ISO 27001:2022 Explained: ISMS Certification Guide
ISO 27001:2022 is the global ISMS standard with 93 Annex A controls. Learn the certification process, what auditors check, and get a readiness checklist.
Introduction
Over 70,000 organizations in more than 150 countries hold ISO/IEC 27001 certification — and that number grows by roughly 20% annually. For a voluntary standard, its adoption rate reflects a market reality: in Europe, the Middle East, Asia-Pacific, and an increasing number of US government and financial sector supply chains, ISO 27001 certification is the de facto entry requirement for enterprise contracts.
ISO 27001 is not a checklist. It is a management system standard — which means the auditor is not just checking whether you have a firewall. They are checking whether your organization has a functioning process for continuously identifying risks, selecting controls, implementing them, measuring their effectiveness, and improving. An organization with impeccable technical controls but no documented risk management process will fail the certification audit.
The 2022 revision — ISO/IEC 27001:2022 — reduced the 2013 edition’s 114 controls to 93, restructured around 4 themes, and added 11 new controls explicitly addressing cloud security, threat intelligence, and secure software development. Organizations certified under the 2013 edition were required to transition to the 2022 edition by October 31, 2025. Any organization still operating under a 2013-edition certificate after that date is in violation of the standard’s transition requirements.
This article explains the ISMS structure, what the certification audit covers, and what your team must prepare.
What Is ISO 27001?
ISO/IEC 27001:2022 specifies requirements for establishing, implementing, maintaining, and continually improving an Information Security Management System (ISMS). Published jointly by the International Organization for Standardization (ISO) and the International Electrotechnical Commission (IEC), it is the only certifiable international information security management standard.
Scope: ISO 27001 applies to all types and sizes of organizations — commercial, governmental, and non-profit — regardless of industry. Unlike PCI DSS (payment), HIPAA (healthcare), or automotive frameworks like TISAX, ISO 27001 is sector-neutral.
Structure: ISO 27001:2022 follows the ISO High Level Structure (HLS) — the same 10-clause framework used by ISO 9001 (quality), ISO 14001 (environment), and ISO 22301 (business continuity). This harmonized structure makes integrated management systems (IMS) combining multiple ISO standards operationally manageable.
Normative references: ISO 27001 must be read alongside ISO/IEC 27002:2022, which provides implementation guidance for each of the 93 Annex A controls. ISO/IEC 27005:2022 governs the risk management methodology.
Certification: Issued by accredited third-party certification bodies (CBs) — not by ISO itself. The CB conducts Stage 1 (documentation review) and Stage 2 (implementation audit) assessments. Certificates are valid for 3 years, subject to annual surveillance audits. Non-conformities found during surveillance can result in certificate suspension or withdrawal.
How ISO 27001 Works
The ISMS Lifecycle (Clauses 4–10)
ISO 27001:2022’s requirements are in Clauses 4 through 10. Annex A contains the reference control set. Here is what each clause requires:
Clause 4 — Context: Define the ISMS scope. Document which parts of the organization, which locations, which processes, and which assets are within scope. Identify internal and external factors that affect information security. Document the needs and expectations of interested parties (customers, regulators, supply chain partners).
Clause 5 — Leadership: Top management must demonstrate leadership and commitment — not delegate it. This means signing the information security policy, ensuring resources are available, and participating in management reviews. Auditors interview C-level executives and board members to verify genuine leadership involvement.
Clause 6 — Planning: Conduct an information security risk assessment following a documented methodology (ISO/IEC 27005:2022 provides the framework). Identify risks, assign ownership, evaluate likelihood and impact, select risk treatment options (accept, mitigate, transfer, avoid), and produce a risk treatment plan. Produce the Statement of Applicability (SoA) covering all 93 Annex A controls.
Clause 7 — Support: Ensure the organization has competent people, adequate resources, and appropriate communication. Document all competence records (training, qualifications) for roles with information security responsibilities.
Clause 8 — Operation: Implement the risk treatment plan. Execute the controls selected in the SoA. Manage operational risks. Control changes to the ISMS.
Clause 9 — Performance Evaluation: Measure, monitor, and evaluate the ISMS. Conduct internal audits at planned intervals. Conduct management reviews. Define what is measured and how.
Clause 10 — Improvement: Address nonconformities with corrective actions. Continually improve the ISMS based on audit findings, incident analysis, and management review outputs.
The 93 Annex A Controls (ISO/IEC 27002:2022)
Annex A groups 93 controls into 4 themes:
Organizational Controls (37 controls — 5.1–5.37): Policies, roles, asset management, supplier relationships, incident management, business continuity, compliance. Key controls include: threat intelligence (5.7 — new in 2022), cloud services security (5.23 — new), information classification (5.12), and contact with authorities (5.5).
People Controls (8 controls — 6.1–6.8): Screening, terms and conditions of employment, awareness, training, and disciplinary process. All staff with information security responsibilities must be competent — competence records are a standard evidence request.
Physical Controls (14 controls — 7.1–7.14): Physical perimeter, entry controls, clear desk and clear screen, equipment maintenance, and physical media transfer. Secure disposal of media (7.14) directly references NIST SP 800-88 methods.
Technological Controls (34 controls — 8.1–8.34): Access rights management, encryption (8.24), key management (8.24), network security (8.20), secure development (8.25–8.29), web filtering (8.23 — new), data masking (8.11 — new), and vulnerability management (8.8).
ISO 27001 Certification Readiness Checklist
Use this checklist to assess readiness before engaging a certification body. Items in Clauses 4–10 are normative requirements — failure produces a nonconformity. Annex A items must be either implemented or justified as not applicable in the SoA.
Clause 4 — Context
- ISMS scope document: defines organizational boundaries, locations, technologies, and exclusions
- Context analysis: internal factors (culture, resources, maturity) and external factors (regulatory, market, supply chain) documented
- Interested parties register: lists requirements of regulators, customers, shareholders, and employees relevant to information security
Clause 5 — Leadership
- Information Security Policy signed by top management, communicated to all staff
- Information security roles and responsibilities assigned and documented
- Evidence of management involvement: meeting minutes, risk review attendance, resource allocation decisions
Clause 6 — Planning
- Risk assessment methodology documented (scope, criteria, methodology, risk owner assignment)
- Risk register: all identified risks documented with likelihood, impact, risk owner, and risk level
- Risk treatment plan: for each accepted mitigation, the specific Annex A control selected and responsible person named
- Statement of Applicability (SoA): all 93 Annex A controls listed with applicability decision and justification for each — CRITICAL document
- Residual risk accepted by management: formal sign-off on treated risk levels
Clause 7 — Support
- Competence records: training certificates, qualifications, or experience evidence for all IS roles
- Security awareness training: documented for all staff, with attendance records
- Communication plan: who communicates what, to whom, and how often regarding ISMS matters
Clause 8 — Operation
- Risk treatment controls implemented as specified in the risk treatment plan
- Change management: procedure for controlling changes that could affect ISMS
- Supplier security: contracts with key suppliers include information security requirements
Clause 9 — Performance Evaluation
- Internal audit program: documented plan with scheduled intervals; completed internal audit reports
- Management review: documented review with input (audit results, incidents, risks, objectives) and output (decisions, resource allocation)
- KPIs or metrics: defined measures of ISMS effectiveness (not just counting controls — measuring whether they work)
Clause 10 — Improvement
- Nonconformity and corrective action log: tracks findings, root cause analysis, corrective actions, and effectiveness review
- Continual improvement records: demonstrates ISMS has evolved based on findings and feedback
Critical Annex A Technological Controls (Clause 8 reference)
- 8.2 Privileged access rights: documented process for granting, reviewing, and revoking privileged access
- 8.5 Secure authentication: MFA implemented for all privileged access and remote access
- 8.8 Management of technical vulnerabilities: documented vulnerability scanning and patch management process
- 8.12 Data leakage prevention: controls to detect and prevent unauthorized exfiltration of sensitive data
- 8.24 Use of cryptography: documented encryption policy specifying algorithms, key lengths, and key management procedures
- 8.25–8.29 Secure development: secure coding standards, security testing in CI/CD, vulnerability scanning of code
- 8.34 Protection of information systems during audit testing: controls to prevent audit activities disrupting production
Evidence Most Commonly Requested in Stage 2 Audits
- SoA version matching the audit date — auditors compare SoA to implemented controls
- Risk register with treatment status for all High and Critical risks
- Last 3 internal audit reports with nonconformity findings and corrective actions
- Last management review minutes with evidence of top management attendance
- Sample evidence for 5–10 Annex A controls (logs, screenshots, config exports, training records)
ISO 27001 vs SOC 2
| Dimension | ISO/IEC 27001:2022 | SOC 2 (AICPA TSC 2017) |
|---|---|---|
| Type | International standard with third-party certification | US attestation with CPA firm report |
| Output | Certificate (3-year validity) | Type I or Type II report |
| Scope | Entire organization (defined ISMS scope) | Specific service system |
| Geography | Global — Europe, APAC, Middle East, government | Dominant in US enterprise SaaS |
| Controls | 93 Annex A controls | 5 Trust Services Categories (CC, A, PI, C, P) |
| Risk management | Normative requirement (Clauses 6–8) | Not explicitly required |
| Audit body | ISO-accredited certification body | Any licensed CPA firm |
| Cost | USD 5,000–USD 50,000+ depending on scope | USD 30,000–USD 100,000+ for Type II |
| Renewal | 3-year certificate + annual surveillance | New report each audit period |
Many organizations pursue both certifications because they address different audience requirements. ISO 27001 satisfies European and government procurement requirements; SOC 2 Type II satisfies US enterprise buyers. The ISMS established for ISO 27001 significantly reduces the effort of achieving SOC 2, since both require risk assessment, access controls, encryption, incident response, and audit logging.
Real-World Use Cases
Cloud service providers: A cloud storage vendor serving European enterprise customers is often required to hold ISO 27001 certification as a supplier qualification. The customer’s procurement team requests the certificate and the SoA to verify the scope covers the cloud infrastructure used for the customer’s data. A certificate scoped to the vendor’s headquarters office but not its data centers is insufficient.
Financial services: A fintech company providing payment processing infrastructure to banks must hold ISO 27001 as a condition of their supplier contracts with financial institutions. The bank’s third-party risk management process requires annual evidence of certification maintenance, including the most recent surveillance audit report.
NIS2 Directive compliance: The EU NIS2 Directive (Directive 2022/2555) requires “essential entities” — operators of critical infrastructure — to implement cybersecurity risk management measures. ISO 27001 is explicitly recognized as a framework for satisfying NIS2’s technical and organizational requirements. Organizations subject to NIS2 are increasingly treating ISO 27001 certification as the path to demonstrating compliance.
Common Mistakes to Avoid
Treating the SoA as a formality. The Statement of Applicability is the most important document in your ISO 27001 program. Auditors cross-reference it against evidence collected during the Stage 2 audit. If the SoA says control 8.24 (cryptography) is applicable and implemented, the auditor will ask for evidence: the encryption policy, key management procedures, and a sample of implemented controls. A SoA where every control is marked “applicable” without genuine implementation is a fast path to major nonconformities.
No management engagement. ISO 27001 Clause 5 is explicit: top management must demonstrate leadership and commitment. Many organizations treat ISO 27001 as an IT project. When the Stage 2 auditor requests a management review meeting and finds that the CISO attended alone while the CEO and CTO delegated attendance, this is evidence of insufficient leadership — a potential nonconformity under Clause 5.1.
Static risk assessment. Risk assessments age. New systems, new threat actors, new attack techniques, and new regulatory requirements all change the risk landscape. An organization that conducted a thorough risk assessment in Year 1 and has not updated it since is in violation of Clause 8.2 (information security risk assessment) and Clause 10.2 (continual improvement). The risk register must be a living document reviewed at least annually and whenever significant changes occur.
Getting Started
Start by defining your ISMS scope. Be specific: which business units, which locations, which IT systems, and which data assets are within scope. A narrower, well-defined scope is easier to certify and audit than a vague enterprise-wide scope. Many organizations start with a specific product or service and expand later.
Conduct a gap analysis against ISO 27001:2022. For each of the 10 clauses and 93 Annex A controls, document your current state. Identify which clauses are missing documentation, which controls are partially implemented, and which have no implementation at all. This gap analysis becomes the foundation of your project plan.
Assign a project owner — an Information Security Manager or CISO equivalent — with executive sponsorship. Book a provisional Stage 1 audit date with a certification body 6 to 9 months out. Working backward from that date gives you a project timeline.
For the cryptographic controls required under Annex A 8.24, see AES-256-GCM explained: authenticated encryption without the jargon. For understanding how ISO 27001 key management requirements translate to cloud infrastructure, read key management services: AWS KMS, Azure Key Vault, GCP KMS.
FAQ
Common questions — answered in plain English.
What is ISO 27001?
What is the difference between ISO 27001 and SOC 2?
How long does ISO 27001 certification take?
What are the Annex A controls in ISO 27001:2022?
What is the Statement of Applicability in ISO 27001?
What are the penalties for ISO 27001 non-compliance?
References
- [1]
- [2]
- [3]
- [4]
- [5]NIST Cybersecurity Framework 2.0NIST, 2024