ISO 27001 Starts With a Question: Is Leadership Involved?
A customer may ask for the certificate. Directors still need to own the priorities, resources and risk decisions that make security work.

5 October 2026
Whether I'm helping a company implement ISO 27001 or conducting an internal audit, one of my first questions is: how involved are the directors? A customer may have asked for a certificate. A sales opportunity may depend on it. Those are perfectly reasonable reasons to start. What interests me is what happens next.
Does the CEO approve the project and leave someone else to collect the paperwork? Or does leadership want to understand how the company operates, improve its security and have an independent certification body assess the resulting management system? The starting point can be the same. The commitment behind it makes a considerable difference.
A recent Sirius Legal article about NIS2 and directors' liability brought that question back to mind. It is a useful prompt for a broader conversation: what does taking responsibility for information security look like in a small company?
Use the framework to understand the business
ISO/IEC 27001 gives you a structured way to manage information security risks. For a SaaS company or SME, that starts with understanding the information you handle, the services you depend on, the commitments you make to customers and the consequences if something goes wrong.
From there, you can choose improvements that fit the business. Who owns an important supplier? Have we tested recovery? Can we remove access when someone leaves? Do we know which risks remain and why we are accepting them? The framework helps connect those everyday questions to responsibilities, decisions and evidence.
This should be proportionate. A small team does not need to copy a multinational's bureaucracy. ISO's management-system guidance recognises that a small organisation can rely on strong leadership from its owner and clear responsibilities without extensive documentation. What matters is that the agreed process works and improves as the company changes.
Leadership has decisions to make
A security lead, consultant or fractional CISO can assess risks, explain options and coordinate the work. Directors and the management team still need to make the business decisions: which risks matter most, what gets time and budget, and which remaining risks the organisation is prepared to accept.
Imagine a recovery test shows that restoring an important service takes much longer than the business can tolerate. Recording the finding is useful. Improving the recovery process may require engineering time, supplier changes or revised customer commitments. Someone with the authority to set those priorities needs to act.
For me, involvement means leaders understand the significant risks, ask questions and follow up on decisions. They make time for substantive management reviews and check whether previous actions were completed. They do not need to configure every firewall. They do need enough understanding to challenge an assurance that everything is fine.
The certificate is evidence of a continuing process
Independent certification is valuable. It assesses whether the information security management system conforms to the standard within its stated scope. It gives customers a recognised form of assurance, while findings can help the organisation improve.
A certificate does not promise that every product is secure or that an incident will never happen. Nor is the job finished when it arrives. Risks, suppliers and operations change, so the management system needs continued attention. If certification is your goal, build that habit while preparing for the audit.
Why I welcome NIS2's focus on management
What I like about NIS2 is that it makes leadership's responsibility explicit. For essential and important entities within its scope, Article 20 of the directive puts approval and oversight of cybersecurity risk-management measures with the management body. It also requires its members to undertake training so they can understand risks and assess the measures.
In Belgium, the NIS2 law implements these duties in Article 31 and provides for management accountability in Article 61. A cyber incident does not automatically make every director personally liable; the relevant duties and circumstances matter. The practical message is clear: approving a security budget once and then forgetting the subject is inadequate oversight.
Not every SaaS company or SME falls directly within NIS2. Applicability depends on the services, size, jurisdiction and relevant exceptions; use the CCB's Belgian guidance to assess your situation. Supplying an in-scope customer can bring contractual security requirements, but does not automatically put every supplier in scope.
A properly scoped ISO 27001 certification can support Belgium's recognised assurance approach when the CCB's conditions are met. It does not replace separate NIS2 obligations such as incident reporting or management training. A working management system helps directors fulfil their role; they still need to exercise it.
In the Netherlands, NIS2 is implemented through the Cyberbeveiligingswet, which entered into force on 15 August 2026. For essential and important entities under the law, the board must approve cybersecurity risk-management measures and oversee their implementation. Executive directors also have specific training requirements. The national details differ, but the practical message is the same: appointing a CISO does not remove leadership's responsibility.
Five questions for the next leadership meeting
- Which information and services would hurt the business most if compromised?
- Which significant risks are we accepting, and who approved that decision?
- What evidence shows our important security measures actually work?
- Which improvement is waiting for a decision about budget, time or priorities?
- Was our last management review a genuine two-way discussion about our security status, risks and next steps, with clear decisions and owners, or just a checklist to approve?
Those questions are useful whether you are pursuing certification, directly subject to NIS2 or simply trying to run a dependable company. A customer request can start the project. Leadership's continued involvement is what gives it lasting value.
At Coding Mammoth, we help SaaS companies and SMEs turn ISO 27001 into practical ways of working, with implementation support and internal audits. One of our first conversations will be about the people who can make the decisions and follow them through.