Hael
Book a meeting
ISO 27001 · Introduction

ISO 27001 Explained

Hael · Published 7 August 2026 · Last reviewed 7 August 2026 · 7 min read
Key takeaways
  • ISO/IEC 27001 is a management system standard for information security. It certifies how you manage security, not any individual product.
  • ISO/IEC 27001:2022 is the only operative version. The transition window for 2013 certificates closed on 31 October 2025.
  • Annex A lists 93 controls across four themes. You select what applies based on your risk assessment and justify the rest.
  • Certification lasts three years with annual surveillance audits, and an internal audit is required every year.
  • More than 70,000 organisations hold certification worldwide, which is why buyers treat it as the default security credential.

What the standard is

ISO/IEC 27001 is the international standard for information security management. It asks you to build an information security management system, usually shortened to ISMS: a set of policies, roles, risk processes and controls that governs how your organisation protects information.

It does not certify a product or a piece of infrastructure. It certifies that you run a system for managing security risk, and that the system actually operates. That is why the certificate travels: it says something about the organisation rather than about one server.

The current version

ISO/IEC 27001:2022 was published in October 2022, alongside ISO/IEC 27002:2022, which is the companion guidance explaining how the controls work.

The 2013 edition has been retired. Organisations holding 2013 certificates had until 31 October 2025 to transition, and certificates not transitioned by then lapsed. There is no transition audit route any more, so an organisation with a lapsed certificate faces full initial certification, meaning Stage 1 and Stage 2 at full cost.

Amendment 1, published in February 2024, added a climate change consideration to Clause 4.1 and to the interested parties requirement in Clause 4.2. It is a small change with a real consequence: your context analysis has to record whether climate change is a relevant issue for your ISMS, and most auditors now look for it.

What the standard asks for

Clauses 4 to 10 are the mandatory requirements. Annex A is the control list.

ClauseWhat it requires
4. ContextUnderstand your organisation and interested parties, and define the ISMS scope
5. LeadershipAn information security policy, assigned roles, and demonstrated commitment from the top
6. PlanningRisk assessment, risk treatment, a Statement of Applicability, objectives, and planning of changes under Clause 6.3
7. SupportResources, competence, awareness, communication and documented information
8. OperationRunning the risk assessment and treatment, and controlling operational processes
9. Performance evaluationMonitoring, measurement, internal audit and management review
10. ImprovementNonconformity handling, corrective action and continual improvement

The 93 controls

The 2022 edition restructured Annex A from 114 controls in fourteen domains into 93 controls in four themes.

ThemeReferenceControls
OrganizationalA.537
PeopleA.68
PhysicalA.714
TechnologicalA.834

Eleven controls are genuinely new, covering areas the 2013 edition did not address well: threat intelligence, information security for cloud services, ICT readiness for business continuity, physical security monitoring, configuration management, information deletion, data masking, data leakage prevention, monitoring activities, web filtering and secure coding. In practice this is where most implementation effort concentrates.

You do not implement all 93. You select controls based on your risk assessment, then record the decisions in a Statement of Applicability, explaining which apply, which do not, why, and how the applicable ones are implemented. That document is the first thing an auditor reads.

How certification works

StepWhat happens
Gap analysisCompare your current position against the standard and plan the work
ImplementationBuild the ISMS: scope, policy, risk process, controls, documentation
OperateRun it long enough to produce records an auditor can sample
Internal auditRequired by Clause 9.2. Cannot be performed by your certification body
Management reviewLeadership formally reviews the system and records decisions
Stage 1 auditThe certification body reviews documentation and readiness
Stage 2 auditThe certification body tests whether the ISMS operates in practice
CertificateValid three years, with surveillance audits in years two and three

Certification comes from an accredited certification body, accredited in turn by a national accreditation body such as UKAS in the United Kingdom or ANAB in the United States, under ISO/IEC 17021. That standard prevents a certification body from consulting on the system it will certify, which is why implementation and certification always come from different suppliers.

Why buyers ask for it

It is the default security credential in international procurement. More than 70,000 organisations hold it worldwide, so a buyer's vendor review process can simply ask for it and expect an answer.

Unlike SOC 2, it produces a certificate you can publish. A buyer can verify it without a confidentiality agreement, which makes it far easier to use in sales.

Outside the United States it is usually the first thing asked for. Inside the United States, SOC 2 often comes first, and many companies eventually hold both. Because the underlying controls overlap heavily, the second costs far less than the first. See our SOC 2 service page.

What it does not do

It does not mean you have never been breached, and it does not mean you never will be. It means an accredited third party examined how you manage security risk and found the system conformant.

It does not cover AI governance. Where AI is part of what you deliver, buyers increasingly ask questions the ISMS does not reach, which is what ISO/IEC 42001 addresses. The two integrate. See our ISO/IEC 42001 service page.

What to do next

Decide your scope before anything else. It sets your audit fee, your workload, and whether the certificate answers your buyer's question.

Our free readiness diagnostic gives a first view, and the ISO 27001 service page sets out how a programme runs.

References

FAQ

What is ISO 27001?

The international standard for information security management. It certifies that your organisation runs an information security management system, not that any product is secure.

Which version applies now?

ISO/IEC 27001:2022, plus Amendment 1 of February 2024. The 2013 edition is retired and its certificates lapsed after 31 October 2025.

How many controls are there?

Annex A lists 93 controls in four themes. You select what applies based on your risk assessment and justify exclusions in a Statement of Applicability.

How long does certification last?

Three years, with surveillance audits in years two and three and recertification at the end of the cycle.

Is it the same as SOC 2?

No. ISO 27001 produces a publishable certificate about your management system. SOC 2 produces a private report about your controls over a period. Many organisations hold both.

About Hael

Hael is an advisory firm specialising in AI governance and security compliance. We take companies through ISO 27001, ISO/IEC 42001, SOC 2 and the EU AI Act, from first assessment to certificate, and maintain the position afterwards. We are not a certification body and we do not issue certificates. On engagements involving regulated financial services firms we work alongside Buckingham Capital Consulting, the partner firm that has advised payment and e-money firms on authorisation and compliance since 2013.

This guide is general information and is not professional advice on your particular circumstances.

Free check

See where you stand on ISO 27001, free.

Answer a short set of questions and see what ISO 27001 expects of your AI systems and where you stand today. No sign-up to see your result.

Applicability

Whether ISO 27001 applies to how you use AI, and to which systems.

What is expected

Risk classification, governance, documentation and human oversight.

Where you stand

A banded result, pointed at the gaps that matter most.

What you get

On screen in about five minutes, pre-scoped to ISO 27001.

Or speak to us about your deadline. Book a meeting.