When an industrial company or a finance department talks to me about "compliance," the word almost always covers two different things that get conflated: quality (ISO 9001) and information security (ISO 27001). This isn't a semantic detail — it completely changes what needs to be built into a website, a form, or an automated workflow.
ISO 9001: process quality, not data security
ISO 9001 governs quality management: how an organization structures its processes to deliver a consistent result and satisfy its customers. Applied to a website or an automation, this translates into a method: scoping, step-by-step validation, documentation, traceable decisions — rather than improvisation.
ISO 27001: information security
ISO 27001 targets a different goal: protecting sensitive data (clients, contracts, financial data) against loss, leaks, or unauthorized access. It's the standard that matters when a law firm, a finance department, or an industrial company asks "where does my data go" and "who can access it."
Both standards share the same structure (Annex SL), which explains the confusion — but one is about quality, the other about security. A website or an automation can target one, the other, or both, depending on the client's real need.
Why this matters for your project, even without certification
I'm not a certified ISO auditor — and I don't claim to be. As part of my computer engineering education (associate degree, professional bachelor's degree, followed by 12 engineering-level units at CNAM Grand Est), I completed a module dedicated to audit and information-security frameworks, validated by an exam. This training shapes how I structure a project: auditing what's in place before any decision, documented scoping, and hosting and integration choices designed around data protection, not the other way around.
In practice, this shows up in my working method: the "Technical audit & scoping" phase present in every offer isn't a stylistic exercise — it's the first building block of an approach built for rigor, the kind expected by clients used to audits and strict specifications.
Why SMEs and professional firms can no longer ignore this
Small organizations aren't spared: the majority of successful cyberattacks in France target very small and medium businesses, with an average cost running into the hundreds of thousands of euros per incident. Full ISO 27001 certification, meanwhile, represents an investment of several thousand euros and several months — out of reach for many of the organizations I work with.
That's exactly where my role sits: without pursuing formal certification, applying the right practices (secure hosting, access management, GDPR-compliant forms, backups, documentation) from the design stage of a website or an automation, to reduce risk without the cost of a full certification process.
In summary
ISO 9001 structures the quality of the work. ISO 27001 structures the protection of the data. You don't need to be certified to benefit from both — you need a provider who understands them and applies them from the scoping stage of your project onward.