●Enterprise Cybersecurity & Compliance●Cloud & Infrastructure Security●Offensive Security Testing●Governance & Risk Management
●Enterprise Cybersecurity & Compliance●Cloud & Infrastructure Security●Offensive Security Testing●Governance & Risk Management
ISO/IEC 27001:2022 · ISMS

ISO 27001 Certification & Implementation — turn information security into a business advantage.

Build a practical, risk-based Information Security Management System that protects confidentiality, integrity and availability — while giving customers, partners and leadership confidence in how information risk is managed.

Risk-based approach
Audit-ready evidence
Continual improvement
ISO 27001ISO 27002Annex ASoARisk Assessment
Cybersecurity Information Security Management
ISMS focus
Risk → Control → Evidence
Framework
ISO 27001 · 27002 · Annex A
ISMSRisk-based management
Annex AControl framework
SoAStatement of Applicability
3 YrsCertification cycle
AnnualSurveillance audits
Core ISMS capabilities we deliver
ISMS ScopeRisk AssessmentRisk TreatmentSoAControlsInternal AuditManagement ReviewCorrective Action
ISO 27001 explained

What is ISO 27001?

ISO/IEC 27001 is the internationally recognized standard for establishing, implementing, maintaining and continually improving an Information Security Management System (ISMS). It gives organizations a structured, risk-based way to protect information and manage information security risks across people, processes, technology and business operations.

Confidentiality

Ensure information is accessible only to authorized people, systems and processes.

Integrity

Protect information from unauthorized alteration and maintain its accuracy and reliability.

Availability

Keep information and supporting systems available when the business and authorized users need them.

Why ISO 27001 is needed

Because security risks are business risks.

Organizations depend on information, applications, cloud services, employees, suppliers and connected infrastructure. ISO 27001 provides a management framework to identify what can go wrong, assess the impact, decide how risks should be treated, assign ownership and continually verify that safeguards remain effective.

Reduce unmanaged risk

Identify threats, vulnerabilities, impacts and unacceptable risks instead of relying on assumptions or isolated technical controls.

Meet stakeholder expectations

Demonstrate a systematic approach to information security for customers, partners, management, regulators and other interested parties.

Protect business continuity

Strengthen resilience by considering information, systems, suppliers, people, physical facilities and operational dependencies together.

Business value

Benefits of implementing ISO 27001

ISO 27001 turns information security into a managed business capability rather than a collection of disconnected security activities.

Stronger customer trust

Show that information security is governed through defined processes and an independently assessable management system.

Better risk decisions

Give leadership visibility into information risks, treatment priorities, residual risk and accountable owners.

Improved compliance readiness

Bring legal, regulatory, contractual and business information-security requirements into one structured management framework.

Clear accountability

Assign responsibilities and authorities for information security so security ownership is not limited to the IT department.

Continuous improvement

Use metrics, internal audits, management reviews, incidents and corrective actions to improve the ISMS over time.

Competitive advantage

Use a recognized information-security framework to strengthen enterprise credibility and support security-conscious sales processes.

Core features

Key features of ISO 27001

The standard combines governance, risk management, operational controls, measurement and continual improvement into one connected ISMS.

01Risk-based management — Identify, evaluate and treat information-security risks using defined criteria and accountable risk ownership.
02ISMS governance — Establish leadership commitment, policy, roles, responsibilities, resources and organizational direction.
03Control framework — Use Annex A and ISO 27002 guidance as a reference for selecting controls appropriate to the organization and its risks.
04Security awareness — Build competence and awareness so information security responsibilities become part of everyday work.
05Operational security — Embed security requirements into access, asset, supplier, application, network, physical and information-management processes.
06Performance evaluation — Monitor ISMS performance and control effectiveness using meaningful measures aligned with security objectives.
07Internal audit — Evaluate whether the ISMS is implemented and maintained effectively and identify opportunities for corrective action.
08Continual improvement — Correct nonconformities and continually improve the suitability, adequacy and effectiveness of the ISMS.
Security transformation

How ISO 27001 improves a company's security posture

Implementation creates a repeatable security-management cycle: understand the business, identify risk, select appropriate safeguards, collect evidence, measure effectiveness and improve.

Step 01From unknown assets to visibility

Define the ISMS scope and identify information assets, systems, processes, people, suppliers and supporting environments.

Step 02From assumptions to measured risk

Use a consistent risk methodology to understand likelihood, impact and risk acceptance thresholds.

Step 03From controls to accountable treatment

Map risks to treatment actions, selected controls, responsible owners, priorities, timelines and residual-risk decisions.

Step 04From policies to evidence

Connect policies and procedures to operational records, training, reviews, monitoring and other evidence that demonstrates implementation.

Step 05From periodic fixes to continual improvement

Use internal audit, management review, metrics, incidents and corrective actions to continuously strengthen the security program.

Why ISO 27001

Security is bigger than technology.
It is an enterprise responsibility.

Effective information security is an enterprise responsibility spanning people, processes, technology, governance, suppliers and physical environments — not merely an IT exercise.

Protect critical information

Manage risks to the confidentiality, integrity and availability of information and information assets through a systematic ISMS.

ConfidentialityIntegrityAvailability

Build customer confidence

An accredited certificate can demonstrate to customers and partners that defined information-security processes are in place and independently assessed.

TrustAssuranceAudit

Strengthen governance

Give leadership a coherent way to understand information risk, assign responsibilities, review performance and make risk-informed decisions.

GovernanceRiskOwnership

Support compliance

Design the ISMS around relevant legal, regulatory, contractual and business requirements rather than treating compliance as disconnected checklists.

LegalRegulatoryContractual

Improve continuously

Use monitoring, internal audit, management review, corrective action and changing risk information to keep the ISMS effective.

MonitorAuditImprove

Make security repeatable

Move from isolated controls to an interconnected management system that produces dependable outcomes and evidence over time.

ProcessEvidenceOutcomes
ISO 27001 framework

Understand the standard without the noise.

ISO/IEC 27001:2022 sets the requirements for the ISMS. The certifiable requirements are set out in Clauses 4–10, while Annex A acts as a reference control set.

04Context of the organization
05Leadership
06Planning
07Support
08Operation
09Performance evaluation
10Improvement
Annex AReference control set
ISMS ScopeInformation Security PolicyRisk AssessmentRisk TreatmentStatement of ApplicabilityInternal AuditManagement ReviewCorrective Action
Controls & Annex A

Controls should follow risk — not the other way around.

Organizations select controls appropriate to their risk treatment and context. Annex A provides a reference set; the Statement of Applicability records what is selected, what is excluded and why, and what has been implemented.

01

Organizational

Governance, policies, asset and supplier management, threat intelligence, information classification and related organizational safeguards.

02

People

Competence, awareness, responsibilities, employment lifecycle, remote working and human-centered security practices.

03

Physical

Secure areas, equipment, environmental protection, physical access and protection of information-processing facilities.

04

Technological

Access control, authentication, secure development, network security, malware protection, logging, backup and technical safeguards.

Implementation roadmap

A structured route from gap analysis to an auditable ISMS.

A practical implementation sequence is: establish the management framework, understand context and scope, assess and treat risk, select controls, implement them, train people, operate the ISMS, then monitor, audit and improve.

01Context, scope & governance — Understand internal/external context, interested parties, business objectives, assets, technology and the boundaries of the ISMS. Establish leadership, roles and resources.
02Policy & risk methodology — Define the information security policy, risk assessment approach and risk acceptance criteria aligned with organizational needs.
03Risk assessment & treatment — Identify assets, threats, vulnerabilities and impacts; evaluate risks; determine treatment options and assign accountable risk owners.
04SoA & control implementation — Build the Statement of Applicability, document rationale for selections/exclusions, implement the treatment plan and create supporting procedures and evidence.
05Awareness, operations & incidents — Train affected staff, operate the ISMS, manage resources and maintain processes for detecting and responding to information security incidents.
06Measure, audit & improve — Monitor performance and control effectiveness, conduct internal audits, perform management reviews, address nonconformities and continually improve.
ISO 27001 Roadmap

Your ISO 27001 roadmap — from kickoff to certificate.

A realistic, stage-by-stage path for a focused scope in a small-to-medium organization. Timelines vary with scope, sites, technology complexity and how much work your team can own in parallel.

01

Kickoff & scope

Agree objectives, sponsor, budget and the exact ISMS boundary — which people, processes, locations, systems and suppliers are inside scope.

Week 1–2
02

Gap assessment

Assess current practice against ISO 27001:2022 clauses and Annex A. Produce a prioritised gap report and action plan.

Week 2–4
03

Risk assessment

Define the risk methodology, identify assets, threats and vulnerabilities, evaluate risks and agree risk acceptance criteria with leadership.

Week 4–8
04

Risk treatment & SoA

Select controls, document rationale for inclusions and exclusions, and finalise the Statement of Applicability with owners and timelines.

Week 8–10
05

Implement controls

Roll out the treatment plan — policies, procedures, access, supplier, technical and physical controls — and evidence the operating state.

Week 10–18
06

Internal audit & review

Run a full internal audit cycle, hold the management review, close nonconformities and confirm corrective-action effectiveness.

Week 18–22
07

Stage 1 & Stage 2

Support the certification body's Stage 1 readiness review and Stage 2 implementation audit through to certificate issuance.

Week 22–26
Milestone 1 · Scope frozenISMS boundary, sponsor and budget confirmed in writing.
Milestone 2 · SoA signed offControls selected, justifications recorded, owners assigned.
Milestone 3 · Internal audit closedFindings addressed and evidence of operation exists.
Milestone 4 · Certificate issuedStage 2 passed; the three-year cycle begins.
Evidence that stands up to scrutiny

Build the system — and the proof behind it.

A mature ISMS is more than policies. It connects documented decisions, responsibilities, risk treatment, operational procedures, records, monitoring and review into a coherent evidence trail.

Core ISMS documentation

Policy, scope, context, interested-party requirements, risk methodology/results, objectives, Statement of Applicability and document/record controls.

Risk & treatment evidence

Risk register, treatment decisions, owners, residual-risk acceptance, implementation status, priorities, responsibilities and timelines.

Operational evidence

Procedures, work instructions, training and awareness records, incident records, technical/organizational control evidence and relevant management records.

Certification readiness

Prepare before the auditor arrives.

A strong certification-readiness approach includes a comprehensive readiness review, close scrutiny of the SoA, completion of an internal-audit cycle for key areas and staff preparation before the initial external audit.

01 • READINESSGap & evidence review — Validate the ISMS against requirements and confirm that evidence exists for implemented arrangements.
02 • STAGE 1Documentation & readiness — The certification body assesses the organization's preparedness and the maturity of its management-system arrangements.
03 • STAGE 2Implementation audit — Demonstrate that the ISMS is implemented and operating effectively across its defined scope.
04 • CONTINUOUSSurveillance & improvement — Maintain the ISMS, update the SoA when necessary, monitor effectiveness and address findings through continual improvement.
Certificate lifecycle

Inside the three-year certification cycle.

Certification is not a one-time exercise. Across the three-year cycle, the certification body checks in through annual surveillance audits and a recertification audit before expiry — and in between, the ISMS itself has to keep operating and improving. Here's what that cycle actually looks like stage by stage.

Month 0Stage 1 + Stage 2

The certification body reviews readiness and documented arrangements, then assesses implementation and effectiveness. Success leads to certification within the defined scope.

~Month 12First surveillance audit

Checks that the ISMS still conforms and operates, and that risks, controls, objectives, internal audits and corrective actions remain actively managed.

~Month 24Second surveillance audit

Continues to verify conformity and evidence, and reviews how changes in business, technology, suppliers, threats and obligations affect the risk picture.

Before Month 36Recertification audit

Evaluates continued conformity and overall effectiveness of the ISMS before the certificate expires; if successful, the next three-year cycle begins.

M0Initial certification
M12Surveillance audit
M24Surveillance audit
M36Recertification audit
Why surveillance audits matter

Certification must remain a
living security system.

Surveillance is designed to provide ongoing confidence that the ISMS remains implemented and effective — not simply that documentation existed on the day of the original audit.

Validate controls

Confirm that relevant controls and operating processes continue to function as intended and that evidence is maintained.

ControlsEvidence

Check risk changes

Review how changes in business, technology, suppliers, threats and obligations have affected information-security risks and treatment.

RiskChange

Maintain trust

Regular independent assessment helps customers and stakeholders see that the certified ISMS is being maintained rather than treated as a one-time project.

TrustIndependence
Accreditation matters

Not all ISO 27001 certificates are positioned the same way.

ANAB, UKAS, UAF and JAS-ANZ are accreditation bodies, not different versions of ISO 27001. An accredited certification body performs the ISO 27001 assessment and issues the certificate under its accredited scope. The accreditation behind the certification body can affect recognition, procurement acceptance and stakeholder confidence.

ANABUnited States

ANSI National Accreditation Board accredits management-system certification bodies, including ISO/IEC 27001 schemes within its scope.

UKASUnited Kingdom

UKAS is the UK national accreditation body and accredits certification bodies for management-system certification within defined scopes.

UAFInternational

United Accreditation Foundation provides accreditation for management-system certification bodies and has an ISMS / ISO 27001 accreditation scope.

JAS-ANZAustralia & New Zealand

JAS-ANZ is the joint accreditation body for Australia and New Zealand and includes ISO/IEC 27001:2022 within its management-system accreditation schemes.

India: NABCB

The National Accreditation Board for Certification Bodies is a key Indian accreditation route for management-system certification bodies, including ISMS schemes.

What to verify

Check the certification body's accreditation, its exact ISO/IEC 27001 scope, the certificate scope, issuing entity, status and applicable certification cycle.

Accredited ≠ guaranteed

Accreditation provides confidence in the competence and impartiality of the certification process; it does not replace checking the actual certificate and its current status.

Why CyberAtrix

Performance. Delivery. Costing.
Built around your business.

CyberAtrix approaches ISO 27001 as a practical security transformation — not a documentation-only exercise. Our focus is to make the ISMS understandable, implementable, auditable and useful to the organization after certification. We also integrate with related services such as VAPT, ISO 9001, ISO 42001 and GRC services.

CyberAtrix Delivery Model

Risk → Control → Evidence → Assurance

A practical operating model for turning ISO 27001 requirements into measurable security outcomes.

01UnderstandBusiness context & scope
02IdentifyRisks & control objectives
03ImplementControls & validation
04EvidenceCollect & remediate
05AssurePrepare for assessment

Performance

Focused execution, clear ownership, measurable milestones and security outcomes that go beyond paperwork.

OwnershipMilestones

Delivery

A structured journey from scope and gap assessment through risk, SoA, controls, evidence, internal audit and certification readiness.

StructureJourney

Costing

Practical, right-sized engagement models designed to avoid unnecessary complexity while keeping the implementation aligned with business needs.

Right-sizedAligned

Experienced analysts

Hands-on security experience helps connect ISO requirements with real operational, technical and business realities.

Hands-onPractical
Experience • Expertise • Authoritativeness • Trust

Who reviews this content

This page is reviewed by CyberAtrix leadership and checked against the published ISO/IEC 27001:2022 and ISO/IEC 27002:2022 texts.

Rakesh H Kotian, Chief Executive Officer of CyberAtrix

Rakesh H Kotian

Chief Executive Officer, CyberAtrix

ISO 27001 Lead Auditor (LA) • ISO 27001 Lead Implementer (LI)

Reviewed & updated: 21 September 2026

Experience

Hands-on ISMS implementation, internal audit and certification-readiness work across multiple sectors.

Expertise

Led by Rakesh H Kotian, ISO 27001 Lead Auditor & Lead Implementer, with deep knowledge of ISO 27001:2022, ISO 27002, risk management, and GRC.

Authoritativeness

Content is grounded in primary sources: the official ISO, NIST and OWASP references listed below.

Trust

Transparent, myth-busting guidance. We tell you what the standard actually requires — not what generates unnecessary paperwork or consulting fees.

Reference Standards

Grounded in recognized security
and assurance frameworks.

These references provide context for the standards, controls and security practices used across our engagements. They are shown as references — not as endorsements or certifications of CyberAtrix.

ISO
INFORMATION SECURITY

ISO/IEC 27001:2022

Requirements for establishing, implementing, maintaining and continually improving an information security management system.

Official ISO reference ↗
27002
CONTROL GUIDANCE

ISO/IEC 27002:2022

Information security controls — guidance for selecting, implementing and managing information security controls.

Official ISO reference ↗
NIST
CYBER RISK

Cybersecurity Framework 2.0

A flexible framework for helping organizations understand, assess, prioritize and communicate cybersecurity risk.

Official NIST reference ↗
OWASP
APPLICATION SECURITY

OWASP Top 10:2025

A current awareness resource highlighting major web application security risks and secure-development priorities.

Official OWASP reference ↗

Framework names and marks belong to their respective owners. CyberAtrix does not represent that an engagement constitutes certification unless explicitly stated and independently issued by the relevant certification or assurance body.

ISO/IEC 27001:2022

What changed in ISO 27001:2022 — and why it matters now.

The 2022 edition replaced the 2013 version. The transition period ended on 31 October 2025, so a valid certificate must now be to the 2022 edition. Amendment 1:2024 also added a requirement to determine whether climate change is relevant to the ISMS.

93 controls, 4 themes

Annex A now has 93 controls grouped into organizational, people, physical and technological themes, replacing the 114 controls in 14 domains of the 2013 edition.

11 new controls

Threat intelligence, cloud services security, ICT readiness for business continuity, physical security monitoring, configuration management, information deletion, data masking, data leakage prevention, monitoring activities, web filtering and secure coding.

2013 certificates no longer valid

If your certificate still references ISO/IEC 27001:2013, contact your certification body about the route to a 2022 certificate.

Documented information

What ISO 27001 actually requires you to document.

Auditors look for the documented information the standard requires plus whatever your organization needs for the ISMS to work. More paperwork is not the goal.

Framework documents

  • ISMS scope
  • Information security policy
  • Risk assessment and treatment process
  • Statement of Applicability
  • Information security objectives

Results and evidence

  • Risk assessment and treatment results
  • Evidence of competence
  • Monitoring and measurement results
  • Internal audit programme and results

Review and improvement

  • Management review results
  • Nonconformities and corrective actions
  • Change and incident records
  • Supplier and access-control evidence
Planning your project

How long does ISO 27001 take,
and what drives the cost?

Every scope is different, so we size the work after understanding your context. These are the factors that matter most.

Typical timeline

A focused scope in a smaller organization often needs roughly 3 to 6 months from gap assessment to the Stage 1 audit. Larger, multi-site or highly regulated scopes usually take longer.

Consulting cost drivers

Headcount in scope, number of sites, cloud and technology complexity, existing documentation, security maturity and how much of the work your team can own.

Certification body fees

Audit fees are paid separately to your accredited certification body and depend on scope and audit days. Ask for a written quote covering the full three-year cycle.

Also comparing frameworks? See our SOC 2, ISO 27701, ISO 22301 and PCI DSS services.

Offensive security

Know your attack surface before attackers do.

CyberAtrix combines automated discovery with manual validation to uncover vulnerabilities that matter — with clear severity, business impact, evidence and remediation guidance.

Web ApplicationsAPIsMobileAWS / AzureSaaSNetworkProxmoxADThick Client
View VAPT Services →
Frequently asked questions

ISO 27001 questions, answered.

Common questions organizations ask when planning ISO 27001 implementation and certification.

What is ISO 27001?

ISO/IEC 27001 is the international requirements standard for an Information Security Management System (ISMS). It provides a systematic, risk-based framework for managing information security across people, processes and technology, helping organizations protect the confidentiality, integrity and availability of information.

Does ISO 27001 guarantee that an organization is completely secure?

No. Certification is assurance that an ISMS is being managed against the requirements of the standard; it is not a product badge or an absolute guarantee that every security threat is prevented. It demonstrates that a systematic, risk-based management system is in place and independently assessed.

What is a Statement of Applicability?

The Statement of Applicability records the controls selected for the ISMS, including the rationale for inclusions and exclusions, additional controls where relevant, and implementation status. It is a key document that connects risk treatment decisions to the controls actually implemented.

How does ISO 27001 implementation work?

A practical implementation starts with context and scope, leadership and policy, risk methodology and assessment, risk treatment, control selection and the Statement of Applicability, followed by implementation, awareness, operation, monitoring, internal audit, management review and continual improvement.

How long is an ISO 27001 certificate valid?

An ISO 27001 certificate is typically valid for three years. During that cycle the certification body performs surveillance audits at least annually (commonly around months 12 and 24), and a recertification audit before expiry (around month 36) starts the next cycle. Exact scheduling follows your certification body's programme.

Is ISO 27001 only for technology companies?

No. The ISMS standard is not restricted to a specific geography, sector or product. It can be applied to organizations that rely on information and information-processing systems, including financial services, healthcare, manufacturing, government, professional services and non-profits.

Can ISO 27001 work with ISO 9001 and other management systems?

Yes. The common high-level structure of management-system standards can make integration practical, allowing context, leadership, internal audit, documentation and continual-improvement processes to be shared where appropriate. This reduces duplication and improves overall governance.

What is the difference between ANAB, UKAS, UAF, and JAS-ANZ?

These are accreditation bodies, not different versions of ISO 27001. ANAB covers the United States, UKAS covers the United Kingdom, UAF is international, and JAS-ANZ covers Australia and New Zealand. An accredited certification body performs the ISO 27001 assessment and issues the certificate under its accredited scope.

Is ISO 27001:2013 still valid?

No. The transition period to ISO/IEC 27001:2022 ended on 31 October 2025, so certificates issued to the 2013 edition are no longer valid. Organizations now need certification to the 2022 edition.

How many controls are in ISO 27001:2022 Annex A?

Annex A of ISO/IEC 27001:2022 lists 93 controls in four themes (organizational, people, physical and technological), down from 114 controls in 14 domains in the 2013 edition. Eleven controls are new.

How long does ISO 27001 implementation take?

It depends on scope, size, existing security maturity and available resources. A focused scope in a smaller organization often takes roughly 3 to 6 months from gap assessment to the Stage 1 audit; larger or multi-site scopes usually take longer.

Which documents does ISO 27001 require?

Documented information includes the ISMS scope, information security policy, risk assessment and treatment process, Statement of Applicability, security objectives, evidence of competence, and records of monitoring, internal audits, management reviews and corrective actions. Supporting procedures depend on your risks and controls.

What is the difference between ISO 27001 and SOC 2?

ISO 27001 is a certifiable management-system standard assessed by an accredited certification body. SOC 2 is an attestation report issued by a licensed CPA firm against the Trust Services Criteria. Many organizations pursue both; see our SOC 2 services.

Have an ISO 27001 objective?

Tell us what you need to achieve and we will help map the right engagement.

Talk to an Expert →
Ready when you are

Drop your enquiry with confidence.

Tell us your organization size, scope, locations and current security maturity. We'll help you understand the right ISO 27001 implementation path, certification approach and effort required.

Start Your ISO 27001 Enquiry →