ISO 27001 certification in Angola
ISO 27001 is the international standard for information security management systems. We prepare the controls; the audit is independent, conducted by DQS.

What ISO 27001 is
ISO 27001 requires identifying information assets, assessing risks, selecting controls, managing access, responding to incidents and ensuring continuity of critical operations.
How we prepare the certification
- 01ScopeServices, processes and locations covered.
- 02Risk assessmentAssets, threats, vulnerabilities and acceptance criteria.
- 03ControlsSelection of applicable controls and the statement of applicability.
- 04ImplementationAccess, logging, backups, suppliers, continuity.
- 05Evidence of operationIncidents, restore tests, access reviews.
- 06Internal audit and certificationInternal verification and a two-stage DQS audit.
Export Lab prepares. DQS certifies.
Certification is only meaningful when it is independent. That is why the roles are clearly separated: Export Lab provides consulting, implementation and preparation; the certification audit is conducted by DQS, a German certifier present in more than 60 countries, autonomously and impartially, under international accreditation rules.
The client gets the best of both worlds: preparation by people who master certifiers' methods, and a certificate issued by an independent, internationally recognised certification body.
The Angolan context
Banking, telecoms, services and infrastructure operators in Angola face growing information and personal data protection requirements from regulators and international partners.
Cost and timeline: what makes them vary
We do not publish list prices for ISO 27001, because the effort is not the same in two different organisations. The investment always has two separate components: preparation, delivered by Export Lab, and the certification audit, billed by the certification body.
What drives cost: ISMS scope (units, services and locations included), number of critical systems and suppliers, applicable Annex A controls, and the technical gaps identified — access management, logging and monitoring, backups, continuity and secure development.
What drives the timeline: Drivers are the information security risk assessment, closing technical gaps that depend on investment or third parties, and the time needed to evidence controls in operation (access records, restore tests, incident management).
After the initial assessment, scope, schedule and price are presented in writing, before any commitment.
What your company gains
- Critical information protected and access controlled.
- Client and regulator requirements met and demonstrable.
- Incident response tested, not improvised.
Frequently asked questions
- Who needs ISO 27001?
- Organisations handling sensitive data or critically dependent on systems: banking and financial services, telecoms, healthcare, technology, and suppliers assessed by international clients through security questionnaires.
- Is ISO 27001 mandatory in Angola?
- ISO 27001 is voluntary. Personal data protection obligations and sector regulator requirements exist independently of the standard; certification demonstrates that controls are implemented and third-party audited.
- How much does ISO 27001 certification cost?
- There is no list price. The figure follows from scope and starting point — specifically: ISMS scope (units, services and locations included), number of critical systems and suppliers, applicable Annex A controls, and the technical gaps identified — access management, logging and monitoring, backups, continuity and secure development. Preparation and the certification audit are billed separately, the latter by the certification body.
- How long does ISO 27001 implementation take?
- We do not quote fixed timelines before the assessment. Drivers are the information security risk assessment, closing technical gaps that depend on investment or third parties, and the time needed to evidence controls in operation (access records, restore tests, incident management). A realistic schedule is set out in the proposal.
- Who issues the certificate? Does Export Lab also certify?
- No. Export Lab prepares and implements; the ISO 27001 certification audit is conducted independently by DQS. Whoever prepares cannot certify, and that separation is what gives the certificate value with clients and regulators.
- What happens after certification?
- Three-year cycle with annual DQS audits. Risk reassessment, an up-to-date statement of applicability, continuity and restore testing, incident management and internal audit are kept live.
- Do we need to certify the whole company?
- No. The ISMS scope is defined by services, processes and locations, and it is common to start with the service clients assess. The scope is stated on the certificate, so it should match what you need to demonstrate commercially.
1 network specialist in this area
Independent network consultants specialising in Information Security and ISO 27001.