Compliance9 min read5 October 2026

ISO 27001 and Website Security: What UK Businesses Need to Know | Yrzo AI

How ISO 27001 relates to website security for UK businesses. Understand the certification requirements, penetration testing obligations, and how Yrzo AI helps.

By Yrzo AI — UK cybersecurity specialists

What Is ISO 27001?

ISO/IEC 27001 is the internationally recognised standard for Information Security Management Systems (ISMS). Published jointly by the International Organization for Standardization (ISO) and the International Electrotechnical Commission (IEC), it sets out the requirements for establishing, implementing, maintaining, and continually improving an organisation's approach to information security.

For UK businesses, ISO 27001 certification signals to customers, partners, and regulators that you take information security seriously and have implemented a systematic, audited framework to protect it. Unlike the UK GDPR, which is a legal obligation, ISO 27001 is a voluntary certification — but it's increasingly demanded by enterprise customers, NHS procurement teams, financial services regulators, and government suppliers as a condition of doing business.

At its core, ISO 27001 is not a checklist of specific technical controls. It's a management framework that requires you to identify your information assets, assess the risks to them, implement appropriate controls, and continuously review whether those controls are working. Your website — and the customer data it holds, processes, and transmits — sits squarely within scope.

ISO 27001 and the Annex A Controls

The standard's normative clauses (4 through 10) describe the management framework itself. Annex A lists 93 controls across four themes — Organisational, People, Physical, and Technological — that organisations typically select from based on their risk assessment. Several of these controls are directly relevant to website security.

**A.8.8 — Management of technical vulnerabilities** requires you to have a process for obtaining information about technical vulnerabilities, evaluating your exposure to them, and taking appropriate actions. This explicitly includes vulnerability scanning and penetration testing as mechanisms for discharging this control.

**A.8.9 — Configuration management** requires that hardware, software, services, and networks are securely configured and that configurations are documented and maintained. This covers your web servers, CMS platforms, and cloud hosting configurations.

**A.5.14 — Information transfer** covers the security of data transferred to and from external parties — relevant to any API integrations your website uses.

**A.8.25 through A.8.34** cover the full software development lifecycle security requirements, which apply if you build web applications internally.

The key principle: Annex A is not a mandated list you must implement wholesale. You implement the controls relevant to the risks you've identified. But if your risk assessment identifies web vulnerabilities as a material risk — which it will, for any business with a public website — controls like A.8.8 are effectively mandatory in practice.

Does ISO 27001 Require Penetration Testing?

ISO 27001 does not use the words "penetration testing" in its normative text. However, ISO 27002:2022 (the implementation guidance that accompanies the standard) states under A.8.8 that organisations should use penetration testing to assess the effectiveness of protective controls, detect known vulnerabilities, and test the robustness of information processing facilities. This is about as close to a mandate as implementation guidance gets.

In practice, ISO 27001 certification auditors will ask how you assess your exposure to technical vulnerabilities. Most UK businesses pursuing ISO 27001 certification conduct annual web penetration tests as a core part of their technical vulnerability management programme. The test report becomes evidence for the auditor that control A.8.8 is being actively discharged.

The Relationship Between ISO 27001 and UK GDPR

ISO 27001 and the UK GDPR are complementary but distinct. GDPR is the law; ISO 27001 is a framework. However, implementing ISO 27001 provides substantial evidence that you're meeting your GDPR obligations around data security.

Article 32 of the UK GDPR requires you to implement "appropriate technical and organisational measures" to ensure a level of security appropriate to the risk. The ICO has stated in its guidance that recognised standards like ISO 27001 can be used to demonstrate compliance with this requirement.

If you face an ICO investigation following a data breach, being ISO 27001 certified — and having current penetration test evidence — dramatically strengthens your position compared to an organisation that has no documented security programme.

Building Website Security into Your ISO 27001 ISMS

Scoping

Your ISMS scope defines what's included in the certification. If your website processes personal data, handles customer payments, or provides a customer portal, it should be within scope. Be careful about artificially narrowing the scope to exclude systems that are genuinely relevant to your information security risk — auditors are alert to this.

Risk Assessment

ISO 27001 requires a formal risk assessment methodology. For your website, this means identifying assets (customer data, payment systems, source code, credentials), identifying threats (SQL injection, brute force, session hijacking, data exfiltration), assessing likelihood and impact, and selecting controls to treat the risks.

A web penetration test feeds directly into this process — it provides empirical evidence of which threats are actually exploitable, rather than theoretical assessments. Read more about [web application security testing](/blog/web-application-security-testing-uk) to understand what a thorough assessment covers.

Evidence Collection

ISO 27001 auditors require evidence that your controls are operating effectively. For web security, this means:

- Penetration test reports (ideally with a retest confirming findings were remediated) - Vulnerability scan results and remediation tracking logs - Records of security patches applied to web infrastructure - Web application firewall configuration and alerting logs - SSL certificate management records

Keep these records organised and accessible. Auditors will ask for them.

Continuous Improvement

ISO 27001 is not a one-time certification. You must continuously monitor and improve your ISMS. For website security, this means scheduling regular penetration tests, monitoring for new vulnerabilities in the software your website uses, and reviewing your security controls whenever significant changes are made to your website or infrastructure.

ISO 27001 vs Cyber Essentials: What's the Difference?

UK businesses often ask whether they should pursue Cyber Essentials, ISO 27001, or both.

[Cyber Essentials](/blog/cyber-essentials-certification-uk) is a UK government-backed scheme focused on five specific technical controls: firewalls, secure configuration, access control, malware protection, and patch management. It's relatively quick and inexpensive to achieve, and it's often required for UK government contracts.

ISO 27001 is far more comprehensive. It covers governance, risk management, supplier security, business continuity, and the full range of information security controls. It takes longer and costs more to achieve, but it signals a much more mature security posture and is often required by large enterprise customers.

Many UK businesses start with Cyber Essentials for the government contract requirement and work toward ISO 27001 as their security programme matures. Web penetration testing is relevant to both pathways.

How Yrzo AI Supports Your ISO 27001 Programme

Regular penetration testing is a core component of any credible ISO 27001 ISMS. Yrzo AI provides automated web penetration testing that generates a formal, risk-rated PDF report — exactly the kind of documented evidence that satisfies Annex A.8.8 requirements and gives your ISO 27001 auditor confidence that your technical vulnerability management is active and effective.

Our reports include a clear scope statement, methodology description, risk-rated findings with evidence, and remediation guidance — everything your security team and auditor need for a complete picture of your web security posture.

[Start your web security scan at yrzoai.dev](https://yrzoai.dev) — whether you're pursuing ISO 27001, maintaining an existing certification, or simply building evidence of your security due diligence for customers and regulators.

Find out if your website has these vulnerabilities

Yrzo AI runs 44 automated security checks and delivers a full report in under 20 minutes. Starting from £399.

Scan your website →