ISO 27001, clause by control.
ISO 27001 is the international standard for an information security management system — a governance framework rather than a control checklist. Whether a customer is asking for the certificate or you are pursuing it on your own terms, we take you through clauses 4 to 10, all 93 Annex A controls and the two-stage audit.
What ISO/IEC 27001 is
A management system standard, which is why it is harder than a control checklist and why the certificate is worth something.
ISO/IEC 27001 specifies the requirements for an information security management system — the governance around how an organisation identifies security risk, decides what to do about it, and keeps doing it. The current version, ISO/IEC 27001:2022, was published in October 2022.
It has two halves. Clauses 4 to 10 are the mandatory requirements: context, leadership, planning, support, operation, performance evaluation and improvement. They are not optional and they are not selectable. Annex A lists 93 controls in four themes, and you choose from them on the basis of your own risk assessment — recording every decision in a Statement of Applicability.
That structure is the whole point. ISO 27001 does not tell you to buy a particular tool; it asks you to show that you understood your risks, chose proportionate controls, ran them, measured them, audited yourself and fixed what you found. An auditor who cannot see that loop will not certify a well-secured organisation.
The 2013 version is gone. The transition window closed on 31 October 2025 and certificates issued against it expired with it. If you are working from a 2013 gap analysis, it is describing a standard nobody can certify you against.
In four themes, selected by risk and every one of them addressed in the Statement of Applicability.
Two-stage initial audit, annual surveillance audits, full recertification in year three.
Who needs ISO 27001
-
Nobody, legally — and almost everybody, commercially
ISO 27001 is voluntary. What makes it non-optional is a customer’s procurement questionnaire, and that is a harder deadline than most statutes.
-
SaaS and cloud providers
The single most common trigger. Enterprise buyers increasingly treat a certificate as a gate rather than a differentiator.
-
Anyone handling customer data at scale
Processors, hosting providers and analytics platforms — where your customers have to evidence their own supply chain.
-
Regulated and public-sector suppliers
Financial services, health and government tenders frequently name it, sometimes alongside a national scheme.
-
Organisations already running GDPR work
Article 32 asks for appropriate technical and organisational measures. An ISMS is the most legible way to show you have them.
-
AI-first companies
ISO 42001 for the AI management system sits on top of 27001 rather than beside it. Most teams certify the security one first.
ISO 27001:2022 vs 2013
The 2013 column is here because people still arrive with a 2013 mental model — not because it is still an option.
| Aspect | ISO 27001:2013 Withdrawn | ISO 27001:2022 Current |
|---|---|---|
| Published | ISO/IEC 27001:2013 | ISO/IEC 27001:2022, published October 2022 |
| Status | Withdrawn Certificates expired 31 October 2025 | Current The only certifiable version |
| Annex A controls | 114 controls | 93 controls — consolidated, not reduced in substance |
| Grouping | 14 domains (A.5 to A.18) | 4 themes — organisational, people, physical, technological |
| New controls | — | 11 added, including threat intelligence, cloud services, data leakage prevention, secure coding and web filtering |
| Control attributes | None | Five attributes per control — type, properties, cybersecurity concepts, operational capabilities, security domains |
| Cloud | Addressed indirectly | A named control for information security in the use of cloud services |
| Clauses 4–10 | The same seven | Substantively the same, with wording tightened |
| Transition | Window ran to 31 October 2025 | Closed Any remaining 2013 certificate is no longer valid |
The transition window is closed, not closing
Most material still online counts down to 31 October 2025 as a future deadline. It passed. Certificates issued or reissued against ISO/IEC 27001:2013 during the transition period expired on that date, and no accredited body can certify against the 2013 version now. If your certificate has not been transitioned, the position is not that you are late — it is that you are not certified, and a customer checking the register will see that before you have a chance to explain it. The route back is a certification audit against the 2022 version, not a transition audit.
How iDharma supports ISO 27001
Six workstreams from asset inventory to internal audit, each answering a named clause — because at Stage 2 the auditor asks by clause.
Asset inventory and classification
Every information asset registered with an owner and a classification, because the risk assessment, the controls and the Statement of Applicability are all built on top of it.
Addresses: Clause 8 A.5.9–5.13
Risk assessment and treatment
A repeatable method, a populated risk register, and a treatment plan with owners and dates — the three artefacts an auditor asks for in the first hour.
Addresses: Clause 6.1
Statement of Applicability
All 93 controls addressed with an included-or-excluded decision and its justification. The SoA is mandatory and it is where thin programmes become visible.
Addresses: Clause 6.1.3
ISMS policy and procedure set
The documented information the standard requires, written to your operations rather than adopted generically — which is the difference an auditor notices immediately.
Addresses: Clause 7.5
Monitoring, measurement and metrics
What you measure, how often, who reviews it and what happens when it moves — clause 9.1 asks for all four and most programmes can answer two.
Addresses: Clause 9.1
Internal audit and management review
An audit programme with real independence, findings tracked to closure, and a management review that produces decisions rather than minutes.
Addresses: Clauses 9.2, 9.3
Built for ISO 27001:2022 certification
The four artefacts that decide whether Stage 2 goes well.
All 93 accounted for
Every control included or excluded with a written justification, cross-referenced to the risk that drove the decision.
A plan, not a register
Owners, dates and residual risk accepted by someone with the authority to accept it.
A full cycle before Stage 2
Certification auditors look for evidence the ISMS has already audited itself and acted on what it found.
Work that carries
The asset register, risk method and control set carry into ISO 42001, SOC 2 and GDPR Article 32 with mapping rather than rewriting.
Everything the standard asks for
Seven mandatory clauses and 93 Annex A controls, addressed end to end — with the counts, rather than a percentage nobody can check.
The bars are full because the standard leaves no choice. A Statement of Applicability that skips a control is a nonconformity regardless of how sensible the omission looks — excluding one is fine, failing to mention it is not. What varies between organisations is not how many controls are addressed but how many are implemented, and that number belongs in your SoA rather than on our page.
The mandatory clauses
Not selectable, not risk-based, not negotiable. Clauses 1 to 3 are scope, references and terms — which is why everyone says “four to ten”.
Context of the organisation
What the ISMS is for, who cares about it, and where its boundary sits. Get the scope wrong here and every later argument is about the wrong system.
- Internal and external issues identified
- Interested parties and their requirements
- ISMS scope defined and defensible
- The ISMS established and maintained
Leadership
Top management commitment expressed as decisions and resources rather than a signed foreword to the policy.
- Demonstrated leadership and commitment
- An information security policy that is actually used
- Roles, responsibilities and authorities assigned
- Security objectives owned at the top
Planning
The risk work, and the Statement of Applicability that comes out of it. This clause is where most certification effort actually goes.
- Risk assessment process defined and repeatable
- Risk treatment plan with owners
- Statement of Applicability covering all 93 controls
- Measurable objectives and plans to reach them
Support
The resources, competence, awareness and documented information without which the rest is aspiration.
- Resources allocated to the ISMS
- Competence evidenced, not asserted
- Awareness across the workforce
- Documented information controlled and versioned
Operation
Running the thing: planning and controlling the processes, and reassessing risk when something material changes.
- Operational planning and control
- Risk assessments performed at planned intervals
- Risk treatment implemented and evidenced
- Changes controlled, outsourced processes governed
Performance evaluation
Monitoring and measurement, internal audit, and management review — the three ways the ISMS finds out whether it is working.
- What is measured, how and how often
- An internal audit programme with independence
- Findings tracked to closure
- Management review producing decisions
Improvement
Nonconformity, corrective action and continual improvement. An ISMS with no findings is read as an ISMS that is not looking.
- Nonconformities recorded and analysed
- Root cause addressed, not just the symptom
- Corrective actions verified as effective
- Continual improvement demonstrated over time
Clause 6 is where the effort actually goes. The risk assessment, the treatment plan and the Statement of Applicability between them account for most of a first certification, and they are the three documents a Stage 1 auditor opens first. A programme that is strong on controls and thin on clause 6 fails in a way that is expensive to fix late.
93 controls, four themes
The 2022 revision consolidated 114 controls in 14 domains into 93 in four. You select from them by risk — but every one has to be addressed in the Statement of Applicability, included or excluded.
Organisational
Policies, roles, supplier relationships, incident management, continuity and compliance — the largest theme and the one most often under-evidenced.
- Information security policies
- Segregation of duties
- Supplier and cloud service security
- Incident management and evidence collection
- Threat intelligence — new in 2022
People
Screening, terms of employment, awareness, disciplinary process and what happens when someone leaves or changes role.
- Screening and terms of employment
- Awareness, education and training
- Disciplinary process
- Responsibilities after termination
- Remote working
Physical
Perimeters, entry, equipment, clear desk and secure disposal. Frequently the thinnest section in a cloud-native organisation, and auditors know it.
- Physical security perimeters and entry
- Securing offices and facilities
- Equipment siting and protection
- Clear desk and clear screen
- Physical security monitoring — new in 2022
Technological
Access control, cryptography, logging, secure development and the majority of what an engineering team already recognises as security work.
- Access control and privileged access
- Cryptography and key management
- Logging and monitoring activities
- Secure development and coding
- Data masking and leakage prevention — new in 2022
The eleven controls added in 2022
- Threat intelligence
- Information security for the use of cloud services
- ICT readiness for business continuity
- Physical security monitoring
- Configuration management
- Information deletion
- Data masking
- Data leakage prevention
- Monitoring activities
- Web filtering
- Secure coding
The two-stage audit, and what follows
Conducted by an accredited certification body. Stage 1 reads what you wrote; Stage 2 tests whether it is true.
Documentation review
The auditor reads the ISMS: scope, policy, risk method, Statement of Applicability, internal audit and management review records. The output is a readiness verdict and a findings list, not a certificate.
- Scope and boundary examined
- Statement of Applicability reviewed
- Evidence of internal audit and management review
- Gaps raised before Stage 2 is booked
Certification audit
The auditor tests whether the ISMS described in Stage 1 is the one you actually operate — sampling controls, interviewing people and following evidence trails.
- Controls tested in practice
- Staff interviewed across functions
- Nonconformities graded major or minor
- Certificate issued once majors are closed
Then a three-year cycle
Initial certification
Stage 1 and Stage 2, then the certificate. Valid for three years from issue.
- Two-stage audit
- Major nonconformities closed first
- Certificate scope fixed to your ISMS scope
Surveillance audits
A lighter annual audit sampling part of the ISMS, confirming it is still operating and improving.
- Annual, smaller scope
- Findings from last time revisited
- Changes to scope or risk examined
Recertification
A full audit of the whole ISMS again, and a new three-year certificate.
- Full-scope reassessment
- Three-year improvement trend examined
- New certificate issued
A 26-week path to Stage 1
Structured from gap analysis to the certification audit. The constraint is rarely the controls — it is having enough operating history to evidence them.
Scoping and gap analysis
Decide what the ISMS covers
- ISMS scope and boundary agreed
- Asset inventory built with owners
- Gap analysis against clauses 4–10
- Gap analysis against all 93 controls
Risk assessment and treatment
The clause 6 work, which is most of it
- Risk method defined and repeatable
- Risk register populated and owned
- Treatment plan with dates
- Statement of Applicability drafted
Implementation
Close the gaps, leave the evidence
- Policies and procedures written to your operations
- Technical controls implemented
- Awareness and competence evidenced
- Records generated as controls run
Audit and certification
Audit yourself before someone else does
- Full internal audit cycle completed
- Management review held and minuted
- Corrective actions closed
- Stage 1 booked with the certification body
Twenty-six weeks assumes reasonable security hygiene to start from. Where the asset inventory and the risk method have to be built from nothing, twelve months is the honest number — and the binding constraint is not writing the controls but running them long enough to have records an auditor can sample.
The ISO 27001 document set
24 documents an ISMS is expected to produce, grouped the way Annex A groups its controls — tailored to your scope rather than adopted generically, which is the difference a Stage 1 auditor notices in the first ten minutes.
ISMS core
- Information Security Policy
- ISMS Scope & Context
- Risk Assessment Methodology
- Risk Treatment Plan
- Statement of Applicability
- Internal Audit Programme
- Management Review Pack
- Corrective Action Procedure
People & physical
- Acceptable Use Policy
- Screening & Onboarding Standard
- Security Awareness Programme
- Disciplinary Process
- Remote & Hybrid Working Policy
- Physical Security Standard
- Clear Desk & Clear Screen
- Secure Disposal Procedure
Technical & operational
- Access Control Standard
- Cryptography & Key Management
- Logging & Monitoring Standard
- Configuration Management
- Secure Development Policy
- Supplier & Cloud Security Policy
- Incident Response Plan
- Business Continuity & ICT Readiness
Frequently asked questions
The standard, the controls, and what certification actually involves.
What is ISO 27001?
The international standard for an information security management system — a governance framework rather than a technical checklist. It sets mandatory requirements in clauses 4 to 10 and lists 93 controls in Annex A that you select from on the basis of your own risk assessment.
Is the 2013 version still valid?
No. The transition period closed on 31 October 2025 and certificates issued against ISO/IEC 27001:2013 expired with it. If you are still holding one, you are not certified — and a customer checking the certificate register will see that before you tell them.
What changed in the 2022 revision?
Annex A was restructured from 114 controls in 14 domains to 93 in four themes, eleven controls were added — including threat intelligence, cloud services, data leakage prevention and secure coding — and every control gained five attributes for filtering. The clauses themselves are substantively the same.
Is ISO 27001 mandatory?
Not legally, almost anywhere. It becomes effectively mandatory through procurement: enterprise buyers increasingly treat the certificate as a gate. That is a commercial deadline rather than a regulatory one, and it is usually tighter.
Do we have to implement all 93 controls?
No — you have to consider all 93 and record a decision on each. Controls are selected on the basis of your risk assessment, and exclusions are legitimate where justified. What is not legitimate is a Statement of Applicability that does not address a control at all.
What is the Statement of Applicability?
The document listing every Annex A control with whether it applies, why, and its implementation status. It is mandatory, it is the first thing an auditor reads, and it is where a thin programme becomes visible fastest.
Can we certify only part of the business?
Yes. The certificate names the ISMS scope, and a narrow scope is legitimate — but customers read the scope statement, and a certificate covering one product line will not satisfy a buyer asking about another.
How does it relate to ISO 42001 and SOC 2?
ISO 42001 is the AI management system standard and is built to sit on top of 27001, sharing the same clause structure. SOC 2 is an attestation rather than a certification, with heavily overlapping controls — most organisations doing both build one control set and report it twice.
How long does certification take?
Six months is a realistic target for an organisation starting from reasonable security hygiene; twelve is common where the asset inventory and risk method have to be built from nothing. The constraint is rarely the controls — it is having enough operating history to evidence them.
What happens in the two audit stages?
Stage 1 is a documentation review producing a readiness verdict and a findings list. Stage 2 tests whether the ISMS you documented is the one you run, by sampling controls and interviewing people. Major nonconformities must be closed before a certificate is issued.
Do we need an internal audit before certification?
Yes, and a complete one. Clause 9.2 requires an internal audit programme, and certification auditors specifically look for evidence that the ISMS has already audited itself and acted on the findings. Turning up to Stage 2 without one is the most common avoidable failure.
What does an iDharma readiness review cost and how long does it take?
It is scoped before you are charged. The variables are the ISMS scope, how much of the asset inventory and risk method already exist, and whether you are certifying alongside ISO 42001; we tell you the shape of all three after a short scoping call.
Read it at source
ISO standards are copyright and are not free to read, so nothing on this page quotes the text. Where a clause matters to a decision, buy the standard.
Primary sources
ISO and the accreditation forum. External links; the first two are paid.
Related on this site
The standards and regimes that most often share a scope with 27001.
- ISO/IEC 42001 AI management system controls, clause by clause
- SOC 2 Trust services criteria for systems handling customer data
- GDPR Lawful basis, DPIAs, data subject rights and Article 22
- AI governance policy templates The ISMS document set, mapped clause by clause
- Every framework we audit against The full catalog, by region and kind
Ready to achieve ISO 27001 certification?
We scope the ISMS, build the asset inventory and risk method, draft the Statement of Applicability, run the internal audit and hand you to the certification body ready — scoped before you are charged.
iDharma is not an accredited certification body and does not issue ISO 27001 certificates — certifying an ISMS you helped build would not be independent, and no accredited body may do both. We prepare you; an accredited body certifies you.
From Insights
Before you commission one
How to Prepare for an AI Audit: The Readiness Checklist
Six things to have ready before the engagement starts. Assembling them takes a fortnight off the clock — and tends to find the first two findings before an auditor does.
Read the notesWhat Is an AI Audit? Scope, Standards, and What You Get
An independent review of what your AI actually does, measured against a named standard — not a certificate, and not a review of what the documentation says it does.
Read the notesWhat an AI Governance Framework Actually Contains
Five working parts, not a policy document. What each one has to do, how to tell whether yours is real, and why a framework is not the same thing as compliance.
Read the guide