← ISO and SOC Certifications

ISO/IEC 27001

Information security management systems — Requirements. Updated: September 29, 2026.

ISO/IEC 27001 is the international standard for an information security management system, and it is the certificate most often demanded by enterprise customers outside North America. It is worth being precise about what it certifies, because the common misunderstanding causes real disappointment: it does not certify that your systems are secure. It certifies that you have a working management system for deciding what your security risks are, doing something about them, checking whether that worked, and improving it.

That sounds like a weaker claim, and in one sense it is. In another it is a stronger one, because a snapshot of good controls decays and a management system is what stops it.

Which Edition

The current edition is ISO/IEC 27001:2022. The transition from the 2013 edition closed on 31 October 2025, so certificates citing 2013 are no longer valid — worth checking if a supplier shows you one. A 2024 amendment added climate-change considerations to the context clauses, alongside the same change made across the other ISO management system standards.

What the Standard Actually Requires

The requirements are in clauses 4 to 10, and these are the part that is mandatory. Annex A, which everyone talks about, is a reference list you select from.

Annex A, and Why It Is Less Technical Than Expected

Bar showing the 93 Annex A controls split into 37 organizational, 8 people, 14 physical and 34 technological

You do not have to implement all 93. You assess your risks, decide which controls apply, and record the decision — including your reasons for excluding any — in the Statement of Applicability. The SoA is the most important document in the whole system and the first thing an auditor reads, because it is where your claims and your risk assessment have to agree.

The proportions on that chart are the useful finding. Only about a third of the controls are technological, which is why a company with genuinely excellent engineering can still be a long way from certifiable: what is missing is the supplier management, the documented incident process, the records of awareness training, and the evidence that any of it happened.

Getting Certified

Eight steps to certification: gap analysis, scope and risk, implementation, running the system, internal audit and management review, stage 1, stage 2, and the certificate

A few things that are not obvious from the diagram:

What It Costs You in Practice

Beyond the certification body's fees, which scale with headcount, sites and scope complexity:

Where It Meets the Infrastructure

Most of the technological controls map onto work that is worth doing anyway, and that we cover elsewhere on this site: hardened builds, access control, patch management, logging and monitoring, backup and tested restores, network segmentation, and continuity planning. If those are in place and documented, the technological third of Annex A is largely a matter of writing down what you already do.

Related

ISO/IEC 27017 and ISO/IEC 27018 extend it for cloud services, ISO/IEC 27701 extends it for privacy, and SOC 2 is the North American alternative covering much of the same ground by a different mechanism.

This page explains the standard from an infrastructure perspective. We are not a certification body or an accredited auditor, and this is not legal advice. Confirm the current edition and your own obligations before committing.