Compliance & regulation
Formal proof from an approved outside body that an organisation's security meets a published standard such as ISO 27001.
Formal
A certificate issued by an officially approved certification body after an outside audit in two stages shows that an ISMS meets every requirement of ISO 27001; it runs for three years, kept alive by yearly follow-up audits. ISO 27002 is guidance only and cannot be certified against.
In plain English
Like a driving test - you may already drive carefully, but only the examiner's pass gives you a licence that strangers will trust.
In practice
Several municipalities require ISO 27001 certification in a tender for hosting their case systems, so a Danish hosting company books a certification body, passes both audit stages and attaches the certificate to its bid.
Why it matters
Customers cannot inspect every supplier themselves, so they rely on the certificate - but it proves that a working system exists, not that a breach cannot happen.