ISO 27001, explained for teams getting ready

ISO/IEC 27001 is the international standard for running information security as a managed system. Here is what it asks for, how certification works, and where startups usually fall short.

Assess ISO 27001 free

23 questions · about 12 min · no signup

Type
Certifiable standard
Current edition
ISO/IEC 27001:2022
Annex A
93 controls in 4 themes
Certificate
3 years, audited yearly

This guide is growing. A fuller ISO 27001 guide, with requirement-by-requirement detail and worked examples, is being written. Last updated 1st October 2026.

On this page
01

What is ISO 27001?

ISO/IEC 27001 sets out the requirements for an information security management system, or ISMS: the policies, processes and controls an organization uses to manage risks to the information it holds. It is published jointly by ISO and the IEC, and the current edition is ISO/IEC 27001:2022.

It is not a list of tools to buy. The standard asks you to understand your risks, choose controls that treat them, run those controls, and keep improving. An accredited certification body can then audit you against it and issue a certificate.

02

Who asks for ISO 27001?

  • Enterprise customers and partners, often as a condition in vendor security reviews and contracts.
  • International customers, for whom ISO 27001 is a common baseline for a supplier's security.
  • Your own team, as a structured way to run security as the company grows.

ISO 27001 is voluntary: no law requires it in general. In practice it becomes a requirement when customers write it into contracts or make it a condition of a deal.

03

What ISO 27001 requires

The standard has two parts. Clauses 4 to 10 describe the management system itself, and Annex A lists reference controls.

  • Context of the organization (clause 4): the scope of the ISMS, interested parties and what they need.
  • Leadership (clause 5): top management commitment, an information security policy, and clear roles.
  • Planning (clause 6): risk assessment, risk treatment and information security objectives.
  • Support (clause 7): resources, competence, awareness and documented information.
  • Operation (clause 8): carrying out the risk assessment and the risk treatment plan.
  • Performance evaluation (clause 9): monitoring, internal audit and management review.
  • Improvement (clause 10): nonconformities, corrective action and continual improvement.
04

The 93 Annex A controls

The 2022 edition reorganised Annex A from 114 controls in 14 domains into 93 controls in four themes. You do not have to implement all of them: you select the controls that treat your risks and record why each is included or excluded in a Statement of Applicability.

Theme

Organizational

Controls

37

Examples

Policies, supplier security, incident management, business continuity

Theme

People

Controls

8

Examples

Screening, awareness training, confidentiality agreements

Theme

Physical

Controls

14

Examples

Secure areas, equipment protection, physical security monitoring

Theme

Technological

Controls

34

Examples

Access rights, vulnerability management, logging, cryptography, secure development

Eleven controls were new in 2022, including threat intelligence, information security for cloud services, data leakage prevention and secure coding. Certificates issued against the 2013 edition had to transition to the 2022 edition by 31 October 2025.

05

How ISO 27001 certification works

  • Scope and gap assessment: decide what the ISMS covers and compare where you are with what the standard asks.
  • Build and run the ISMS: risk assessment, Statement of Applicability, policies and controls, then evidence that they operate.
  • Internal audit and management review: both are required before the certification audit.
  • Stage 1 audit: the certification body reviews your documentation and whether you are ready.
  • Stage 2 audit: auditors test that the ISMS and its controls work in practice.
  • Certificate and surveillance: the certificate lasts three years, with surveillance audits in the first and second years and a recertification audit in the third.
06

Where startups usually fall short

  • A risk assessment that was never documented, or never updated after the first version.
  • A Statement of Applicability that does not match what is actually in place.
  • Access reviews that happen informally, with no record to show an auditor.
  • Vulnerability and patch management with no defined timelines.
  • Supplier security handled case by case instead of through a process.
  • No internal audit or management review before the certification audit.
07

What the free assessment covers

The free SwaSec ISO 27001 assessment asks 23 questions across 5 domains and takes about 12 minutes. It scores where you stand and ties each gap to the clause, control or article it relates to.

  • ISMS Clauses (4-10). Management system requirements covering context, leadership, planning, support, operation, performance evaluation, and improvement.
  • A.5 Organizational Controls. Controls related to organizational policies, roles, responsibilities, threat intelligence, and supplier management.
  • A.6 People Controls. Controls related to personnel security throughout the employment lifecycle.
  • A.7 Physical Controls. Controls related to physical security perimeters, entry controls, and environmental protection.
  • A.8 Technological Controls. Controls related to access management, vulnerability management, configuration, logging, cryptography, and secure development.

Start the ISO 27001 assessment. It is a self-assessment, not an audit or a certification.

08

How ISO 27001 overlaps with other frameworks

ISO 27001 shares 9 areas with the other frameworks SwaSec covers. Where it can, the assessment asks a shared area once, and the answer counts toward each framework.

  • Security Policy, shared with ISO 42001, SOC 2 and GDPR. Asked once.
  • Risk Assessment, shared with ISO 42001, SOC 2, GDPR and EU AI Act. Asked separately, because each framework wants something different.
  • Access Control, shared with SOC 2. Asked once.
  • Incident Response, shared with SOC 2 and GDPR. Asked once.
  • Vendor/Supplier Management, shared with ISO 42001, SOC 2 and GDPR. Asked once.
  • Logging and Monitoring, shared with SOC 2. Asked once.
  • Change Management / Secure Development, shared with ISO 42001 and SOC 2. Asked once.
  • Training and Awareness, shared with ISO 42001 and SOC 2. Asked once.
  • Business Continuity and Recovery, shared with SOC 2. Asked once.
09

Frequently asked questions

Is ISO 27001 mandatory?

No. It is a voluntary standard. It often becomes a requirement in practice when customers write it into contracts or vendor security reviews.

What is the difference between ISO 27001 and SOC 2?

ISO 27001 certifies that you run an information security management system, and is audited by an accredited certification body. SOC 2 is an attestation report from a licensed CPA firm on how specific controls are designed and operate. Many of their controls overlap, so preparing for one helps with the other.

Do I need to implement all 93 Annex A controls?

No. You select the controls that treat your risks, and record why each control is included or excluded in your Statement of Applicability.

How long does ISO 27001 certification take?

It depends on your starting point and your scope. Most of the time goes into building the ISMS and running it long enough to produce evidence for the Stage 2 audit. A gap assessment is the quickest way to see how far you are from that point.

What does the free SwaSec ISO 27001 assessment cover?

23 questions across 5 domains, taking about 12 minutes, with no signup. It gives you a score for ISO 27001, the gaps it found, and the clause, control or article each gap relates to.

10

Sources

This guide is general information, not legal advice. Last updated 1st October 2026.

The other frameworks