Skip to content

ISO/IEC 27001

What it is

The leading international standard for an Information Security Management System (ISMS) — a documented, risk-driven management system for protecting information, not just a checklist of technical controls. Current version: ISO/IEC 27001:2022.

Who it applies to

Voluntary, but the de-facto global expectation for commercial and international B2B buyers. A company gets certified by an accredited external auditor; certification is valid ~3 years with annual surveillance audits.

Disclaimer. Not legal/compliance advice. Verified 2026-05-29.


Two parts

  1. The management-system clauses (4–10). The mandatory ISMS requirements: context, leadership, planning, risk assessment & treatment, support, operation, performance evaluation, and continual improvement. This is what you’re actually certified against.
  2. Annex A controls. A reference set of controls you select from based on your risk assessment, documented in a Statement of Applicability (SoA). The 2022 revision restructured Annex A into 93 controls across 4 themesOrganizational, People, Physical, Technological (down from 114 controls / 14 domains in the 2013 version), and added controls like threat intelligence, cloud security, and secure coding. The implementation guidance lives in ISO/IEC 27002:2022.

Relationship to SOC 2 / FedRAMP

  • vs SOC 2: ISO 27001 certifies you have a working ISMS; SOC 2 reports on whether your controls operated effectively. Many companies do both — ISO for international buyers, SOC 2 for US buyers. The underlying controls overlap heavily.
  • vs FedRAMP: FedRAMP’s NIST 800-53 baseline is broader and more prescriptive. Build to FedRAMP and an ISO 27001 SoA is largely a re-mapping exercise.


Sources (verified 2026-05-29)

ClaimSource
ISO/IEC 27001:2022 standardISO 27001
Annex A: 93 controls in 4 themes (2022)ISO/IEC 27002:2022