What ISO/IEC 27001 is
ISO/IEC 27001 is the international standard for an information security management system (ISMS). It sets requirements for how an organization identifies information security risks, selects controls to treat them, and reviews and improves the system over time. The current edition is ISO/IEC 27001:2022.
Organizations pursue certification when customers, partners or tenders ask for it. Requests are common in international procurement and public sector contracts. An accredited certification body audits the ISMS against the standard and, if it conforms, issues a certificate for the scope you define.
Key facts
Clauses 4 to 10
The management system requirements: context of the organization, leadership, planning, support, operation, performance evaluation and improvement. All of them apply to every certified ISMS.
Annex A
93 reference controls in four themes: organizational (37), people (8), physical (14) and technological (34). You select controls through risk treatment.
Statement of Applicability
A required document that lists each Annex A control, whether it is included, the justification, and whether it is implemented.
Risk assessment and treatment
A defined, repeatable method to identify, analyze and evaluate risks, and a treatment plan approved by risk owners.
Internal audit and management review
The internal audit checks the ISMS against the standard and your own requirements. Management review records leadership decisions about the ISMS. Certification bodies expect both before the Stage 2 audit.
Certification cycle
Stage 1 reviews documentation and readiness. Stage 2 assesses whether the ISMS is implemented and effective. Certificates are valid for three years, with surveillance audits in between and a recertification audit before expiry.
2024 amendment
ISO/IEC 27001:2022/Amd 1:2024 adds a requirement to consider whether climate change is a relevant issue when defining context in clauses 4.1 and 4.2.
How readiness works with us
We help you define the ISMS scope: the products, services, locations, teams and systems included, and the interfaces and dependencies at the boundary. A clear scope statement decides what the certificate covers and what the auditor will examine.
We assess your current state against clauses 4 to 10 and the Annex A controls. We review documents, configurations, access, logs and records, and we interview control owners. The result is a gap list ranked by audit impact and effort, with an owner for each item.
We help you set up the risk assessment method and risk register, write the Statement of Applicability, update policies and implement controls. We also help plan the internal audit and management review. The internal auditor must be objective and impartial, so they should not audit their own work.
Before the certification audit we test a sample of controls and records the way an auditor would. During Stage 1 and Stage 2 we help your team respond to requests and explain technical controls. If the auditor raises nonconformities, we help you plan and evidence the corrective actions.
What you receive
Each engagement has a fixed scope agreed at the start. These are the outputs your team keeps.
Gap assessment
- ISMS scope statement draft
- Status against clauses 4 to 10 and Annex A
- Prioritized remediation plan with owners and target dates
ISMS documentation
- Risk assessment method and risk register
- Statement of Applicability
- Policies and procedures updated where gaps exist
Controls and evidence
- Controls implemented or improved in your environment
- Evidence organized by clause and control for the auditor
- Setup in your compliance platform if you use one
Testing and audit support
- Pre-audit testing results
- Support for internal audit and management review
- Help during Stage 1, Stage 2 and corrective actions
Control areas we commonly implement
Access control and identity
Annex A 5.15 to 5.18, 8.2 and 8.5: access rules, identity lifecycle, MFA, privileged access and access reviews. We can deploy identity with Keycloak.
Vulnerability management
Annex A 8.8: scanning, patch timelines and tracking to closure. We also run application and cloud infrastructure security testing.
Logging and monitoring
Annex A 8.15 and 8.16: centralized logs, alerting and records of review. We deploy open-source monitoring such as Wazuh.
Incident management
Annex A 5.24 to 5.28: planning, assessment, response, lessons learned and evidence collection.
Supplier relationships
Annex A 5.19 to 5.23: supplier inventory, security terms in agreements, monitoring of suppliers and use of cloud services.
Change management
Annex A 8.32: approval, testing and records for changes to systems and software.
Backups
Annex A 8.13: backup schedules, restore tests and retention aligned with your requirements.
ISO/IEC 27001 and SOC 2 compared
Many controls overlap. If you plan both, we scope them together so one set of controls and evidence supports both audits.
| Topic | ISO/IEC 27001 | SOC 2 |
|---|---|---|
| Result | Certificate issued by an accredited certification body | Attestation report with an opinion issued by a licensed CPA firm |
| Basis | ISMS requirements in clauses 4 to 10, plus controls selected from Annex A through risk treatment | Trust Services Criteria for the categories in scope |
| What customers see | The certificate and scope statement, and often the Statement of Applicability on request | The full report with system description, controls, tests and results, usually shared under NDA |
| Cycle | Three-year certificate with surveillance audits in between | A new report for each period, often annually |
| Often requested by | International customers and public sector buyers | North American customers, especially for SaaS |
Who does what
We help you build or improve the ISMS and prepare for the audits. We scope, assess, help implement controls, test them and support your team during the certification audit. We do not certify organizations or issue certificates.
Your certification body, accredited by a national accreditation body, performs the Stage 1 and Stage 2 audits, decides whether to certify, issues the certificate and runs the surveillance and recertification audits.
Your team owns the ISMS. Top management sets the information security policy and objectives, assigns roles and takes part in management review. Risk owners approve risk treatment. Control owners operate the controls and keep the records.
Common questions
How long does readiness take?
It depends on your scope and how mature your security program is today. During scoping we give you a plan with dates for each phase, including time for the internal audit and management review before Stage 2.
Can you work with our compliance platform?
Yes. If you use Vanta, Drata or a similar platform, we work inside it. We map controls, connect integrations and upload evidence. If you do not use one, we organize documents and records in a structure your auditor can follow.
Do you certify us?
No. An accredited certification body performs the certification audits and issues the certificate. We prepare your team and support you during the audits.
Can you help after certification?
Yes, through a retainer. We can help with risk reviews, internal audits, management review, corrective actions and preparation for surveillance and recertification audits.
Our certificate is to the 2013 edition. What now?
The transition period to ISO/IEC 27001:2022 ended on 31 October 2025, so certificates to the 2013 edition are no longer valid. Ask your certification body about the route to certification against the 2022 edition. We can assess you against it, update your Statement of Applicability to the new Annex A structure and prepare evidence for their audit.
What do we need to prepare?
A named owner on your side, a sponsor in top management, a draft of what you want the certificate to cover, and your current policies, asset inventory and vendor list. An NDA can be in place before we start.
How to prepare
Decide what the certificate needs to cover. Look at the customer and tender requests you have received and the products, sites and teams they relate to.
Gather what you already have: policies, an asset inventory, a vendor list, an architecture diagram, any existing risk register and records of past incidents. Gaps are expected. The gap assessment exists to find them.
Choose an internal owner for the ISMS and a sponsor in top management who can attend management review. If you have already selected a certification body, share their contact so we can align on audit dates early.
Surveillance and recertification
Certification starts a three-year cycle. The certification body runs surveillance audits in the years between initial certification and recertification, and a recertification audit before the certificate expires. Each surveillance audit covers part of the ISMS and checks that it is still operating.
To stay ready, keep the ISMS running between audits: review risks when your systems or business change, complete internal audits and management reviews on schedule, close corrective actions and keep control records current. We can support this work through a retainer.

