ISO 27001 Explained
- ISO/IEC 27001 is a management system standard for information security. It certifies how you manage security, not any individual product.
- ISO/IEC 27001:2022 is the only operative version. The transition window for 2013 certificates closed on 31 October 2025.
- Annex A lists 93 controls across four themes. You select what applies based on your risk assessment and justify the rest.
- Certification lasts three years with annual surveillance audits, and an internal audit is required every year.
- More than 70,000 organisations hold certification worldwide, which is why buyers treat it as the default security credential.
What the standard is
ISO/IEC 27001 is the international standard for information security management. It asks you to build an information security management system, usually shortened to ISMS: a set of policies, roles, risk processes and controls that governs how your organisation protects information.
It does not certify a product or a piece of infrastructure. It certifies that you run a system for managing security risk, and that the system actually operates. That is why the certificate travels: it says something about the organisation rather than about one server.
The current version
ISO/IEC 27001:2022 was published in October 2022, alongside ISO/IEC 27002:2022, which is the companion guidance explaining how the controls work.
The 2013 edition has been retired. Organisations holding 2013 certificates had until 31 October 2025 to transition, and certificates not transitioned by then lapsed. There is no transition audit route any more, so an organisation with a lapsed certificate faces full initial certification, meaning Stage 1 and Stage 2 at full cost.
Amendment 1, published in February 2024, added a climate change consideration to Clause 4.1 and to the interested parties requirement in Clause 4.2. It is a small change with a real consequence: your context analysis has to record whether climate change is a relevant issue for your ISMS, and most auditors now look for it.
What the standard asks for
Clauses 4 to 10 are the mandatory requirements. Annex A is the control list.
| Clause | What it requires |
|---|---|
| 4. Context | Understand your organisation and interested parties, and define the ISMS scope |
| 5. Leadership | An information security policy, assigned roles, and demonstrated commitment from the top |
| 6. Planning | Risk assessment, risk treatment, a Statement of Applicability, objectives, and planning of changes under Clause 6.3 |
| 7. Support | Resources, competence, awareness, communication and documented information |
| 8. Operation | Running the risk assessment and treatment, and controlling operational processes |
| 9. Performance evaluation | Monitoring, measurement, internal audit and management review |
| 10. Improvement | Nonconformity handling, corrective action and continual improvement |
The 93 controls
The 2022 edition restructured Annex A from 114 controls in fourteen domains into 93 controls in four themes.
| Theme | Reference | Controls |
|---|---|---|
| Organizational | A.5 | 37 |
| People | A.6 | 8 |
| Physical | A.7 | 14 |
| Technological | A.8 | 34 |
Eleven controls are genuinely new, covering areas the 2013 edition did not address well: threat intelligence, information security for cloud services, ICT readiness for business continuity, physical security monitoring, configuration management, information deletion, data masking, data leakage prevention, monitoring activities, web filtering and secure coding. In practice this is where most implementation effort concentrates.
You do not implement all 93. You select controls based on your risk assessment, then record the decisions in a Statement of Applicability, explaining which apply, which do not, why, and how the applicable ones are implemented. That document is the first thing an auditor reads.
How certification works
| Step | What happens |
|---|---|
| Gap analysis | Compare your current position against the standard and plan the work |
| Implementation | Build the ISMS: scope, policy, risk process, controls, documentation |
| Operate | Run it long enough to produce records an auditor can sample |
| Internal audit | Required by Clause 9.2. Cannot be performed by your certification body |
| Management review | Leadership formally reviews the system and records decisions |
| Stage 1 audit | The certification body reviews documentation and readiness |
| Stage 2 audit | The certification body tests whether the ISMS operates in practice |
| Certificate | Valid three years, with surveillance audits in years two and three |
Certification comes from an accredited certification body, accredited in turn by a national accreditation body such as UKAS in the United Kingdom or ANAB in the United States, under ISO/IEC 17021. That standard prevents a certification body from consulting on the system it will certify, which is why implementation and certification always come from different suppliers.
Why buyers ask for it
It is the default security credential in international procurement. More than 70,000 organisations hold it worldwide, so a buyer's vendor review process can simply ask for it and expect an answer.
Unlike SOC 2, it produces a certificate you can publish. A buyer can verify it without a confidentiality agreement, which makes it far easier to use in sales.
Outside the United States it is usually the first thing asked for. Inside the United States, SOC 2 often comes first, and many companies eventually hold both. Because the underlying controls overlap heavily, the second costs far less than the first. See our SOC 2 service page.
What it does not do
It does not mean you have never been breached, and it does not mean you never will be. It means an accredited third party examined how you manage security risk and found the system conformant.
It does not cover AI governance. Where AI is part of what you deliver, buyers increasingly ask questions the ISMS does not reach, which is what ISO/IEC 42001 addresses. The two integrate. See our ISO/IEC 42001 service page.
What to do next
Decide your scope before anything else. It sets your audit fee, your workload, and whether the certificate answers your buyer's question.
Our free readiness diagnostic gives a first view, and the ISO 27001 service page sets out how a programme runs.
References
FAQ
What is ISO 27001?
The international standard for information security management. It certifies that your organisation runs an information security management system, not that any product is secure.
Which version applies now?
ISO/IEC 27001:2022, plus Amendment 1 of February 2024. The 2013 edition is retired and its certificates lapsed after 31 October 2025.
How many controls are there?
Annex A lists 93 controls in four themes. You select what applies based on your risk assessment and justify exclusions in a Statement of Applicability.
How long does certification last?
Three years, with surveillance audits in years two and three and recertification at the end of the cycle.
Is it the same as SOC 2?
No. ISO 27001 produces a publishable certificate about your management system. SOC 2 produces a private report about your controls over a period. Many organisations hold both.
About Hael
Hael is an advisory firm specialising in AI governance and security compliance. We take companies through ISO 27001, ISO/IEC 42001, SOC 2 and the EU AI Act, from first assessment to certificate, and maintain the position afterwards. We are not a certification body and we do not issue certificates. On engagements involving regulated financial services firms we work alongside Buckingham Capital Consulting, the partner firm that has advised payment and e-money firms on authorisation and compliance since 2013.
This guide is general information and is not professional advice on your particular circumstances.