ISO/IEC 27001
Information security management systems — Requirements. Updated: September 29, 2026.
ISO/IEC 27001 is the international standard for an information security management system, and it is the certificate most often demanded by enterprise customers outside North America. It is worth being precise about what it certifies, because the common misunderstanding causes real disappointment: it does not certify that your systems are secure. It certifies that you have a working management system for deciding what your security risks are, doing something about them, checking whether that worked, and improving it.
That sounds like a weaker claim, and in one sense it is. In another it is a stronger one, because a snapshot of good controls decays and a management system is what stops it.
Which Edition
The current edition is ISO/IEC 27001:2022. The transition from the 2013 edition closed on 31 October 2025, so certificates citing 2013 are no longer valid — worth checking if a supplier shows you one. A 2024 amendment added climate-change considerations to the context clauses, alongside the same change made across the other ISO management system standards.
What the Standard Actually Requires
The requirements are in clauses 4 to 10, and these are the part that is mandatory. Annex A, which everyone talks about, is a reference list you select from.
- Clause 4 — Context. Who your interested parties are, what they require of you, and what the scope of the system is. The scope decision is the single largest lever on cost and credibility, and it is made here.
- Clause 5 — Leadership. A policy, assigned roles, and demonstrable management commitment. Auditors test this by talking to senior people, and it is where certification attempts most often fail for reasons that have nothing to do with technology.
- Clause 6 — Planning. Risk assessment and risk treatment, plus measurable objectives. This is the engine of the whole standard.
- Clause 7 — Support. Resources, competence, awareness, communication, and document control.
- Clause 8 — Operation. Actually doing what you planned, and keeping the records that prove it.
- Clause 9 — Performance evaluation. Monitoring and measurement, internal audit, and management review. All three are mandatory and all three produce records.
- Clause 10 — Improvement. Handling nonconformities with corrective action, and improving continually.
Annex A, and Why It Is Less Technical Than Expected
You do not have to implement all 93. You assess your risks, decide which controls apply, and record the decision — including your reasons for excluding any — in the Statement of Applicability. The SoA is the most important document in the whole system and the first thing an auditor reads, because it is where your claims and your risk assessment have to agree.
The proportions on that chart are the useful finding. Only about a third of the controls are technological, which is why a company with genuinely excellent engineering can still be a long way from certifiable: what is missing is the supplier management, the documented incident process, the records of awareness training, and the evidence that any of it happened.
Getting Certified
A few things that are not obvious from the diagram:
- Stage 1 is supposed to produce findings. It is a readiness check, and an auditor telling you what is missing is the service you are paying for. Treating it as a failure is a misunderstanding.
- Step 4 cannot be shortened much. The auditor needs records of the system having operated — an internal audit that happened, a management review with minutes, incidents handled through the process, risks reviewed. A system switched on three weeks before the audit has none of that, and no amount of documentation substitutes.
- Nonconformities are graded. Minor ones usually allow the certificate to be issued with a corrective action plan; a major one has to be closed first, sometimes with a return visit.
- Choose the certification body on accreditation, not price. The body should be accredited by a national accreditation body operating under the international mutual recognition arrangement — in Bulgaria, the Bulgarian Accreditation Service. Unaccredited certificates exist, cost less, and are rejected by the procurement departments you bought them for.
What It Costs You in Practice
Beyond the certification body's fees, which scale with headcount, sites and scope complexity:
- Six to twelve months for a first certification from a standing start.
- A named owner with genuine time allocated. The most common cause of failure is not a missing control but nobody having been given the job.
- Evidence discipline, permanently. Decisions that were made but not recorded did not happen, as far as an audit is concerned. This is the habit change, and it is the one that annoys engineers most.
- An annual rhythm that never stops — internal audit, management review, risk reassessment, surveillance audit. Budget for it as an operating cost, not a project.
Where It Meets the Infrastructure
Most of the technological controls map onto work that is worth doing anyway, and that we cover elsewhere on this site: hardened builds, access control, patch management, logging and monitoring, backup and tested restores, network segmentation, and continuity planning. If those are in place and documented, the technological third of Annex A is largely a matter of writing down what you already do.
Related
ISO/IEC 27017 and ISO/IEC 27018 extend it for cloud services, ISO/IEC 27701 extends it for privacy, and SOC 2 is the North American alternative covering much of the same ground by a different mechanism.
This page explains the standard from an infrastructure perspective. We are not a certification body or an accredited auditor, and this is not legal advice. Confirm the current edition and your own obligations before committing.