Sooner or later a big customer, a security questionnaire, or a board member asks the question that starts every compliance journey: "Are we ISO 27001 certified?" ISO/IEC 27001 is the most widely recognised information security standard in the world, and a certificate against it is often the price of entry to enterprise and international deals. But the certificate is a by-product. What ISO 27001 actually asks you to build is an information security management system (ISMS) — a repeatable, risk-driven way of running security that an independent auditor can inspect and vouch for. This guide explains what the standard requires, how to get certified, what it costs in time and money, and how it lines up with SOC 2 and NIST CSF 2.0 so you are not building three programmes when one will do.

The short version

ISO 27001 is a management-system standard, which is the single most important thing to understand about it. It is not primarily a list of security controls; it is a specification for a system that manages security. The clauses that carry the word "shall" — Clauses 4 through 10 — are the mandatory requirements you are audited against. Annex A is a catalogue of 93 controls you choose from based on your risk assessment, documented in a Statement of Applicability (SoA). You get certified by an accredited certification body through a two-stage audit, and you keep the certificate for a three-year cycle with annual surveillance audits. Most first-timers reach certification in six to twelve months. The recurring win is that once the ISMS exists, SOC 2 and NIST CSF become largely a matter of re-presenting evidence you already produce.

ISMS, Annex A, and the two things people confuse

Two documents make up the ISO 27001 family, and conflating them is the most common early mistake.

  • ISO/IEC 27001 is the auditable standard — the requirements (Clauses 4–10) plus Annex A, which lists the controls by reference. This is what you get certified against.
  • ISO/IEC 27002 is the implementation guidance — a companion that describes, in detail, how to implement each Annex A control. You are never certified against 27002; you use it as the instruction manual.

The current editions are the 2022 revisions of both, plus Amendment 1:2024, which added climate-change considerations to the context and interested-parties clauses (4.1 and 4.2). The amendment introduced no new Annex A controls — the count remains 93 — but every certified organisation now has to consider whether climate change is a relevant issue for its ISMS and whether any interested party has climate-related requirements. For most software companies the answer is a short documented "considered, not material," but it must be on the record.

The mandatory clauses: what "shall" actually means

Clauses 4–10 are where certification is won or lost, because they contain every "shall" in the standard. An auditor works through them methodically. In plain terms:

Clause Requirement What it means in practice
4 — ContextUnderstand the organisation and define ISMS scopeWrite down your internal/external issues, interested parties (customers, regulators, staff) and their requirements — and draw a clear boundary around what the ISMS covers.
5 — LeadershipTop-management commitment, policy, rolesLeadership signs the information security policy, assigns responsibilities, and is demonstrably engaged. Auditors interview executives — this cannot be delegated away.
6 — PlanningRisk assessment, risk treatment, objectivesThe heart of the ISMS: a documented risk assessment methodology, a risk register, a risk treatment plan, and the Statement of Applicability. Also security objectives you can measure.
7 — SupportResources, competence, awareness, documentationTrained people, security-awareness activity, and controlled documents (versioned, approved, accessible).
8 — OperationRun the risk treatment, control the operationActually execute the plan and keep records that prove the controls run — not just that they exist on paper.
9 — Performance evaluationMonitoring, internal audit, management reviewMeasure whether the ISMS works, run at least one internal audit, and hold a documented management review before the certification audit.
10 — ImprovementNonconformity, corrective action, continual improvementWhen something goes wrong, log it, find root cause, fix it, and show the system learns. This is the "continual improvement" auditors look for.

Notice how little of this is technical. Clauses 4–10 are a governance loop — Plan, Do, Check, Act — and they are deliberately the same shape as every other ISO management standard, which is why an ISO 9001 quality manager recognises the structure immediately.

Annex A: the 93 controls in four themes

The 2022 revision reorganised the old 114 controls into 93 controls across four themes, and added eleven genuinely new ones. You do not implement all 93 by default — you select the applicable ones through your risk assessment and justify every inclusion and exclusion in the SoA. The four themes:

  • A.5 Organizational (37 controls) — policies, roles, supplier and cloud security, threat intelligence, incident management, information classification. The largest theme, and the most governance-heavy.
  • A.6 People (8 controls) — screening, terms of employment, awareness, disciplinary process, remote working, confidentiality agreements.
  • A.7 Physical (14 controls) — secure areas, equipment, clear desk/screen, secure disposal, physical entry. Lighter for cloud-native companies, but never zero.
  • A.8 Technological (34 controls) — access control, cryptography, logging and monitoring, secure development, vulnerability and configuration management, data leakage prevention, backup.

The eleven new-in-2022 controls are the ones a 2015-era programme is most likely to miss: threat intelligence (A.5.7), information security for cloud services (A.5.23), ICT readiness for business continuity (A.5.30), physical security monitoring (A.7.4), configuration management (A.8.9), information deletion (A.8.10), data masking (A.8.11), data leakage prevention (A.8.12), monitoring activities (A.8.16), web filtering (A.8.23), and secure coding (A.8.28). Every Annex A control also carries five attributes (control type, information security properties, cybersecurity concepts, operational capabilities, security domains) that let you filter and report on them — useful when you map to other frameworks. Our free ISO 27001 Annex A control reference has a page per control with implementation notes, and the Control Mapper crosswalks each one to SOC 2 and NIST.

The Statement of Applicability: the document that runs the audit

If Clause 6 is the heart of the ISMS, the Statement of Applicability is the artefact the auditor spends the most time in. The SoA lists every one of the 93 Annex A controls and, for each, states: whether it applies, the justification, whether it is implemented, and how. Controls you exclude must have a defensible reason ("no physical offices, so A.7 entry controls are handled by our data-centre provider"), not silence. The SoA is where risk assessment meets control selection, and a thin or contradictory SoA is the fastest route to an audit finding. Treat it as a living document tied to your risk register, not a one-time spreadsheet.

How certification actually works

You are certified by an accredited certification body (not by ISO itself, and not by a consultant), through a defined audit sequence:

  • Stage 1 — documentation review. The auditor checks that your ISMS exists on paper: scope, policies, risk assessment, SoA, internal audit and management review records. They flag gaps before the real audit, so Stage 1 is as much a rehearsal as a test.
  • Stage 2 — certification audit. The auditor tests whether the ISMS actually operates: interviews, sampled evidence, walkthroughs of controls. Findings are graded as major (a whole requirement missing — blocks certification until fixed) or minor (a lapse — certification can proceed with a corrective-action plan).
  • Certification decision. An independent reviewer at the certification body issues the certificate, valid for three years.
  • Surveillance audits. Years 1 and 2 bring lighter surveillance audits to confirm the ISMS is still running; year 3 is a full recertification. The message is unmissable: ISO 27001 is a system you operate continuously, not a project you finish.

A realistic implementation roadmap

For an organisation starting from scratch, a pragmatic sequence looks like this:

  • Phase 1 (weeks 1–4): scope and buy-in. Define the ISMS scope, secure executive sponsorship and budget, and appoint an ISMS owner. Getting scope right — which products, teams, and locations are in — prevents most later pain.
  • Phase 2 (weeks 4–10): risk assessment and gap analysis. Adopt a risk methodology, build the risk register, and run a gap analysis against Annex A. This tells you which controls you already have and which you must build.
  • Phase 3 (weeks 8–20): build controls and documentation. Close the gaps, write the mandatory documents and policies, and produce the Statement of Applicability. This is the longest phase and overlaps the previous one.
  • Phase 4 (weeks 16–24): operate and generate evidence. Run the ISMS long enough to produce records — auditors want to see controls operating over time, not switched on last week.
  • Phase 5 (weeks 20–28): internal audit and management review. Both are mandatory and both must happen before the certification audit. Fix what the internal audit finds.
  • Phase 6 (weeks 24–36): Stage 1 and Stage 2 audits. Book the certification body early — good ones have lead times.

Six to nine months is typical for a focused small or mid-sized company; larger or more complex scopes run to a year or more. A risk register and a control-mapping tool remove a lot of the spreadsheet drudgery from phases 2 and 3.

What it costs

Budget in three buckets. First, certification-body fees — the Stage 1 + Stage 2 audit and the three years of surveillance — which scale with headcount and scope, typically low-to-mid five figures for an SMB over the cycle. Second, internal effort, usually the biggest real cost: someone owning the ISMS for months, plus the time of everyone who builds and runs controls. Third, tooling and remediation — whatever you must buy or fix to close gaps (MFA, logging, endpoint protection, a policy platform). Consultants are optional and can accelerate a first certification, but they cannot be your auditor — accreditation rules forbid the same body from consulting and certifying. Beware anyone who offers a "guaranteed" certificate; that is a red flag, not a service.

The evidence auditors actually want

ISO 27001 runs on documented information. The mandatory records an auditor will ask for include: the ISMS scope, information security policy, risk assessment and treatment methodology and results, the Statement of Applicability, security objectives, evidence of competence and awareness, monitoring and measurement results, the internal audit programme and results, management review minutes, and records of nonconformities and corrective actions. Beyond the mandatory set, they sample operational evidence — access reviews, change tickets, backup restores, incident records, supplier assessments — to confirm the selected Annex A controls really run. The rule of thumb: if a control cannot produce a timestamped record, an auditor will treat it as not operating. This is exactly why teams that already run scripted, exportable operations (see our note on PowerShell for evidence generation) find audits easier — the evidence is a by-product of how they already work.

ISO 27001 vs SOC 2 vs NIST CSF — and how they fit together

These three frameworks overlap far more than they differ, which is the good news if you face more than one.

  • ISO 27001 is an internationally recognised certification against a management-system standard. You either hold the certificate or you do not. It is favoured in Europe, the UK, and for international deals.
  • SOC 2 is a US-centric attestation report written by a CPA firm against the AICPA Trust Services Criteria — you share the report, not a pass/fail badge. Common for US SaaS. See the SOC 2 guide.
  • NIST CSF 2.0 is a voluntary framework for organising and communicating cyber-risk management, with no certification at all. It is the common language many programmes use underneath. See the NIST CSF 2.0 guide.

The controls beneath them are largely the same security practices, so the smart play is to build one control set and map it to each framework's language. Our Control Mapper exists precisely for this "implement once, satisfy many" approach — the same discipline you apply to third-party risk management when a vendor's ISO certificate lets you shortcut your own review.

The mistakes that cost time and money

  • Scoping too wide, too early. A sprawling first-time scope multiplies the evidence burden. Certify the core product and organisation first; expand scope at recertification.
  • Treating the SoA as paperwork. A Statement of Applicability that does not trace to the risk register is the classic audit finding. Build them together.
  • Buying documents, not building a system. Template policy packs get you a binder, not an ISMS. Auditors test whether the system operates, and generic policies no one follows fail Stage 2.
  • Skipping the internal audit and management review. Both are mandatory and both must precede certification. Teams routinely forget them and lose weeks.
  • Letting it lapse after year one. Surveillance audits are unforgiving of a programme that went quiet. The ISMS has to keep running — access reviews, risk updates, incident handling — every quarter.
  • Ignoring the climate amendment. Since Amendment 1:2024, "we considered climate change and documented the conclusion" must appear somewhere. Its absence is an easy, avoidable finding.

Bottom line

ISO 27001 rewards organisations that treat security as a system rather than a scramble. The certificate opens doors, but the ISMS behind it — the risk assessment, the control selection, the evidence, the continual improvement — is what actually makes you more secure, and what makes the next framework cheaper. Build the management system once, map it to SOC 2 and NIST CSF 2.0, and you turn a compliance cost into reusable infrastructure. Start with scope and a real risk assessment; everything else follows from those two.

Frequently asked questions

What is ISO 27001 and what is an ISMS?

ISO/IEC 27001 is the international standard for an information security management system (ISMS) — a structured, risk-based way of managing the security of information. An ISMS is the set of policies, processes, risk assessments and controls that runs security as a continuous system rather than a one-off project. ISO 27001 specifies the requirements (Clauses 4–10) that an accredited auditor certifies you against, plus Annex A, a catalogue of 93 controls you select from based on your risks.

How many controls are in ISO 27001:2022?

Annex A of ISO 27001:2022 contains 93 controls, organised into four themes: Organizational (A.5, 37 controls), People (A.6, 8 controls), Physical (A.7, 14 controls) and Technological (A.8, 34 controls). This is a reorganisation of the 114 controls in the 2013 version, with eleven new controls added — including threat intelligence, cloud security, secure coding and data leakage prevention. Amendment 1:2024 added climate-change considerations to the management clauses but introduced no new Annex A controls, so the count remains 93.

How long does ISO 27001 certification take?

Most first-time organisations reach certification in six to twelve months, depending on size, scope and how much security maturity already exists. The sequence is scope and buy-in, risk assessment and gap analysis, building controls and documentation, operating the ISMS long enough to generate evidence, a mandatory internal audit and management review, then the Stage 1 and Stage 2 certification audits. The certificate is valid for three years, with annual surveillance audits and a full recertification in year three.

What is the difference between ISO 27001 and ISO 27002?

ISO 27001 is the auditable standard containing the requirements and Annex A control list — it is what you get certified against. ISO 27002 is the accompanying implementation guidance that explains, in detail, how to implement each Annex A control. You are never certified against ISO 27002; you use it as the how-to manual while your certification is assessed against ISO 27001.

What is a Statement of Applicability (SoA)?

The Statement of Applicability is the mandatory document that lists all 93 Annex A controls and, for each, records whether it applies to your organisation, the justification for inclusion or exclusion, and how it is implemented. It ties your risk assessment to your control selection and is the document auditors scrutinise most closely. Exclusions must be justified, not simply omitted, and the SoA should be kept current alongside the risk register.

Does ISO 27001 certification satisfy SOC 2 or NIST requirements?

Not automatically, but the underlying controls overlap heavily, so an ISO 27001 ISMS gives you most of what SOC 2 and NIST CSF 2.0 need. SOC 2 is a separate CPA attestation against the AICPA Trust Services Criteria, and NIST CSF 2.0 is a voluntary framework with no certification — but the security practices they assess are largely the same. Building one control set and mapping it to each framework (a "test once, satisfy many" approach) is far more efficient than running three separate programmes.