All frameworks
Certifiable standardGlobal

ISO 27001

ISO/IEC 27001:2022

ISO/IEC 27001 specifies the requirements for an information security management system (ISMS): a governed, risk-based way of protecting information that an accredited certification body can audit and certify. The 2022 edition has 93 Annex A controls in four themes.

Who it reaches

  • Companies whose customers ask for an internationally recognised security certificate, especially outside the United States.
  • Suppliers to regulated sectors, where the certificate answers most of a security questionnaire in one line.
  • Organisations that need a single control framework to carry several laws: NIS2, DORA and the GDPR security duty all map onto it.

What the audit checks

  1. 01Stage 1: a readiness review of the scope, policy, risk assessment, statement of applicability, internal audit and management review.
  2. 02Stage 2: the certification audit, sampling controls across the scope for design and operation.
  3. 03Annual surveillance audits in years one and two, a recertification audit in year three.

A typical engagement

Durations are ranges seen in practice for a mid-sized organisation starting from a working security function; a first-time programme runs longer, a mature one shorter.

PhaseWeeks
Scope and gap assessment2 to 4
Risk assessment and treatment plan2 to 4
Implement controls and documentation8 to 20
Operate, internal audit, management review8 to 12
Stage 1 and Stage 2 certification audits2 to 6

Evidence to have ready

  • Scope statement and ISMS policy
  • Risk assessment methodology, register and treatment plan
  • Statement of applicability against the 93 controls
  • Asset inventory with owners and classification
  • Access control records and periodic access reviews
  • Change, incident and vulnerability management logs
  • Supplier register and security terms
  • Business continuity and backup test records
  • Awareness training records
  • Internal audit report and management review minutes

Dates

  • Transition from ISO 27001:2013 ended
All regulatory deadlines

Questions people ask

How long is an ISO 27001 certificate valid?
Three years, subject to passing annual surveillance audits. A recertification audit before the end of year three issues a new three-year certificate.
Who can issue an ISO 27001 certificate?
A certification body accredited for ISO/IEC 27001 by a national accreditation body such as UKAS, DAkkS, ANAB or RvA. The auditor must be independent of anyone who helped build the ISMS.
Is ISO 27001 the same as SOC 2?
No. ISO 27001 certifies a management system against a fixed standard; SOC 2 is an attestation report on controls against the AICPA Trust Services Criteria. They overlap heavily and can be audited together.
What changed in the 2022 edition?
Annex A was restructured from 114 controls in 14 domains to 93 controls in four themes, with eleven new controls including threat intelligence, cloud services security, configuration management and data leakage prevention. Transition from the 2013 edition ended on 31 October 2025.

Go deeper