

Select a target. Two questions follow, and the file reaches the desk on WhatsApp. A reply comes within four working hours.