What is ISO 27001? The standard, the controls and certification

What is ISO 27001? The standard, the controls and certification

Written By
13 min read
Last Updated On17 Sept 2026

TLDR

ISO 27001 is the international standard for information security, built around a management system (ISMS) that protects confidentiality, integrity and availability. The requirements sit in clauses 4 to 10, and Annex A adds 93 controls across four themes, each of which you justify as applicable or excluded in a Statement of Applicability. An accredited certification body audits in two stages, documentation first and practice second, and the certificate is valid for three years with annual surveillance audits.

ISO 27001 is the international standard for information security. It sets out how to build an information security management system, an ISMS, and what that system has to do. Certification means an independent auditor has checked that the system works in your organisation, not just on paper. This guide walks through what the standard asks for: the requirements in clauses 4 to 10, the 93 controls in Annex A, the documents you must be able to show, and how the audit itself works.

What ISO 27001 is

ISO 27001, in full ISO/IEC 27001, is a globally recognised standard for information security. That global recognition is the point: a certificate is read the same way in London, Berlin, Singapore and New York, which is why it turns up in procurement questionnaires everywhere. The current edition dates from 2022, with a 2024 amendment that adds climate change to the factors you weigh when determining context.

At its centre is the information security management system, the ISMS. That is not a tool you buy. It is a structured way of protecting information: policies, procedures, technical measures and the people who run them, working as one system. The standard does not tell you which technology to use. It tells you to know your risks, put deliberate measures against them, and be able to demonstrate those measures work.

Three ideas run through the whole standard:

  • Confidentiality means information is only available to those entitled to it. A leaked customer list breaks it.
  • Integrity means information stays accurate and complete. Wrong financial figures or a corrupted database break it.
  • Availability means information is there when you need it. A site that is down, or a backup you cannot reach, breaks it.

What the standard requires: clauses 4 to 10

The first three clauses cover scope, references and definitions. The requirements an auditor tests you against sit in clauses 4 to 10:

  • Clause 4, context of the organisation. Who your interested parties are, what they require, and which part of the organisation falls inside the ISMS scope.
  • Clause 5, leadership. Management sets the policy, assigns roles and responsibilities, and makes resources available.
  • Clause 6, planning. The risk assessment, the choice of treatment per risk, and measurable information security objectives.
  • Clause 7, support. Competence, awareness, communication and control of documented information.
  • Clause 8, operation. Actually running those processes, and keeping risk assessments current when things change.
  • Clause 9, performance evaluation. Monitoring and measurement, an internal audit, and a management review.
  • Clause 10, improvement. Recording nonconformities and acting on them.

Clause 6 is about your risks and clause 9 is about evidence that the system works. Together they form the Plan-Do-Check-Act cycle the rest of the standard rests on. Each clause broken down requirement by requirement sits in the ISO 27001 reference guide.

Annex A: 93 controls in four themes

Annex A lists 93 controls across four themes:

  • Organisational, 37 controls: policies, roles, supplier relationships, incident management, continuity.
  • People, 8 controls: screening, awareness, disciplinary process, remote working.
  • Physical, 14 controls: building access, equipment security, cabling, storage media.
  • Technological, 34 controls: access control, cryptography, logging, network security, secure development.

You do not have to apply all of them. You do have to justify, control by control, whether it applies and why you excluded anything. That reasoning goes into the Statement of Applicability, and it is usually the first document an auditor asks for, because it shows every decision you made in one place.

This is where the 2022 edition differs most from the old one. The 114 controls in fourteen sections became 93 controls in four themes, with eleven genuinely new subjects, among them threat intelligence, information security for cloud services, data masking and data leakage prevention. The related standard ISO 27002 explains how to implement each one, which is the difference between ISO 27001 and ISO 27002.

The documents you must have

The standard calls for "documented information" in several places. Taken together that comes down to:

  • the ISMS scope
  • the information security policy
  • the risk assessment and risk treatment process, plus their results
  • the Statement of Applicability
  • the information security objectives
  • evidence of competence for people with a role in the ISMS
  • the results of monitoring and measurement
  • the internal audit programme and its results
  • the results of the management review
  • records of nonconformities and corrective actions

Writing policy is the easy half. The hard half is evidence that the controls actually run: access reviews, test results, management review minutes, closed incidents. You collect that through the year, not in the week before the audit.

How certification works

The order is fixed. First you set the scope: which parts of the organisation, which systems and which information the ISMS covers. Then you assess risk and decide which Annex A controls you apply, with a justification for what you leave out. Then the system has to run for real: policy approved, evidence accumulating, an internal audit completed and a management review held.

Only then does a certification body get involved, and it audits in two stages. Stage 1 examines your documentation: is the system there and is it complete. Stage 2 examines how it works in practice, through interviews and sampling your evidence. That audit is carried out by an independent, accredited certification body. A software vendor never certifies you, which is precisely what gives the certificate its value.

The certificate is then valid for three years, with a surveillance audit each year and a recertification audit at the end. What it costs depends on your size and scope, because the certification body charges per audit day. ISO 27001 costs covers the budget, and planning your ISO 27001 journey puts the phases on a timeline.

Is ISO 27001 mandatory

No. ISO 27001 is a voluntary standard. In practice it is often required anyway, usually by a customer in a tender or a contract. NIS2 and DORA set information security requirements that sit close to ISO 27001 without naming the standard, so a working ISMS helps you there too. Some sectors have their own standard built on ISO 27001, such as NEN 7510 for Dutch healthcare.

When to start

The easiest time to start is while the team is small and the processes are simple. There are no entrenched habits to unpick and no legacy estate to document. A team of five to ten people can stand up a working ISMS in a few months; the same work across fifty people with older processes stretches into a year. Think you are too small? Three triggers say otherwise.

The second moment arrives with your first enterprise customers. Once prospects ask about your security measures, or attach a security questionnaire to an RFP, the market is telling you certification is expected. Waiting until you are already negotiating is too late, because the process takes months and few customers will wait. The fastest way to get certified as a startup shows what a short path looks like.

The third signal is your own risk. You start with a simple application, and before long you are processing personal data, financial information and business-critical customer data. If a breach today could end the company, a formal ISMS has stopped being optional. Insurers increasingly ask for the same evidence before they write cybersecurity cover.

Common mistakes when starting

Three traps come up most often. The full list is in the 7 biggest ISO 27001 pitfalls.

  • Starting too late. Teams try to do in three weeks what takes three months. Either the audit is failed, or the certificate arrives attached to an ISMS assembled so hastily that nobody uses it.
  • No clear owner. Everyone agrees security matters and nobody is accountable. Name one person on day one, and give them the time and the mandate.
  • Stacking controls without a risk assessment. Enthusiastic teams implement dozens of controls without knowing which risks they cover. Start with the risk assessment, and you know where the effort belongs.

How Tidal Control helps

Our platform is built to shorten this path:

  • Automated tests check continuously that your controls still work. Rather than manually verifying that multi-factor authentication is on everywhere, the system tests it and flags what drifts.
  • Every requirement pre-mapped, so you see what the standard asks per control, which evidence belongs to it, and how far along you are.
  • Policy templates with the instructions built in, so you adapt documents instead of writing them from scratch.
  • Continuous evidence collection, with evidence captured and linked to the right control as work happens. That removes the scramble before an audit.

Which platform fits, and where they differ, is covered in how to choose the right ISO 27001 software.

Frequently asked questions

What is the difference between ISO 27001 and ISO 27002?

ISO 27001 holds the requirements you are certified against. ISO 27002 is guidance that explains, control by control, how you might implement what Annex A names. So you certify against 27001 and use 27002 as the manual.

How long is an ISO 27001 certificate valid?

Three years. During that period the certification body runs a surveillance audit each year to confirm the ISMS is still working. At the end of the three years a recertification audit follows, comparable to the original Stage 2.

What does ISO 27001 certification cost?

The cost has two parts. The audit is bought from an accredited certification body that charges per audit day, and the number of days follows from your size and the scope of your ISMS. The larger part is usually implementation: the time your own team spends on risk assessment, controls, policy and evidence. There is no standard rate, so ask for a quote based on your own scope.

Who carries out the ISO 27001 audit?

An independent, accredited certification body. Tidal does not certify you itself, and that independence is what gives the certificate its weight: an auditor with no stake in the outcome tests whether your ISMS works in practice. Tidal gets you ready for that audit. Our customers have passed more than 50 audits, with 0 to 2 findings on average.

Do I need prior ISO 27001 experience to start?

No. Most teams that certify have never run an ISMS before. What you need is someone accountable, management that frees up time, and a method for working through the requirements in order. The standard itself is readable, and the reference guide translates each clause into what you actually have to produce.

Next step

Three things are worth doing before you open the standard. Work out which information is critical and where it lives. Decide who owns information security. Write a rough inventory of the measures you already take, however informal. With those on paper you start deliberately instead of overwhelmed.

Want to know where you stand? Take the free quickscan, or book a demo to see how Tidal Control gets you from plan to certificate.

Subscribe now for monthly updates: what's new at Tidal, framework news, and compliance resources.

By submitting your email you agree to our Privacy Policy.