Compliance

ISO 27001:2022 Explained: ISMS Certification Guide

ISO 27001:2022 is the global ISMS standard with 93 Annex A controls. Learn the certification process, what auditors check, and get a readiness checklist.

Editorial Team ·
13 min read intermediate

Introduction

Over 70,000 organizations in more than 150 countries hold ISO/IEC 27001 certification — and that number grows by roughly 20% annually. For a voluntary standard, its adoption rate reflects a market reality: in Europe, the Middle East, Asia-Pacific, and an increasing number of US government and financial sector supply chains, ISO 27001 certification is the de facto entry requirement for enterprise contracts.

ISO 27001 is not a checklist. It is a management system standard — which means the auditor is not just checking whether you have a firewall. They are checking whether your organization has a functioning process for continuously identifying risks, selecting controls, implementing them, measuring their effectiveness, and improving. An organization with impeccable technical controls but no documented risk management process will fail the certification audit.

The 2022 revision — ISO/IEC 27001:2022 — reduced the 2013 edition’s 114 controls to 93, restructured around 4 themes, and added 11 new controls explicitly addressing cloud security, threat intelligence, and secure software development. Organizations certified under the 2013 edition were required to transition to the 2022 edition by October 31, 2025. Any organization still operating under a 2013-edition certificate after that date is in violation of the standard’s transition requirements.

This article explains the ISMS structure, what the certification audit covers, and what your team must prepare.

What Is ISO 27001?

ISO/IEC 27001:2022 specifies requirements for establishing, implementing, maintaining, and continually improving an Information Security Management System (ISMS). Published jointly by the International Organization for Standardization (ISO) and the International Electrotechnical Commission (IEC), it is the only certifiable international information security management standard.

Scope: ISO 27001 applies to all types and sizes of organizations — commercial, governmental, and non-profit — regardless of industry. Unlike PCI DSS (payment), HIPAA (healthcare), or automotive frameworks like TISAX, ISO 27001 is sector-neutral.

Structure: ISO 27001:2022 follows the ISO High Level Structure (HLS) — the same 10-clause framework used by ISO 9001 (quality), ISO 14001 (environment), and ISO 22301 (business continuity). This harmonized structure makes integrated management systems (IMS) combining multiple ISO standards operationally manageable.

Normative references: ISO 27001 must be read alongside ISO/IEC 27002:2022, which provides implementation guidance for each of the 93 Annex A controls. ISO/IEC 27005:2022 governs the risk management methodology.

Certification: Issued by accredited third-party certification bodies (CBs) — not by ISO itself. The CB conducts Stage 1 (documentation review) and Stage 2 (implementation audit) assessments. Certificates are valid for 3 years, subject to annual surveillance audits. Non-conformities found during surveillance can result in certificate suspension or withdrawal.

How ISO 27001 Works

The ISMS Lifecycle (Clauses 4–10)

ISO 27001:2022’s requirements are in Clauses 4 through 10. Annex A contains the reference control set. Here is what each clause requires:

Clause 4 — Context: Define the ISMS scope. Document which parts of the organization, which locations, which processes, and which assets are within scope. Identify internal and external factors that affect information security. Document the needs and expectations of interested parties (customers, regulators, supply chain partners).

Clause 5 — Leadership: Top management must demonstrate leadership and commitment — not delegate it. This means signing the information security policy, ensuring resources are available, and participating in management reviews. Auditors interview C-level executives and board members to verify genuine leadership involvement.

Clause 6 — Planning: Conduct an information security risk assessment following a documented methodology (ISO/IEC 27005:2022 provides the framework). Identify risks, assign ownership, evaluate likelihood and impact, select risk treatment options (accept, mitigate, transfer, avoid), and produce a risk treatment plan. Produce the Statement of Applicability (SoA) covering all 93 Annex A controls.

Clause 7 — Support: Ensure the organization has competent people, adequate resources, and appropriate communication. Document all competence records (training, qualifications) for roles with information security responsibilities.

Clause 8 — Operation: Implement the risk treatment plan. Execute the controls selected in the SoA. Manage operational risks. Control changes to the ISMS.

Clause 9 — Performance Evaluation: Measure, monitor, and evaluate the ISMS. Conduct internal audits at planned intervals. Conduct management reviews. Define what is measured and how.

Clause 10 — Improvement: Address nonconformities with corrective actions. Continually improve the ISMS based on audit findings, incident analysis, and management review outputs.

The 93 Annex A Controls (ISO/IEC 27002:2022)

Annex A groups 93 controls into 4 themes:

Organizational Controls (37 controls — 5.1–5.37): Policies, roles, asset management, supplier relationships, incident management, business continuity, compliance. Key controls include: threat intelligence (5.7 — new in 2022), cloud services security (5.23 — new), information classification (5.12), and contact with authorities (5.5).

People Controls (8 controls — 6.1–6.8): Screening, terms and conditions of employment, awareness, training, and disciplinary process. All staff with information security responsibilities must be competent — competence records are a standard evidence request.

Physical Controls (14 controls — 7.1–7.14): Physical perimeter, entry controls, clear desk and clear screen, equipment maintenance, and physical media transfer. Secure disposal of media (7.14) directly references NIST SP 800-88 methods.

Technological Controls (34 controls — 8.1–8.34): Access rights management, encryption (8.24), key management (8.24), network security (8.20), secure development (8.25–8.29), web filtering (8.23 — new), data masking (8.11 — new), and vulnerability management (8.8).

This video explains ISO 27001's ISMS structure and the certification process. Pay particular attention to the risk assessment and Statement of Applicability sections — these are the most commonly cited nonconformity areas in Stage 2 audits.

ISO 27001 Certification Readiness Checklist

Use this checklist to assess readiness before engaging a certification body. Items in Clauses 4–10 are normative requirements — failure produces a nonconformity. Annex A items must be either implemented or justified as not applicable in the SoA.

Clause 4 — Context

  1. ISMS scope document: defines organizational boundaries, locations, technologies, and exclusions
  2. Context analysis: internal factors (culture, resources, maturity) and external factors (regulatory, market, supply chain) documented
  3. Interested parties register: lists requirements of regulators, customers, shareholders, and employees relevant to information security

Clause 5 — Leadership

  1. Information Security Policy signed by top management, communicated to all staff
  2. Information security roles and responsibilities assigned and documented
  3. Evidence of management involvement: meeting minutes, risk review attendance, resource allocation decisions

Clause 6 — Planning

  1. Risk assessment methodology documented (scope, criteria, methodology, risk owner assignment)
  2. Risk register: all identified risks documented with likelihood, impact, risk owner, and risk level
  3. Risk treatment plan: for each accepted mitigation, the specific Annex A control selected and responsible person named
  4. Statement of Applicability (SoA): all 93 Annex A controls listed with applicability decision and justification for each — CRITICAL document
  5. Residual risk accepted by management: formal sign-off on treated risk levels

Clause 7 — Support

  1. Competence records: training certificates, qualifications, or experience evidence for all IS roles
  2. Security awareness training: documented for all staff, with attendance records
  3. Communication plan: who communicates what, to whom, and how often regarding ISMS matters

Clause 8 — Operation

  1. Risk treatment controls implemented as specified in the risk treatment plan
  2. Change management: procedure for controlling changes that could affect ISMS
  3. Supplier security: contracts with key suppliers include information security requirements

Clause 9 — Performance Evaluation

  1. Internal audit program: documented plan with scheduled intervals; completed internal audit reports
  2. Management review: documented review with input (audit results, incidents, risks, objectives) and output (decisions, resource allocation)
  3. KPIs or metrics: defined measures of ISMS effectiveness (not just counting controls — measuring whether they work)

Clause 10 — Improvement

  1. Nonconformity and corrective action log: tracks findings, root cause analysis, corrective actions, and effectiveness review
  2. Continual improvement records: demonstrates ISMS has evolved based on findings and feedback

Critical Annex A Technological Controls (Clause 8 reference)

  1. 8.2 Privileged access rights: documented process for granting, reviewing, and revoking privileged access
  2. 8.5 Secure authentication: MFA implemented for all privileged access and remote access
  3. 8.8 Management of technical vulnerabilities: documented vulnerability scanning and patch management process
  4. 8.12 Data leakage prevention: controls to detect and prevent unauthorized exfiltration of sensitive data
  5. 8.24 Use of cryptography: documented encryption policy specifying algorithms, key lengths, and key management procedures
  6. 8.25–8.29 Secure development: secure coding standards, security testing in CI/CD, vulnerability scanning of code
  7. 8.34 Protection of information systems during audit testing: controls to prevent audit activities disrupting production

Evidence Most Commonly Requested in Stage 2 Audits

  1. SoA version matching the audit date — auditors compare SoA to implemented controls
  2. Risk register with treatment status for all High and Critical risks
  3. Last 3 internal audit reports with nonconformity findings and corrective actions
  4. Last management review minutes with evidence of top management attendance
  5. Sample evidence for 5–10 Annex A controls (logs, screenshots, config exports, training records)

ISO 27001 vs SOC 2

DimensionISO/IEC 27001:2022SOC 2 (AICPA TSC 2017)
TypeInternational standard with third-party certificationUS attestation with CPA firm report
OutputCertificate (3-year validity)Type I or Type II report
ScopeEntire organization (defined ISMS scope)Specific service system
GeographyGlobal — Europe, APAC, Middle East, governmentDominant in US enterprise SaaS
Controls93 Annex A controls5 Trust Services Categories (CC, A, PI, C, P)
Risk managementNormative requirement (Clauses 6–8)Not explicitly required
Audit bodyISO-accredited certification bodyAny licensed CPA firm
CostUSD 5,000–USD 50,000+ depending on scopeUSD 30,000–USD 100,000+ for Type II
Renewal3-year certificate + annual surveillanceNew report each audit period

Many organizations pursue both certifications because they address different audience requirements. ISO 27001 satisfies European and government procurement requirements; SOC 2 Type II satisfies US enterprise buyers. The ISMS established for ISO 27001 significantly reduces the effort of achieving SOC 2, since both require risk assessment, access controls, encryption, incident response, and audit logging.

Real-World Use Cases

Cloud service providers: A cloud storage vendor serving European enterprise customers is often required to hold ISO 27001 certification as a supplier qualification. The customer’s procurement team requests the certificate and the SoA to verify the scope covers the cloud infrastructure used for the customer’s data. A certificate scoped to the vendor’s headquarters office but not its data centers is insufficient.

Financial services: A fintech company providing payment processing infrastructure to banks must hold ISO 27001 as a condition of their supplier contracts with financial institutions. The bank’s third-party risk management process requires annual evidence of certification maintenance, including the most recent surveillance audit report.

NIS2 Directive compliance: The EU NIS2 Directive (Directive 2022/2555) requires “essential entities” — operators of critical infrastructure — to implement cybersecurity risk management measures. ISO 27001 is explicitly recognized as a framework for satisfying NIS2’s technical and organizational requirements. Organizations subject to NIS2 are increasingly treating ISO 27001 certification as the path to demonstrating compliance.

Common Mistakes to Avoid

Treating the SoA as a formality. The Statement of Applicability is the most important document in your ISO 27001 program. Auditors cross-reference it against evidence collected during the Stage 2 audit. If the SoA says control 8.24 (cryptography) is applicable and implemented, the auditor will ask for evidence: the encryption policy, key management procedures, and a sample of implemented controls. A SoA where every control is marked “applicable” without genuine implementation is a fast path to major nonconformities.

No management engagement. ISO 27001 Clause 5 is explicit: top management must demonstrate leadership and commitment. Many organizations treat ISO 27001 as an IT project. When the Stage 2 auditor requests a management review meeting and finds that the CISO attended alone while the CEO and CTO delegated attendance, this is evidence of insufficient leadership — a potential nonconformity under Clause 5.1.

Static risk assessment. Risk assessments age. New systems, new threat actors, new attack techniques, and new regulatory requirements all change the risk landscape. An organization that conducted a thorough risk assessment in Year 1 and has not updated it since is in violation of Clause 8.2 (information security risk assessment) and Clause 10.2 (continual improvement). The risk register must be a living document reviewed at least annually and whenever significant changes occur.

Getting Started

Start by defining your ISMS scope. Be specific: which business units, which locations, which IT systems, and which data assets are within scope. A narrower, well-defined scope is easier to certify and audit than a vague enterprise-wide scope. Many organizations start with a specific product or service and expand later.

Conduct a gap analysis against ISO 27001:2022. For each of the 10 clauses and 93 Annex A controls, document your current state. Identify which clauses are missing documentation, which controls are partially implemented, and which have no implementation at all. This gap analysis becomes the foundation of your project plan.

Assign a project owner — an Information Security Manager or CISO equivalent — with executive sponsorship. Book a provisional Stage 1 audit date with a certification body 6 to 9 months out. Working backward from that date gives you a project timeline.

For the cryptographic controls required under Annex A 8.24, see AES-256-GCM explained: authenticated encryption without the jargon. For understanding how ISO 27001 key management requirements translate to cloud infrastructure, read key management services: AWS KMS, Azure Key Vault, GCP KMS.

FAQ

Common questions — answered in plain English.

What is ISO 27001?
ISO/IEC 27001 is an international standard published by the International Organization for Standardization (ISO) and the International Electrotechnical Commission (IEC) that specifies requirements for establishing, implementing, maintaining, and continually improving an Information Security Management System (ISMS). The current version is ISO/IEC 27001:2022, which replaced the 2013 edition. Certification demonstrates that your organization systematically manages information security risks.
What is the difference between ISO 27001 and SOC 2?
ISO 27001 is an international standard with formal third-party certification issued by an accredited certification body — once certified, you hold the certificate for 3 years (with annual surveillance audits). SOC 2 is a US attestation framework where a CPA firm attests to control effectiveness for a specific period — it produces a report, not a certificate. ISO 27001 is preferred in Europe, Asia-Pacific, and government supply chains; SOC 2 is dominant in US enterprise SaaS sales. Many organizations pursue both.
How long does ISO 27001 certification take?
Typically 6 to 18 months from initiation to first certification, depending on organizational size, current security maturity, and whether a consultant is engaged. The Stage 1 audit (documentation review) and Stage 2 audit (implementation verification) are separated by typically 1 to 3 months. After initial certification, annual surveillance audits maintain the certificate, and a recertification audit is required every 3 years.
What are the Annex A controls in ISO 27001:2022?
ISO 27001:2022 has 93 controls in Annex A, organized into 4 themes: Organizational controls (37), People controls (8), Physical controls (14), and Technological controls (34). The 2022 revision added 11 new controls including threat intelligence (5.7), cloud security (5.23), web filtering (8.23), data masking (8.11), and secure coding (8.28). Organizations must apply all relevant controls or justify exclusions in their Statement of Applicability.
What is the Statement of Applicability in ISO 27001?
The Statement of Applicability (SoA) is a required document under ISO 27001 Clause 6.1.3(d) that lists all 93 Annex A controls and, for each: whether it is applicable, whether it is implemented, and the justification for inclusion or exclusion. Auditors review the SoA to verify that the organization has considered every control and made a documented, risk-based decision about each. An incomplete or unjustified SoA is a major nonconformity.
What are the penalties for ISO 27001 non-compliance?
ISO 27001 is a voluntary standard — there are no government-imposed penalties for not being certified. However, loss of certification (or failure to achieve it) has significant business consequences: many government procurement frameworks (UK Cyber Essentials Plus, EU NIS2), enterprise supply chains, and financial sector requirements mandate ISO 27001. A suspended or withdrawn certificate can disqualify an organization from contracts worth millions.

References

  1. [1]
  2. [2]
  3. [3]
  4. [4]
  5. [5]