Operational guidance, not legal advice. This page distills named public sources (regulator guidance and industry practice). It is not a legal determination, not a notification decision, and not a substitute for your counsel, insurer, or a retained DFIR firm. Verify applicability and current deadlines for your facts and jurisdiction.

What is ISO/IEC 27001?

Last verified

ISO/IEC 27001:2022 is a voluntary international standard for an information security management system. Clauses 4–10 set certifiable ISMS requirements; Annex A lists 93 selectable controls. This page is not legal advice, does not determine YOUR obligations, does not start a clock, and does not file.

Explainer, last verified 10 September 2026 against the ISO/IEC 27001:2022 standard page, ISO/IEC 27002:2022 guidance, and IAF transition arrangements. ISO 27001 is a voluntary standard, not a law. A certificate is issued only by an IAF-MLA accredited certification body after Stage 1 and Stage 2. It is not a SOC 2 attestation report and not a determination that you must certify.

What this page is, and what it is not

Audience: a founder, CTO, CISO, compliance owner, or auditor who wants a plain-language account of what ISO/IEC 27001 actually certifies before deciding whether to pursue it.

This page is not legal advice. Reading it does not determine YOUR obligations, does not decide that ISO 27001 applies to your organisation, does not start a clock, and does not file anything with a certification body, an accreditation body, or a regulator. Last verified 10 September 2026.

ISO/IEC 27001 is a voluntary standard, not a law. Nobody is required by the standard itself to get certified. Demand usually comes from contracts, tenders, and market expectation — different kinds of authority from a statute. Work out applicability with counsel and your commercial team before treating this page as a programme plan.

  • An information security management system (ISMS) is the ongoing machinery of scope, risk decisions, selected controls, internal audit, and management review — not a one-time configuration snapshot.
  • Clauses 4–10 are the certifiable management-system requirements: context, leadership, planning, support, operation, performance evaluation, and improvement.
  • Annex A is a catalogue of 93 controls in four themes. You select from it through the Statement of Applicability. The catalogue is not a mandatory checklist of all 93.
  • Only an IAF-MLA accredited certification body, operating to ISO/IEC 17021-1 and the ISMS-specific ISO/IEC 27006, issues a recognised certificate. This product does not.

Clauses 4–10 compared with Annex A

The most common mix-up is treating Annex A as the standard. The certifiable requirements live in Clauses 4–10. Annex A is the reference set you compare against when you write the Statement of Applicability under Clause 6.1.3. Last verified 10 September 2026. Not legal advice.

Clause or annex compared with what this page does and does not do (not a determination; not legal advice; last verified 10 September 2026)
Clause or annexWhat it isKind of textWhat this page does not do
Clauses 4–10Certifiable ISMS requirements: context, leadership, planning, support, operation, performance evaluation, improvement.Certification standard — applies because you sought accredited certification, or a contract requires it.Does not decide that you must implement an ISMS, and does not start a clock.
Clause 6.1.3 / Statement of ApplicabilityList necessary controls, justify inclusion, justify any Annex A exclusion, and state implementation status.Certification standard (planning).Does not write your SoA or judge whether an exclusion is defensible on your facts.
Annex A (2022)93 controls in four themes: Organizational 37, People 8, Physical 14, Technological 34. Replaces the 2013 layout of 114 controls in 14 domains.Reference control catalogue, selectable via the SoA — not a mandate to implement all 93.Does not claim every control is mandatory, and does not rank themes.
ISO/IEC 27002:2022Implementation guidance for the Annex A controls, including the 11 controls new in 2022 such as threat intelligence, cloud services, ICT readiness for business continuity, configuration management, data leakage prevention, and secure coding.Guidance — not the certifiable management-system text.Does not quote paywalled clause text, and does not substitute 27002 for 27001.
Accredited certificateIssued by an IAF-MLA accredited certification body after Stage 1 (documentation/readiness) and Stage 2 (implementation/effectiveness). Typical cycle is three years, with surveillance in years 1 and 2.Certification outcome under ISO/IEC 17021-1 and ISO/IEC 27006.Does not issue a certificate, does not produce an auditor's opinion, and does not file.
SOC 2 report (contrast)A CPA attestation report against the AICPA Trust Services Criteria — an opinion, not an ISO certificate.Attestation criteria, not an ISMS certification standard.Does not decide which artefact your buyers want. See the SOC 2 vs ISO 27001 page in this cluster.

What “certified” means, and what it does not

A recognised ISO/IEC 27001 certificate is a statement by an accredited certification body that your ISMS meets Clauses 4–10, with Annex A controls selected and justified in the SoA. The certificate is typically valid for three years, subject to surveillance. Last verified 10 September 2026. Not legal advice.

It is not a SOC 2 report. SOC 2 is a CPA attestation against the AICPA Trust Services Criteria. ISO 27001 is accredited certification against a management-system standard. Different artefact, different authority, different buyer audience. Neither is a law.

Under IAF transition arrangements, accredited certificates against the 2013 edition expired by 31 October 2025. New and continuing certifications run against the 2022 edition — 93 controls / four themes, not the 2013 114 / 14-domain layout.

Checklist

This list is the checklist artifact for this page. It is a question list, not a determination that you must certify. Last verified 10 September 2026. Not legal advice.

  • Can we name whether anyone is actually asking for an ISO/IEC 27001 certificate — a buyer, a tender, or a regulator — versus a SOC 2 report?
  • Have we separated Clauses 4–10 (the ISMS we would have to run) from Annex A (the controls we would select via a SoA)?
  • Do we know that only an IAF-MLA accredited certification body issues a recognised certificate, and that ISO/IEC 17021-1 and ISO/IEC 27006 constrain that body?
  • Have we recorded that ISO 27001 is a voluntary standard, not a law, so we are not treating this page as a mandate?
  • Do we know the 2022 control counts — Organizational 37, People 8, Physical 14, Technological 34 — and that a 2013 certificate is no longer a continuing accredited option after 31 October 2025?
  • Have we listed the mandatory documented information we would need if we proceed: scope, information security policy, risk assessment and treatment, SoA, internal-audit results, management review, corrective actions?

What to do now

None of these steps is a legal determination. None of them starts a clock or files anything with a certification body.

  • Decide with counsel and sales whether anyone is actually asking for ISO 27001, a SOC 2 report, or both — before scoping an ISMS.
  • Read the who-needs and SOC 2 vs ISO 27001 pages in this cluster if the demand is still fuzzy.
  • If you proceed, write a draft scope and a first-pass risk assessment; do not start by trying to implement all 93 Annex A controls.
  • Confirm any certification body you might use appears in IAF CertSearch for ISO/IEC 27001, accredited by an IAF-MLA body such as UKAS or ANAB.
  • Re-verify the citations below at least annually, and record the date you did it.

Where this shows up in ShipReady Metrics

Only shipped behaviour is described here. ShipReady Metrics does not issue certificates, does not produce an auditor's opinion, and is not a downloadable evidence binder. Human judgment and an accredited certification body remain required.

If you already have a session: signed-in app → Compliance holds ISO/IEC 27001 in the 24-framework library. Annex A is crosswalked to about 72 canonical controls with a crosswalk-density honesty layer — coverage, not a pass.

Evidence collection records control-mapped artifacts. Evidence review is the human overlay: a named human can accept a manual row as met or reject it as a gap, with a timestamp. That is not a certificate and not an auditor's opinion.

The obligation map lists frameworks you marked in-scope. That mark is a scoping input you control; it is not a legal opinion that ISO 27001 applies. The policies library and cyber risk register store YOUR artefacts; they do not write the SoA for you.

Primary sources (last verified 10 September 2026)

ISO/IEC 27001:2022 is the certification standard. ISO/IEC 27002:2022 is guidance for Annex A. IAF publishes the forum arrangements and CertSearch for verifying accredited certificates. This page paraphrases; it does not quote paywalled clause text. Not legal advice.

Frequently asked questions