Book an Appointment

ISO/IEC 27001: The certifiable standard for information security

What the standard requires, how the path to certification works and why an ISMS based on ISO/IEC 27001 holds up as evidence towards customers, partners and supervisory authorities.

ISO/IEC 27001 is the internationally established, certifiable standard for information security management systems (ISMS). It does not define a checklist of individual measures but a management system: the organisation identifies its risks, selects measures derived from them and continuously demonstrates their effectiveness. The current edition, ISO/IEC 27001:2022, combines the mandatory requirements of clauses 4 to 10 with the control catalogue in Annex A; the transition period from the previous :2013 edition ended on 31 October 2025. For many companies, certification today is less a nice-to-have than a ticket to entry – as structural evidence for NIS2, as a foundation for TISAX and as an answer to recurring customer audits.

The Essentials at a Glance

01

Structure of the standard: clauses 4 to 10

ISO/IEC 27001:2022 follows the harmonised basic structure of the ISO management system standards (High Level Structure). The mandatory requirements are set out in clauses 4 to 10: context of the organization (4), leadership (5), planning (6), support (7), operation (8), performance evaluation (9) and improvement (10). Together they map the PDCA cycle – from understanding the environment through risk assessment and implementation to internal audit, management review and continual improvement. Thanks to the common structure, the ISMS can be integrated with other management systems such as ISO 9001.

02

Annex A: 93 controls in four themes

Annex A contains 93 reference controls in four themes: organizational controls (A.5, 37), people controls (A.6, 8), physical controls (A.7, 14) and technological controls (A.8, 34). Implementation guidance is provided by the companion standard ISO/IEC 27002:2022. Selection is risk-based: each control is documented in the Statement of Applicability as applicable or – with justification – as excluded. Since the transition period ended on 31 October 2025, only certificates issued against the :2022 edition are valid.

03

The certification cycle: Stage 1, Stage 2, surveillance

Initial certification takes place in two stages: in the Stage 1 audit, the certification body reviews the ISMS documentation and readiness for certification (including scope, risk assessment and Statement of Applicability); in the Stage 2 audit, it verifies effective implementation in practice – with interviews, site walkthroughs and sampling. The certificate is valid for three years; annual surveillance audits take place in the two following years, and a recertification audit is conducted before the cycle expires. The requirements for accredited certification bodies are governed by ISO/IEC 17021-1 and ISO/IEC 27006-1:2024; in Germany, DAkkS is the competent accreditation body.

04

Value as evidence: NIS2, TISAX, customer audits

A certified ISMS is the standard way to demonstrate systematic security management. For the NIS2 Directive (EU) 2022/2555, ENISA has mapped the risk management measures under Art. 21(2) in its Technical Implementation Guidance (06/2025) to, among others, ISO/IEC 27001:2022 – a certificate does not automatically replace NIS2 compliance, but it structurally covers the required measures to a large extent. The automotive industry's TISAX assessment catalogue VDA ISA has been aligned with ISO/IEC 27001:2022 since version 6; the TISAX label is assessed separately, but an existing ISMS considerably shortens the preparation. In customer audits and tenders, the certificate reduces recurring individual attestations and questionnaires.

05

Typical implementation journey: from gap analysis to operation

Implementation starts with a gap analysis against clauses 4 to 10 and Annex A, together with defining the scope. This is followed by risk assessment and risk treatment (clause 6), from which the Statement of Applicability (SoA) is derived. Policies, processes and controls are then implemented and embedded in day-to-day operations; before the certification audit, certification bodies generally expect at least one complete internal audit and one management review. The duration depends on the organisation's size, scope and maturity level – from a few months to more than a year.

06

Amendment 1:2024: “Climate action changes”

ISO/IEC 27001:2022/Amd 1:2024 was published in February 2024. The change is small but binding: under clause 4.1, the organisation must determine whether climate change is a relevant issue for its ISMS; in clause 4.2, a new note clarifies that interested parties may have climate-related requirements. It does not introduce new controls or a new certificate – auditors do, however, expect a documented, reasoned assessment. No successor edition of the standard has been announced to date; ISO/IEC 27001:2022 remains the current edition (as of July 2026).

Standards & Sources

The content on this page is based on the following publicly available guides and studies.

ISO/IEC · 2022

ISO/IEC 27001:2022 – Information security, cybersecurity and privacy protection – Information security management systems – Requirements

Current edition of the standard with the mandatory requirements of clauses 4–10 and Annex A (93 controls in four themes).

ISO/IEC · 2024

ISO/IEC 27001:2022/Amd 1:2024 – Amendment 1: Climate action changes

Amends clause 4.1 (determining whether climate change is a relevant issue) and clause 4.2 (note on climate-related requirements of interested parties).

ISO/IEC · 2024

ISO/IEC 27006-1:2024 – Requirements for bodies providing audit and certification of information security management systems – Part 1: General

Together with ISO/IEC 17021-1, governs the requirements for accredited certification bodies, including the audit process and minimum audit duration.

ENISA · 2025

Technical Implementation Guidance on Cybersecurity Risk Management Measures (Version 1.0)

Maps the NIS2 risk management measures under Art. 21(2) to ISO/IEC 27001:2022 and NIST CSF 2.0 and specifies types of evidence per requirement.

Amtsblatt der EU / EUR-Lex · 2022

Richtlinie (EU) 2022/2555 (NIS2)

Art. 21(2) defines the cybersecurity risk management measures for which an ISMS based on ISO/IEC 27001 serves as structural evidence.

ENX Association · 2023

ISA Version 6 Now Available

Announcement of version 6 of the VDA ISA catalogue, which underpins the TISAX process and is aligned with ISO/IEC 27001:2022.

ISO/IEC 27001 on your agenda?

In a no-obligation initial consultation, we assess where your ISMS stands today and which path to certification is realistic for your organisation.