Skip to main content
RiskZeroCertifiers

ISO/IEC 27001:2022

ISO 27001, explained by the people who audit it

ISO/IEC 27001 is the international standard for managing information security. This page covers what it requires, what certification actually proves, and what to expect if you decide to pursue it.

Definition

What ISO 27001 is

ISO/IEC 27001 is a standard published jointly by the International Organization for Standardization and the International Electrotechnical Commission. It specifies the requirements for an information security management system, usually shortened to ISMS: the policies, processes, roles, and controls an organization uses to protect the confidentiality, integrity, and availability of its information.

The standard does not tell you which firewall to buy or how long passwords should be. It tells you to understand your risks, decide how to treat them, implement controls, check that they work, and improve. That risk-based approach is what makes it applicable to a ten-person startup and a global bank alike.

The current edition is ISO/IEC 27001:2022. It replaced the 2013 edition, and the transition period ended on 31 October 2025. All certificates are now issued against the 2022 edition.

Clauses 4 to 10

How the standard is structured

The mandatory requirements sit in seven clauses. They follow the harmonized structure shared by ISO 9001, ISO 14001, and ISO 22301, so organizations with other management systems will recognize the shape.

  1. Clause 4

    Context of the organization

    Who you are, who cares about your security, and what the ISMS covers.

  2. Clause 5

    Leadership

    Top management commitment, the security policy, and who is responsible for what.

  3. Clause 6

    Planning

    Risk assessment, risk treatment, the Statement of Applicability, and security objectives.

  4. Clause 7

    Support

    Resources, competence, awareness, communication, and control of documents.

  5. Clause 8

    Operation

    Running the processes, repeating the risk assessment, and implementing the treatment plan.

  6. Clause 9

    Performance evaluation

    Monitoring and measurement, internal audit, and management review.

  7. Clause 10

    Improvement

    Handling nonconformities, corrective action, and continual improvement.

Annex A

The 93 controls, in four themes

Annex A is a reference list of information security controls. Your risk assessment determines which apply. The 2022 edition reorganised the list from 14 domains into four themes and added 11 new controls.

37

Organizational controls

Policies, roles, supplier management, incident management, cloud services, threat intelligence, legal requirements.

8

People controls

Screening, terms of employment, awareness training, disciplinary process, remote working, confidentiality agreements.

14

Physical controls

Secure areas, entry controls, physical security monitoring, equipment, clear desk, secure disposal.

34

Technological controls

Access control, malware protection, logging and monitoring, backup, cryptography, secure development, configuration management.

For a control-by-control look at what changed, readthe 11 new controls in ISO/IEC 27001:2022.

Certification

What certification actually proves

Anyone can claim to follow ISO 27001. Certification means an independent, accredited certification body has audited the ISMS and confirmed it conforms to the standard. The audit has two stages, the decision is made by someone other than the auditor, and the certificate is valid for three years subject to annual surveillance.

A certificate proves that, on the dates audited, the organization had a management system that met the requirements and was operating effectively within the stated scope. It does not prove the organization is unbreachable, and a certification body that suggests otherwise should be treated with caution. It proves that security is managed, measured, and improved, which is what customers and regulators are actually asking about.

Accredited versus unaccredited

Certification bodies are themselves assessed by national accreditation bodies against ISO/IEC 17021-1 and ISO/IEC 27006-1. A certificate from an accredited body is recognized internationally through the International Accreditation Forum. Certificates from unaccredited providers are cheaper and are frequently rejected by procurement teams. Always check.

The full sequence, from application to recertification, is described on ourcertification process page.

Demand

Who needs it

The demand for ISO 27001 almost always comes from outside. Common triggers are:

  • An enterprise customer's security questionnaire that asks for the certificate.
  • A public sector tender that lists accredited certification as a qualifying requirement.
  • A bank, insurer, or payment partner running third-party due diligence.
  • Investors or acquirers assessing the maturity of the control environment.
  • A regulator that accepts certification as evidence of governance.

The sectors where we see the most demand are SaaS and cloud,fintech,healthcare technology,managed services,public sector supply, andprofessional services.

Planning

Time and cost

Building an ISMS takes most organizations three to nine months depending on their starting point. The certification audit itself takes eight to twelve weeks from contract to certificate for an audit-ready ISMS. Our article on how long certification takesbreaks this down.

Audit fees are calculated from the number of people and sites in scope and the complexity of the operation, following rules that all accredited bodies must apply. Our pricing page explains the factors that determine audit time and what a quote should include.

Questions

Common questions about the standard

Is ISO 27001 a legal requirement?
No. It is a voluntary standard. The requirement comes from customers, tenders, and sometimes regulators who accept it as evidence of good security governance. In practice, for suppliers to enterprises and the public sector, it is often a condition of doing business.
What is the difference between ISO 27001 and ISO 27002?
ISO 27001 is the requirements standard you certify against. ISO 27002 is a guidance document describing the Annex A controls in detail and how to implement them. You cannot be certified to ISO 27002, but auditors and implementers use it constantly.
Do we have to implement all 93 Annex A controls?
No. You must consider all of them and record in the Statement of Applicability which apply and why. Controls can be excluded with justification, for example physical security monitoring for an organization with no premises. What you cannot do is ignore a control without explaining why.
What is a Statement of Applicability?
A document listing every Annex A control with a statement of whether it applies, the justification, and whether it is implemented. It links your risk treatment decisions to the controls you operate and is one of the first things an auditor reads.
Can a small company be certified?
Yes. The standard scales. A ten-person company can have a lean, effective ISMS and an initial audit of a few days. Some of the cleanest ISMSs belong to small companies where everyone understands the whole system.

Ready to find out where you stand?

Not ready yet? SRG helps organizations build the ISMS and attests the package before it reaches us. If your package is ready, request a quote and we will reserve your dates.