Information security

ISO/IEC 27001 — Information Security Management

ISO/IEC 27001:2022 International standard Current edition published in 2022

Published Reviewed

What is ISO 27001?

ISO 27001 specifies requirements for an information security management system that identifies risk, selects controls and supports independent certification of systematic security management.

At a glance
JurisdictionInternational standard
AuthorityISO/IEC 27001:2022
Current statusCurrent edition published in 2022
Reviewed

Why it matters operationally

ISO 27001 is voluntary in law and mandatory in practice: it is the certificate enterprise customers ask for before they sign, and the backbone regulators accept as evidence of systematic security. Certification is not a document — it is a living system of risk decisions, controls, internal audits and management reviews, checked by an accredited auditor every year and re-certified every three. The 2022 edition restructured Annex A into 93 controls, and certificates against the 2013 edition expired at the 31 October 2025 transition deadline.

Are you aware?

The dates that bind

31 Oct 2025

The 2013 edition is retired

Certificates issued against ISO/IEC 27001:2013 expired at the transition deadline. A certificate — yours or a supplier’s — citing 2013 is not a valid certification.

Every 12 months

Surveillance audits are annual

Between three-year recertifications, accredited bodies run yearly surveillance audits. Internal audits and a management review must have happened before they arrive — with records.

93 controls

Annex A was rebuilt in 2022

The 2022 edition reorganised Annex A into 93 controls across four themes and added controls such as threat intelligence, cloud security and data leakage prevention. Statements of Applicability written for 2013 do not map one-to-one.

Where to start

  1. 1

    Define the ISMS scope deliberately — which entities, sites, systems and services — because everything the auditor checks flows from that boundary.

  2. 2

    Run the risk assessment and record treatment decisions in a Statement of Applicability against the 93 Annex A controls.

  3. 3

    Schedule the internal audit and management review before the certification body arrives, and keep the evidence of both.

Authority links

Read the official sources

The official text is the authority. This guide is only a short orientation for operational planning.

Common questions

Frequently asked questions

Is ISO 27001 legally required?

No law mandates it, but contracts increasingly do — enterprise procurement, cyber-insurance and public tenders routinely require the certificate. It also maps well onto legal duties such as the security obligations in EU cybersecurity and data-protection law.

How is it different from SOC 2?

ISO 27001 certifies your management system against a fixed international requirements standard; SOC 2 is an attestation report on controls you selected, against the AICPA trust services criteria. US customers often ask for SOC 2, European and global ones for ISO 27001 — many organisations maintain both from one control set.

How long does certification take?

Typically several months to build an auditable ISMS, then a two-stage certification audit. The certificate runs on a three-year cycle with annual surveillance in between — the system has to keep operating, not just exist on paper.

Side by side

Key terms in this guide

A quick self-check

Are you ready?

  • Is your Statement of Applicability written against the 2022 edition’s 93 controls — or still against 2013?
  • Have this year’s internal audit and management review actually happened, with records?
  • Could you show an auditor the risk treatment decision behind any control they point at?
  • Do you check your critical suppliers’ certificates for edition and scope, not just their existence?

Every question above has a written, evidence-backed answer in a well-run compliance record. If one made you pause, that pause is the gap.

This guide is general information about public law, not legal advice, and does not create a client relationship. Rules change and apply differently by situation. Verify the current official source and seek qualified advice where needed.