ISO/IEC 27001:2022 follows the harmonised basic structure of the ISO management system standards (High Level Structure). The mandatory requirements are set out in clauses 4 to 10: context of the organization (4), leadership (5), planning (6), support (7), operation (8), performance evaluation (9) and improvement (10). Together they map the PDCA cycle – from understanding the environment through risk assessment and implementation to internal audit, management review and continual improvement. Thanks to the common structure, the ISMS can be integrated with other management systems such as ISO 9001.
ISO/IEC 27001: The certifiable standard for information security
What the standard requires, how the path to certification works and why an ISMS based on ISO/IEC 27001 holds up as evidence towards customers, partners and supervisory authorities.
93reference controls in Annex A of ISO/IEC 27001:2022
4themes: organizational, people, physical, technological
2audit stages for initial certification: Stage 1 and Stage 2
3years of certificate validity — with annual surveillance audits
ISO/IEC 27001 is the internationally established, certifiable standard for information security management systems (ISMS). It does not define a checklist of individual measures but a management system: the organisation identifies its risks, selects measures derived from them and continuously demonstrates their effectiveness. The current edition, ISO/IEC 27001:2022, combines the mandatory requirements of clauses 4 to 10 with the control catalogue in Annex A; the transition period from the previous :2013 edition ended on 31 October 2025. For many companies, certification today is less a nice-to-have than a ticket to entry – as structural evidence for NIS2, as a foundation for TISAX and as an answer to recurring customer audits.
Milestones around ISO/IEC 27001:2022
From Amendment 1 to the status as of July 2026 — tap a milestone for details.
Feb 2024
Amendment 1:2024 published
ISO/IEC 27001:2022/Amd 1:2024 (“Climate action changes”) is published. The change is small but binding: under clause 4.1, the organisation must determine whether climate change is a relevant issue for its ISMS.
06/2025
ENISA guidance maps NIS2 to the standard
ENISA's Technical Implementation Guidance maps the NIS2 risk management measures under Art. 21(2) to, among others, ISO/IEC 27001:2022 — a certificate does not automatically replace NIS2 compliance, but it structurally covers the required measures to a large extent.
31 Oct 2025
Transition period from :2013 ends
The transition period from the previous :2013 edition ends. From this date, only certificates issued against the :2022 edition are valid.
Jul 2026
ISO/IEC 27001:2022 remains the current edition
No successor edition of the standard has been announced to date; ISO/IEC 27001:2022 remains the current edition (as of July 2026).
The Essentials at a Glance
Six topic blocks — tap to expand.
Annex A at a glance: four themes
93 reference controls, selected on a risk basis — one tab per theme.
- 37 organizational reference controls in theme A.5.
- Each control is documented in the Statement of Applicability as applicable or — with justification — as excluded.
- 8 people reference controls in theme A.6.
- Selection is risk-based — not a checklist of individual measures.
- 14 physical reference controls in theme A.7.
- Implementation guidance is provided by the companion standard ISO/IEC 27002:2022.
- 34 technological reference controls in theme A.8.
- Since the transition period ended on 31 October 2025, only certificates issued against the :2022 edition are valid.
Standards & Sources
The content on this page is based on the following publicly available guides and studies.
ISO/IEC 27001:2022 – Information security, cybersecurity and privacy protection – Information security management systems – Requirements
Current edition of the standard with the mandatory requirements of clauses 4–10 and Annex A (93 controls in four themes).
ISO/IEC 27001:2022/Amd 1:2024 – Amendment 1: Climate action changes
Amends clause 4.1 (determining whether climate change is a relevant issue) and clause 4.2 (note on climate-related requirements of interested parties).
ISO/IEC 27006-1:2024 – Requirements for bodies providing audit and certification of information security management systems – Part 1: General
Together with ISO/IEC 17021-1, governs the requirements for accredited certification bodies, including the audit process and minimum audit duration.
Technical Implementation Guidance on Cybersecurity Risk Management Measures (Version 1.0)
Maps the NIS2 risk management measures under Art. 21(2) to ISO/IEC 27001:2022 and NIST CSF 2.0 and specifies types of evidence per requirement.
Richtlinie (EU) 2022/2555 (NIS2)
Art. 21(2) defines the cybersecurity risk management measures for which an ISMS based on ISO/IEC 27001 serves as structural evidence.
ISA Version 6 Now Available
Announcement of version 6 of the VDA ISA catalogue, which underpins the TISAX process and is aligned with ISO/IEC 27001:2022.
ISO/IEC 27001 on your agenda?
In a no-obligation initial consultation, we assess where your ISMS stands today and which path to certification is realistic for your organisation.