
Guide
What is ISO 27001?
What the certificate actually certifies, why the scope statement matters more than the certificate, what changed in the 2022 revision, and the transition deadline that has already passed.
ISO/IEC 27001 is the international standard for an information security management system. It is worth being precise about that phrase, because the most common misreading of a certificate is that it says an organisation is secure. It does not. It says an organisation runs a defined management system over a defined scope, and an accredited body has checked that the system works. The scope is the part buyers should read and almost nobody does. Two other things are frequently out of date in published summaries: the 2022 revision restructured Annex A into 93 controls, and the transition deadline for the old version passed on 31 October 2025.
Last reviewed:
What the certificate certifies, and what it does not
ISO/IEC 27001 specifies requirements for an information security management system: a documented, operating process for deciding what could go wrong, choosing what to do about it, doing it, and checking whether it worked.
Certification means an accredited body audited that system and found it conformant. It is genuine evidence, and it is evidence of a specific thing.

- 193 controls, four themes 37 organisational, 8 people, 14 physical, 34 technological
- 2The scope statement Written by the organisation. Read this, not the logo
- 3A three year cycle Two-stage audit, then annual surveillance
What a certificate does not say is worth stating explicitly, because supplier assurance questionnaires routinely treat it as though it did.
It does not say the organisation is secure. It does not say it has never been breached. It does not say any particular control is implemented, because Annex A controls can be excluded with justification. And it says nothing at all about parts of the business outside the scope.
Read the scope, not the certificate
This is the single most useful habit available to anyone assessing a supplier, and it takes about ninety seconds.
The organisation writes its own scope statement. A legitimate, accredited, entirely genuine certificate can be scoped to one product, one team, one office or one data centre. The certificate looks identical either way. The logo on the supplier's website looks identical either way.
A scope worth relying on
- Names the service you are actually buying.
- Covers the locations and people who will handle your data.
- Includes the development and support functions behind the product.
- Matches what the sales conversation described.
A scope that tells you very little
- Names a subsidiary, a single office, or a corporate function.
- Excludes the platform your data will sit on.
- Covers the ISMS itself rather than any delivery capability.
- Is vague enough that it could mean anything.
So ask for two documents rather than the certificate: the scope statement and the Statement of Applicability. The first tells you what was audited. The second tells you what the organisation decided it did not need, and why, which is frequently the more revealing of the two.
A supplier that will not share either is telling you something as well.
Annex A, and what the 2022 revision changed
The 2022 revision restructured the control set substantially. The 2013 version listed 114 controls across 14 domains. The current version lists 93 across four themes, having merged overlapping controls and added eleven that did not previously exist.
93
controls in Annex A
Down from 114, by merging rather than removing
37
organisational
The largest theme, A.5
34
technological
A.8, and where most new controls landed
11
controls that are new
Including cloud, secure coding and threat intelligence
The eleven new controls are the clearest signal of what changed in practice, because they name things the 2013 version had no home for.
The eleven controls introduced in 2022
| Ref | Control | Why it appeared |
|---|---|---|
| A.5.7 | Threat intelligence | Defence is expected to be informed by what attackers are actually doing |
| A.5.23 | Information security for use of cloud services | The 2013 set had no control naming cloud at all |
| A.5.30 | ICT readiness for business continuity | Continuity planning that includes the technology, not just the process |
| A.7.4 | Physical security monitoring | Detection in physical space, alongside logical monitoring |
| A.8.9 | Configuration management | Baselines and drift, which underpin most other technical controls |
| A.8.10 | Information deletion | Data that should no longer exist is a liability that accumulates |
| A.8.11 | Data masking | Reducing exposure in test, analytics and support environments |
| A.8.12 | Data leakage prevention | Egress as a first-class concern |
| A.8.16 | Monitoring activities | Detection as an explicit requirement rather than an implied one |
| A.8.23 | Web filtering | Restricting what internal systems can reach outward |
| A.8.28 | Secure coding | Security in development, named rather than assumed |
Read that list as a description of what changed in the threat landscape between 2013 and 2022. Cloud, egress, detection and software supply are the themes, and they are the same themes that appear in NIS2's Article 21.
Annex A is not the standard
This is the misunderstanding that costs the most time, and it is visible in almost every summary of ISO 27001 published online, including the ones that list all 93 controls and stop there.
The requirements of the standard are clauses 4 to 10. Annex A is a reference set of controls you select from when treating risk. It is normative, so you must consider it, and it is not the thing you are certified against. An organisation can exclude Annex A controls with justification and still certify. An organisation cannot exclude a clause.
The clauses, which are the actual requirements
| Clause | What it requires | What auditors find missing |
|---|---|---|
| 4. Context | Understand the organisation, interested parties, and set the ISMS scope | A scope written for convenience rather than derived from anything |
| 5. Leadership | Policy, roles and responsibilities, and demonstrated top management commitment | Commitment asserted in a policy nobody at that level has read |
| 6. Planning | Risk assessment and treatment, the Statement of Applicability, security objectives | Objectives that are not measurable, so nothing can be reported against them |
| 7. Support | Resources, competence, awareness, communication, documented information | Competence claimed without any record of how it was established |
| 8. Operation | Actually carrying out the planned processes and keeping evidence | The plan exists; the records that it ran do not |
| 9. Performance evaluation | Monitoring, measurement, internal audit, management review | Internal audit done by the person who built the system |
| 10. Improvement | Nonconformity, corrective action, continual improvement | A corrective action log with no closed items in it |
Two consequences worth acting on. If you are implementing, the clauses are where the effort actually goes and the controls are comparatively straightforward, which is the reverse of how most projects are planned. And if you are assessing a supplier, asking about clause 9 tells you far more than asking which controls they implemented: an organisation that runs genuine internal audits and management reviews has a system, and one that does not has a document set.
What actually fails an audit
Auditors raise nonconformities, and the distinction between the two kinds decides whether you get a certificate this year.
A major nonconformity is a systemic failure: an absent required process, a total breakdown of one, or several minors pointing at the same root cause. It blocks certification until it is resolved and verified.
A minor nonconformity is a lapse in an otherwise functioning process, and is normally closed through corrective action without blocking the certificate.
ISO 27001 or SOC 2
Buyers ask for one or the other and the two are not equivalent, so it is worth knowing which question each answers before choosing.
ISO 27001 certifies a management system against an international standard, by an accredited body, and produces a certificate with a scope. It is a pass-or-fail assessment of whether the system conforms. It is the more widely recognised of the two outside the United States, and it is what European procurement and NIS2-driven supply chain questionnaires tend to name.
SOC 2 is an attestation report written by a licensed accountant, against trust services criteria, describing controls and, in a Type II report, testing their operation over a period. The output is a long report you read rather than a certificate you display. It is dominant in United States technology procurement.
The practical differences: ISO 27001 requires you to define scope and justify exclusions; SOC 2 requires you to select criteria and describe controls. ISO gives a buyer a short document to check, SOC 2 gives them a detailed one to read. Organisations selling into both markets frequently end up doing both, and the overlap in underlying work is substantial even though neither certificate satisfies the other requirement.
The Statement of Applicability
Clause 6.1.3 requires a Statement of Applicability: a record of every Annex A control, whether it is applicable, whether it is implemented, and the justification either way.
It is the most under-appreciated document in the standard. Everything else describes intent; this records decisions. An organisation that has excluded a control has to say so and say why, in writing, to an auditor.
Two practical uses follow. If you are implementing, the Statement of Applicability is the artefact that forces the honest conversation about what you are genuinely going to do rather than what the policy claims. If you are assessing a supplier, it is the document that shows you their exclusions, which is where the interesting questions live.
The transition deadline that has already passed
Most published guidance on ISO 27001 still describes the move from the 2013 version to 2022 as something to plan for. It is not.
The 2013 to 2022 transition, which is over
Oct 2022
ISO/IEC 27001:2022 published
Annex A restructured into 93 controls across four themes.
Feb 2024
Amendment 1 published
Climate change added to clauses 4.1 and 4.2. No new Annex A controls.
1 May 2024
New audits must use the 2022 version
Any initial or recertification audit starting from this date is conducted against 2022.
31 Oct 2025
2013 certificates cease to be valid
The transition window closed. Certificates not converted by this date expired rather than lapsing into a grace period.
The consequence for an organisation that missed it is worth stating plainly, because it is harsher than a missed deadline usually is: there is no transition route any more. Conversion was a defined, lighter process available until the deadline. After it, the path back to certification is a full initial certification, stage one and stage two, as though the organisation had never been certified.
What certification actually involves
From nothing to a certificate
- 1
Define the scope, carefully
weeks 1 to 3
This decision shapes cost, effort and how much the certificate is worth to a buyer. Narrow scopes certify faster and persuade less.
- 2
Assess risk and decide treatment
weeks 3 to 8
Clause 6.1. Identify what could go wrong, decide what to do, record who owns it. This drives everything downstream.
- 3
Produce the Statement of Applicability
weeks 8 to 10
All 93 controls, applicable or not, implemented or not, justified either way.
- 4
Operate the system and collect evidence
3 to 6 months
The part that cannot be compressed. An auditor needs records of the system running, not a description of how it would run.
- 5
Internal audit and management review
1 month before
Both are mandatory clauses and both are commonly left until an auditor asks. Doing them properly finds the gaps first.
- 6
Stage one, then stage two
the audit
Stage one reviews documentation and readiness; stage two tests whether the system operates. Certificate runs three years with annual surveillance.
What it costs, honestly
Published figures for ISO 27001 are unusually unreliable because they routinely quote one component and omit the rest. There are four, and only the first has a list price.
Certification body fees are quoted per audit day and scale with headcount, sites and scope complexity. For a small organisation with a single site and a narrow scope this is the smallest of the four numbers, and it recurs: annual surveillance audits for two years, then recertification in year three.
Internal effort is the largest cost and almost never appears in a quote. Someone has to run the risk assessment, write the documented information, chase evidence and prepare for the audit. For a first certification that is routinely a substantial fraction of one person's year, whether or not anybody counts it that way.
Consultancy, if used, sits between them and varies enormously by how much of the work is transferred rather than guided.
Remediation is the genuine unknown. The risk assessment produces a treatment plan, and whatever that plan says needs buying or building is uncosted until you have done it. An organisation that has never had an asset inventory or a joiners and leavers process will find the standard has opinions about both.
The reliable planning statement is therefore not a number. It is that scope drives everything: a narrow first scope certifies faster and cheaper, and buys less. Widening later is a smaller exercise than starting wide, which is the argument for a deliberate narrow start rather than an accidental one.
Amendment 1, and why climate change is in a security standard
In February 2024 ISO published Amendment 1 to ISO/IEC 27001:2022, adding climate change to the context clauses. Clause 4.1 now requires an organisation to determine whether climate change is a relevant issue for its management system, and a note to clause 4.2 acknowledges that interested parties may have climate-related requirements.
No Annex A controls were added, and the change is small in text. It is worth knowing about for two reasons: it applies to every certified organisation regardless of when it certified, and an auditor can ask about it. The defensible answer is a recorded determination, including a determination that it is not relevant, with a reason.
Where to go next
The Annex A browser on this site lists all 93 controls with what each one actually asks for, filterable by theme, and marks the eleven that are new. It is faster than reading the standard and it is free.
The Statement of Applicability generator produces the clause 6.1.3 document from your own decisions, in your browser, without uploading anything.
If the reason you are reading this is NIS2, the mapping is close enough to be useful: the ten measures in Article 21(2) sit almost cleanly on top of a working ISMS, which is why organisations with one find NIS2 an extension rather than a rebuild.
Common questions
›What does ISO 27001 certification actually prove?
That an organisation operates an information security management system meeting the standard's requirements, across a scope it defined itself, and that an accredited certification body audited it. It is evidence of a working process for identifying and treating risk. It is not a statement that the organisation is secure, that it has never been breached, or that any particular control is in place.
›Why does the scope statement matter so much?
Because the organisation writes it, and it can be narrow. A certificate scoped to one product line, one office or one data centre says nothing about the rest of the company. When assessing a supplier, the scope statement and the Statement of Applicability tell you what was actually audited; the certificate alone tells you only that something was.
›How many controls are in ISO 27001:2022?
Annex A lists 93 controls in four themes: 37 organisational, 8 people, 14 physical and 34 technological. The 2013 version had 114 controls across 14 domains. The 2022 revision merged overlapping controls and introduced 11 new ones, including threat intelligence, cloud services, secure coding and data leakage prevention.
›Is the ISO 27001:2013 transition deadline still open?
No. It closed on 31 October 2025, and certificates against the 2013 version ceased to be valid on that date. An organisation that missed it does not transition now; it undergoes a full initial certification against the 2022 version. Any guide still describing the transition as upcoming is out of date.
›What is the Statement of Applicability?
A document listing every Annex A control, whether it applies, whether it is implemented, and the justification for including or excluding it. It is a mandatory output of clause 6.1.3 and is the single most useful document to request from a supplier, because it shows what the organisation decided it did not need and why.
›How long does ISO 27001 certification take?
For an organisation starting without a management system, six to twelve months to reach the audit is typical, followed by a two-stage certification audit. The certificate then runs three years, with surveillance audits usually annual and a recertification audit before it expires. The variable is rarely the controls; it is producing the evidence that the system operates.
›Does ISO 27001 now require climate change to be considered?
Yes, in a limited way. Amendment 1, published in February 2024, added climate change to clause 4.1, so an organisation must determine whether it is a relevant issue for the management system, and a note to clause 4.2 acknowledging that interested parties may have climate-related requirements. No Annex A controls were added.
Where to go next