Audit Readiness Group
ISO 9001A customer is requiring it5 min read

A customer is asking for ISO 9001 and ISO 27001. Can one system cover both?

One management system, two certificates. The shared clause structure means audits, reviews and document control serve both. The security controls themselves are separate work and the larger half.

What to do now

Establish three facts before you plan anything.

Which standard is actually required, and by when. Customers sometimes name ISO 27001 when what they want is answers to a security questionnaire, and those are very different purchases. Ask whether a certificate is required or whether evidence of specific controls satisfies them.

Whether the scopes are the same. Your quality certificate may cover one plant. Information security scope often has to cover the whole company, because that is where the data moves. Different scopes are allowed and common, and they change the cost of both.

What you already have. If you hold ISO 9001, you already own the machinery that both standards share, and that is more than most people assume.

Then sequence deliberately. Quality first is the usual order when both are required at once, because the habits an ISO 9001 system builds are exactly what an information security system reuses. If one has a hard customer deadline, that one goes first regardless.

What it costs

The overlap is real and it is structural rather than operational.

Annex SL, the harmonized structure ISO applies to its management system standards, means ISO 9001 and ISO 27001 share the same ten-clause skeleton: context, leadership, planning, support, operation, performance evaluation, improvement. In practice that means one internal audit program, one management review cycle, one corrective action process, one competence framework, and one approach to documented information can serve both certificates.

What does not overlap is clause 8, and clause 8 is where the work is. ISO 9001's operational clause is about controlling production and service provision. ISO 27001's is about risk treatment and a set of security controls, plus the Statement of Applicability that records which apply to you and why. That half is new work, and it is the larger half.

Timelines reflect that. ISO 9001 certification for a manufacturer typically runs three to six months with help. A first ISO 27001 certification at a mid-market manufacturer typically runs nine to eighteen months: months to scope and stand up the system, three to six more operating it so there is evidence to audit, then the two audit stages.

The market reflects it too. The United States held roughly 28,800 ISO 9001 certificates in 2024 and about 4,260 ISO 27001 certificates. Manufacturers are a small share of the second number, which is why most vendors selling ISO 27001 readiness have never been in a plant.

What good looks like

One system that genuinely runs once, not two systems sharing a filing cabinet.

One audit program covering both scopes, with auditors competent in each. A quality auditor is not qualified to audit access control, and an information security auditor is not qualified to audit calibration. Integration is structural; competence is not transferable.

One management review whose agenda covers the inputs both standards require, attended by people who can allocate resources.

One corrective action process, so a finding is a finding regardless of which standard raised it.

Clear scope statements on each certificate, so nobody assumes the quality scope and the security scope are the same when they are not.

The failure mode is a system that says integrated and runs parallel: two schedules, two review meetings, two sets of records, and one of each pair quietly neglected between audits. Auditors find that quickly, because the neglected half has gaps the active half does not.

When to bring in outside help

When both are required at once and the sequence is not obvious. Getting the order wrong is expensive in a way that is hard to see until month four.

When the security half starts. ISO 27001's risk treatment and Statement of Applicability are genuinely different work from anything a quality management system contains, and the controls have to be real rather than documented.

When your customer's questionnaire has already arrived. Those documents are written for software companies. Answering them for a manufacturer, accurately and without over-committing, is a specific skill.

You do not need help to decide whether the requirement is a certificate or a questionnaire. Ask your customer.

How ARG does it

We run both sides of this, which is unusual and is the reason the firm exists in the shape it does.

The quality practice, led by a certified ISO 9001 lead auditor, prepares the management system: scope, processes, documentation that matches the floor, the audit program, and the review cycle. Those are the parts both certificates rest on, and they are built once.

The security practice, Adversarial Risk Group, does the work underneath the information security half: on-site physical audits and continuous adversarial testing of the human and physical surfaces that a control framework assumes are handled. That testing produces the evidence a security management system needs, rather than assertions about controls nobody has tried to defeat.

Where the two meet is customer property. Clause 8.5.3 of ISO 9001 already obliges you to protect a customer's intellectual property and personal data. Most manufacturers meet that obligation for material and not for files, and that gap is usually the first thing an information security scope has to close.

We prepare you for both audits. Neither certificate comes from us, and the registrars that issue them are independent of us by rule and by design.

FAQ

Does an ISO 9001 certificate help with ISO 27001?

It helps with the shared skeleton: audit program, management review, document control, corrective action, competence. It does nothing for the security controls, which are most of the work.

Can one certification body do both?

If it holds accreditation for both standards. You will often meet two auditors on the same visit, because the competence requirements differ.

Which should we do first?

Usually whichever a customer is demanding with a date attached. Where both are open, quality first is the common order because it builds the management habits the security system reuses.

Is ISO 27001 the same as SOC 2?

No. SOC 2 is an attestation report from a CPA firm, common in software. ISO 27001 is a certification against an international standard. Customers sometimes ask for one when they would accept the other, so ask which they need.

Do we need ISO 27001 just to protect customer drawings?

Usually not. Your confidentiality agreement sets the obligation, and ISO 9001 clause 8.5.3 already requires you to protect customer property. A certificate becomes the answer when your customer requires one.

Sources

  • ISO 9001:2015 and ISO/IEC 27001 clause structures under the harmonized (Annex SL) format; ISO 9001 clause 8.5.3.
  • ARG market research 2026, section 2.1 for United States certificate counts, section 5.5 for the 27001 adjacency and the absence of manufacturing-native providers, section 7.2 for ISO 9001 timelines.
  • ISO 27001 first-certification timeline: adversarialrisk.com security glossary, ISO 27001 entry.

Tell us which audit is on your calendar.

A gap assessment is a flat-fee, on-site project led by a certified ISO 9001 lead auditor. Three founding-client spots are open for the quality practice.

We prepare you for certification. We never issue it. Your registrar's independence is the point.

Author: David AshbyUpdated 2026-09-12Audit Readiness Group