Information security
ISO/IEC 27001 — Information Security Management
Published Reviewed
What is ISO 27001?
ISO 27001 specifies requirements for an information security management system that identifies risk, selects controls and supports independent certification of systematic security management.
| Jurisdiction | International standard |
|---|---|
| Authority | ISO/IEC 27001:2022 |
| Current status | Current edition published in 2022 |
| Reviewed |
Why it matters operationally
ISO 27001 is voluntary in law and mandatory in practice: it is the certificate enterprise customers ask for before they sign, and the backbone regulators accept as evidence of systematic security. Certification is not a document — it is a living system of risk decisions, controls, internal audits and management reviews, checked by an accredited auditor every year and re-certified every three. The 2022 edition restructured Annex A into 93 controls, and certificates against the 2013 edition expired at the 31 October 2025 transition deadline.
Are you aware?
The dates that bind
The 2013 edition is retired
Certificates issued against ISO/IEC 27001:2013 expired at the transition deadline. A certificate — yours or a supplier’s — citing 2013 is not a valid certification.
Surveillance audits are annual
Between three-year recertifications, accredited bodies run yearly surveillance audits. Internal audits and a management review must have happened before they arrive — with records.
Annex A was rebuilt in 2022
The 2022 edition reorganised Annex A into 93 controls across four themes and added controls such as threat intelligence, cloud security and data leakage prevention. Statements of Applicability written for 2013 do not map one-to-one.
Where to start
- 1
Define the ISMS scope deliberately — which entities, sites, systems and services — because everything the auditor checks flows from that boundary.
- 2
Run the risk assessment and record treatment decisions in a Statement of Applicability against the 93 Annex A controls.
- 3
Schedule the internal audit and management review before the certification body arrives, and keep the evidence of both.
Authority links
Read the official sources
The official text is the authority. This guide is only a short orientation for operational planning.
Common questions
Frequently asked questions
Is ISO 27001 legally required?
No law mandates it, but contracts increasingly do — enterprise procurement, cyber-insurance and public tenders routinely require the certificate. It also maps well onto legal duties such as the security obligations in EU cybersecurity and data-protection law.
How is it different from SOC 2?
ISO 27001 certifies your management system against a fixed international requirements standard; SOC 2 is an attestation report on controls you selected, against the AICPA trust services criteria. US customers often ask for SOC 2, European and global ones for ISO 27001 — many organisations maintain both from one control set.
How long does certification take?
Typically several months to build an auditable ISMS, then a two-stage certification audit. The certificate runs on a three-year cycle with annual surveillance in between — the system has to keep operating, not just exist on paper.
Side by side
Compared against
Key terms in this guide
A quick self-check
Are you ready?
- Is your Statement of Applicability written against the 2022 edition’s 93 controls — or still against 2013?
- Have this year’s internal audit and management review actually happened, with records?
- Could you show an auditor the risk treatment decision behind any control they point at?
- Do you check your critical suppliers’ certificates for edition and scope, not just their existence?
Every question above has a written, evidence-backed answer in a well-run compliance record. If one made you pause, that pause is the gap.