ISO/IEC 27001 is the international standard for information security management systems (ISMS). It defines the requirements for establishing, implementing, maintaining and continually improving a system that protects the confidentiality, integrity and availability of information. The current version is ISO/IEC 27001:2022, amended in 2024. Organizations of any size and sector can certify against it through an accredited certification body.
The standard is published jointly by the International Organization for Standardization (ISO) and the International Electrotechnical Commission (IEC). It does not prescribe firewalls, tools or specific technology. It prescribes a management system: a structured way of deciding what needs protection, treating the risks, and proving that the whole arrangement works.
What does ISO 27001 require?
The requirements sit in clauses 4 to 10. An organization that wants certification has to meet all of them. In short, you must understand your context, secure leadership commitment, assess and treat information security risks, provide resources and competence, run the resulting processes, measure performance, and improve.
Clause | Requirement area |
|---|---|
4 | Context of the organization, including the ISMS scope |
5 | Leadership, the information security policy, roles |
6 | Planning, risk assessment, risk treatment, objectives |
7 | Support: resources, competence, awareness, communication, documented information |
8 | Operation of the processes planned in clause 6 |
9 | Performance evaluation: monitoring, internal audit, management review |
10 | Improvement: nonconformity, corrective action, continual improvement |
The 12-step implementation roadmap in this guide walks through these requirements in the order a real project follows.
What is Annex A?
Annex A is a reference set of 93 information security controls, grouped into four themes. During risk treatment you compare your chosen controls against this list to confirm nothing necessary has been overlooked, and you record the outcome in the Statement of Applicability.
Theme | Controls | Examples |
|---|---|---|
A.5 Organizational | 37 | Policies, supplier relationships, cloud services |
A.6 People | 8 | Screening, terms of employment, remote working |
A.7 Physical | 14 | Physical entry, equipment, clear desk |
A.8 Technological | 34 | Access rights, logging, secure coding, backups |
Not every control applies to every organization. Applicability is a risk-based decision that you justify, control by control. The Annex A section of this guide covers all four themes in detail.
ISO 27001 vs ISO 27002
The two standards are companions and are often confused. ISO 27001 contains the requirements and is the standard you certify against. ISO 27002 contains implementation guidance for the 93 controls: what each control is for and how it is typically put into practice. You cannot certify against ISO 27002. When a contract asks for "ISO 27001 certification", it means an accredited certificate for the management system.
Why organizations implement ISO 27001
Three drivers appear in almost every project. First, customers: security questionnaires and tenders increasingly accept an accredited certificate in place of lengthy individual audits. Second, regulation: frameworks such as NIS2 and DORA demand structured, risk-based security management, and an ISMS provides exactly that structure. Third, the organization itself: a functioning ISMS replaces scattered, personality-dependent security work with defined responsibilities and repeatable processes.
How certification works
Certification is performed by an accredited certification body, not by ISO itself. The initial audit has two stages: stage 1 reviews your documentation and readiness, stage 2 examines whether the ISMS actually operates. A certificate is valid for three years, with surveillance audits in year one and year two and a recertification audit in year three. The certification process article explains each stage.
The 2022 revision and the 2024 amendment
ISO/IEC 27001:2022 restructured Annex A from 114 controls in 14 sections into 93 controls in 4 themes and introduced 11 new controls, including threat intelligence, cloud services security, data leakage prevention and secure coding. Amendment 1, published in 2024, added climate change to the context analysis: organizations must determine whether climate change is a relevant issue for their ISMS. The transition period for the 2013 edition ended in October 2025, so all valid certificates now reference the 2022 edition.
Frequently asked questions
Is ISO 27001 mandatory?
No law makes ISO 27001 certification mandatory in general. It becomes binding through contracts and tenders, and regulators increasingly treat it as evidence of the structured security management that laws such as NIS2 require.
Who can get certified?
Organizations certify their management system; there is no company size requirement. Individuals earn personal credentials instead, such as the TRECCERT ISO 27001 Lead Implementer certification.
How long does implementation take?
Most organizations need between three and twelve months from project start to certification audit, depending on size, scope and existing maturity. The implementation roadmap covers typical timelines.


