RMG Solutions
//
Guide

ISO 27001 Certification in Morocco: Complete 2026 Guide

ISO 27001 in Morocco 2026: detailed certification steps, costs in MAD, timelines, accredited bodies and BERD financing. Complete guide for Moroccan SMEs.

RMG SolutionsApril 30, 202613 min read

Why Moroccan Companies Are Pursuing ISO 27001 in 2026

In April 2025, the cyberattack against Morocco's CNSS exposed the personal data of nearly two million Moroccan employees (names, bank account numbers, salaries) and the records of 499,881 companies. The incident put information systems security back at the center of executive attention, well beyond the public sector.

That context is not incidental for ISO 27001 certification. One of the publicly drawn lessons from the breach: buying point cybersecurity services is not enough if the information security management system is not structured. That is exactly what ISO 27001 formalizes.

Today, only about 40 organizations are certified ISO 27001 in Morocco. That is low for a market this size. By comparison, Turkey has several thousand. The scarcity cuts both ways: it signals that adoption remains weak, but it also gives early movers a real competitive advantage.

Concrete Reasons Driving Certification

Moroccan companies starting an ISO 27001 program in 2026 rarely do so for philosophical reasons. The motivations are pragmatic:

Customer requirements. European and American multinationals increasingly require their subcontractors and service providers to hold ISO 27001 certification or an equivalent compliance attestation. For IT services, BPO, and nearshore companies based at Casanearshore, this has become a de facto prerequisite for accessing European clients.

Public and parapublic tenders. OCP, Renault Morocco, and several public institutions now include ISO 27001 certification or equivalent security requirements in their IT vendor specifications. Not being certified means being disqualified before even bidding.

DNSSI and Law 05-20 compliance. The DNSSI (National Information Systems Security Directive) is explicitly based on the Moroccan standard NM ISO/IEC 27002, which is the ISO 27001 control catalog. A well-run ISO 27001 project covers the vast majority of DNSSI requirements. For vital infrastructure operators subject to Law 05-20, it is the most direct path to regulatory compliance. See our detailed analysis in the DGSSI compliance guide for Morocco.

Personal data protection. Since February 2025, the CNDP has stepped up enforcement under Law 09-08. ISO 27001 is the most credible demonstration that an organization applies adequate security measures to protect the personal data it processes. For broader threat context, see our cybersecurity guide for Moroccan SMEs.

The differentiation effect. Being among the 40 certified organizations in Morocco places you in a select group. In a market where trust is a scarce asset, this signal carries real weight.


What ISO 27001 Certification Actually Requires

Before discussing process and cost, it is worth clarifying what the standard requires, and what it does not.

The ISMS: A Management System, Not a Checklist

ISO 27001 requires the implementation of an Information Security Management System (ISMS). The word "system" matters. It is not about installing an antivirus and writing an IT charter. An ISMS is a governance structure that covers:

  • Identification and classification of information assets (data, software, hardware, people)
  • Systematic risk assessment of those assets
  • Selection and implementation of appropriate protection measures
  • Continuous monitoring, measurement, and improvement of the whole

The standard also requires formal management commitment. This is not a stylistic clause: auditors verify concretely that the executive committee has approved the security policy, allocates resources, and participates in ISMS reviews.

The 93 Annex A Controls

The current version, ISO/IEC 27001:2022, includes 93 security controls grouped into 4 themes:

ThemeNumber of controlsExamples
Organizational controls37Security policy, asset management, information classification, supplier relationships
People controls8Background checks, awareness, termination responsibilities
Physical controls14Physical security perimeter, equipment protection, media security
Technological controls34Access control, encryption, logging, backup, vulnerability management

A point that is often misunderstood: you are not required to apply all 93 controls. The standard requires that you justify exclusions in a document called the Statement of Applicability (SoA). It is a strategic document that auditors examine carefully to verify the consistency between your risk analysis and your control choices.

What Auditors Actually Look For

Certification auditors are not chasing perfect policies on paper. They look for evidence that the system actually works: access logs that show rights are managed, management review records that exist and were acted on, internal audit results with corrective actions tracked.

The phrase that captures the expected mindset: simple and lived beats exhaustive and ignored.


The Certification Path: From Gap Analysis to Audit

The certification journey breaks into several phases. The durations below reflect an organization starting from scratch. Organizations with existing security maturity can compress some phases.

PhaseTypical durationDescription
Gap analysis2 to 4 weeksAssessment of the gap between current state and ISO 27001 requirements
Risk assessment3 to 4 weeksRisk identification, analysis, and treatment (ISO 27005 or EBIOS RM)
Documentation and policies4 to 8 weeksISMS policy drafting, procedures, SoA, risk treatment plan
Control implementation8 to 16 weeksTechnical and organizational rollout of selected controls
Internal audit2 to 3 weeksInternal verification before the certification audit
Stage 1 audit (documentary)1 to 2 daysDocument review by the certification body
Stage 1 non-conformity remediation2 to 4 weeksClosing gaps identified before the on-site audit
Stage 2 audit (on-site)3 to 5 daysFull on-site assessment by the certification body
Standard total6 to 12 months
Fast track total3 to 6 monthsPossible with existing security maturity and dedicated support

~40

Certified organizations in Morocco

6-12 months

Standard certification timeline

70%

BERD funding available

93

Annex A controls (ISO 27001:2022)

Typical ISO 27001 certification schedule (6-12 months)

Phase 1: The Gap Analysis

The gap analysis is the first concrete piece of work. It compares your current situation (existing policies, controls in place, actual practices) to the 93 Annex A controls and the requirements of clauses 4 to 10 of the standard.

The output is a dashboard that gives, for each requirement, a status (compliant, partially compliant, non-compliant) and a priority rating. This document drives the rest of the project.

A frequent mistake at this stage: assessing compliance based on existing documents rather than actual practice. A certification auditor will not just read your procedures. They will interview your teams to verify that the procedures are actually applied.

To kick off the gap analysis phase, our DGSSI compliance evaluator covers domains very close to ISO 27001 Annex A and gives a first overview in 5 minutes.

Phase 2: The Risk Assessment

The risk assessment is the methodological core of ISO 27001. Two methods are commonly used in Morocco:

  • ISO 27005: information security risk assessment method, recommended by the standard for direct alignment.
  • EBIOS Risk Manager: a method developed by the French ANSSI, widely adopted by Francophone consultants and compatible with ISO 27001.

The assessment must cover all assets within the ISMS scope, identify associated threats and vulnerabilities, and produce a Risk Treatment Plan (RTP) that justifies each treatment decision. Our risk assessment service draws on both methods depending on each organization's context.

Phase 3: Documentation and Policies

ISMS documentation must include at minimum:

  • The information security policy (approved by management)
  • The Statement of Applicability (SoA)
  • The Risk Treatment Plan (RTP)
  • Mandatory procedures (incident management, internal audit, non-conformities, corrective actions)
  • Evidence records (logs, reports, audit results)

The classic trap is producing copy-pasted policies from templates downloaded online. Experienced auditors recognize these templates immediately. If they do not match your organization's reality, that is a guaranteed major non-conformity.

Phase 4: Control Implementation

This is the longest phase. It covers very concrete actions: configuring access control rules, setting up an access rights review procedure, deploying a logging system, training teams on incident management, updating contracts with critical suppliers.

Continuous security event monitoring is part of the required technological controls. A security monitoring system in place before the Stage 2 audit is not only useful for compliance: it also provides the operational evidence auditors will request.

Phase 5: Internal Audit

ISO 27001 requires an internal ISMS audit. This audit cannot be performed by the people responsible for the audited areas. A minimum level of independence is required. For SMEs without a qualified internal auditor, calling on an external provider is the usual solution. Our security audit practice covers this step.

Phases 6 and 7: The Certification Audits

The Stage 1 audit is a documentary audit. The certification body's auditor reviews your documents (SoA, RTP, ISMS policy, internal audit results) to verify that the ISMS is sufficiently documented to move forward. It lasts 1 to 2 days depending on organization size.

The Stage 2 audit is the full on-site audit. The auditor interviews your teams, examines your operational evidence, and tests the reality of your ISMS. It lasts 3 to 5 days. At the end, they issue a report with findings classified as major non-conformities, minor non-conformities, and observations. Major non-conformities must be closed before the certificate is issued.


How Much Does ISO 27001 Certification Cost in Morocco

The question always comes up, and the honest answer is: "it depends." But here are real ballpark figures for the Moroccan market.

Certification Body Fees

These costs cover only the certification body's fees (Bureau Veritas, SGS, TÜV, IMANOR, etc.) for conducting Stage 1 and Stage 2 audits, and then annual surveillance audits. They do not cover advisory support.

Organization sizeInitial certification (Stage 1 + Stage 2)Annual surveillance audit
SME (under 50 employees)60,000 to 120,000 MAD30,000 to 50,000 MAD
Mid-size (50 to 250 employees)120,000 to 250,000 MAD50,000 to 80,000 MAD
Large organization (250+ employees)250,000 MAD and up80,000 MAD and up

Estimates based on Moroccan market data. Tariffs vary by certification body, certification scope, and activity complexity.

The ISO 27001 certificate is valid for 3 years. During that period, the certification body conducts an annual surveillance audit (years 1 and 2), then a full recertification audit in year 3.

Advisory Support Cost

Advisory support cost depends on your organization size, the chosen scope, and especially your existing security maturity. An organization that already has a security policy, an asset inventory, and properly configured access control tools needs much less work than one starting from scratch.

For that reason, we do not publish a fixed rate. Contact us for a free initial diagnostic that will allow us to estimate the work volume precisely.

BERD Financing: Up to 70% of Advisory Costs Subsidized

This is the point many Moroccan companies miss: the European Bank for Reconstruction and Development (EBRD/BERD) runs a support program for eligible Moroccan SMEs that can finance up to 70% of consulting fees, including for ISO 27001 certification projects.

The BERD Morocco program has been active since 2012 and has supported over 533 companies. Eligible Moroccan SMEs receive a direct subsidy on consultant fees, on the condition that they engage a provider listed in the BERD network.

This funding fundamentally changes the equation: a 200,000 MAD support project can come down to 60,000 MAD net of BERD subsidy. Our team can guide you through the application process and verify your eligibility during the initial diagnostic.

Need expert guidance?

Leave your details and an RMG Solutions expert will contact you within 24h.

Your data stays confidential

ISO 27001 and the DNSSI: How They Fit Together

The DNSSI (National Information Systems Security Directive, January 2023 version) is explicitly based on the Moroccan standard NM ISO/IEC 27002, which is the ISO 27001 control catalog. The mapping between the two frameworks is very close.

ISO 27001 / DNSSI Mapping

DNSSI domainMatching ISO 27001:2022 themeControls covered
Security policyOrganizational controlsA.5.1 Information security policies
Security organizationOrganizational controlsA.5.2 Roles and responsibilities
Asset managementOrganizational controlsA.5.9 to 5.12 Inventory and classification
HR securityPeople controlsA.6.1 to 6.8
Physical securityPhysical controlsA.7.1 to 7.14
Operations managementTechnological controlsA.8.1 to 8.12
Access controlTechnological controlsA.8.2 to 8.5
Incident managementOrganizational controlsA.5.24 to 5.28
Business continuityOrganizational controlsA.5.29 to 5.30
Legal complianceOrganizational controlsA.5.31 to 5.36

A well-run ISO 27001 project meets the vast majority of DNSSI requirements. In practice, if you are subject to both the DNSSI (because you are a public institution, vital infrastructure, or digital operator) and want ISO 27001 certification, the two efforts share 80 to 85% of their work.

What the DNSSI Adds Beyond ISO 27001

DGSSI compliance has Moroccan specifics that ISO 27001 does not automatically cover:

  • The classification of information systems into Class A, B, or C defined jointly with the DGSSI
  • Mandatory homologation before deploying any sensitive information system (Class A)
  • Incident notification to maCERT within regulatory deadlines
  • Mandatory use of PASSI providers qualified by the DGSSI for sensitive system audits

The optimal strategy for organizations subject to both frameworks: use the ISO 27001 project as the foundation of the DGSSI compliance program, then layer on the Moroccan specifics. This approach avoids duplicating documentation effort and reduces the global cost of running both projects separately.

Our regulatory compliance service integrates these Moroccan specifics into every ISO 27001 program we run.


How to Choose Your Certification Body

Choosing the certification body is a decision worth thinking through. Every accredited body issues an internationally valid ISO 27001 certificate, but they differ on several dimensions.

Main Bodies Active in Morocco

BodyOriginStrengthsConsiderations
IMANORMorocco (national)National body, potentially lower fees, NM ISO/IEC 27001 certificationMore limited international network
Bureau VeritasFranceStrong international recognition, accepted by European clients, established local presencePricing aligned with international standards
SGSSwitzerlandGlobal network, strong recognition in industrial and agro-food sectorsLess specialized in cybersecurity
TÜV RheinlandGermanyExcellent recognition in Germany and Central Europe, strong in technology sectorsLess dense local presence in Morocco
VigicertMoroccoLocal actor with regional expertise, COFRAC-accreditedInternational recognition lower than the global groups
DNVNorwayStrong in energy, maritime, and industrial sectorsLess present in the Moroccan market

Selection Criteria

Recognition by your target customers. If your main goal is European market access, a Bureau Veritas or TÜV Rheinland certificate will generally be better recognized by European clients than a body unknown outside Morocco. If your goal is DGSSI compliance or Moroccan public-sector tenders, IMANOR is perfectly suitable.

Accreditation. Verify that the body is accredited by an IAF (International Accreditation Forum) member. In France, that is COFRAC. In Morocco, it is SEMAC. A certificate issued by a non-accredited body has no legal value.

Independence. It is strongly advised not to choose the same body for advisory support and certification. The ISO 27006 standard governs this independence, and good certification bodies refuse to audit systems they helped build. Choose your consultant and your certifier separately.

Availability and lead time. Auditor calendars can be packed. Schedule your Stage 2 audit at least 2 to 3 months in advance.


Mistakes That Make Certifications Fail

Across projects that do not succeed, or that succeed with heavy non-conformities, five mistakes recur.

Mistake 1: No Real Management Commitment

This is the number one cause of failure, no contest. ISO 27001 formally requires that management "demonstrate leadership and commitment toward the ISMS" (clause 5.1 of the standard). In practice, that means the CISO or security project lead cannot carry this project alone. If the CEO has not approved the security policy, does not participate in management reviews, and cannot explain ISMS stakes when asked by the auditor, that is a major non-conformity.

The fix: involve management from the gap analysis phase, with a presentation of business stakes (not technical details) and a documented formal commitment.

Mistake 2: Copy-Pasted Templates

Many organizations download ISO 27001 policy templates from the internet and adapt them minimally. Experienced auditors recognize these documents within minutes. Worse: if a control on your SoA says "applicable" but the corresponding policy does not describe how it applies to your specific context, that is a non-conformity.

Every document must reflect your organization's reality: your real assets, your real risks, your real procedures. A 3-page document matching your actual operations beats a 50-page copy-paste manual.

Mistake 3: A Scope That Is Too Wide

Certifying "the entire company" all at once is a frequent mistake, especially for first certifications. The wider the scope, the more complex, costly, and risky the project.

The recommended strategy: start by certifying a limited but meaningful scope, for example the IT department, the "software development" division, or the data center. Once the ISMS is running smoothly on that scope, extending to other activities is much smoother.

Mistake 4: Neglecting Operational Evidence

ISO 27001 requires not only that controls be in place, but also that their application be proven. If your access rights review procedure calls for a quarterly review, the auditor will ask to see the last 4 reports. If they do not exist, that is a non-conformity, even if the review actually happened but was not documented.

Start building operational evidence at the start of the implementation phase, not 3 weeks before the audit.

Mistake 5: Neglecting Post-Certification Surveillance

The ISO 27001 certificate is valid for 3 years, but surveillance audits happen every year. Some organizations earn their certificate then relax their effort, assuming the annual auditor will be lenient. They are not. If the ISMS has degraded since initial certification (no more management reviews, untracked incidents, unreviewed access rights), the surveillance auditor can suspend or withdraw the certificate.

Continuous surveillance is part of the ISMS. Operational maintenance of the ISMS between annual audits matters as much as initial certification.


The RMG Solutions Approach

From initial audit to certification, with one provider. Most GRC firms stop at advisory: they assess your maturity, write a report, and leave you to implement controls with other providers. RMG Solutions runs the full ISO 27001 certification journey end-to-end: gap analysis, ISMS construction, drafting policies that reflect your reality, deployment of technical controls (logging, access control, encryption), preparation for internal audit, and coordination with the certification body for Stage 1 and Stage 2 audits. We can implement technical controls ourselves because we are also a cybersecurity provider and an infrastructure provider: the SIEM, monitoring, and access management are not subcontracted to a third party. For organizations subject to Law 05-20, our program integrates DNSSI specifics from day one (A/B/C classification, maCERT notification, PASSI preparation) into the same project. Based in Hay Riad (Rabat), we are on-site for every critical phase.

Contact us for a free 30-minute initial assessment.


Frequently Asked Questions

Is ISO 27001 certification mandatory in Morocco?

No, ISO 27001 is not legally imposed as a general obligation on private Moroccan companies. However, Law 05-20 imposes an information systems security framework on public administrations, public institutions, and vital infrastructure operators. ISO 27001 is the recognized mechanism for meeting these requirements. Beyond that, in some sectors (IT, BPO, nearshore, suppliers to OCP or Renault Morocco), certification has become a de facto contractual condition.

How long does ISO 27001 certification take in Morocco?

The standard timeline is between 6 and 12 months, from gap analysis to certificate issuance. A 3-to-6-month fast track is possible for organizations that already have existing security maturity: a formalized security policy, access control tools in place, documented incident management practices. Organizations starting from scratch need the full timeline. The limiting factor is often control implementation and operational evidence buildup.

Does ISO 27001 certification help with DGSSI compliance?

Yes, substantially. The DNSSI is directly inspired by ISO/IEC 27002, the ISO 27001 control catalog. A well-run ISO 27001 project covers 80 to 85% of DNSSI requirements. The elements ISO 27001 does not automatically cover are A/B/C classification of information systems per DGSSI nomenclature, mandatory homologation of sensitive systems, and incident notification to maCERT. These additions layer onto an existing ISO 27001 ISMS without difficulty.

Can a 30-person SME get ISO 27001 certified?

Yes, without reservation. The standard does not set a minimum size threshold. SMEs of 10 to 15 people are ISO 27001 certified in France, Belgium, and other Francophone countries. The key is to define an appropriate scope (software development activities or managed services, rather than "the entire company") and to keep documentation proportional to actual organization size. For a 30-person SME, the project is entirely manageable in 6 to 9 months with appropriate support. BERD financing, which covers up to 70% of consulting costs for eligible SMEs, makes the project financially accessible.

What happens after certification is awarded?

The ISO 27001 certificate is valid for 3 years, but surveillance audits are conducted every year (typically at 12 and 24 months). These audits verify that the ISMS continues to function and improve. At the end of year 3, a full recertification audit is required to maintain certification. Between audits, the organization must maintain its ISMS practices: regular management reviews, incident management, access rights review, annual internal audits. A well-structured ISMS from the start makes this maintenance relatively light.

By RMG Solutions

Certified Odoo Partner | Cybersecurity | Infrastructure | GRC

Last updated : April 30, 2026

Compliance & Certification

ISO 27001, DGSSI, Law 09-08, we guide you toward regulatory compliance.