Standard · Current edition: ISO/IEC 27001:2022

ISO/IEC 27001 Certification

Information security management systems

ISO/IEC 27001 is the international reference standard for information security. Certification demonstrates to customers, partners and authorities that the organisation systematically manages risks to the confidentiality, integrity and availability of information.

Current edition
ISO/IEC 27001:2022
Intended for
IT and software companies, cloud and outsourcing providers, financial services, healthcare, telecommunications and any organisation processing sensitive information
Certificate validity
3 years, with annual surveillance audits
Integrates with
ISO 9001
Overview

What is ISO 27001

ISO/IEC 27001:2022 specifies the requirements for establishing, implementing, maintaining and continually improving an information security management system (ISMS). The core of the standard is the information security risk assessment and treatment process, on the basis of which the organisation selects the necessary controls and documents them in the Statement of Applicability.

Annex A of the 2022 edition contains 93 reference controls grouped into four themes: organisational controls, people controls, physical controls and technological controls. Controls introduced in 2022 include threat intelligence, information security for use of cloud services, ICT readiness for business continuity, monitoring activities, web filtering and secure coding.

ISO/IEC 27001 certification is increasingly a contractual condition in relationships with enterprise and public sector customers, and a means of demonstrating the technical and organisational measures required by the GDPR and by network and information systems security legislation (NIS2).

Who it is for
  • Software development companies, SaaS and managed IT service providers
  • Outsourcing providers (BPO, contact centres, data processing)
  • Financial institutions, fintech, insurance and their suppliers
  • Organisations in healthcare, telecommunications, energy and other sectors covered by NIS2
  • Any organisation that wants to demonstrate a verifiable level of information security to its customers
Benefits

Benefits of ISO 27001 certification

01

Contractual requirement met

A credible response to security questionnaires and to the requirements of enterprise and public sector customers.

02

Risks managed systematically

Risk assessment and treatment become a repeatable process with owners and deadlines.

03

Support for GDPR and NIS2

Demonstrating the appropriate technical and organisational measures required by data protection and cybersecurity legislation.

04

Operational resilience

Business continuity, incident management and ICT readiness reduce the impact of security events.

05

Customer trust

An internationally recognised certificate, verifiable online, rather than self-declarations.

06

Supplier control

Security requirements in supplier relationships and in the use of cloud services.

Structure of the standard

Main requirements of the standard

The standard follows the high level structure (Annex SL) common to ISO management system standards, with its requirements set out in clauses 4 to 10.

  1. Clause 4

    Context of the organisation

    Internal and external issues, interested parties and their requirements, the scope of the ISMS, including interfaces and dependencies with other organisations.

  2. Clause 5

    Leadership

    Management commitment, the information security policy, roles, responsibilities and authorities.

  3. Clause 6

    Planning

    Information security risk assessment and treatment, the Statement of Applicability, security objectives and planning of changes.

  4. Clause 7

    Support

    Resources, competence, awareness, communication and documented information.

  5. Clause 8

    Operation

    Operational planning and control, performing risk assessments at planned intervals and implementing the risk treatment plan.

  6. Clause 9

    Performance evaluation

    Monitoring, measurement, analysis and evaluation, internal audit and management review.

  7. Clause 10

    Improvement

    Continual improvement, nonconformity and corrective action.

Edition notes

The 2022 edition and the end of the transition

ISO/IEC 27001:2022 replaced the 2013 edition. The transition period ended on 31 October 2025; all valid certificates must be issued to the 2022 edition, with Annex A restructured into 4 themes and 93 controls.

Amendment 1:2024 on climate change

Clauses 4.1 and 4.2 require determining the relevance of climate change for the ISMS, for example regarding infrastructure availability and business continuity.

How It Works

The Certification Process

A clear and transparent process, from application to certificate issuance.

  1. 01

    Application and quotation

    Send us your organisation's details and the standard you are aiming for. We review your application and prepare a tailored quotation, including the audit duration and plan.

  2. 02

    Stage 1 audit

    We review your management system documentation and assess how ready your organisation is for the certification audit.

  3. 03

    Stage 2 audit

    The on-site audit checks that the system is implemented and effective against the requirements of the standard.

  4. 04

    Decision and certificate

    The certification committee reviews the audit report and issues the certificate, valid for 3 years.

Maintaining certification

Annual surveillance audits and a recertification audit at the end of the three-year cycle keep your certificate valid without interruption.

Certification Regulations
Frequently asked questions

Frequently asked questions about ISO 27001

Can't find the answer you are looking for?

Contact us
What is the Statement of Applicability (SoA)?
It is the document in which the organisation lists the Annex A controls (and any additional controls), indicates for each whether it is applicable or excluded, the justification and the implementation status. The SoA links the results of the risk assessment to the implemented controls and is verified in detail during the audit.
Does ISO/IEC 27001 cover GDPR requirements?
Partially. ISO/IEC 27001 demonstrates the technical and organisational security measures, but does not cover all GDPR obligations (legal bases, data subject rights, records of processing). The ISO/IEC 27701 extension specifically addresses the management of personal information.
Is the organisation or the software product certified?
The information security management system of the organisation is certified, for a defined scope (for example, the development and operation of a platform, a data centre, a service). Products themselves are not ISO/IEC 27001 certified.
What documents and evidence are needed for the audit?
The ISMS scope, the security policy, the risk assessment methodology and results, the risk treatment plan, the Statement of Applicability, evidence that controls operate (logs, access reviews, restore tests, incident management, training), internal audit reports and the management review.
How does it relate to NIS2?
NIS2 legislation requires essential and important entities to take cybersecurity risk management measures. An ISMS certified to ISO/IEC 27001 provides a structured framework for demonstrating many of these measures, although the specific legal obligations (incident notification, registration with the authority) remain the responsibility of the organisation.
Related standards

Integrated certification

Standards that share the same structure can be implemented as one integrated system and audited together in a single combined audit, reducing total audit time.

Contact

Request a quote for ISO 27001 certification

Tell us a little about your organisation and the standard you are aiming for. We will come back to you with a quotation and a proposed audit schedule as soon as possible.

Working Hours
L-V: 09:00 - 18:00
Contact us