ISO 27001: Clauses, Annex A and Certification

ISO 27001 explained: clauses, Annex A controls and certification

ISO 27001 is the international standard for information security management. It sets out how a company should identify risks to the information it holds, put controls in place, and prove to an independent auditor that the system works.

  • Glossary
  • Compliance

The short answer

ISO 27001 asks an organisation to work out what could go wrong with the information it holds, decide which controls reduce that risk, and show the whole arrangement is reviewed regularly. An independent certification body then audits the organisation and issues the certificate. The current version is ISO/IEC 27001:2022.

The arrangement the standard describes is called an ISMS, an information security management system. The name is heavier than the idea: it means written rules, a named owner for each one, and records showing the rules are followed. The standard is less interested in which tools you buy than in whether someone is accountable for security and can demonstrate it.

Most companies pursue certification because a customer asked for it. It is the security credential enterprise buyers recognise across Europe and Asia, so it usually surfaces during procurement or due diligence.

The two parts of ISO 27001

The standard has two parts, and they carry different weight. Clauses 4 to 10 are compulsory: no organisation is certified without meeting all of them. Annex A is a list of controls to choose from, selected according to the risks you identified.

Clauses 4 to 10 Mandatory. All must be met to certify. 4 Context of the organisation 5 Leadership 6 Planning and risk assessment 7 Support and competence 8 Operation 9 Performance evaluation 10 Improvement Annex A 93 controls, selected by risk, in four themes. Organisational Policies, suppliers, incident management 37 People 8 Physical Facilities, equipment, clear desk 14 Technological Access control, cryptography, logging 34
Swipe to see the full diagram. Block height reflects the number of controls in each theme. Organisational controls account for the largest share by some distance.

A common misunderstanding is that all 93 controls are compulsory. They are not. Controls are selected by risk assessment, and every exclusion is justified in the Statement of Applicability.

Which version applies

The 2022 edition replaced the 2013 one, reorganising Annex A from 114 controls into 93 and adding 11 new ones, including cloud services security and secure coding. The transition period closed on 31 October 2025, so all certification now runs against the 2022 edition.

The six documents you must have

An auditor assesses evidence, not intent. These six records are required whatever the size of the organisation.

ISMS scope

Which parts of the business, systems and locations are covered.

Information security policy

The approved statement of objectives, signed off by leadership.

Risk assessment and treatment

The risks identified and the decision taken on each one.

Statement of Applicability

Every Annex A control, whether it applies, and why any were excluded.

Internal audit results

Proof you audited yourself before the certification body arrived.

Management review records

Minutes showing leadership reviewed performance and acted on it.

How certification actually works

An accredited certification body runs a two-stage audit. The certificate then lasts three years, subject to annual surveillance audits.

GETTING CERTIFIED Gap analysis Current vs required Implement Controls and ISMS Internal audit Management review Stage 1 audit Documentation Stage 2 audit Controls in use Certificate issued, valid 3 years STAYING CERTIFIED Surveillance, year 1 Surveillance, year 2 Recertification, year 3
Swipe to see the full diagram. Stage 1 examines whether the documentation exists. Stage 2 examines whether the controls are actually operating.

ISO 27001 or SOC 2?

Buyers ask for one or the other. They are different instruments.

ISO 27001SOC 2
OutcomeA certificate against a published standardAn attestation report on controls
Issued byAn accredited certification bodyA licensed CPA firm
RecognitionInternational, strongest in Europe and AsiaMainly North America
CycleThree years, with annual surveillance auditsRepeated annually

How Osto supports ISO 27001

Osto maps controls across 200+ frameworks, ISO 27001 among them, and collects evidence directly from the modules that implement those controls: access management, logging, endpoint protection, vulnerability testing and cloud posture. Osto prepares you to be audit-ready and supplies the evidence. The audit itself, and the certificate, come from an accredited certification body.

Free security assessment

Build the controls, then collect the evidence

Osto deploys the security controls ISO 27001 expects and maps the evidence automatically. Tell us your scope and we will tailor a plan.

Get a free security assessment Book a platform walkthrough

200+ frameworks · Evidence from your own controls · One platform, everything

Frequently asked questions

What is ISO 27001?

ISO/IEC 27001 is the international standard for an information security management system. It sets out how an organisation identifies information security risks and selects, implements and reviews the controls that address them. Organisations are certified against it by an accredited certification body.

How many controls does ISO 27001 have?

The 2022 edition lists 93 controls in Annex A, arranged in four themes: organisational (37), people (8), physical (14) and technological (34). Not all of them apply to every organisation. Controls are selected on the basis of a risk assessment, and exclusions are justified in the Statement of Applicability.

What is the difference between ISO 27001 and ISO 27002?

ISO 27001 is the certifiable standard, containing the requirements an organisation must meet. ISO 27002 is a guidance document that explains how to implement the Annex A controls in practice. Organisations are certified against 27001; they are not certified against 27002.

How long does ISO 27001 certification take?

It depends on the scope and on how much already exists. The time goes into implementing controls, producing the mandatory documentation, and completing an internal audit and management review before the certification body runs its two-stage audit. Certification bodies also have their own scheduling lead times.

Is ISO 27001 mandatory?

No. Certification is voluntary and no law requires it. In practice it becomes a commercial requirement, since enterprise customers, particularly in Europe and Asia, frequently require it in contracts or vendor due diligence.