Framework guide

ISO/IEC 27001: the ISMS standard, explained

ISO/IEC 27001 is the international standard for information security. It certifies your Information Security Management System (ISMS) — the way you manage risk and protect data. The 2022 version defines 93 Annex A controls across four themes, and you get certified by passing a two-stage independent audit.

What it is

ISO/IEC 27001 sets the requirements for an Information Security Management System — a risk-based framework of policies, roles, processes, and controls for protecting information. It’s built to be certified: an accredited body audits your ISMS and issues a certificate recognized worldwide. The current version is ISO/IEC 27001:2022.

Who needs it

Any organization that handles sensitive data and needs to prove strong security — especially SaaS and technology companies, service providers, and vendors selling to enterprise or government buyers. It’s often the first certification customers ask for, and larger contracts frequently depend on holding it.

The ISMS & Annex A

93 controls across four themes

The management-system clauses run your ISMS; Annex A is the catalogue of controls you select from, grouped into four themes in the 2022 revision.

Organizational controls

Policies, roles, supplier and cloud security, threat intelligence, and how you govern information security day to day — the largest of the four themes.

People controls

Screening, terms of employment, awareness and training, disciplinary process, and responsibilities when people join, move, or leave.

Physical controls

Secure areas, equipment protection, clear-desk and clear-screen practices, and safe disposal — protecting the tangible side of security.

Technological controls

Access control, cryptography, logging and monitoring, secure development, backups, and protection against malware and data leakage.

Certification path

From readiness to certificate

1

Scope & ISMS

Define the boundary of your ISMS, set objectives, run a risk assessment, and select controls. Produce your policies and Statement of Applicability.

2

Stage 1 — readiness review

The auditor reviews your documentation and ISMS design to confirm you're ready for the full audit and flags any gaps to close first.

3

Stage 2 — certification audit

The auditor tests that your controls operate in practice, sampling evidence. Pass, and an accredited body issues your ISO 27001 certificate.

4

Surveillance & recertification

Certification lasts three years with annual surveillance audits to confirm your ISMS keeps working, then a full recertification.

The Statement of Applicability

The Statement of Applicability (SoA) is the heart of your ISMS. It lists every Annex A control, says whether you’ve applied it, and justifies each decision — including any control you’ve deliberately excluded and why. Auditors read the SoA to understand the boundary of your ISMS and to confirm your controls match your risks. A tool like Komply builds and maintains the SoA for you, with per-control justifications and framework linkage in one living document.

Quick comparison

ISO 27001 vs SOC 2

 ISO 27001SOC 2
What it isCertification against a standardAttestation report by a CPA firm
RecognitionInternationalPrimarily United States
Built on an ISMS
OutputPass/fail certificateDetailed report to read
Renewal3-year cycle + surveillanceTypically annual
FAQ

ISO 27001, answered

Get ISO 27001-ready, faster

Komply drafts your policies and SoA, tracks evidence, and runs a Stage 1 readiness check — so you walk into your audit prepared.