ISO 27001 is the international standard for information security management. It sets out how a company should identify risks to the information it holds, put controls in place, and prove to an independent auditor that the system works.
The short answer
ISO 27001 asks an organisation to work out what could go wrong with the information it holds, decide which controls reduce that risk, and show the whole arrangement is reviewed regularly. An independent certification body then audits the organisation and issues the certificate. The current version is ISO/IEC 27001:2022.
The arrangement the standard describes is called an ISMS, an information security management system. The name is heavier than the idea: it means written rules, a named owner for each one, and records showing the rules are followed. The standard is less interested in which tools you buy than in whether someone is accountable for security and can demonstrate it.
Most companies pursue certification because a customer asked for it. It is the security credential enterprise buyers recognise across Europe and Asia, so it usually surfaces during procurement or due diligence.
On this page
The two parts of ISO 27001
The standard has two parts, and they carry different weight. Clauses 4 to 10 are compulsory: no organisation is certified without meeting all of them. Annex A is a list of controls to choose from, selected according to the risks you identified.
A common misunderstanding is that all 93 controls are compulsory. They are not. Controls are selected by risk assessment, and every exclusion is justified in the Statement of Applicability.
Which version applies
The 2022 edition replaced the 2013 one, reorganising Annex A from 114 controls into 93 and adding 11 new ones, including cloud services security and secure coding. The transition period closed on 31 October 2025, so all certification now runs against the 2022 edition.
The six documents you must have
An auditor assesses evidence, not intent. These six records are required whatever the size of the organisation.
ISMS scope
Which parts of the business, systems and locations are covered.
Information security policy
The approved statement of objectives, signed off by leadership.
Risk assessment and treatment
The risks identified and the decision taken on each one.
Statement of Applicability
Every Annex A control, whether it applies, and why any were excluded.
Internal audit results
Proof you audited yourself before the certification body arrived.
Management review records
Minutes showing leadership reviewed performance and acted on it.
How certification actually works
An accredited certification body runs a two-stage audit. The certificate then lasts three years, subject to annual surveillance audits.
ISO 27001 or SOC 2?
Buyers ask for one or the other. They are different instruments.
| ISO 27001 | SOC 2 | |
|---|---|---|
| Outcome | A certificate against a published standard | An attestation report on controls |
| Issued by | An accredited certification body | A licensed CPA firm |
| Recognition | International, strongest in Europe and Asia | Mainly North America |
| Cycle | Three years, with annual surveillance audits | Repeated annually |
How Osto supports ISO 27001
Osto maps controls across 200+ frameworks, ISO 27001 among them, and collects evidence directly from the modules that implement those controls: access management, logging, endpoint protection, vulnerability testing and cloud posture. Osto prepares you to be audit-ready and supplies the evidence. The audit itself, and the certificate, come from an accredited certification body.
Free security assessment
Build the controls, then collect the evidence
Osto deploys the security controls ISO 27001 expects and maps the evidence automatically. Tell us your scope and we will tailor a plan.
Get a free security assessment Book a platform walkthrough200+ frameworks · Evidence from your own controls · One platform, everything
Frequently asked questions
What is ISO 27001?
ISO/IEC 27001 is the international standard for an information security management system. It sets out how an organisation identifies information security risks and selects, implements and reviews the controls that address them. Organisations are certified against it by an accredited certification body.
How many controls does ISO 27001 have?
The 2022 edition lists 93 controls in Annex A, arranged in four themes: organisational (37), people (8), physical (14) and technological (34). Not all of them apply to every organisation. Controls are selected on the basis of a risk assessment, and exclusions are justified in the Statement of Applicability.
What is the difference between ISO 27001 and ISO 27002?
ISO 27001 is the certifiable standard, containing the requirements an organisation must meet. ISO 27002 is a guidance document that explains how to implement the Annex A controls in practice. Organisations are certified against 27001; they are not certified against 27002.
How long does ISO 27001 certification take?
It depends on the scope and on how much already exists. The time goes into implementing controls, producing the mandatory documentation, and completing an internal audit and management review before the certification body runs its two-stage audit. Certification bodies also have their own scheduling lead times.
Is ISO 27001 mandatory?
No. Certification is voluntary and no law requires it. In practice it becomes a commercial requirement, since enterprise customers, particularly in Europe and Asia, frequently require it in contracts or vendor due diligence.

