What is ISO 27001? The Complete Beginner Guide (2026)
ISO/IEC 27001 is the international standard for an Information Security Management System (ISMS). It does not tell you which firewall to buy - it requires you to build a management system that identifies your information security risks and treats them consistently, with evidence an auditor can verify.
What ISO 27001 actually certifies
Certification covers your management system, not a product. An auditor checks that you defined a scope, obtained leadership commitment, assessed risks, selected controls, and that you monitor, audit and improve the system over time. That is why a 20-person SaaS company and a bank can both be certified - the standard scales with your risk.
What changed in the 2022 revision
- The standard was restructured and renamed ISO/IEC 27001:2022.
- Annex A now contains 93 controls in four themes instead of 114 in 14 domains.
- 11 new controls were added, including threat intelligence, cloud security, ICT readiness for business continuity, secure coding, and data masking.
- Certificates against the old 2013 version had to transition - any certificate you see today should be 2022-based.
The structure: Clauses 4-10
- Clause 4 - Context: internal/external issues, interested parties, ISMS scope.
- Clause 5 - Leadership: management commitment, policy, roles.
- Clause 6 - Planning: risk assessment, risk treatment, Statement of Applicability (SoA), objectives.
- Clause 7 - Support: competence, awareness, documented information.
- Clause 8 - Operation: doing what you planned, including periodic risk assessments.
- Clause 9 - Performance evaluation: metrics, internal audit, management review.
- Clause 10 - Improvement: nonconformities and corrective action.
Annex A: 93 controls in four themes
- Organizational (37): policies, vendor relationships, incident management, business continuity.
- People (8): screening, terms of employment, awareness training.
- Physical (14): perimeters, entry controls, equipment protection.
- Technological (34): access control, cryptography, logging, secure development.
How certification works
- Stage 1 audit: the certification body reviews documentation and readiness.
- Stage 2 audit: the auditor checks the ISMS is actually implemented and effective.
- Surveillance audits: annual check-ins in years 1 and 2.
- Recertification: full audit at year 3, then the cycle repeats.
How to start implementing (this week)
- Define scope and get a signed information security policy (Clauses 4-5).
- Run a gap assessment to see where you stand.
- Perform a risk assessment using a documented 5x5 method.
- Export a risk register with owners, treatments and target dates.
- Use the register to build your Statement of Applicability, then schedule an internal audit.
Common beginner mistakes
- Writing 80 policies before doing a single risk assessment (the standard is risk-driven, not document-driven).
- Scoping too broadly - certify the part of the business clients care about first.
- Treating the SoA as a checklist instead of a justified decision record.
Free tools for this guide
ISO 27001 Gap Assessment · ISO 27001 Risk Calculator · Risk Register Generator
Continue in this cluster
Frequently asked questions
Is ISO 27001 mandatory?
No. It is a voluntary international standard. However, enterprise contracts, tenders and sector regulations often make certification a practical requirement to win business, especially in SaaS, fintech and healthcare.
How long does ISO 27001 certification take?
Most small to mid-size organizations take 3 to 12 months from kickoff to certificate, depending on scope, existing maturity and how much documentation already exists.
What is the difference between ISO 27001 and ISO 27002?
ISO 27001 defines the requirements for the management system and is the standard you certify against. ISO 27002 is the companion code of practice explaining how to implement the Annex A controls.
Do I need a consultant to get certified?
No, but experienced help shortens the timeline. You can self-implement using the standard, a gap assessment and a solid risk register - the free tools on this site produce the core artifacts.
Can you explain this in an interview?
CyberVerse AI asks you this topic out loud and grades your answer like a hiring manager.
Practice with CyberVerse AI →