ISO/IEC 27001:2022 · 93 ANNEX A CONTROLS · THE 2013 TRANSITION CLOSED 31 OCT 2025

ISO 27001, clause by control.

ISO 27001 is the international standard for an information security management system — a governance framework rather than a control checklist. Whether a customer is asking for the certificate or you are pursuing it on your own terms, we take you through clauses 4 to 10, all 93 Annex A controls and the two-stage audit.


Four brass emblems on stone plinths — a compass, a magnifier over an open book, a laurel wreath around an eye, and a winged clock Illustrative materials
A management system, not a checklist
Clauses 4–10 Statement of Applicability Risk treatment 93 controls Stage 1 & Stage 2
The standard

What ISO/IEC 27001 is

A management system standard, which is why it is harder than a control checklist and why the certificate is worth something.

ISO/IEC 27001 specifies the requirements for an information security management system — the governance around how an organisation identifies security risk, decides what to do about it, and keeps doing it. The current version, ISO/IEC 27001:2022, was published in October 2022.

It has two halves. Clauses 4 to 10 are the mandatory requirements: context, leadership, planning, support, operation, performance evaluation and improvement. They are not optional and they are not selectable. Annex A lists 93 controls in four themes, and you choose from them on the basis of your own risk assessment — recording every decision in a Statement of Applicability.

That structure is the whole point. ISO 27001 does not tell you to buy a particular tool; it asks you to show that you understood your risks, chose proportionate controls, ran them, measured them, audited yourself and fixed what you found. An auditor who cannot see that loop will not certify a well-secured organisation.

The 2013 version is gone. The transition window closed on 31 October 2025 and certificates issued against it expired with it. If you are working from a 2013 gap analysis, it is describing a standard nobody can certify you against.

Annex A 93 controls

In four themes, selected by risk and every one of them addressed in the Statement of Applicability.

Certificate 3 years

Two-stage initial audit, annual surveillance audits, full recertification in year three.

Who needs ISO 27001

  • Nobody, legally — and almost everybody, commercially

    ISO 27001 is voluntary. What makes it non-optional is a customer’s procurement questionnaire, and that is a harder deadline than most statutes.

  • SaaS and cloud providers

    The single most common trigger. Enterprise buyers increasingly treat a certificate as a gate rather than a differentiator.

  • Anyone handling customer data at scale

    Processors, hosting providers and analytics platforms — where your customers have to evidence their own supply chain.

  • Regulated and public-sector suppliers

    Financial services, health and government tenders frequently name it, sometimes alongside a national scheme.

  • Organisations already running GDPR work

    Article 32 asks for appropriate technical and organisational measures. An ISMS is the most legible way to show you have them.

  • AI-first companies

    ISO 42001 for the AI management system sits on top of 27001 rather than beside it. Most teams certify the security one first.

Side by side

ISO 27001:2022 vs 2013

The 2013 column is here because people still arrive with a 2013 mental model — not because it is still an option.

Comparison of ISO/IEC 27001:2022 and ISO/IEC 27001:2013
Aspect ISO 27001:2013 Withdrawn ISO 27001:2022 Current
Published ISO/IEC 27001:2013 ISO/IEC 27001:2022, published October 2022
Status Withdrawn Certificates expired 31 October 2025 Current The only certifiable version
Annex A controls 114 controls 93 controls — consolidated, not reduced in substance
Grouping 14 domains (A.5 to A.18) 4 themes — organisational, people, physical, technological
New controls 11 added, including threat intelligence, cloud services, data leakage prevention, secure coding and web filtering
Control attributes None Five attributes per control — type, properties, cybersecurity concepts, operational capabilities, security domains
Cloud Addressed indirectly A named control for information security in the use of cloud services
Clauses 4–10 The same seven Substantively the same, with wording tightened
Transition Window ran to 31 October 2025 Closed Any remaining 2013 certificate is no longer valid

The transition window is closed, not closing

Most material still online counts down to 31 October 2025 as a future deadline. It passed. Certificates issued or reissued against ISO/IEC 27001:2013 during the transition period expired on that date, and no accredited body can certify against the 2013 version now. If your certificate has not been transitioned, the position is not that you are late — it is that you are not certified, and a customer checking the register will see that before you have a chance to explain it. The route back is a certification audit against the 2022 version, not a transition audit.

How we help

How iDharma supports ISO 27001

Six workstreams from asset inventory to internal audit, each answering a named clause — because at Stage 2 the auditor asks by clause.

Asset inventory and classification

Every information asset registered with an owner and a classification, because the risk assessment, the controls and the Statement of Applicability are all built on top of it.

Addresses: Clause 8 A.5.9–5.13

Risk assessment and treatment

A repeatable method, a populated risk register, and a treatment plan with owners and dates — the three artefacts an auditor asks for in the first hour.

Addresses: Clause 6.1

Statement of Applicability

All 93 controls addressed with an included-or-excluded decision and its justification. The SoA is mandatory and it is where thin programmes become visible.

Addresses: Clause 6.1.3

ISMS policy and procedure set

The documented information the standard requires, written to your operations rather than adopted generically — which is the difference an auditor notices immediately.

Addresses: Clause 7.5

Monitoring, measurement and metrics

What you measure, how often, who reviews it and what happens when it moves — clause 9.1 asks for all four and most programmes can answer two.

Addresses: Clause 9.1

Internal audit and management review

An audit programme with real independence, findings tracked to closure, and a management review that produces decisions rather than minutes.

Addresses: Clauses 9.2, 9.3

Built for ISO 27001:2022 certification

The four artefacts that decide whether Stage 2 goes well.

SoA

All 93 accounted for

Every control included or excluded with a written justification, cross-referenced to the risk that drove the decision.

Risk treatment

A plan, not a register

Owners, dates and residual risk accepted by someone with the authority to accept it.

Internal audit

A full cycle before Stage 2

Certification auditors look for evidence the ISMS has already audited itself and acted on what it found.

Multi-framework

Work that carries

The asset register, risk method and control set carry into ISO 42001, SOC 2 and GDPR Article 32 with mapping rather than rewriting.

Coverage

Everything the standard asks for

Seven mandatory clauses and 93 Annex A controls, addressed end to end — with the counts, rather than a percentage nobody can check.

93 Annex A controls Across four themes
7 Mandatory clauses Clauses 4 to 10
100% Addressed in the SoA Included or excluded, with a reason
11 New in 2022 Cloud, threat intel, secure coding and more
7/7 Clauses 4–10 Mandatory requirements
37/37 Organisational A.5
8/8 People A.6
14/14 Physical A.7
34/34 Technological A.8

The bars are full because the standard leaves no choice. A Statement of Applicability that skips a control is a nonconformity regardless of how sensible the omission looks — excluding one is fine, failing to mention it is not. What varies between organisations is not how many controls are addressed but how many are implemented, and that number belongs in your SoA rather than on our page.

Clauses 4–10

The mandatory clauses

Not selectable, not risk-based, not negotiable. Clauses 1 to 3 are scope, references and terms — which is why everyone says “four to ten”.

Clause 4

Context of the organisation

What the ISMS is for, who cares about it, and where its boundary sits. Get the scope wrong here and every later argument is about the wrong system.

  • Internal and external issues identified
  • Interested parties and their requirements
  • ISMS scope defined and defensible
  • The ISMS established and maintained
Clause 5

Leadership

Top management commitment expressed as decisions and resources rather than a signed foreword to the policy.

  • Demonstrated leadership and commitment
  • An information security policy that is actually used
  • Roles, responsibilities and authorities assigned
  • Security objectives owned at the top
Clause 6

Planning

The risk work, and the Statement of Applicability that comes out of it. This clause is where most certification effort actually goes.

  • Risk assessment process defined and repeatable
  • Risk treatment plan with owners
  • Statement of Applicability covering all 93 controls
  • Measurable objectives and plans to reach them
Clause 7

Support

The resources, competence, awareness and documented information without which the rest is aspiration.

  • Resources allocated to the ISMS
  • Competence evidenced, not asserted
  • Awareness across the workforce
  • Documented information controlled and versioned
Clause 8

Operation

Running the thing: planning and controlling the processes, and reassessing risk when something material changes.

  • Operational planning and control
  • Risk assessments performed at planned intervals
  • Risk treatment implemented and evidenced
  • Changes controlled, outsourced processes governed
Clause 9

Performance evaluation

Monitoring and measurement, internal audit, and management review — the three ways the ISMS finds out whether it is working.

  • What is measured, how and how often
  • An internal audit programme with independence
  • Findings tracked to closure
  • Management review producing decisions
Clause 10

Improvement

Nonconformity, corrective action and continual improvement. An ISMS with no findings is read as an ISMS that is not looking.

  • Nonconformities recorded and analysed
  • Root cause addressed, not just the symptom
  • Corrective actions verified as effective
  • Continual improvement demonstrated over time

Clause 6 is where the effort actually goes. The risk assessment, the treatment plan and the Statement of Applicability between them account for most of a first certification, and they are the three documents a Stage 1 auditor opens first. A programme that is strong on controls and thin on clause 6 fails in a way that is expensive to fix late.

Annex A

93 controls, four themes

The 2022 revision consolidated 114 controls in 14 domains into 93 in four. You select from them by risk — but every one has to be addressed in the Statement of Applicability, included or excluded.

37 A.5 · controls

Organisational

Policies, roles, supplier relationships, incident management, continuity and compliance — the largest theme and the one most often under-evidenced.

  • Information security policies
  • Segregation of duties
  • Supplier and cloud service security
  • Incident management and evidence collection
  • Threat intelligence — new in 2022
8 A.6 · controls

People

Screening, terms of employment, awareness, disciplinary process and what happens when someone leaves or changes role.

  • Screening and terms of employment
  • Awareness, education and training
  • Disciplinary process
  • Responsibilities after termination
  • Remote working
14 A.7 · controls

Physical

Perimeters, entry, equipment, clear desk and secure disposal. Frequently the thinnest section in a cloud-native organisation, and auditors know it.

  • Physical security perimeters and entry
  • Securing offices and facilities
  • Equipment siting and protection
  • Clear desk and clear screen
  • Physical security monitoring — new in 2022
34 A.8 · controls

Technological

Access control, cryptography, logging, secure development and the majority of what an engineering team already recognises as security work.

  • Access control and privileged access
  • Cryptography and key management
  • Logging and monitoring activities
  • Secure development and coding
  • Data masking and leakage prevention — new in 2022

The eleven controls added in 2022

  • Threat intelligence
  • Information security for the use of cloud services
  • ICT readiness for business continuity
  • Physical security monitoring
  • Configuration management
  • Information deletion
  • Data masking
  • Data leakage prevention
  • Monitoring activities
  • Web filtering
  • Secure coding
Certification

The two-stage audit, and what follows

Conducted by an accredited certification body. Stage 1 reads what you wrote; Stage 2 tests whether it is true.

Stage 1

Documentation review

The auditor reads the ISMS: scope, policy, risk method, Statement of Applicability, internal audit and management review records. The output is a readiness verdict and a findings list, not a certificate.

  • Scope and boundary examined
  • Statement of Applicability reviewed
  • Evidence of internal audit and management review
  • Gaps raised before Stage 2 is booked
Stage 2

Certification audit

The auditor tests whether the ISMS described in Stage 1 is the one you actually operate — sampling controls, interviewing people and following evidence trails.

  • Controls tested in practice
  • Staff interviewed across functions
  • Nonconformities graded major or minor
  • Certificate issued once majors are closed

Then a three-year cycle

Year 0

Initial certification

Stage 1 and Stage 2, then the certificate. Valid for three years from issue.

  • Two-stage audit
  • Major nonconformities closed first
  • Certificate scope fixed to your ISMS scope
Years 1–2

Surveillance audits

A lighter annual audit sampling part of the ISMS, confirming it is still operating and improving.

  • Annual, smaller scope
  • Findings from last time revisited
  • Changes to scope or risk examined
Year 3

Recertification

A full audit of the whole ISMS again, and a new three-year certificate.

  • Full-scope reassessment
  • Three-year improvement trend examined
  • New certificate issued
Implementation

A 26-week path to Stage 1

Structured from gap analysis to the certification audit. The constraint is rarely the controls — it is having enough operating history to evidence them.

Weeks 1–6

Scoping and gap analysis

Decide what the ISMS covers

  • ISMS scope and boundary agreed
  • Asset inventory built with owners
  • Gap analysis against clauses 4–10
  • Gap analysis against all 93 controls
Weeks 7–13

Risk assessment and treatment

The clause 6 work, which is most of it

  • Risk method defined and repeatable
  • Risk register populated and owned
  • Treatment plan with dates
  • Statement of Applicability drafted
Weeks 14–20

Implementation

Close the gaps, leave the evidence

  • Policies and procedures written to your operations
  • Technical controls implemented
  • Awareness and competence evidenced
  • Records generated as controls run
Weeks 21–26

Audit and certification

Audit yourself before someone else does

  • Full internal audit cycle completed
  • Management review held and minuted
  • Corrective actions closed
  • Stage 1 booked with the certification body

Twenty-six weeks assumes reasonable security hygiene to start from. Where the asset inventory and the risk method have to be built from nothing, twelve months is the honest number — and the binding constraint is not writing the controls but running them long enough to have records an auditor can sample.

Documented information

The ISO 27001 document set

24 documents an ISMS is expected to produce, grouped the way Annex A groups its controls — tailored to your scope rather than adopted generically, which is the difference a Stage 1 auditor notices in the first ten minutes.

ISMS core

  • Information Security Policy
  • ISMS Scope & Context
  • Risk Assessment Methodology
  • Risk Treatment Plan
  • Statement of Applicability
  • Internal Audit Programme
  • Management Review Pack
  • Corrective Action Procedure

People & physical

  • Acceptable Use Policy
  • Screening & Onboarding Standard
  • Security Awareness Programme
  • Disciplinary Process
  • Remote & Hybrid Working Policy
  • Physical Security Standard
  • Clear Desk & Clear Screen
  • Secure Disposal Procedure

Technical & operational

  • Access Control Standard
  • Cryptography & Key Management
  • Logging & Monitoring Standard
  • Configuration Management
  • Secure Development Policy
  • Supplier & Cloud Security Policy
  • Incident Response Plan
  • Business Continuity & ICT Readiness
Questions

Frequently asked questions

The standard, the controls, and what certification actually involves.

1 The standard and the versions
What is ISO 27001?

The international standard for an information security management system — a governance framework rather than a technical checklist. It sets mandatory requirements in clauses 4 to 10 and lists 93 controls in Annex A that you select from on the basis of your own risk assessment.

Is the 2013 version still valid?

No. The transition period closed on 31 October 2025 and certificates issued against ISO/IEC 27001:2013 expired with it. If you are still holding one, you are not certified — and a customer checking the certificate register will see that before you tell them.

What changed in the 2022 revision?

Annex A was restructured from 114 controls in 14 domains to 93 in four themes, eleven controls were added — including threat intelligence, cloud services, data leakage prevention and secure coding — and every control gained five attributes for filtering. The clauses themselves are substantively the same.

Is ISO 27001 mandatory?

Not legally, almost anywhere. It becomes effectively mandatory through procurement: enterprise buyers increasingly treat the certificate as a gate. That is a commercial deadline rather than a regulatory one, and it is usually tighter.

2 Scope, controls and the SoA
Do we have to implement all 93 controls?

No — you have to consider all 93 and record a decision on each. Controls are selected on the basis of your risk assessment, and exclusions are legitimate where justified. What is not legitimate is a Statement of Applicability that does not address a control at all.

What is the Statement of Applicability?

The document listing every Annex A control with whether it applies, why, and its implementation status. It is mandatory, it is the first thing an auditor reads, and it is where a thin programme becomes visible fastest.

Can we certify only part of the business?

Yes. The certificate names the ISMS scope, and a narrow scope is legitimate — but customers read the scope statement, and a certificate covering one product line will not satisfy a buyer asking about another.

How does it relate to ISO 42001 and SOC 2?

ISO 42001 is the AI management system standard and is built to sit on top of 27001, sharing the same clause structure. SOC 2 is an attestation rather than a certification, with heavily overlapping controls — most organisations doing both build one control set and report it twice.

3 Getting certified
How long does certification take?

Six months is a realistic target for an organisation starting from reasonable security hygiene; twelve is common where the asset inventory and risk method have to be built from nothing. The constraint is rarely the controls — it is having enough operating history to evidence them.

What happens in the two audit stages?

Stage 1 is a documentation review producing a readiness verdict and a findings list. Stage 2 tests whether the ISMS you documented is the one you run, by sampling controls and interviewing people. Major nonconformities must be closed before a certificate is issued.

Do we need an internal audit before certification?

Yes, and a complete one. Clause 9.2 requires an internal audit programme, and certification auditors specifically look for evidence that the ISMS has already audited itself and acted on the findings. Turning up to Stage 2 without one is the most common avoidable failure.

What does an iDharma readiness review cost and how long does it take?

It is scoped before you are charged. The variables are the ISMS scope, how much of the asset inventory and risk method already exist, and whether you are certifying alongside ISO 42001; we tell you the shape of all three after a short scoping call.

Further reading

Read it at source

ISO standards are copyright and are not free to read, so nothing on this page quotes the text. Where a clause matters to a decision, buy the standard.

Ready when you are

Ready to achieve ISO 27001 certification?

We scope the ISMS, build the asset inventory and risk method, draft the Statement of Applicability, run the internal audit and hand you to the certification body ready — scoped before you are charged.

iDharma is not an accredited certification body and does not issue ISO 27001 certificates — certifying an ISMS you helped build would not be independent, and no accredited body may do both. We prepare you; an accredited body certifies you.