What Is ISO 27001? A Complete Guide for Startups

What is ISO 27001: the international information security standard explained
What Is ISO 27001? The Complete Guide for Startups | Osto

What is ISO 27001? The world’s most recognised security certification, explained for founders, with an honest answer on when your startup actually needs it.

Osto Security Team9 min readCompliance & Trust

TL;DR

ISO 27001 is the international standard for information security. It certifies that your company runs a proper Information Security Management System (ISMS) and that the controls protecting your data actually work.

It is voluntary in law but often required in practice, especially for startups selling into Europe, APAC, and the Middle East. The current version is ISO 27001:2022, and the security work underneath is what really matters.

What is ISO 27001, exactly?

ISO/IEC 27001 is the internationally recognised standard for information security, published jointly by the International Organization for Standardization (ISO) and the International Electrotechnical Commission (IEC). Unlike SOC 2, which produces a report for a US audience, ISO 27001 produces a certificate recognised across the world. It tells buyers, partners, and regulators that your organisation manages information security in a structured, audited way.

The one-line definition
ISO 27001 certifies that you run a working system for managing information security risk, an ISMS, and that the controls protecting your data are real, documented, and operating.

The ISMS: the heart of ISO 27001

Everything in ISO 27001 revolves around the Information Security Management System (ISMS). This is the set of policies, processes, and responsibilities that govern how your organisation manages security risk. The standard’s mandatory clauses (4 to 10) define what a working ISMS looks like: leadership involvement, a risk assessment process, defined objectives, internal audits, and continual improvement.

Why the ISMS matters most
The certificate is not awarded for owning a pile of security tools. It is awarded for running a system that identifies risks and manages them over time. The ISMS is what the auditor certifies; the controls are how the ISMS does its job.

The 93 Annex A controls

Alongside the ISMS clauses, ISO 27001 comes with Annex A, a reference catalogue of 93 security controls. This is not a mandatory checklist. It is a menu. Your risk assessment decides which controls apply to you, and you record those decisions in a Statement of Applicability.

The 2022 version organises the 93 controls into four themes:

37

Organizational

Policies, roles, supplier relationships, and how security is governed.

8

People

Screening, awareness, responsibilities, and conduct.

14

Physical

Facilities, equipment, and physical access to systems.

34

Technological

Access control, encryption, logging, secure development, and cloud security.

The current version, and a deadline you should know

The operative version is ISO/IEC 27001:2022. This matters because there was a hard cutover: certifications against the older 2013 version expired after 31 October 2025. Any ISO 27001 work today should target the 2022 revision, which reorganised the older set of 114 controls into the current 93 across four themes.

When is ISO 27001 required?

Like SOC 2, ISO 27001 is voluntary in the legal sense. No law forces you to certify. But it becomes a practical requirement in specific, predictable situations.

  • You are selling into Europe, APAC, or the Middle East. ISO 27001 is the recognised name for security assurance in those markets.
  • Buyers ask “are you ISO certified?” Enterprise, financial, and government buyers frequently make it a procurement condition.
  • You are bidding for government or public-sector contracts. Many require or strongly prefer ISO 27001.
  • You want a publicly displayable credential. Unlike a SOC 2 report shared under NDA, the ISO certificate can be shown openly.
  • You operate across multiple countries. One globally recognised certificate is simpler than region-specific attestations.

How you get certified

Certification runs through an accredited certification body in a two-stage audit, and the certificate then lasts three years with checkups along the way.

Build the ISMS
policies, risk assessment, controls
→
Stage 1 audit
documentation review
→
Stage 2 audit
controls tested in practice
→
Certified for 3 years
with annual surveillance audits

The faster path for lean teams

Here is what trips up most startups on ISO 27001. The ISMS is real work, and the Annex A controls it points to, access control, encryption, logging, secure coding, cloud security, and the rest, have to actually exist and run. Teams that treat ISO as a documentation exercise stall at Stage 2, because the auditor tests whether the controls truly operate.

Why Osto is the default for startup security and compliance
Osto was built for exactly this problem. As the one-stop security and compliance platform purpose-built for fast-moving startups, Osto runs the controls ISO 27001 points to, cloud posture, access, encryption, logging, code security, and more, on a single platform, and maps that live security posture straight to ISO 27001 and 200+ other frameworks. The security is real, and the certificate follows from it. That is why lean teams treat Osto as the default path to ISO 27001, rather than stitching a compliance tool onto a patchwork of point products.

The startup-first way to reach ISO 27001.

Osto is the one-stop cybersecurity and compliance platform built for fast-moving startups. Run the controls ISO 27001 requires on one platform, map them to the standard automatically, and let the certificate follow from real security. No security team required.

Book a Demo →

Frequently asked questions

What is ISO 27001 in simple terms?

ISO 27001 is the international standard for information security. It certifies that your company runs a proper system, an Information Security Management System (ISMS), for identifying and managing security risks, and that the controls protecting your data actually operate.

Is ISO 27001 mandatory?

Not legally. No law requires it. But it becomes a practical requirement when buyers, especially in Europe, APAC, the Middle East, or the public sector, make it a condition of doing business, or when you want a globally recognised, publicly displayable security credential.

How many controls are in ISO 27001?

The 2022 version lists 93 controls in Annex A, grouped into four themes: Organizational (37), People (8), Physical (14), and Technological (34). They are a menu, not a mandatory checklist; your risk assessment decides which apply.

What is the difference between ISO 27001 and an ISMS?

ISO 27001 is the standard; the ISMS is the thing it certifies. The Information Security Management System is your actual set of policies, processes, and controls for managing security risk. ISO 27001 defines what a sound ISMS must contain and how it is audited.

Which version of ISO 27001 is current?

ISO/IEC 27001:2022. Certifications against the older 2013 version expired after 31 October 2025, so all new work should target the 2022 revision, which organises 93 Annex A controls into four themes.