ISO 27001 vs ISO 27002: a common source of confusion, cleared up. One is the standard you certify against, the other is the guidance that tells you how.
TL;DR
ISO 27001 is the certifiable standard. It defines the ISMS and lists the Annex A controls you must consider. ISO 27002 is the companion guidance that explains, in detail, how to implement each of those controls.
You get certified against ISO 27001, never ISO 27002. Think of 27001 as the what and 27002 as the how. You use both, but only one appears on your certificate.
On this page
ISO 27001 vs ISO 27002: the short answer
The two are companions, not competitors. ISO 27001 is the standard that sets the requirements for an information security management system and lists the reference controls in Annex A. ISO 27002 is a separate document that takes each of those controls and explains how to implement it, with detailed guidance, purpose statements, and practical advice. You certify against 27001; you consult 27002 while doing the work.
How ISO 27001 and ISO 27002 fit together
In the 2022 versions, the two line up neatly. The 93 controls in Annex A of ISO 27001 mirror the controls detailed in ISO 27002, so you can move from the short control title in 27001 to the full implementation guidance in 27002 for the same reference number.
Side by side
| Aspect | ISO 27001 | ISO 27002 |
|---|---|---|
| What it is | The certifiable standard | Implementation guidance |
| What it answers | What your ISMS must do | How to implement each control |
| Can you certify against it? | Yes | No |
| Contains the ISMS clauses? | Yes, Clauses 4 to 10 | No |
| Level of control detail | Short titles in Annex A | Full guidance per control |
| When you use it | Scoping, certification, audit | While implementing controls |
How you use each in practice
In a real certification project, they play different roles at different moments. You work from ISO 27001 to understand the requirements, define your ISMS, and prepare for the audit. You reach for ISO 27002 when your team asks “so how do we actually do this control properly?” for a specific Annex A item.
The lean-team path: less guidance-chasing, more running controls
ISO 27002 exists because implementing controls correctly is genuinely hard, which is why a whole document is devoted to explaining how. For a lean team, the challenge is not reading the guidance, it is turning it into controls that actually operate and produce evidence.
From guidance to controls that actually run.
Osto is the one-stop cybersecurity and compliance platform built for fast-moving startups. Run the controls ISO 27002 describes, mapped straight to ISO 27001, with evidence in one place. No security team required.
Frequently asked questions
What is the difference between ISO 27001 and ISO 27002?
ISO 27001 is the certifiable standard that defines the ISMS and lists the Annex A controls. ISO 27002 is companion guidance explaining how to implement each control in detail. You certify against 27001; you consult 27002 while doing the work.
Can you get certified in ISO 27002?
No. ISO 27002 is guidance, not a certifiable standard. Certification is only against ISO 27001. ISO 27002 supports implementation but is never the thing you are audited against.
Do I need both ISO 27001 and ISO 27002?
In practice, yes. You work from ISO 27001 for the requirements and certification, and you use ISO 27002 for detailed guidance on how to implement each control well. They are designed to be used together.
How do the control numbers relate between them?
In the 2022 versions they align: the 93 Annex A controls in ISO 27001 mirror the controls detailed in ISO 27002, so the same reference number takes you from the short title to the full implementation guidance.
Which one do I start with?
Start with ISO 27001 to understand the requirements and define your ISMS, then use ISO 27002 as a reference when implementing specific controls. The certificate you are working toward is ISO 27001.

