SYSTEM CERTIFICATION SERVICES
Need ISO 27001 Certification for Your Business?
Speak with our certification specialists to understand certification requirements, audit process, implementation timelines and accredited certification services.
FREQUENTLY ASKED QUESTIONS
Frequently Asked Questions
There is no single price for a small company because certification effort depends on the ISMS scope, employee count, locations, business activities and audit requirements. SCS Certification can review these details and provide a quotation based on the actual certification scope.
Startup pricing depends mainly on the size and complexity of the proposed ISMS rather than simply the company's age. A focused startup scope can have different certification requirements from a larger multi-location organization. Contact SCS Certification with your company details for a tailored quotation.
Important factors include employee numbers, locations, ISMS scope, business complexity, information systems, operational processes and audit requirements. The cost should therefore be assessed against the actual organization rather than using a generic online price.
Yes. You can submit your company activity, employee strength, locations, intended ISMS scope and other relevant information online. SCS Certification can use these details to assess your requirements and prepare a certification quotation.
Provide your company activity, UAE location, number of employees, proposed certification scope and any customer, tender or contractual requirement. SCS Certification can review the information and provide the appropriate certification quotation and next steps.
An initial quotation can be discussed using your proposed activities and information-security requirements. However, the final certification arrangement depends on the confirmed scope, locations and applicable audit requirements. Early scope discussions can help prevent an unsuitable quotation later.
A smaller and clearly defined scope may require less audit effort than a broad multi-location scope, but pricing depends on the complete certification requirements. The scope should never be artificially restricted merely to reduce cost if important activities or information are actually part of the ISMS.
The enquiry, quotation, document exchange and certification planning can be handled online. The certification assessment itself must follow the applicable audit and certification requirements. SCS Certification can explain which parts of the process can be completed remotely.
Online communication does not determine certificate validity. What matters is the certification body's competence, applicable accreditation and scope, the defined ISMS scope and completion of the required certification assessment. These points should be checked before engaging any provider.
Yes, the application and many administrative stages can be handled remotely. Audit arrangements depend on the organization's scope, locations and applicable certification requirements. SCS Certification can explain the practical arrangements for your organization.
Start by defining the ISMS scope, identifying information-security risks, establishing and implementing the ISMS, conducting internal audit and management review, and completing an independent certification audit. SCS Certification can discuss your scope and certification requirements before the process begins.
The fastest legitimate route is to define the scope early, assess existing controls, address important gaps, prepare the required evidence and schedule the certification audit as soon as the organization is ready. Contact SCS Certification with your deadline so the available certification timeline can be assessed.
An urgent certification request still has to follow the applicable assessment process. If you have a fixed customer deadline, contact SCS Certification early with the deadline, required scope and current ISMS status so a realistic certification plan can be considered.
If a tender requires ISO 27001, the organization should start as early as possible because implementation, internal audit, management review and independent assessment may be required. SCS Certification can review the requirement and discuss the available certification timeline.
Begin with a clear ISMS scope and gap assessment rather than creating documents without understanding the organization's risks. Prioritize the required management-system processes, controls, evidence, internal audit and management review before the certification audit.
The preparation period varies considerably according to the organization's existing security practices, scope, number of locations and available resources. An SME with mature processes may require less preparation than an organization building an ISMS from the beginning.
Yes. ISO 27001 is a management-system standard and does not require every organization to maintain a large internal cybersecurity department. The organization must nevertheless have appropriate responsibilities, processes, resources and controls for its defined ISMS scope.
Yes. Responsibilities can be allocated according to the organization's size and structure. The important issue is whether the ISMS requirements are effectively implemented, maintained and supported by appropriate personnel and management.
Potentially, yes. Certification focuses on the organization's defined ISMS and its ability to demonstrate conformity, rather than simply on customer numbers. A startup should have sufficient operational processes and evidence within its certification scope.
A newly established organization can pursue certification if it has sufficient implemented processes and evidence for the proposed ISMS scope. The practical timing depends on how much of the business operation and security management system is already functioning.
Yes. Previous ISO certification is not a prerequisite for ISO 27001 certification. The organization needs to establish, implement, maintain and demonstrate conformity of the relevant ISMS requirements.
The initial enquiry normally requires company information, business activities, locations, employee numbers and the proposed ISMS scope. The management-system documentation and records required for the assessment depend on the organization's activities and implementation.
Evidence can include policies, risk assessments, treatment decisions, asset information, access-management records, incident records, supplier controls, training evidence, internal audit results, management review records and other applicable operational evidence.
An organization pursuing ISO 27001 certification needs an appropriate information-security management framework, including the required policies and processes applicable to its scope. The precise documentation should reflect the organization's context and risks rather than being copied from a generic template.
Risk assessment is an important part of establishing an effective ISMS. The organization needs to identify relevant information-security risks and determine appropriate treatment within its management system before certification assessment.
Organizations implementing ISO/IEC 27001 normally establish a Statement of Applicability as part of the ISMS to address the applicable controls and their inclusion or exclusion with justification. It should reflect the organization's actual risks and certification scope.
Templates can help organize documentation, but they should be adapted to the organization's actual activities, risks, systems and responsibilities. Copying generic documents without implementing the underlying processes is unlikely to provide sufficient evidence of an effective ISMS.
SCS Certification can explain the certification and audit requirements applicable to your proposed scope. The organization remains responsible for implementing its management system and maintaining the evidence needed to demonstrate conformity.
ISO 27001 does not simply require an organization to purchase a particular cybersecurity product. The ISMS should identify and treat relevant risks using appropriate organizational, people, physical and technological measures.
The appropriate technical controls depend on the organization's systems, risks and operating environment. ISO 27001 is risk-based, so a firewall should not be treated as a universal standalone certification requirement.
The need for penetration testing depends on the organization's risk assessment, technology environment, applicable controls and security objectives. ISO 27001 should not be reduced to a fixed checklist of technical tests.
Vulnerability management should be addressed according to the organization's information-security risks and applicable controls. The exact technical activities should be determined based on the systems, threats and risk-treatment approach.
An effective ISMS needs appropriate arrangements for managing information-security incidents. The organization's incident-management approach should reflect its risks, services, systems and responsibilities within the certification scope.
ISO 27001 can cover information-security risks associated with cloud services when they fall within the organization's ISMS scope. Cloud-specific guidance such as ISO/IEC 27017 can provide additional context for cloud-security practices.
ISO 27001 addresses information-security management and can include risks involving personal information. Organizations with significant privacy responsibilities may also consider a privacy management standard such as ISO/IEC 27701 alongside ISO 27001.
ISO 27001 is a management-system standard for information security rather than a simple technical cybersecurity test. It establishes requirements for managing information-security risks through an ISMS and can incorporate cybersecurity controls appropriate to the organization's risks.
No. ISO/IEC 27001 can be applied to organizations across sectors because information-security risks exist wherever important information is processed, stored or transferred. ISO itself states that the standard is designed for organizations of different sizes and sectors.
Yes. Manufacturing, logistics, healthcare, professional services, education, retail and other non-IT businesses can use ISO 27001 when information security is important to their operations or stakeholder requirements.
Yes. Consultancies that handle confidential client information, contracts, intellectual property, employee information or digital systems may use ISO 27001 to establish a structured information-security management system.
Yes. Accounting and professional-services organizations can pursue ISO 27001 where protecting financial records, client information and confidential documents is important to their business requirements.
Yes. Law firms frequently handle confidential client information and sensitive legal records. ISO 27001 can provide a structured framework for managing information-security risks associated with those activities.
Yes. Real estate companies handling customer information, property records, contracts, financial information or digital platforms can establish an ISMS around the relevant activities.
Yes. E-commerce businesses can apply ISO 27001 to information-security risks associated with customer information, online systems, payment-related processes, suppliers and internal business information.
Yes. Fintech organizations can use ISO 27001 to establish a structured approach to information-security risks. The final scope should reflect the actual services, technology environment, information assets and responsibilities of the fintech business.
Yes. A DIFC organization can pursue ISO 27001 where it is relevant to its information-security objectives, customer expectations or contractual requirements. Sector-specific regulatory and contractual obligations should be considered separately from ISO certification.
Yes. Organizations operating in ADGM can pursue ISO 27001 according to their business activities and defined ISMS scope. Any applicable ADGM, customer, contractual or sector-specific requirements should be considered alongside the certification process.
Yes. SaaS businesses can define an ISMS around their software service, supporting infrastructure, personnel, information assets and relevant third parties. SCS Certification can review the SaaS business model and proposed scope when preparing a certification quotation.
Yes. Cloud providers can pursue ISO 27001 for an appropriate ISMS scope covering their information-security responsibilities. Additional cloud-security guidance may also be relevant depending on the service model.
Yes. A software development company can establish an ISMS covering relevant development activities, repositories, systems, personnel, customer information and supporting processes.
Yes. MSPs can use ISO 27001 to manage information-security risks associated with customer environments, service operations, privileged access, personnel, suppliers and supporting infrastructure.
Yes. A data-centre organization can establish an ISMS covering the information-security responsibilities within its defined operational scope. The certification scope should accurately identify the services, facilities and responsibilities being assessed.
Yes. Logistics companies increasingly process operational, customer, employee and supply-chain information. ISO 27001 can be applied to the information-security management activities within the organization's defined scope.
Yes. Manufacturers can apply ISO 27001 to corporate information, production-related systems, intellectual property, supplier information, operational technology interfaces and other information assets included within the ISMS scope.
Yes. Healthcare organizations handling patient, employee, operational or other sensitive information can establish an ISMS covering relevant information-security risks. Healthcare-specific regulatory obligations should also be assessed separately.
Yes. Educational organizations can use ISO 27001 for information-security risks involving student records, staff information, learning systems, applications, research information and other information assets within scope.
Yes. Recruitment companies handling candidate profiles, identification information, employment records and customer information can use ISO 27001 to establish a structured information-security management system.
Yes. Marketing agencies handling customer databases, campaign information, analytics, credentials, intellectual property and personal information can define an appropriate ISMS around those activities.
Yes. ISO 27001 is not restricted to technology suppliers. Any government supplier that handles information within an appropriate scope can consider certification, subject to the customer's or tender authority's specific requirements.
The scope should describe the actual services, information assets, systems, locations, personnel and processes that the organization intends to have certified. A scope should be neither unnecessarily broad nor misleadingly narrow.
It can be possible to define certification around a particular service or product environment when the proposed scope accurately represents the organization's activities and information-security responsibilities. The supporting processes and resources necessary to operate that service may also need to be considered.
Potentially, if the department represents a clearly defined and auditable organizational activity and the scope accurately describes the boundaries and interfaces involved. The proposed scope should be reviewed carefully before certification.
Yes, a certification scope can sometimes be limited to a defined location and its associated activities. The organization must ensure that the scope accurately captures the information-security responsibilities relevant to that location.
Multi-site certification can be considered when the organizational structure, management system and applicable audit requirements support it. The locations and activities covered should be clearly defined in the certification scope.
It may be possible depending on the organization's structure, scope and applicable certification arrangements. The overseas activity and location would need to be properly considered when establishing the certification scope and audit programme.
Yes, where those cloud operations form part of the organization's information-security responsibilities. The scope should identify the relevant services, systems, processes and responsibilities rather than relying solely on the company's registered free-zone address.
Yes. Outsourced services and suppliers can be considered within the organization's information-security risk management. The ISMS should establish appropriate supplier and third-party controls according to the organization's risks.
Yes. Remote working can be included within the ISMS where employees access or handle information within the certification scope. Appropriate controls should address remote access, devices, information handling and relevant security risks.
Yes. Home-based working arrangements can form part of the organization's information-security environment. The applicable controls should reflect risks associated with remote access, devices, communications and information handling.
Supplier and third-party security can be addressed within the ISMS. The organization should identify relevant supplier risks and establish appropriate requirements, monitoring and controls based on those risks.
Certification applies to the defined ISMS scope and the organization's information-security management system. If customer information is included within that scope, the organization must manage the relevant risks and controls appropriately.
No. ISO 27001 is a risk-management and information-security management standard, not a guarantee that cyber incidents can never occur. It provides a systematic framework for identifying, treating and continually managing information-security risks.
No certification can guarantee absolute security. ISO 27001 demonstrates conformity of the defined management system with the applicable requirements at the time of assessment and supports ongoing risk management and improvement.
No. Penetration testing and ISO 27001 address different purposes. Technical testing may be one element of an organization's broader security and risk-management programme where justified by the organization's environment and risks.
No. ISO 27001 and SOC 2 are different assurance frameworks with different structures and purposes. Some organizations pursue both when customers or markets request different forms of security assurance.
Yes. Organizations may use ISO 27001 as an information-security management framework and pursue SOC 2 separately where customer or market requirements call for it. The appropriate combination depends on the organization's business and assurance requirements.
Yes. Organizations can integrate ISO 27001 with other management-system standards where their structures and processes allow it. An integrated approach can reduce duplicated management activities while retaining the requirements of each applicable standard.
Yes. Information security and business continuity can be managed through coordinated management-system processes. The organization should nevertheless address the individual requirements of each standard within its applicable scope.
Yes. Organizations can coordinate information-security and privacy management where appropriate. ISO 27701 focuses on privacy information management, while ISO 27001 establishes the requirements for an information-security management system.
ISO/IEC 27001 specifies requirements for an information-security management system and is the principal ISO 27000-family standard used for ISMS certification. ISO/IEC 27002 provides a reference set of information-security controls and implementation guidance; it is not itself the equivalent of ISO 27001 certification.
ISO 27002 is primarily a controls and guidance standard rather than the standalone ISMS certification standard. Organizations generally use its guidance to support their ISO 27001 information-security controls rather than treating ISO 27002 as a separate equivalent certification.
The current published ISO/IEC 27001 standard is ISO/IEC 27001:2022, with Amendment 1:2024 also published. Organizations should confirm the applicable edition and certification requirements with their certification body.
The official standard is ISO/IEC 27001:2022, titled “Information security, cybersecurity and privacy protection — Information security management systems — Requirements.” ISO identifies it as the requirements standard for an ISMS.
ISO explains that organizations can implement ISO/IEC 27001 to establish, maintain and continually improve an ISMS, and they may choose to undergo certification to demonstrate conformity to stakeholders and customers. ISO also notes that certification by an accredited conformity assessment body can provide an additional layer of confidence.
The appropriate accreditation requirement depends on how and where the certificate will be used. Where a customer, tender or regulatory requirement specifies accredited certification, the organization should verify the certification body's relevant accreditation and scope before beginning the audit.
Check the relevant accreditation body's official information and confirm that the certification body is accredited for ISO/IEC 27001 and the applicable certification scope. If the certificate is intended for a tender or major customer, verify the acceptance requirement before certification.
Yes, where accredited certification is required, it is important to verify that the certification body's accreditation covers the applicable ISO/IEC 27001 certification activity and relevant scope. A general claim of accreditation should not be treated as sufficient evidence.
Organizations should consider accreditation, applicable scope, competence, audit arrangements, industry understanding and the intended use of the certificate. If the certificate will be submitted to a customer or tender authority, its specific acceptance requirements should be checked before selection.
Compare the relevant accreditation, ISO 27001 scope, audit competence, certification process, industry experience, geographic coverage, service arrangements and quotation. The lowest quotation should not be the only selection criterion.
Ask about accreditation, certification scope, audit stages, audit duration, surveillance, certificate cycle, applicable fees, auditor competence and the process for addressing findings. If a customer or tender requires specific certification conditions, provide those requirements before signing.
Yes. You can provide your proposed scope, business activity, locations and any customer or contractual requirement for an initial discussion. SCS Certification can explain the certification process and applicable certification considerations before the quotation and audit stages.
SCS Certification can explain certification requirements and scope considerations based on the information you provide. The organization remains responsible for accurately defining its business activities, systems and information-security responsibilities within the proposed scope.
A multi-location organization can discuss its proposed UAE scope with SCS Certification. The certification arrangement and audit programme depend on the locations, activities, organizational structure and applicable certification requirements.
Yes, organizations operating in UAE free zones can pursue ISO 27001 certification where appropriate. The certification scope should reflect the actual services, information assets, processes and responsibilities rather than merely the company's free-zone registration.
SCS Certification can discuss certification requirements for SaaS organizations, including the proposed ISMS scope, services, locations, information assets and certification process. Providing these details allows a more appropriate quotation to be prepared.
Yes. An organization with established security policies, controls and risk-management processes can use its existing arrangements as part of its ISO 27001 preparation, subject to demonstrating conformity with the applicable requirements.
An existing accredited certification may be eligible for transfer subject to the applicable transfer requirements and review of the certificate's status. SCS Certification can review the available certification information before confirming the appropriate route.
Certification transfer may be possible before expiry, subject to the applicable requirements. Organizations should begin early, especially if the certificate is needed continuously for customers, tenders or supplier qualification.
The organization should contact its certification body before expiry and understand the applicable recertification, surveillance or transfer requirements. If uninterrupted certification is commercially important, waiting until the final days can create avoidable problems.
Certification is maintained through the applicable certification cycle and surveillance activities. The organization must continue operating and improving its ISMS and address applicable audit findings rather than treating certification as a one-time documentation exercise.
Certification normally involves ongoing surveillance according to the applicable certification scheme and audit programme. Organizations should confirm the exact surveillance arrangements with their certification body when reviewing the certification quotation.
ISO management-system certification operates through a certification cycle, with ongoing surveillance and recertification activities. The organization should plan these activities in advance to maintain certification without unnecessary interruption.
Yes, an organization can define a certification scope around its UAE activities where that scope accurately reflects the business and information-security responsibilities being assessed.
A focused service scope may be possible if the boundaries, supporting processes and information-security responsibilities can be clearly defined and independently assessed. The scope should not exclude processes that are necessary for the effective operation of the service.
Scope exclusions need to be technically and organizationally justified. If the development team is responsible for systems or information included in the ISMS, excluding it may not accurately represent the organization's information-security responsibilities.
Physical locations and controls should be considered according to the information-security risks associated with the defined scope. An office should not be excluded merely because the organization wants a smaller certificate if activities performed there support the certified service.
Employees and their responsibilities can fall within the ISMS scope, but certification is not an individual employee certification. The organization must establish appropriate information-security responsibilities, awareness and controls for personnel relevant to the scope.
Yes. ISO/IEC 27001 addresses information in different forms, not only digital systems. Paper records can therefore be considered within the organization's information-security risk management where relevant to the ISMS scope.
Yes. Cloud-based information can be included within an organization's ISMS when it falls within the defined scope. The organization should identify relevant cloud risks, responsibilities and controls.
Mobile devices can fall within the ISMS where employees use them to access, process or store information covered by the certification scope. Appropriate controls should be selected according to the organization's risk assessment.
Remote access can be included within the ISMS and should be managed according to the organization's information-security risks. Authentication, authorization, device security and monitoring may all be relevant depending on the environment.
Supplier and third-party information-security risks can be addressed through the organization's ISMS. The organization should determine appropriate supplier requirements, assessment and monitoring based on the risks associated with outsourced services.
Personnel awareness and competence are important parts of an effective information-security management system. Organizations should establish appropriate awareness and training arrangements for people whose activities affect information security.
Yes. ISO 27001 is a management-system standard, so information security is not intended to be treated solely as an IT responsibility. Management involvement, accountability and review are important elements of an effective ISMS.
Certification can provide structured evidence that an organization operates an independently assessed information-security management system. However, customers may still request additional technical or contractual information beyond the ISO certificate.
It can support customer assurance by providing independent evidence of an established information-security management system. Whether it satisfies a particular customer's onboarding requirement depends on that customer's procurement and security criteria.
Yes, an ISO 27001 certificate can be relevant where customers use information-security certification as part of supplier assessment or qualification. The customer may still impose additional security requirements.
ISO/IEC 27001 is internationally recognized and can provide a common management-system framework for demonstrating information-security practices to customers and partners in different markets. Individual customers may nevertheless have additional requirements.
Yes. ISO 27001 is designed around proactive information-security risk management rather than requiring an organization to have experienced a security incident. The purpose is to identify and manage relevant risks systematically.
Yes. Cybersecurity tools address particular technical or operational needs, while ISO 27001 establishes a management framework for identifying risks, assigning responsibilities, selecting controls, monitoring performance and continually improving information security.
Certification can provide customers and other interested parties with independent evidence that an organization's defined ISMS has been assessed against ISO/IEC 27001 requirements. The practical value depends on the customer's expectations and the organization's actual implementation.
The business case depends on the organization's customers, information-security risks, contractual requirements and growth plans. SMEs that handle sensitive information or regularly face security assurance requirements may find a formal ISMS particularly relevant.
It can be commercially relevant where the startup sells to enterprise customers, processes sensitive information, operates cloud services or expects customers to request formal security assurance. The decision should be based on the startup's actual market and information-security requirements.
Define the intended scope, identify the information and services involved, review existing security practices, consider applicable customer requirements and identify significant gaps. Then contact SCS Certification with the business and scope information to discuss the certification route.
Send your company activity, number of employees, UAE locations, proposed ISMS scope, technology or service environment and any customer, tender or contractual requirement. Existing ISO certificates or information-security documentation can also help provide useful context.
Yes. Obtaining a quotation before implementation is often useful because it allows the organization to understand the certification arrangement and audit requirements before planning the project.
SCS Certification can discuss the certification stages and the information needed to establish an appropriate audit programme. The organization's readiness, scope and operational evidence will determine the practical timeline.
Define the scope clearly, maintain required records, complete internal audit and management review, ensure relevant personnel understand their responsibilities and address identified gaps before the certification audit. Early planning is especially important when a customer deadline is involved.
Common causes can include an unclear scope, incomplete implementation, insufficient evidence, unavailable personnel, incomplete internal audit or management review, unresolved findings and scheduling constraints. Early readiness planning can reduce avoidable delays.
An organization should be adequately prepared for the certification assessment and able to demonstrate conformity with applicable requirements. If important parts of the ISMS are still being developed, a readiness or gap review can help identify what remains to be addressed before the certification audit.
Obtain the customer's exact requirement, including the requested standard, certification scope, accreditation conditions and deadline. Then contact SCS Certification with that information so the certification route and practical timeline can be assessed before you commit to a provider.
Review the tender wording carefully and confirm whether a valid certificate, accredited certification, particular scope or specific certification-body requirements are stated. Then provide those requirements to SCS Certification for review and certification planning.
SCS Certification can explain the certification requirements and audit expectations applicable to your proposed scope. A formal readiness or gap assessment should be distinguished from the independent certification decision itself to preserve the required impartiality.
A scope may be unnecessarily broad if it includes activities, locations or information-security responsibilities that are not relevant to the business objective of certification. However, it should still accurately capture the dependencies and supporting processes necessary for the certified service.
A scope may be problematic if it excludes important processes, systems, people or locations that are necessary for delivering the certified service or managing its information-security risks. The scope should represent the real boundaries of the ISMS.
This depends on the legal and organizational structure, shared management system and certification scope. Multiple legal entities require careful consideration of how the ISMS is governed and what exactly is being certified.
It may be possible depending on the management structure, operational responsibilities and certification scope. The relationship between the parent and subsidiary should be clearly understood when determining the ISMS boundaries.
Yes, outsourced infrastructure can be considered within the organization's information-security risk management. The organization must clearly understand its responsibilities and the relevant supplier controls.
Cloud applications can be included within the organization's information-security environment where they support activities within the ISMS scope. The organization should assess the associated access, data, supplier and configuration risks.
Cloud environments such as AWS, Azure or Google Cloud can be part of an organization's ISMS scope when they support the certified services. The organization should address the information-security responsibilities that it controls within the applicable cloud arrangement.
No. ISO 27001 does not prescribe one particular cloud provider. The organization should select and manage technology and suppliers according to its information-security risks and business requirements.
AI systems can be included in an ISMS where they process or support information within the organization's scope. Organizations using AI may also consider ISO/IEC 42001 where an AI management system is relevant to their objectives.
Yes. ISO 27001 provides a structured approach to information-security risk management, including risks associated with personal information. Organizations with broader privacy-management requirements may consider ISO/IEC 27701 as an additional standard.
ISO 27001 can support information-security controls relevant to privacy obligations, but it is not itself a GDPR certification. Organizations should assess the applicable privacy laws and requirements separately.
No. ISO 27001 certification does not replace applicable UAE laws, regulations or sector-specific requirements. It provides an information-security management framework that may support an organization's broader compliance programme.
No. An ISO 27001 certification audit assesses conformity of the ISMS against the applicable standard. A separate cybersecurity assessment may examine technical vulnerabilities or security conditions beyond the purpose of management-system certification.
No. Penetration testing and ISO 27001 certification serve different purposes. Penetration testing can be one security activity within an organization's wider risk-management programme where appropriate.
A certificate can provide useful evidence of an independently assessed ISMS, but each customer may have different scope, accreditation, technical and contractual requirements. Always check whether the customer's specific acceptance conditions are satisfied.
No certificate should be assumed to satisfy every tender automatically. The tender may specify the required standard, accreditation, scope, validity or certification-body conditions. Review the tender requirements before selecting the certification arrangement.
Obtain the customer's exact requirement before certification and confirm the required standard, scope, accreditation and validity conditions. SCS Certification can review the information you provide and discuss the appropriate certification arrangement.
Send SCS Certification your company activity, UAE location, employee strength, proposed ISMS scope, technology environment and any customer, tender or contractual requirement. The team can then discuss the certification process, applicable audit arrangements and quotation for your organization.