ISO/IEC 27001: the ISMS standard, explained
ISO/IEC 27001 is the international standard for information security. It certifies your Information Security Management System (ISMS) — the way you manage risk and protect data. The 2022 version defines 93 Annex A controls across four themes, and you get certified by passing a two-stage independent audit.
What it is
ISO/IEC 27001 sets the requirements for an Information Security Management System — a risk-based framework of policies, roles, processes, and controls for protecting information. It’s built to be certified: an accredited body audits your ISMS and issues a certificate recognized worldwide. The current version is ISO/IEC 27001:2022.
Who needs it
Any organization that handles sensitive data and needs to prove strong security — especially SaaS and technology companies, service providers, and vendors selling to enterprise or government buyers. It’s often the first certification customers ask for, and larger contracts frequently depend on holding it.
93 controls across four themes
The management-system clauses run your ISMS; Annex A is the catalogue of controls you select from, grouped into four themes in the 2022 revision.
Organizational controls
Policies, roles, supplier and cloud security, threat intelligence, and how you govern information security day to day — the largest of the four themes.
People controls
Screening, terms of employment, awareness and training, disciplinary process, and responsibilities when people join, move, or leave.
Physical controls
Secure areas, equipment protection, clear-desk and clear-screen practices, and safe disposal — protecting the tangible side of security.
Technological controls
Access control, cryptography, logging and monitoring, secure development, backups, and protection against malware and data leakage.
From readiness to certificate
Scope & ISMS
Define the boundary of your ISMS, set objectives, run a risk assessment, and select controls. Produce your policies and Statement of Applicability.
Stage 1 — readiness review
The auditor reviews your documentation and ISMS design to confirm you're ready for the full audit and flags any gaps to close first.
Stage 2 — certification audit
The auditor tests that your controls operate in practice, sampling evidence. Pass, and an accredited body issues your ISO 27001 certificate.
Surveillance & recertification
Certification lasts three years with annual surveillance audits to confirm your ISMS keeps working, then a full recertification.
The Statement of Applicability
The Statement of Applicability (SoA) is the heart of your ISMS. It lists every Annex A control, says whether you’ve applied it, and justifies each decision — including any control you’ve deliberately excluded and why. Auditors read the SoA to understand the boundary of your ISMS and to confirm your controls match your risks. A tool like Komply builds and maintains the SoA for you, with per-control justifications and framework linkage in one living document.
ISO 27001 vs SOC 2
| ISO 27001 | SOC 2 | |
|---|---|---|
| What it is | Certification against a standard | Attestation report by a CPA firm |
| Recognition | International | Primarily United States |
| Built on an ISMS | ||
| Output | Pass/fail certificate | Detailed report to read |
| Renewal | 3-year cycle + surveillance | Typically annual |
ISO 27001, answered
Get ISO 27001-ready, faster
Komply drafts your policies and SoA, tracks evidence, and runs a Stage 1 readiness check — so you walk into your audit prepared.