Multicert
Information security management system

ISO/IEC 27001 certification for cloud and remote teams

Performed in partnership with an international accredited certification body
In short

We run accredited ISO/IEC 27001 certification for companies whose team and infrastructure live in the cloud. The certificate is issued by our partner body LL-C, accredited by ČIA. Remote auditing follows ISO/IEC 27006-1:2024 and Global ACI-TECH-3-003, so a distributed team does not mean an auditor travelling to every home office. The certification audit starts from EUR 1,390 net (PLN 5,900) for a team of up to five. We certify; we do not implement or consult on the system we audit.

Standard

What you get certified against.

ISO/IEC 27001 specifies requirements for an information security management system. Customers often ask software suppliers for an accredited ISO/IEC 27001 certificate during procurement.

Standard
ISO/IEC 27001:2022 with Amendment 1:2024 — information security management systems (ISMS)
Controls
93 controls in Annex A, grouped in four themes: organizational, people, physical and technological
Certification body
LL-C (Certification) Czech Republic a.s., accredited by the Czech Accreditation Institute (ČIA)
Audit rules
ISO/IEC 17021-1, ISO/IEC 27006-1:2024 and Global ACI-TECH-3-003 (formerly IAF MD 4:2025) for remote auditing
Validity
3 years, with a surveillance audit every year
Cloud and distributed teams

How the audit works when there is no office to visit.

The rules for remote auditing changed between 2024 and 2026. Here is what they mean for a company that runs in the cloud.

  • 01

    Your online environment counts as one site

    Work done in an online environment, wherever your people work, can be treated as a single virtual site. Global ACI-TECH-3-003 counts a virtual site as one site when audit time is calculated.

  • 02

    No accreditation body sign-off for a mostly remote audit

    ISO/IEC 27006-1:2024 removed the requirement to obtain accreditation body approval when remote activities exceed 30% of the planned on-site audit time. The certification body sets the share of remote work in the audit plan, based on its assessment of risks and opportunities.

  • 03

    Remote-only companies: stated on the certificate

    For organisations with few or no relevant physical sites, the audit report and the certification document state that the client operates remotely. If virtual sites are in scope, the audit documentation notes this and names the activities performed there.

  • 04

    Evidence is shown on screen, not handed over

    Access configuration, event logs, repository history and access reviews can be shown on a shared screen. The use of remote tools is agreed with you before the audit, together with information security and data protection measures.

Processes that must run in a physical environment, such as warehousing, manufacturing or repairs, cannot be part of a virtual site; the audit plan states how they are assessed. Global ACI-TECH-3-003 replaced IAF MD 4:2025 from 28 August 2026 without substantive changes.

Process

From inquiry to certificate.

Stage 2 can follow stage 1 closely when stage 1 confirms that your ISMS is ready. The number of audit days is set in the quote.

  1. 01 1–2 days

    Inquiry & quote

    You send the scope, headcount, sites and cloud services. We confirm which audit activities can be remote and quote the full three-year cycle.

  2. 02 about 1 week

    Contract & audit plan

    Contract signing, audit team assignment and agreement on remote tools and data protection measures.

  3. 03 usually remote

    Stage 1 audit

    Review of the ISMS scope, risk assessment and Statement of Applicability, usually remote. Confirms readiness for stage 2.

  4. 04 remote or on-site

    Stage 2 audit

    Evaluation of the implementation and effectiveness of your controls, remote or on-site according to the audit plan.

  5. 05 2–3 weeks

    Certificate

    After any nonconformities are closed: certification decision by a person who did not take part in the audit, then issue of the accredited certificate by LL-C.

Pricing

What it costs.

For ISO/IEC 27001, audit time is set by Annex C of ISO/IEC 27006-1:2024, mainly from the number of people doing work within the ISMS scope and the complexity of the system.

  • Certification audit, stage 1 and stage 2from EUR 1,390 net (PLN 5,900)
  • Surveillance audit, each yearfrom EUR 920 net (PLN 3,900)
  • Recertification after three yearsfrom EUR 1,150 net (PLN 4,900)

Prices apply to an organisation of up to five people in one location and one standard. On-site audits add travel and accommodation at actual cost; remote activities do not. The quote covers the full three-year cycle.

Your quote

What we need for a quote.

With them we calculate audit days and tell you which activities can be remote.

  1. 01 ISMS scope: services, products, processes and information assets covered
  2. 02 Number of people doing work within the scope, including contractors
  3. 03 Physical sites and the processes performed there, plus work done only online
  4. 04 Countries where the team works and the preferred audit language
  5. 05 Cloud services used and how responsibility is shared with providers
  6. 06 Current Statement of Applicability, dates of the internal audit and management review
FAQ

Questions from cloud and AI companies.

Can the whole ISO/IEC 27001 audit be remote?

The accreditation rules do not exclude it, but they do not guarantee it either. The certification body assesses the risks and opportunities of using remote tools and sets the remote and on-site activities in the audit plan. Processes that must run in a physical environment, such as warehousing, manufacturing or repairs, cannot be part of a virtual site; the audit plan states how they are assessed.

Who issues the certificate?

The certificate is issued by our partner certification body LL-C (Certification) Czech Republic a.s., accredited by the Czech Accreditation Institute (ČIA). ČIA is a signatory of the EA MLA and of the Global ACI MRA (which took over the IAF MLA), and its recognised scope includes ISO/IEC 27001. Certificates issued under its accreditation are accepted as equivalent by accreditation bodies that are signatories to these arrangements.

Can I verify the certificate online?

Under IAF MD 28, accredited certification bodies upload data on accredited certificates to the IAF Database, which is searchable through IAF CertSearch. You can also confirm the certificate status directly with the certification body.

How is the price calculated?

Audit time for ISO/IEC 27001 is determined by Annex C of ISO/IEC 27006-1:2024, mainly from the number of people doing work within the ISMS scope and the complexity of the system. For organisations of up to five people in one location, stage 1 and stage 2 start from EUR 1,390 net (PLN 5,900) and each surveillance audit from EUR 920 net (PLN 3,900).

Do you help implement the ISMS?

No. A certification body may not offer or provide management system consultancy (ISO/IEC 17021-1, clause 5.2). You can implement the ISMS yourself or with an independent consultant; we audit and certify it.

Is a remote audit cheaper?

Not automatically. Remote work removes travel and accommodation costs, but Global ACI-TECH-3-003 notes that using remote tools may require additional planning that affects audit duration. The number of audit days follows ISO/IEC 27006-1:2024.

Call
Get a quote