Compliance

ISO

International Organization for Standardization

ISO, the International Organization for Standardization, is an independent, non-governmental federation of national standards bodies from over 160 countries, headquartered in Geneva. It develops and publishes voluntary, consensus-based technical and management system standards spanning everything from screw threads and shipping containers to information security and quality management.

Why ISO matters in a Microsoft estate

ISO matters because customers, resellers, and procurement teams need evidence that controls are defined, operated, and reviewable. A useful glossary definition should help a reader connect the term to audit preparation, policy work, or repeatable assurance activity.

How ISO shows up in practice

ISO itself does not certify organisations against its standards. Certification is instead carried out by accredited, independent certification bodies (often called registrars) that audit an organisation's practices against the relevant published standard and issue a certificate valid for a defined period, typically three years, subject to ongoing surveillance audits. Standards are identified by a number, such as ISO 9001 for quality management or ISO/IEC 27001 for information security management. Many are developed jointly with the International Electrotechnical Commission (IEC), which is why information technology standards frequently carry the ISO/IEC prefix rather than ISO alone.

For IT teams and MSPs operating in a Microsoft 365 or Azure estate, ISO standards matter less as an abstract quality mark and more as a procurement and contractual reality. Enterprise customers, particularly in regulated sectors like finance, healthcare, and government, increasingly specify current ISO certification, most commonly ISO/IEC 27001 for information security, as a prerequisite for supplier onboarding. Losing or lapsing a certification can remove a supplier from a tender shortlist, regardless of the organisation's actual security posture. A common point of confusion is conflating a specific ISO standard's certification with generic "ISO compliance", a phrase with no defined meaning, since ISO publishes thousands of distinct standards covering entirely different domains.

A genuinely useful claim always names the specific standard and, ideally, the specific clauses or annex controls in scope. This matters because certification scope statements can be narrower than they first appear, sometimes covering only a single business unit, site, or product line rather than the whole organisation. Standards themselves are periodically revised, sometimes substantially, such as the 2022 restructuring of ISO/IEC 27001's Annex A controls. Organisations holding certification against an older version are typically given a transition period, often two to three years, to migrate before the older certificate is withdrawn. This is worth checking when evaluating whether a supplier's or customer's current certificate reflects the latest control set.

Glossary