Certifiable standardGlobal
ISO 27001
ISO/IEC 27001:2022
ISO/IEC 27001 specifies the requirements for an information security management system (ISMS): a governed, risk-based way of protecting information that an accredited certification body can audit and certify. The 2022 edition has 93 Annex A controls in four themes.
Who it reaches
- Companies whose customers ask for an internationally recognised security certificate, especially outside the United States.
- Suppliers to regulated sectors, where the certificate answers most of a security questionnaire in one line.
- Organisations that need a single control framework to carry several laws: NIS2, DORA and the GDPR security duty all map onto it.
What the audit checks
- 01Stage 1: a readiness review of the scope, policy, risk assessment, statement of applicability, internal audit and management review.
- 02Stage 2: the certification audit, sampling controls across the scope for design and operation.
- 03Annual surveillance audits in years one and two, a recertification audit in year three.
A typical engagement
Durations are ranges seen in practice for a mid-sized organisation starting from a working security function; a first-time programme runs longer, a mature one shorter.
| Phase | Weeks |
|---|---|
| Scope and gap assessment | 2 to 4 |
| Risk assessment and treatment plan | 2 to 4 |
| Implement controls and documentation | 8 to 20 |
| Operate, internal audit, management review | 8 to 12 |
| Stage 1 and Stage 2 certification audits | 2 to 6 |
Evidence to have ready
- Scope statement and ISMS policy
- Risk assessment methodology, register and treatment plan
- Statement of applicability against the 93 controls
- Asset inventory with owners and classification
- Access control records and periodic access reviews
- Change, incident and vulnerability management logs
- Supplier register and security terms
- Business continuity and backup test records
- Awareness training records
- Internal audit report and management review minutes
Dates
- Transition from ISO 27001:2013 ended
Questions people ask
- How long is an ISO 27001 certificate valid?
- Three years, subject to passing annual surveillance audits. A recertification audit before the end of year three issues a new three-year certificate.
- Who can issue an ISO 27001 certificate?
- A certification body accredited for ISO/IEC 27001 by a national accreditation body such as UKAS, DAkkS, ANAB or RvA. The auditor must be independent of anyone who helped build the ISMS.
- Is ISO 27001 the same as SOC 2?
- No. ISO 27001 certifies a management system against a fixed standard; SOC 2 is an attestation report on controls against the AICPA Trust Services Criteria. They overlap heavily and can be audited together.
- What changed in the 2022 edition?
- Annex A was restructured from 114 controls in 14 domains to 93 controls in four themes, with eleven new controls including threat intelligence, cloud services security, configuration management and data leakage prevention. Transition from the 2013 edition ended on 31 October 2025.