01Structure of the standard: clauses 4 to 10
ISO/IEC 27001:2022 follows the harmonised basic structure of the ISO management system standards (High Level Structure). The mandatory requirements are set out in clauses 4 to 10: context of the organization (4), leadership (5), planning (6), support (7), operation (8), performance evaluation (9) and improvement (10). Together they map the PDCA cycle – from understanding the environment through risk assessment and implementation to internal audit, management review and continual improvement. Thanks to the common structure, the ISMS can be integrated with other management systems such as ISO 9001.
02Annex A: 93 controls in four themes
Annex A contains 93 reference controls in four themes: organizational controls (A.5, 37), people controls (A.6, 8), physical controls (A.7, 14) and technological controls (A.8, 34). Implementation guidance is provided by the companion standard ISO/IEC 27002:2022. Selection is risk-based: each control is documented in the Statement of Applicability as applicable or – with justification – as excluded. Since the transition period ended on 31 October 2025, only certificates issued against the :2022 edition are valid.
03The certification cycle: Stage 1, Stage 2, surveillance
Initial certification takes place in two stages: in the Stage 1 audit, the certification body reviews the ISMS documentation and readiness for certification (including scope, risk assessment and Statement of Applicability); in the Stage 2 audit, it verifies effective implementation in practice – with interviews, site walkthroughs and sampling. The certificate is valid for three years; annual surveillance audits take place in the two following years, and a recertification audit is conducted before the cycle expires. The requirements for accredited certification bodies are governed by ISO/IEC 17021-1 and ISO/IEC 27006-1:2024; in Germany, DAkkS is the competent accreditation body.
04Value as evidence: NIS2, TISAX, customer audits
A certified ISMS is the standard way to demonstrate systematic security management. For the NIS2 Directive (EU) 2022/2555, ENISA has mapped the risk management measures under Art. 21(2) in its Technical Implementation Guidance (06/2025) to, among others, ISO/IEC 27001:2022 – a certificate does not automatically replace NIS2 compliance, but it structurally covers the required measures to a large extent. The automotive industry's TISAX assessment catalogue VDA ISA has been aligned with ISO/IEC 27001:2022 since version 6; the TISAX label is assessed separately, but an existing ISMS considerably shortens the preparation. In customer audits and tenders, the certificate reduces recurring individual attestations and questionnaires.
05Typical implementation journey: from gap analysis to operation
Implementation starts with a gap analysis against clauses 4 to 10 and Annex A, together with defining the scope. This is followed by risk assessment and risk treatment (clause 6), from which the Statement of Applicability (SoA) is derived. Policies, processes and controls are then implemented and embedded in day-to-day operations; before the certification audit, certification bodies generally expect at least one complete internal audit and one management review. The duration depends on the organisation's size, scope and maturity level – from a few months to more than a year.
06Amendment 1:2024: “Climate action changes”
ISO/IEC 27001:2022/Amd 1:2024 was published in February 2024. The change is small but binding: under clause 4.1, the organisation must determine whether climate change is a relevant issue for its ISMS; in clause 4.2, a new note clarifies that interested parties may have climate-related requirements. It does not introduce new controls or a new certificate – auditors do, however, expect a documented, reasoned assessment. No successor edition of the standard has been announced to date; ISO/IEC 27001:2022 remains the current edition (as of July 2026).