ISO/IEC 27001
What it is
The leading international standard for an Information Security Management System (ISMS) — a documented, risk-driven management system for protecting information, not just a checklist of technical controls. Current version: ISO/IEC 27001:2022.
Who it applies to
Voluntary, but the de-facto global expectation for commercial and international B2B buyers. A company gets certified by an accredited external auditor; certification is valid ~3 years with annual surveillance audits.
Disclaimer. Not legal/compliance advice. Verified 2026-05-29.
Two parts
- The management-system clauses (4–10). The mandatory ISMS requirements: context, leadership, planning, risk assessment & treatment, support, operation, performance evaluation, and continual improvement. This is what you’re actually certified against.
- Annex A controls. A reference set of controls you select from based on your risk assessment, documented in a Statement of Applicability (SoA). The 2022 revision restructured Annex A into 93 controls across 4 themes — Organizational, People, Physical, Technological (down from 114 controls / 14 domains in the 2013 version), and added controls like threat intelligence, cloud security, and secure coding. The implementation guidance lives in ISO/IEC 27002:2022.
Relationship to SOC 2 / FedRAMP
- vs SOC 2: ISO 27001 certifies you have a working ISMS; SOC 2 reports on whether your controls operated effectively. Many companies do both — ISO for international buyers, SOC 2 for US buyers. The underlying controls overlap heavily.
- vs FedRAMP: FedRAMP’s NIST 800-53 baseline is broader and more prescriptive. Build to FedRAMP and an ISO 27001 SoA is largely a re-mapping exercise.
Related resources
- SOC 2 — the common US counterpart
- Security Overview & decision guide
Sources (verified 2026-05-29)
| Claim | Source |
|---|---|
| ISO/IEC 27001:2022 standard | ISO 27001 |
| Annex A: 93 controls in 4 themes (2022) | ISO/IEC 27002:2022 |