ISO/IEC 27001

ISO 27001 certification,
explained plainly

ISO/IEC 27001 is the international standard for an information security management system. Here is what certification actually involves: the timeline, the Annex A controls, the Statement of Applicability and the surveillance audits that keep it valid — and how teams run the whole system in one Swiss-hosted workspace.

Book a conversation
Every framework
ISO/IEC 27001SOC 2GDPRHIPAASwiss nFADPNIST CSF 2.0OWASPEU AI Act
ISO/IEC 27001SOC 2GDPRHIPAASwiss nFADPNIST CSF 2.0OWASPEU AI Act
ISO/IEC 27001SOC 2GDPRHIPAASwiss nFADPNIST CSF 2.0OWASPEU AI Act
ISO/IEC 27001SOC 2GDPRHIPAASwiss nFADPNIST CSF 2.0OWASPEU AI Act
  • ISO/IEC 27001
  • SOC 2
  • GDPR
  • HIPAA
  • Swiss nFADP
  • NIST CSF 2.0
  • OWASP
  • EU AI Act
The standard

What ISO/IEC 27001 actually requires.

ISO/IEC 27001 certifies an information security management system (ISMS), not a product. The 2022 revision pairs ten management clauses with 93 Annex A controls, and asks you to run the system, and prove it keeps working, over time.

The clauses (4 to 10)

Context, leadership, planning, support, operation, performance evaluation and improvement — the management-system requirements every ISMS is built on.

Annex A controls

93 controls across four themes: organizational, people, physical and technological. You apply the ones in scope and justify the rest.

The certification cycle

A Stage 1 and Stage 2 audit to certify, then a surveillance audit in years one and two and a full recertification in year three.

An ISMS, not a checklist

Certification confirms a working system: risks identified, controls in place, evidence current, reviewed and improved continually.

The full picture

ISO 27001, from first audit to recertification.

A plain-language walkthrough — what the standard asks for, and what actually keeps a certificate valid between audits.

01

What is ISO/IEC 27001?

ISO/IEC 27001 is the international standard for information security management. It does not certify a product, a server, or a single feature — it certifies that your organization runs a working information security management system (ISMS): a defined way of identifying risks to your information, deciding what to do about them, and proving you actually do it, over and over.

That distinction matters more than it sounds. A certificate on the wall is not the point of ISO 27001; the management system behind it is. An auditor is not asking "is your software secure?" — they are asking "can you show me the system you use to keep it secure, and the evidence that the system runs?" Everything else in the standard follows from that.

The current version is the 2022 revision (ISO/IEC 27001:2022). If you read older guides referring to 114 controls, those describe the 2013 edition — the 2022 revision reorganized the control set into 93 controls across four themes, which we cover below.

ISO 27001 vs ISO 27002

These two get confused constantly, so it is worth being precise. ISO 27001 is the standard you certify against — it sets the requirements for the management system and lists the controls in Annex A. ISO 27002 is the companion guidance that explains, in detail, how to implement each of those controls. You are audited against 27001; you reach for 27002 when you need to know how to actually do a control. There is no separate ISO 27002 certificate.

02

Who needs ISO 27001, and why customers ask for it

ISO 27001 is rarely pursued for its own sake. Most teams go for it because a customer, a tender or a partner asked — it has become the default way to prove information security to someone who cannot audit you themselves. For software vendors, scaleups and managed-service providers selling to larger or regulated organizations, it is increasingly the price of entry to the deal.

It is also chosen because it travels. A single ISO 27001 certificate is recognized internationally and is widely accepted in place of answering endless bespoke security questionnaires, which is why teams selling across borders tend to reach for it before more region-specific frameworks.

If you are weighing whether you need it, the practical test is simple: are you losing or slowing deals because you cannot demonstrate a managed approach to security? If so, ISO 27001 is usually the most widely accepted answer — and the work of getting there is mostly the work of running security well, written down.

03

Defining your ISMS scope

Scope is the first real decision in an ISO 27001 project, and the one that quietly determines how hard the next twelve months will be. Your scope statement defines which parts of your organization the ISMS covers: which teams, systems, locations and information. Scope it too broadly and you have signed up to secure and evidence everything at once. Scope it too narrowly and the certificate will not mean much to the customer asking for it.

Most teams scope the ISMS around the product or service their customers actually care about, plus the systems and people that support it. Write the scope statement plainly enough that an auditor, and a prospect reading your certificate, can tell exactly what it covers.

04

Annex A controls (the 2022 control set)

Annex A is the catalogue of security controls referenced by ISO 27001. The 2022 revision lists 93 controls, grouped into four themes: organizational (37 controls), people (8 controls), physical (14 controls) and technological (34 controls). The technological theme, covering access control, cryptography, logging and secure development, is the one closest to the systems engineers work in every day.

You are not required to implement all 93. You are required to consider each one, decide whether it applies to your scope, implement the ones that do, and justify any you exclude — which is exactly what the Statement of Applicability records.

Risk assessment and risk treatment

The control set is not a shopping list you work through top to bottom. ISO 27001 is risk-based: you assess the risks to the information in your scope, then choose the controls that treat those risks. The risk assessment is the engine that decides which Annex A controls are relevant and why — and keeping it current is most of what running an ISMS actually means.

05

The Statement of Applicability (SoA)

The Statement of Applicability is the document that maps every Annex A control to a clear decision: applicable and implemented, or excluded, with a reason. It is, in practice, the first document an auditor opens, because it tells them the entire shape of your ISMS at a glance — what you decided to do, and the reasoning behind what you left out.

A good SoA is not a formality you generate at the end. It is the running record of your security decisions, and keeping it current is most of what "maintaining" an ISMS actually involves.

06

The documents ISO 27001 expects

Beyond the controls themselves, ISO 27001 expects a defined set of documented information — the records an auditor asks to see. The Statement of Applicability is the best known, but it sits alongside several others that together describe and govern your ISMS.

The core set most teams maintain includes the ISMS scope, the information security policy, the risk assessment and risk treatment methodology, the risk treatment plan, the Statement of Applicability, and the records that prove the system runs: internal audit results, management review minutes and corrective actions. The standard cares less about their format than about whether they are current, consistent and actually used.

In practice this is where ISMS maintenance lives or dies. Documents drift out of date between audits, the policy says one thing and the evidence shows another, and the gap surfaces at the worst possible moment. Keeping them in one place, versioned and linked to the controls they support, is most of what staying certified involves.

07

How ISO 27001 certification works, step by step

Certification is carried out by an accredited certification body, in two stages. Stage 1 is a documentation review: the auditor checks that your ISMS exists on paper — scope, policies, risk assessment, Statement of Applicability, and is ready to be audited. It usually surfaces gaps you fix before going further.

Stage 2 is the main event. The auditor tests whether the system actually operates as documented, sampling evidence across the controls in your scope and interviewing the people who run them. Before Stage 2, the standard expects you to have run at least one internal audit and one management review yourself — you are not certified against a system you have never checked.

From a serious start, most small and mid-size teams reach the Stage 2 audit in three to twelve months, driven mostly by how much security practice already exists and how much of it is written down. The audit is a checkpoint on a system you keep running, not a one-off project that ends when the certificate arrives.

08

Staying certified: surveillance audits and recertification

ISO 27001 certification runs on a three-year cycle. After your initial certification audit, you do not simply hold the certificate untouched — a surveillance audit in years one and two checks that the ISMS is still operating, and a full recertification audit in year three renews the certificate for another cycle.

This is the part teams underestimate. Certification is not an event you survive once; it is a system you keep running. The work that earns the first certificate, keeping the risk assessment current, the Statement of Applicability accurate, the evidence flowing, is the same work that carries you cleanly through every surveillance audit after it. Teams that treat the first audit as a one-off sprint feel the cost again at every renewal; teams that build the ISMS into how they already work do not.

09

What drives the cost of ISO 27001

There is no single price for ISO 27001, because most of the cost is your own effort, not a line item. The certification body charges for the Stage 1 and Stage 2 audits and the annual surveillance audits, scaled to the size and complexity of your scope. That fee is usually the smaller part.

The larger cost is the work of building and running the ISMS: defining scope, assessing risk, writing policies, implementing controls, gathering evidence and keeping all of it current through every audit. Teams that assemble this from spreadsheets and shared drives pay for it again at every surveillance cycle, in the time it takes to reconstruct evidence that was never kept in one place.

Narrowing scope to what your customers actually care about, and maintaining the system continuously rather than rebuilding it before each audit, are the two levers that move total cost the most — far more than the certification body’s fee.

The real problem

Audit-ready is a state you keep, not a sprint you survive.

Most tools optimize for getting the first certificate. The expensive part is the years after — the spreadsheet sprawl, the evidence you reassemble from memory the week before a surveillance audit, the client (or control) you haven't looked at since last cycle. That's the part no first-cert tool was built for.

Spreadsheet sprawl across drives, tabs and inboxes
The week-before scramble, reassembled from memory
The control you haven't looked at since last cycle
Audit-readiness over time
3-year cycle
audit-readyCertSurveillance 1Surveillance 2
Point-in-time tools — scramble & drift
devguard — a state you keep
Run it in devguard

Your ISO 27001 ISMS, in one workspace.

Everything the standard asks you to maintain — controls, policies, evidence, reviews, connected and audit-ready between audits. Pick one to see it.

Every Annex A control, in one view

See all 93 Annex A controls, what is applicable, and where you stand — each mapped to the policies, risks and assets that satisfy it, so your Statement of Applicability stays live instead of being rebuilt before each audit.

Learn more
Control coverage64%
Asset managementCovered
CryptographyPartial
Supplier securityGap
Document once. Reuse across every standard you add.

ISO 27001 overlaps heavily with SOC 2, GDPR and NIS2. Map a control once in devguard and the same policy and evidence satisfy it everywhere it appears — so the second framework is a fraction of the work of the first.

See the full feature comparison

Already certified and dreading the next cycle? See how we help certified companies stay audit-ready.

Already certified? Move your ISO 27001 work across.

If you already hold ISO 27001, you do not want to rebuild your ISMS from a blank page. In a scoped conversation we agree exactly what moves — your controls, policies, risk register, Statement of Applicability and audit history, and run that migration with you, for a fixed scope and a date set before we start. Your existing setup stays untouched and exportable until you are satisfied the new one holds up side by side.

Book a conversation
ISO/IEC 27001 FAQ

ISO/IEC 27001, answered plainly.

How long does ISO 27001 certification take?

For most small and mid-size teams, roughly three to twelve months from a serious start to the certification audit, depending on how much security practice already exists and how much of it is documented. Maintaining it afterwards is the longer game: a surveillance audit each year and a full recertification every three years.

What is the difference between ISO 27001 and ISO 27002?

ISO 27001 is the standard you certify against — it sets the management-system requirements and lists the controls in Annex A. ISO 27002 is the companion guidance that explains how to implement each control. You are audited against 27001; you reach for 27002 to learn how. There is no separate ISO 27002 certificate.

How many controls are in Annex A?

The 2022 revision lists 93 controls across four themes: organizational (37), people (8), physical (14) and technological (34). You apply the ones relevant to your scope and justify any you exclude in your Statement of Applicability. Older guides citing 114 controls describe the 2013 edition.

What is a Statement of Applicability (SoA)?

The SoA lists every Annex A control and records, for each, whether it applies, how it is implemented, and the justification if you have excluded it. Auditors treat it as the index to your ISMS, which is why keeping it current matters as much as creating it.

Do I need a consultant for ISO 27001?

Not necessarily. A consultant can speed up a first certification if you have never built an ISMS. Many certified teams, though, run and maintain theirs in software without an ongoing retainer, and some consultancies run several clients’ ISMSs from one shared workspace.

Can I reuse ISO 27001 evidence for SOC 2 or GDPR?

Largely, yes. ISO 27001 controls map heavily onto SOC 2 and GDPR, so most of the evidence you maintain for one carries over. The work is mapping it once and keeping a single source current rather than running a separate binder per framework.

Keep reading

ISO/IEC 27001 on the blog

  • Pass, fail, error: what a scheduled check proves
  • Seeding a risk register from a threat catalog
  • What ISO 9001 and ISO 27001 share, clause by clause

All ISO/IEC 27001 posts

See how your ISO 27001 setup would look in devguard.

The fastest way to know if this fits is a short conversation about how you run ISO 27001 today — what you maintain, where the audit-cycle effort goes, and what moving it would involve. No deck unless you want one.

Book a conversation
Sign in
Start for free
Book a conversationStart for free