Bond prepares ISO 27001 certification in Iraq and Kurdistan.
The information security management system. It sets who may reach which data, how risk is assessed and treated, and how an incident is handled, and it is the certificate banks, telecom operators and UN agencies ask a supplier for.
ISO 27001 Information security management systems · Information security
What ISO 27001 is
ISO/IEC 27001:2022 is the international standard for an information security management system. It asks a company to list what it holds and what it runs, assess the risk to that information, decide which controls it applies, and record what happens when something goes wrong. It applies to a defined scope of systems, services and sites. The certification body issues the certificate to the company.
What the standard requires
- Clauses 1 to 3 cover scope, normative references and terms. Clauses 4 to 10 are the requirements an auditor checks, and Annex A lists the 93 controls.
- Clause 4, context. List the parties that matter, then fix the scope of the security system by site, service, system and type of data.
- Clause 5, leadership. Management signs the information security policy and names who owns risk, who approves access and who runs incident response.
- Clause 6, planning. Run the risk assessment, write the risk treatment plan, and produce the Statement of Applicability that accepts or excludes each of the 93 Annex A controls with a written reason.
- Clause 7, support. Competence records for the IT and security roles, awareness training for every employee, and version control over the documented information.
- Clause 8, operation. Carry out the risk treatment plan, keep the risk assessment current, and control the changes and the suppliers that touch the scope.
- Clause 9, performance evaluation. Measure the security objectives, run internal audits against every clause and every applied control, and hold a management review.
- Clause 10, improvement. Log every nonconformity and every security incident, find the cause, correct it, and show the correction worked.
- Annex A, 93 controls in four themes: 37 organisational, 8 people, 14 physical and 34 technological. The auditor samples the controls the Statement of Applicability declares in use.
Who needs ISO 27001 in Iraq and Kurdistan
The buyers that ask for ISO 27001
| Buyer or list | What they ask for |
|---|---|
| Central Bank of Iraq licensed payment companies | Electronic payment providers licensed by the Central Bank of Iraq run vendor security reviews. A supplier holding transaction or customer data is asked for ISO/IEC 27001 and for the list of applied controls. |
| Telecom operators | Zain Iraq, Asiacell and Korek Telecom prequalify suppliers who reach network, billing or subscriber systems, and the security certificate is part of that file. |
| UN agencies through UNGM | ungm.org. One free registration covers UNDP, UNICEF, WFP, UNHCR, IOM and FAO. Contracts that involve beneficiary data carry data protection clauses in English. |
| KRG Approved Suppliers Center | asc.gov.krd. Annual registration. Certificates must come from a recognised conformity body to clear the quality criteria. |
| Federal Ministry of Planning | Contractor classification and the federal unified electronic tendering platform. We confirm the current instruction before filing. IT packages carry a security section. |
| Kurdistan and Basra operators | DNO, Genel Energy, Gulf Keystone, HKN and Basrah Gas Company ask IT and communications suppliers how operator data is stored, backed up and deleted. |
| Gulf buyers | Buyers in the UAE, Saudi Arabia and Qatar ask for ISO/IEC 27001 next to local rules such as the Saudi National Cybersecurity Authority Essential Cybersecurity Controls. |
| Foreign parent companies and lenders | They require a certificate from a body accredited under an IAF member, such as Bureau Veritas, SGS or TUV, before a system is connected to theirs. |
Two tracks, you choose one
Certificate track
5 daysA company that has to answer a security clause in a bank, telecom or IT tender before the deadline, or register on the KRG ASC with a recognised certificate. We prepare the compliance system in five working days. The certification body then issues the certificate, and its calendar sits outside those five days.
Steps- We read the tender or the vendor questionnaire and confirm the scope, the standard and the body the buyer accepts.
- We build the asset register and run the risk assessment with the IT owner and the department heads on the first of the five working days.
- We write the risk treatment plan and the Statement of Applicability covering all 93 Annex A controls.
- We write the document set inside those five days: policy, procedures, access rules, incident procedure and supplier controls.
- We train the IT team and the process owners in half day sessions on the records they have to keep.
- We run the first internal audit and the management review in the same five days, then close the findings.
- We book the certification body, prepare the site, attend stage 1 and stage 2, and answer the findings with your team.
- The compliance system, prepared in five working days
- Scope statement covering sites, systems, services and data
- Asset register and risk assessment with rated risks
- Risk treatment plan and Statement of Applicability for all 93 controls
- Information security policy and supporting procedures
- Access control records and supplier security clauses
- Internal audit report and management review minutes
- Corrective action records for every finding
- A three year surveillance and renewal calendar
Implementation track
6 to 14 weeksA company that will be audited on its records by a bank, a telecom operator or a foreign partner, and needs the controls running in daily work.
Steps- We analyse what the company does and what its buyers and tenders require, then send a proposal.
- We build the asset register with the people who run each system and rate the risks with them.
- We agree the risk treatment plan with management and write the Statement of Applicability control by control.
- We write the documentation in Arabic, Kurdish or English and set up the logs the staff will actually fill in.
- We train every department, run the awareness sessions, and hand the records to the control owners.
- We let the system run live for three to four weeks so the certification body sees real access reviews, change records and incident logs.
- We run the internal audit programme and the management review, then prepare the site and attend stage 1 and stage 2.
- Asset register and risk assessment built with the system owners
- Risk treatment plan and Statement of Applicability for all 93 controls
- Full documented system in the working language
- Access review, change and backup records
- Incident log and tested incident response procedure
- Supplier security assessments and contract clauses
- Internal audit programme, reports and management review minutes
- A three year surveillance and renewal calendar we run with you
The certification body issues the certificate.
The implementation track, week by week
| Phase | Weeks | What happens |
|---|---|---|
| Scope and buyer requirements | Weeks 1 to 2 | We confirm which sites, systems, services and data the certificate covers, and which body the buyer accepts. Nothing is written before this is fixed. |
| Asset register and risk assessment | Weeks 2 to 4 | We list every system, database, device and supplier in scope, then rate the risk to each one with the people who run it. |
| Treatment plan and Statement of Applicability | Weeks 3 to 6 | We agree which of the 93 Annex A controls apply, write the reason for every inclusion and exclusion, and set the treatment plan with owners and dates. |
| Documentation and controls | Weeks 4 to 9 | Policy, procedures, access rules, backup and change control, supplier clauses and the incident procedure, written in Arabic, Kurdish or English. |
| Training and awareness | Weeks 7 to 9 | A session per department on the records that department owns, a technical session for the IT team, and a session for management on the review. |
| Records running live | Weeks 8 to 11 | The controls run in daily operations for three to four weeks so there are real access reviews, change records and incident entries for the auditor to sample. |
| Internal audit and management review | Weeks 11 to 12 | We audit every clause and every applied control, log the findings, and hold the management review with the owner. |
| Certification audit | Weeks 12 to 14 | The accredited body runs stage 1 on the documents and the Statement of Applicability, then stage 2 on site. We prepare the site, attend both, and answer the findings. |
What we do, what you do
We do
- Confirm which scope, which standard and which certification body the buyer accepts, before any work starts.
- Build the asset register and run the risk assessment with your system owners.
- Write the risk treatment plan and the Statement of Applicability covering all 93 Annex A controls.
- Write the whole documented system in the language the company works in.
- Train the IT team, the control owners and management on the records they have to keep.
- Run the first internal audit against every clause and every applied control, and chair the management review.
- Select certification bodies, collect their quotes, and book the audit dates.
- Prepare the site, attend stage 1 and stage 2, answer the auditor, and write the corrective actions for every finding.
- Keep the surveillance and recertification dates in a calendar and prepare the company for each audit.
You do
- Name one management representative and one IT owner who can each give about four hours a week.
- Give us the network diagram, the system list, the supplier contracts and any security records you already keep.
- Release each control owner for a half day of training and a half day for the internal audit.
- Approve the risk treatment decisions, which takes the owner or general manager about two hours per review round.
- Have the owner or general manager attend the management review, which takes about two hours.
- Keep the access reviews, change records and incident log filled in during the live period so the auditor sees real evidence.
- Pay the certification body directly, or through us at cost with the receipts.
- Have the owner or general manager present at the opening and closing meetings of the certification audit.
What moves the price
- Number of sites and whether the auditor has to travel to Erbil, Sulaymaniyah, Baghdad or Basra.
- Size of the scope, counted in systems, services, databases and locations rather than in staff alone.
- Effective headcount inside the scope, which sets the auditor days the body calculates.
- Number of Annex A controls declared in use in the Statement of Applicability and how much evidence each one needs.
- Whether cloud services and outsourced hosting sit inside the scope, because each provider has to be assessed.
- Whether the certificate has to come from a body accredited under an IAF member or a locally accredited body is enough.
- Languages the documentation is written in.
- How much usable documentation, logging and monitoring already exists in the company.
- Which track the company takes, the five day certificate track or the 6 to 14 week implementation track.
- Whether ISO/IEC 27001 is built alone or together with ISO 9001 and ISO/IEC 20000-1 as one system, which lowers total auditor days.
The proposal names the scope, the deliverables and the dates before work starts.
ISO 27001 questions we are asked
We prepare the compliance system in five working days on the certificate track. The implementation track runs six to fourteen weeks. The certification body then issues the certificate on its own calendar. Bureau Veritas, SGS, TUV and KQC in Erbil each set their own audit dates.
The proposal names the scope, the deliverables and the dates before work starts.
A certificate from a body accredited by IQAS, for example KQC in Erbil, is valid in Iraq and accepted for KRG lists. IQAS is not a member of the IAF Multilateral Recognition Arrangement. Banks, telecom operators, UN agencies and foreign buyers normally require a body accredited under an IAF member, such as Bureau Veritas, SGS or TUV. We confirm which one the buyer accepts before any body is booked.
Electronic payment companies licensed by the Central Bank of Iraq ask their suppliers for it. Zain Iraq, Asiacell and Korek Telecom prequalify contractors who reach network, billing or subscriber systems. UN agencies contracting through ungm.org attach data protection clauses. KRG ASC registration at asc.gov.krd runs every year and asks for certificates from a recognised conformity body. IT companies bidding to banks and telecom operators in Baghdad and Erbil are usually asked for ISO 9001, ISO/IEC 27001 and ISO/IEC 20000-1 together.
Three years from the date of issue. The certification body runs a surveillance audit each year and a recertification audit in year three. We keep those dates in a calendar and prepare the company for each one. If a surveillance audit is missed the body can suspend the certificate, and a suspended certificate will not pass a list renewal at the KRG ASC or a bank's annual vendor review.
Annex A was rebuilt. The 2013 edition had 114 controls in 14 clauses. The 2022 edition has 93 controls in four themes, including 11 new ones such as threat intelligence, cloud services and data leakage prevention. The transition period for the 2013 edition closed on 31 October 2025, so every new certificate issued in Erbil or Baghdad is against the 2022 edition.
Yes. We work anywhere in Iraq, in Basra, Baghdad, Kirkuk, Erbil, Sulaymaniyah and Duhok, and in the Gulf. The office is in Erbil and the team travels to the site.
Business inquiry
Select a target. Two questions follow, and the file reaches the desk on WhatsApp. A reply comes within four working hours.