Five common myths when SMEs adopt ISO 27001
- Myth 1: Buying a document template equals implementation. Templates are only a starting point; the system must fit how your organization actually operates.
- Myth 2: Security is only the IT department's job. ISO 27001 is a management system requiring leadership commitment and cross-department involvement.
- Myth 3: The bigger the scope, the better. For a first implementation, focus on core business and key assets.
- Myth 4: Certification is one-and-done. Annual surveillance audits and three-yearly re-certification apply; the system needs continual improvement (PDCA).
- Myth 5: Skipping risk assessment. Risk assessment is the core of ISO 27001; skipping it wastes effort on the wrong controls.
ISO 27001:2022 — key changes and transition
- Annex A restructured. Controls streamlined from 114 to 93 across four themes (organizational, people, physical, technological), adding modern controls such as cloud services, threat intelligence, DLP and secure coding.
- Clause refinements. Structure aligned with other ISO management-system standards.
- Transition timeline. Organizations holding 2013 certificates must transition within the defined period. Plan gap analysis and Statement of Applicability updates early.
What is CMMC 2.0, and how should Taiwan suppliers prepare?
CMMC (Cybersecurity Maturity Model Certification) is a US DoD requirement for its supply chain. The rules are now in force: the program rule (32 CFR) took effect in December 2024 and the acquisition rule (48 CFR / DFARS) on 10 November 2025, with a four-phase rollout through 2028.
CMMC 2.0 has three levels: Level 1 (Foundational, annual self-assessment), Level 2 (Advanced, aligned with NIST SP 800-171, some require third-party assessment) and Level 3 (Expert, aligned with NIST SP 800-172, government-led). Taiwan suppliers should confirm the required level, scope their CUI/FCI data flows, run a NIST SP 800-171 gap analysis and invest early. IngSafe partners with a US-based RPO to help.
For more explainer videos on security and certification, subscribe to the IngSafe YouTube channel.
Want to know which approach fits your organization? Contact us.