Independent publication. General information only: not an auditor, certification body, law firm or standards body.
Baseline ReadySecurity & Compliance Intelligence Check your readiness

Framework guide

ISO 27001 readiness and certification explained

Updated Last verified

In short: ISO/IEC 27001:2022 is the international standard for an information security management system (ISMS). Its Annex A lists 93 controls in four themes. An accredited certification body audits you and, if you meet the standard, issues a certificate for a three-year cycle with annual surveillance audits. Certification bodies describe the journey as typically taking 3 to 12 months.

The standard

ISO/IEC 27001:2022 sets out requirements for an information security management system: how an organisation establishes, runs and continually improves the way it manages information security risk. It was published on 25 October 2022, replacing the 2013 edition, and has since been amended by Amendment 1:2024 on climate action changes.

We summarise the standard rather than reproduce it: the text itself is copyrighted and sold by ISO and national standards bodies.

Annex A: 93 controls, four themes

ThemeControls
Organizational37
People8
Physical14
Technological34
Total93

The 2013 edition had 114 controls; the 2022 revision consolidated them into 93 and regrouped them into these four themes. Certification bodies set 31 October 2025 as the deadline for moving certificates from the 2013 to the 2022 edition.

How certification works

  • Who certifies. Certificates are issued by certification bodies that are themselves accredited by accreditation bodies. Check that a certification body is accredited before you engage it.
  • The cycle. A certificate runs for three years. Surveillance audits take place in each of the two years after certification, followed by a recertification audit.
  • How long it takes. Certification bodies and compliance publishers describe the journey to certification as typically 3 to 12 months, depending on scope and how much is already in place.

What implementation usually involves

  1. ISMS scope. Decide which parts of the organisation, locations and systems the ISMS covers.
  2. Risk assessment and treatment. Identify information security risks and decide how each is treated.
  3. Controls. Select the Annex A controls that treat those risks, and record which apply and why.
  4. Internal audit and management review. Check the ISMS works before the certification body does.
  5. Certification audit. The certification body audits the ISMS and, if it conforms, issues the certificate.

A quick self-check of the security foundations these steps build on is in our readiness assessment. Published costs are in the Cost & Readiness Index, and the differences from SOC 2 are in SOC 2 vs ISO 27001.

Only an accredited certification body can certify an ISMS. Nothing here is certification or legal advice, and no checklist guarantees an outcome.