What is ISO 27001? The world’s most recognised security certification, explained for founders, with an honest answer on when your startup actually needs it.
TL;DR
ISO 27001 is the international standard for information security. It certifies that your company runs a proper Information Security Management System (ISMS) and that the controls protecting your data actually work.
It is voluntary in law but often required in practice, especially for startups selling into Europe, APAC, and the Middle East. The current version is ISO 27001:2022, and the security work underneath is what really matters.
On this page
What is ISO 27001, exactly?
ISO/IEC 27001 is the internationally recognised standard for information security, published jointly by the International Organization for Standardization (ISO) and the International Electrotechnical Commission (IEC). Unlike SOC 2, which produces a report for a US audience, ISO 27001 produces a certificate recognised across the world. It tells buyers, partners, and regulators that your organisation manages information security in a structured, audited way.
The ISMS: the heart of ISO 27001
Everything in ISO 27001 revolves around the Information Security Management System (ISMS). This is the set of policies, processes, and responsibilities that govern how your organisation manages security risk. The standard’s mandatory clauses (4 to 10) define what a working ISMS looks like: leadership involvement, a risk assessment process, defined objectives, internal audits, and continual improvement.
The 93 Annex A controls
Alongside the ISMS clauses, ISO 27001 comes with Annex A, a reference catalogue of 93 security controls. This is not a mandatory checklist. It is a menu. Your risk assessment decides which controls apply to you, and you record those decisions in a Statement of Applicability.
The 2022 version organises the 93 controls into four themes:
Organizational
Policies, roles, supplier relationships, and how security is governed.
People
Screening, awareness, responsibilities, and conduct.
Physical
Facilities, equipment, and physical access to systems.
Technological
Access control, encryption, logging, secure development, and cloud security.
The current version, and a deadline you should know
The operative version is ISO/IEC 27001:2022. This matters because there was a hard cutover: certifications against the older 2013 version expired after 31 October 2025. Any ISO 27001 work today should target the 2022 revision, which reorganised the older set of 114 controls into the current 93 across four themes.
When is ISO 27001 required?
Like SOC 2, ISO 27001 is voluntary in the legal sense. No law forces you to certify. But it becomes a practical requirement in specific, predictable situations.
- You are selling into Europe, APAC, or the Middle East. ISO 27001 is the recognised name for security assurance in those markets.
- Buyers ask “are you ISO certified?” Enterprise, financial, and government buyers frequently make it a procurement condition.
- You are bidding for government or public-sector contracts. Many require or strongly prefer ISO 27001.
- You want a publicly displayable credential. Unlike a SOC 2 report shared under NDA, the ISO certificate can be shown openly.
- You operate across multiple countries. One globally recognised certificate is simpler than region-specific attestations.
How you get certified
Certification runs through an accredited certification body in a two-stage audit, and the certificate then lasts three years with checkups along the way.
The faster path for lean teams
Here is what trips up most startups on ISO 27001. The ISMS is real work, and the Annex A controls it points to, access control, encryption, logging, secure coding, cloud security, and the rest, have to actually exist and run. Teams that treat ISO as a documentation exercise stall at Stage 2, because the auditor tests whether the controls truly operate.
The startup-first way to reach ISO 27001.
Osto is the one-stop cybersecurity and compliance platform built for fast-moving startups. Run the controls ISO 27001 requires on one platform, map them to the standard automatically, and let the certificate follow from real security. No security team required.
Frequently asked questions
What is ISO 27001 in simple terms?
ISO 27001 is the international standard for information security. It certifies that your company runs a proper system, an Information Security Management System (ISMS), for identifying and managing security risks, and that the controls protecting your data actually operate.
Is ISO 27001 mandatory?
Not legally. No law requires it. But it becomes a practical requirement when buyers, especially in Europe, APAC, the Middle East, or the public sector, make it a condition of doing business, or when you want a globally recognised, publicly displayable security credential.
How many controls are in ISO 27001?
The 2022 version lists 93 controls in Annex A, grouped into four themes: Organizational (37), People (8), Physical (14), and Technological (34). They are a menu, not a mandatory checklist; your risk assessment decides which apply.
What is the difference between ISO 27001 and an ISMS?
ISO 27001 is the standard; the ISMS is the thing it certifies. The Information Security Management System is your actual set of policies, processes, and controls for managing security risk. ISO 27001 defines what a sound ISMS must contain and how it is audited.
Which version of ISO 27001 is current?
ISO/IEC 27001:2022. Certifications against the older 2013 version expired after 31 October 2025, so all new work should target the 2022 revision, which organises 93 Annex A controls into four themes.

