Book an Appointment

ISO/IEC 27001: The certifiable standard for information security

What the standard requires, how the path to certification works and why an ISMS based on ISO/IEC 27001 holds up as evidence towards customers, partners and supervisory authorities.

Last updated: July 2026 · Valeri Milke, ISO 27001 & ISO 42001 Lead Auditor

93reference controls in Annex A of ISO/IEC 27001:2022
4themes: organizational, people, physical, technological
2audit stages for initial certification: Stage 1 and Stage 2
3years of certificate validity — with annual surveillance audits

ISO/IEC 27001 is the internationally established, certifiable standard for information security management systems (ISMS). It does not define a checklist of individual measures but a management system: the organisation identifies its risks, selects measures derived from them and continuously demonstrates their effectiveness. The current edition, ISO/IEC 27001:2022, combines the mandatory requirements of clauses 4 to 10 with the control catalogue in Annex A; the transition period from the previous :2013 edition ended on 31 October 2025. For many companies, certification today is less a nice-to-have than a ticket to entry – as structural evidence for NIS2, as a foundation for TISAX and as an answer to recurring customer audits.

Milestones around ISO/IEC 27001:2022

From Amendment 1 to the status as of July 2026 — tap a milestone for details.

The Essentials at a Glance

Six topic blocks — tap to expand.

Annex A at a glance: four themes

93 reference controls, selected on a risk basis — one tab per theme.

A.5
  • 37 organizational reference controls in theme A.5.
  • Each control is documented in the Statement of Applicability as applicable or — with justification — as excluded.

Standards & Sources

The content on this page is based on the following publicly available guides and studies.

ISO/IEC · 2022

ISO/IEC 27001:2022 – Information security, cybersecurity and privacy protection – Information security management systems – Requirements

Current edition of the standard with the mandatory requirements of clauses 4–10 and Annex A (93 controls in four themes).

ISO/IEC · 2024

ISO/IEC 27001:2022/Amd 1:2024 – Amendment 1: Climate action changes

Amends clause 4.1 (determining whether climate change is a relevant issue) and clause 4.2 (note on climate-related requirements of interested parties).

ISO/IEC · 2024

ISO/IEC 27006-1:2024 – Requirements for bodies providing audit and certification of information security management systems – Part 1: General

Together with ISO/IEC 17021-1, governs the requirements for accredited certification bodies, including the audit process and minimum audit duration.

ENISA · 2025

Technical Implementation Guidance on Cybersecurity Risk Management Measures (Version 1.0)

Maps the NIS2 risk management measures under Art. 21(2) to ISO/IEC 27001:2022 and NIST CSF 2.0 and specifies types of evidence per requirement.

Amtsblatt der EU / EUR-Lex · 2022

Richtlinie (EU) 2022/2555 (NIS2)

Art. 21(2) defines the cybersecurity risk management measures for which an ISMS based on ISO/IEC 27001 serves as structural evidence.

ENX Association · 2023

ISA Version 6 Now Available

Announcement of version 6 of the VDA ISA catalogue, which underpins the TISAX process and is aligned with ISO/IEC 27001:2022.

ISO/IEC 27001 on your agenda?

In a no-obligation initial consultation, we assess where your ISMS stands today and which path to certification is realistic for your organisation.