ISO 27001
ISO/IEC 27001:2022 – Information Security Management Systems
Organizations must implement a documented Information Security Management System addressing 93 Annex A security controls, subject to annual surveillance audits and full recertification every three years by an accredited certification body.
What this covers
ISO/IEC 27001:2022 is the international standard for Information Security Management Systems. It requires organizations to implement and maintain a documented ISMS addressing 93 Annex A security controls, subject to annual surveillance audits and full recertification every three years by an accredited certification body. ISO 27001 is not a self-declaration – it must be issued by a body accredited by a national accreditation authority.
The 2022 version reduced controls from 114 (in the 2013 standard) to 93 and added 11 new controls specifically addressing threat intelligence, cloud service security, ICT supply chain security, data masking, monitoring activities, configuration management, information deletion, data leakage prevention, web filtering, secure coding, and physical security monitoring. Organizations certified under ISO 27001:2013 had until October 31, 2025 to transition to the 2022 standard.
ISO 27001 functions as a procurement baseline in enterprise and regulated-sector contracts globally. Government suppliers, financial data processors, and healthcare vendors regularly encounter it as a contractual prerequisite. Without a current certificate, vendors are frequently disqualified from enterprise procurement without review. The certificate must be from a nationally accredited certification body – not from ISO directly.
Annual surveillance audits verify ongoing compliance between the three-year full recertification cycles. When evaluating vendors, request the actual certificate including issue date, scope statement, and accreditation body name. A certificate that covers only part of a vendor's product line may not cover the specific service you're procuring – check that the scope includes the relevant service or product.
Frequently asked questions
What changed in ISO 27001:2022 vs the 2013 version?
ISO 27001:2022 reduced Annex A controls from 114 to 93 and added 11 new controls covering threat intelligence, cloud security, data masking, information deletion, and secure coding. Organizations certified under the 2013 standard had until October 2025 to transition. All new certifications must reference the 2022 version.
Is ISO 27001 legally required or voluntary?
ISO 27001 is voluntary but functions as a de facto procurement baseline in most enterprise and regulated-sector contracts. Government suppliers, financial data processors, and healthcare vendors regularly encounter ISO 27001 as a contractual prerequisite. Without it, vendors are often disqualified from enterprise and public sector procurement without review.
How often must ISO 27001 certification be renewed?
After initial Stage 1 (documentation review) and Stage 2 (on-site audit) certification, annual surveillance audits verify ongoing compliance. Full recertification occurs every three years. Certificates are issued by accredited certification bodies – not ISO itself. Verify a vendor's certificate was issued by an accredited body and is not expired.
What does ISO 27001 cover that SOC 2 Type II doesn't?
ISO 27001 is a prescriptive certification requiring a documented ISMS with defined controls covering physical security, HR security, and supplier management. SOC 2 Type II is an auditor's report – not a certification – focused on US trust services criteria. ISO 27001 is globally recognized; SOC 2 Type II is primarily required in North America.