ISO/IEC 27001:2022
ISO 27001, explained by the people who audit it
ISO/IEC 27001 is the international standard for managing information security. This page covers what it requires, what certification actually proves, and what to expect if you decide to pursue it.
Definition
What ISO 27001 is
ISO/IEC 27001 is a standard published jointly by the International Organization for Standardization and the International Electrotechnical Commission. It specifies the requirements for an information security management system, usually shortened to ISMS: the policies, processes, roles, and controls an organization uses to protect the confidentiality, integrity, and availability of its information.
The standard does not tell you which firewall to buy or how long passwords should be. It tells you to understand your risks, decide how to treat them, implement controls, check that they work, and improve. That risk-based approach is what makes it applicable to a ten-person startup and a global bank alike.
The current edition is ISO/IEC 27001:2022. It replaced the 2013 edition, and the transition period ended on 31 October 2025. All certificates are now issued against the 2022 edition.
Clauses 4 to 10
How the standard is structured
The mandatory requirements sit in seven clauses. They follow the harmonized structure shared by ISO 9001, ISO 14001, and ISO 22301, so organizations with other management systems will recognize the shape.
- Clause 4
Context of the organization
Who you are, who cares about your security, and what the ISMS covers.
- Clause 5
Leadership
Top management commitment, the security policy, and who is responsible for what.
- Clause 6
Planning
Risk assessment, risk treatment, the Statement of Applicability, and security objectives.
- Clause 7
Support
Resources, competence, awareness, communication, and control of documents.
- Clause 8
Operation
Running the processes, repeating the risk assessment, and implementing the treatment plan.
- Clause 9
Performance evaluation
Monitoring and measurement, internal audit, and management review.
- Clause 10
Improvement
Handling nonconformities, corrective action, and continual improvement.
Annex A
The 93 controls, in four themes
Annex A is a reference list of information security controls. Your risk assessment determines which apply. The 2022 edition reorganised the list from 14 domains into four themes and added 11 new controls.
37
Organizational controls
Policies, roles, supplier management, incident management, cloud services, threat intelligence, legal requirements.
8
People controls
Screening, terms of employment, awareness training, disciplinary process, remote working, confidentiality agreements.
14
Physical controls
Secure areas, entry controls, physical security monitoring, equipment, clear desk, secure disposal.
34
Technological controls
Access control, malware protection, logging and monitoring, backup, cryptography, secure development, configuration management.
For a control-by-control look at what changed, readthe 11 new controls in ISO/IEC 27001:2022.
Certification
What certification actually proves
Anyone can claim to follow ISO 27001. Certification means an independent, accredited certification body has audited the ISMS and confirmed it conforms to the standard. The audit has two stages, the decision is made by someone other than the auditor, and the certificate is valid for three years subject to annual surveillance.
A certificate proves that, on the dates audited, the organization had a management system that met the requirements and was operating effectively within the stated scope. It does not prove the organization is unbreachable, and a certification body that suggests otherwise should be treated with caution. It proves that security is managed, measured, and improved, which is what customers and regulators are actually asking about.
Accredited versus unaccredited
Certification bodies are themselves assessed by national accreditation bodies against ISO/IEC 17021-1 and ISO/IEC 27006-1. A certificate from an accredited body is recognized internationally through the International Accreditation Forum. Certificates from unaccredited providers are cheaper and are frequently rejected by procurement teams. Always check.
The full sequence, from application to recertification, is described on ourcertification process page.
Demand
Who needs it
The demand for ISO 27001 almost always comes from outside. Common triggers are:
- An enterprise customer's security questionnaire that asks for the certificate.
- A public sector tender that lists accredited certification as a qualifying requirement.
- A bank, insurer, or payment partner running third-party due diligence.
- Investors or acquirers assessing the maturity of the control environment.
- A regulator that accepts certification as evidence of governance.
The sectors where we see the most demand are SaaS and cloud,fintech,healthcare technology,managed services,public sector supply, andprofessional services.
Planning
Time and cost
Building an ISMS takes most organizations three to nine months depending on their starting point. The certification audit itself takes eight to twelve weeks from contract to certificate for an audit-ready ISMS. Our article on how long certification takesbreaks this down.
Audit fees are calculated from the number of people and sites in scope and the complexity of the operation, following rules that all accredited bodies must apply. Our pricing page explains the factors that determine audit time and what a quote should include.
Questions
Common questions about the standard
Is ISO 27001 a legal requirement?
What is the difference between ISO 27001 and ISO 27002?
Do we have to implement all 93 Annex A controls?
What is a Statement of Applicability?
Can a small company be certified?
Ready to find out where you stand?
Not ready yet? SRG helps organizations build the ISMS and attests the package before it reaches us. If your package is ready, request a quote and we will reserve your dates.