2.26
confirmed standards on average
among the 620 ISO 27001 holders
1.18
for everyone else
the other 1033 companies
1.9x
the depth
ISO holders vs the rest
Average confirmed standards
How the two populations spread
How to read this
The causation runs both ways and we cannot separate them here: the controls ISO 27001 requires make further certifications cheap to add, and companies already investing in compliance are likelier to pursue ISO in the first place. Either way, the certificate is a reliable marker of a company that treats security as a programme rather than a checkbox.