top of page
Search

10 Steps to ISO 27001 Certification for Advertising and Creative Agencies

Writer: AKRUP
AKRUP
11 minutes ago
7 min read

Client data, campaign assets and creative intellectual property are now central to agency value. When an enterprise client asks for security evidence, informal good practice may not be enough.

 

ISO 27001 certification provides independently audited evidence that an agency operates a structured information security management system (ISMS). It can support procurement, strengthen client confidence and bring greater control to the tools, people and suppliers involved in campaign delivery.

 

The process is demanding, but it is manageable when the scope, risks and responsibilities are clear from the start.

 

Key takeaways for agency leaders

 

  • ISO/IEC 27001:2022 is the international standard for an information security management system, or ISMS.

  • Compliance means an agency has adopted relevant practices. Certification means an accredited certification body has independently audited the ISMS within an agreed scope.

  • Agency scope often includes client campaign data, production platforms, cloud storage, managed devices, remote workers, freelancers and core suppliers.

  • Annex A contains 93 reference controls. Not every control applies to every agency, but every inclusion or exclusion needs a justified decision.

  • Certification is not a one-off project. Internal audits, management reviews, surveillance audits and improvement activity continue after the certificate is issued.

 

Why creative agencies pursue ISO 27001 certification

 

Procurement teams want reliable assurance

 

Enterprise clients increasingly ask agencies to complete detailed security questionnaires before awarding work. They want confidence that personal data, unreleased campaign material and customer information will not be exposed through weak security controls or unmanaged suppliers.

 

A valid certificate can help, but clients should verify that it was issued by an accredited certification body and check its scope. The same care applies when assessing suppliers' information security credentials, particularly where a production house, analytics provider or freelance network handles sensitive materials.

 

Compliance is not the same as certification

 

An agency may be broadly "ISO 27001 compliant" because it uses multi-factor authentication, has security policies and performs risk reviews. That can be a useful starting point. ISO 27002 can provide implementation guidance for information security controls, but it is not the certification standard.

 

Formal certification goes further. An independent auditor tests whether the ISMS meets the standard and whether it is operating in practice. ISO describes ISO/IEC 27001:2022 as the requirements standard for establishing, implementing, maintaining and continually improving an ISMS in its official ISO/IEC 27001:2022 publication.

 

Steps 1 and 2: Set leadership and scope

 

Step 1: appoint an accountable executive

 

Top management must support the ISMS with decisions, resources and regular oversight. For most agencies, this means a director or founder owns information security at executive level, while an operations lead, IT manager or security lead runs the programme.

 

Create a short project charter that names the ISMS owner, sets a budget and records the business reasons for certification. A strong deliverable is a monthly steering group agenda covering risk, progress, client requirements and decisions needed.

 

A common pitfall is assigning ISO 27001 to one overstretched IT employee. Security reaches HR, client services, finance, production and leadership. It needs authority beyond the IT function.

 

Step 2: define a realistic ISMS scope

 

The scope of the information security management system (ISMS) defines which parts of the agency are covered. It might include the UK agency operation, employees, managed laptops, Microsoft 365 or Google Workspace, project-management tools and campaign asset repositories.

 

It should also explain exclusions. If a separate overseas studio or independent production company is outside the scope, document the boundary and the controls that protect the connection.

 

Avoid an artificially narrow scope that excludes the systems where client information is actually handled. Equally, don't include every global office and legacy system without understanding the cost and evidence burden. The right scope reflects contracts, risk, operational control and client expectations.

 

Steps 3 and 4: Measure gaps and map agency assets

 

Step 3: perform a practical gap analysis

 

Compare current arrangements with ISO 27001 clauses 4 to 10 and the security controls likely to apply. Review policies, access management, supplier checks, incident response, device security, training records and evidence of management oversight.

 

The output should be a prioritised gap register. Each item needs an owner, target date, risk rating and expected evidence. For example, an agency may have a password policy but no documented process for removing a departed freelancer's access to a campaign drive.

 

A gap analysis identifies what is missing. It doesn't prove that a control works every day.

 

Step 4: build an information and asset inventory

 

Agencies often underestimate how widely client information travels. List key information assets, including audience data, pitch documents, media plans, raw footage, design files, account credentials and client contact lists.

 

Record where each asset is stored, who owns it, who can access it and what happens when a project closes. Include agency-owned devices, cloud applications, shared production environments and third-party services.

 

 

A useful asset register links each item to a business owner and classification. This makes later risk assessment far more reliable than relying on a generic spreadsheet.

 

Steps 5 and 6: Assess risk and select controls

 

Step 5: conduct the information security risk assessment

 

Risk assessment is where the ISMS becomes specific to the agency. It considers potential events, likelihood, business impact and existing safeguards.

 

Examples include a freelancer retaining access after a campaign, an account manager sending assets to the wrong contact, a phishing attack on a shared mailbox, or a cloud production tool suffering an outage before launch. Record the risk owner and whether to reduce, accept, avoid or share the risk.

 

The risk register and risk treatment plan should show why actions are proportionate. This makes risk management appropriate to the agency's scope, clients and operating model.

 

A small design studio and a global media agency will not have identical risks or controls.

 

Step 6: create the Statement of Applicability

 

The Statement of Applicability, usually called the SoA, is one of the most important certification documents. It records which Annex A controls apply, why they apply, how they are implemented and why any control is excluded.

 

ISO/IEC 27001:2022 Annex A has 93 controls across organisational, people, physical and technological themes. ISO 27002 may provide supporting implementation guidance, while ISO/IEC 27001:2022 remains the requirements standard for certification. The Annex A control structure is a reference set, not a checklist requiring every agency to implement every control.

 

  An excluded control needs a reason that stands up to the agency's scope and risk assessment. "We are too small" is not a reason on its own.  

 

The responsible role is usually the ISMS manager, with input from IT, HR, operations and senior leadership.

 

Steps 7 and 8: Put the ISMS into daily practice

 

Step 7: implement policies, processes and evidence

 

Policies set direction, but auditors also need evidence that security controls operate in normal agency work. For a creative agency, that could include an information security policy, access control, supplier security, incident management, information classification, remote working and secure offboarding.

 

Turn policies into working routines. Run access reviews for campaign platforms. Keep evidence of security awareness training. Test the incident process. Review supplier contracts where vendors process client data or host campaign materials.

 

A short approval record, a dated access review or a completed training report can be stronger evidence than a polished policy that nobody follows.

 

Step 8: train people and complete internal review

 

Staff awareness must reflect real agency behaviour. Account teams need to recognise social engineering. Creatives need clear rules for sharing files. Managers need to understand reporting routes when a device is lost or a client email is misdirected.

 

Then perform an internal audit against the agreed ISMS scope. The auditor should be sufficiently independent from the work being reviewed. Management must also complete a formal management review, considering audit results, risks, objectives, incidents, resource needs and improvement actions.

 

Where internal security leadership is limited, Virtual CISO services can provide governance oversight without appointing a full-time security executive.

 

Steps 9 and 10: Prepare for certification and maintain it

 

Step 9: complete Stage 1 and Stage 2 audits

 

Choose an accredited certification body with relevant experience and agree the audit scope before scheduling. The stage 1 audit reviews the ISMS scope, methodology, risk treatment plan, Statement of Applicability and core documentation.

 

The stage 2 audit tests implementation through interviews, samples and operational evidence. Auditors may ask to see access reviews, induction training, supplier assessments, incident testing or management review decisions.

 

ISO 27002 can support control implementation, but certification decisions are made against ISO 27001 requirements. The audit process sequence depends on readiness, evidence, findings and audit availability.

 

Step 10: close findings and keep improving

 

If auditors identify nonconformities, address the underlying cause rather than supplying a one-off document. A missing leaver checklist may point to unclear HR ownership. Repeated gaps in access reviews may require an automated reminder, better asset ownership or a revised workflow.

 

For a resource-constrained agency, start with the evidence already available in HR systems, ticketing tools, device management, cloud audit logs and meeting records. Compliance automation can organise evidence for security controls, but it doesn't replace ownership, judgement or evidence that controls work.

 

 

If a significant issue arises close to an audit, ISO 27001 certification specialists can help assess the gap, organise corrective action and prepare a practical response.

 

Timescale and cost factors for agencies

 

A well-prepared agency may achieve certification in around three to nine months. Larger agencies, complex systems, limited audit availability or immature security arrangements can require six to 12 months or more. Scope, headcount, systems, locations, audit availability and maturity all affect both cost and duration. These are planning ranges, not guarantees.

 

Cost depends on headcount, locations, systems, scope, maturity, internal effort and certification fees. Fees from an accredited certification body in the UK are often reported at around £4,000 to £12,000 across a three-year cycle, although complex environments can cost more. Compliance automation tools may create an additional implementation cost, but they aren't mandatory.

 

Plan for more than the certification audit. Budget for security improvements, staff time, internal audits, a surveillance audit in the following years and a recertification audit at the end of the cycle.

 

Frequently asked questions

 

What is an ISMS in an agency?

 

An ISMS is the management system used to control information security. It brings together the agency's policies, risks, objectives, responsibilities, controls and review processes. It covers how people and systems protect information, not only cyber security tools.

 

How does the Statement of Applicability help during an audit?

 

The SoA gives the auditor a clear route from risks to control decisions. It records which ISO/IEC 27001:2022 Annex A controls the agency selected, how they’re applied and why any are excluded. ISO 27002 can help the agency interpret and implement those controls. A weak SoA often exposes weak risk treatment decisions.

 

Can a small agency achieve ISO 27001 certification?

 

Yes, provided its ISMS is proportionate to its scope and risks. A smaller agency may have fewer systems and simpler governance, but it must still demonstrate leadership, risk management, documented processes, evidence and continual improvement.

 

Building security into agency growth

 

ISO 27001 certification isn't a badge earned through templates alone. It's evidence that an agency understands its information security risks, assigns responsibility and can demonstrate its controls work.

 

For creative businesses, a well-run ISMS protects what people value most: client trust, campaign delivery and confidential information. It strengthens the agency's security posture through continuous compliance. That means ongoing alignment with documented ISMS arrangements and continual-improvement obligations, not a permanent guarantee.


If you would like to find out more information or require any ISO 27001 services, please Contact Us

 
 
 

Comments

Rated 0 out of 5 stars.
No ratings yet

Add a rating
bottom of page