Compliance · Global
ISO/IEC 27001:2022Certifiable via accredited body

ISO 27001

Plain-English definition

ISO 27001 is the international standard for an Information Security Management System (ISMS): a formal, documented, risk-based approach to managing information security, not a fixed technical checklist. Certification is issued by an accredited third-party certification body after an audit, and maintained through annual surveillance audits over a 3-year cycle.

Covers the 2022 revision, including the 93 Annex A controls and the Statement of Applicability requirement.

Who needs it

Any organization that wants a recognized, auditable information security credential, most often to satisfy enterprise customer due diligence, win contracts that require it, or formalize a security program that's outgrown informal management.

Key requirements

A documented ISMS scope, a risk assessment and treatment methodology, a Statement of Applicability mapping which of the 93 Annex A controls apply and why, management review, internal audit, and evidence of continual improvement (the PDCA cycle).

Cyber/privacy implications

Security decisions must be traceable to a documented risk assessment, not ad hoc judgment, and every control exclusion in the Statement of Applicability needs a defensible justification an auditor can challenge.

Assessment methodology

Gap assessment against Annex A controls, ISMS scope definition, risk assessment methodology build-out, and a readiness review ahead of the formal certification audit.

Implementation phases

01
Assess

Gap analysis against Annex A controls and current ISMS maturity.

02
Build

Draft the ISMS documentation, risk register, and Statement of Applicability.

03
Certify

Support through Stage 1 and Stage 2 certification audits with an accredited body.

Evidence & documentation requirements

Statement of Applicability, risk assessment and treatment plan, ISMS policy documentation, internal audit records, and management review minutes, all reviewable by the certification auditor.

Common mistakes

Treating the Statement of Applicability as a formality rather than a defensible risk decision; under-scoping the ISMS boundary to exclude systems that should be in scope; letting documentation drift from actual practice between annual surveillance audits.

Related standards

Expert review

Nitzan Levi
Nitzan Levi
Co-Founder, Cybecs · Co-Founder, RedRok · Executive Director, Privacy & GRC · CISM, CISSP, CDPSE, CCSK, CSA

FAQ

Do you perform the certification audit yourselves?
No, certification must be issued by an independent accredited certification body. We prepare you to pass that audit, and can help select a certification body.
How long does certification typically take?
Readiness work is usually 2 to 6 months depending on starting maturity, followed by the certification body's own audit scheduling.
Is ISO 27001 enough on its own for enterprise customers?
It covers most enterprise security due diligence, but some customers also require SOC 2 or framework-specific attestations; we can scope both together.

Request a Gap Assessment

See exactly where your ISMS stands against Annex A before you schedule a certification audit.

Request a Gap Assessment →