ISO/IEC 27001 Information Security Management
· About ISO/IEC 27001 Information Security Management
Key Takeaways
- ISO/IEC 27001 is a voluntary international certification standard, not a law, but organizations that contract for certification must implement an auditable information security management system (ISMS) or lose certification. ISO lists ISO/IEC 27001:2022 as the current edition, with Amendment 1:2024 published in February 2024. [1][2]
- The current certifiable requirements are ISO/IEC 27001:2022 plus ISO/IEC 27001:2022/Amd 1:2024; there is no published ISO/IEC 27001:2026 edition as of 2026-09-06. The amendment adds climate-change consideration in clauses 4.1 and 4.2, but does not replace the 2022 edition. [1][2]
- Organizations seeking certification must define the ISMS scope, assess information-security risks, select controls, and continuously improve the system under a documented management framework. These are the core certifiable obligations in Clause 4 through Clause 10 and Annex A. [1][3]
- Certification bodies and already-certified organizations had to complete transition from ISO/IEC 27001:2013 to ISO/IEC 27001:2022 by 31 October 2025. After that date, the 2013 edition is withdrawn for certification purposes. [4][5]
- ISO/IEC 27001 is globally applicable and can be used by organizations of any size or sector, including entities operating across borders. It does not contain a general statutory exemption for small organizations, but scope, applicability, and controls are risk-based. [1][3]
- Failure to maintain certification does not create direct government fines under the standard itself, but it can trigger contractual loss, audit failure, certification withdrawal, and market-access consequences. Penalties come from certification rules and private contracts, not from ISO enforcement. [1][4]
What It Is
ISO/IEC 27001 is the internationally recognized requirements standard for an information security management system (ISMS), published by ISO and IEC and used for certification by accredited certification bodies. Its scope is organizational rather than sector-specific: it sets the management-system requirements for protecting information confidentiality, integrity, and availability through risk management and continual improvement. [1][3]
The current published requirements edition is ISO/IEC 27001:2022, and ISO shows ISO/IEC 27001:2022/Amd 1:2024 as a published amendment. The amendment was published in February 2024 and introduces climate-change considerations into Clause 4.1 and Clause 4.2. [1][2]
Key dates are as follows:
- 25 October 2022 — ISO/IEC 27001:2022 published. [1][5]
- February 2024 — ISO/IEC 27001:2022/Amd 1:2024 published. [2]
- 31 October 2025 — transition deadline for moving certification from ISO/IEC 27001:2013 to ISO/IEC 27001:2022. [4][5]
The standard is enforced in practice by accredited certification bodies that audit conformity; ISO itself publishes the standard but does not police organizations directly. [1][4]
Who Must Comply
ISO/IEC 27001 applies to any organization that chooses to implement or certify an ISMS, regardless of size, industry, or geography. The standard is intentionally broad and risk-based, so applicability is determined by the organization’s own defined scope and information-security risks rather than by a statutory threshold. [1][3]
There are no universal employee-count, revenue, or data-volume thresholds in the standard. Small and medium-sized organizations can certify, and ISO even publishes a practical guide for SMEs in the 27001 family. [1]
The standard has extraterritorial practical reach in the sense that a multinational can certify a global or regional ISMS scope covering multiple jurisdictions, but ISO/IEC 27001 itself does not override local privacy, cybersecurity, export-control, or sectoral laws. [1][3]
There are no formal exemptions built into the standard for public bodies, nonprofits, startups, or regulated industries; instead, those organizations tailor scope and controls to their own risks and legal obligations. [1][3]
Core Requirements
- Define the ISMS scope. The organization must determine the boundaries and applicability of the ISMS, including internal and external issues and interested-party requirements. [1][3]
- Assess information-security risks. The organization must establish a repeatable risk assessment and risk treatment process that identifies risks to information assets and selects appropriate controls. [1][3]
- Maintain leadership and governance. Top management must show commitment, assign roles and responsibilities, and ensure the ISMS is integrated into the organization’s processes. [3]
- Document and operate the ISMS. The organization must maintain required documented information, operational controls, internal audits, and management review processes. [3]
- Select controls from Annex A or justify alternatives. The organization must create a Statement of Applicability and explain which controls are included, excluded, or implemented by other means. [3]
- Continuously improve the ISMS. Nonconformities must be corrected, performance monitored, and the ISMS improved over time through the Plan-Do-Check-Act model embedded in the standard. [3]
Deadlines and Penalties
| Milestone | Date | What applies | |---|---:|---| | ISO/IEC 27001:2022 published | 25 October 2022 | New edition becomes available for certification. [1][5] | | Climate-action amendment published | February 2024 | Clause 4.1 and 4.2 updated to consider climate change relevance. [2] | | Transition deadline from 2013 edition | 31 October 2025 | Certification bodies and certified organizations must have moved to the 2022 edition. [4][5] |
Maximum fines and other sanctions: ISO/IEC 27001 itself does not prescribe statutory fines or criminal penalties. The main sanctions are private and certification-based: suspension, withdrawal, or non-renewal of certification; failed surveillance audits; contractual breach consequences; and loss of customer or procurement eligibility. [1][4]
How to Comply
- Set the scope and context. Define the organizational boundaries, critical services, external dependencies, interested parties, and legal requirements. This aligns well with ISO 27001 Clause 4 and ISO 42001 style governance discipline where AI is in scope. [1][3]
- Build a risk methodology. Use a formal information-security risk method with criteria for impact, likelihood, acceptance, and treatment. NIST CSF 2.0 can help structure outcomes across identify, protect, detect, respond, and recover. [3]
- Map controls to the risk picture. Select controls from Annex A and document any exclusions or alternative controls in the Statement of Applicability. Where a broader management system is needed, ISO 27001 maps cleanly to control governance and auditability. [3]
- Implement operational controls. Enforce access management, logging, vulnerability handling, supplier security, incident response, backup, and secure change management. This is where ISO 27001 operational controls and NIST CSF 2.0 categories can be paired effectively. [3]
- Formalize monitoring and internal audit. Track incidents, nonconformities, metrics, and control performance, then run periodic internal audits and management reviews. This supports the continuous-improvement cycle required by the standard. [3]
- Align the management system to an external framework. Use ISO 27001 as the certifiable backbone, ISO 27001-style Annex A controls as the control inventory, and ISO 42001 only where AI systems create governance, transparency, or accountability issues. [3]
- Prepare for certification and surveillance. Run a pre-audit, close gaps, and maintain evidence between surveillance audits so the certification body can verify ongoing conformity. [1][4]
Related Regulations
- GDPR — ISO/IEC 27001 often supports GDPR Article 32 security governance, but ISO certification does not itself prove GDPR compliance.
- NIS2 Directive — NIS2 imposes legal cybersecurity duties in the EU, while ISO/IEC 27001 is a voluntary framework that can help evidence maturity.
- DORA — Financial entities subject to DORA may use ISO/IEC 27001 controls to support resilience and governance, but DORA requirements remain separate and binding.
- ISO/IEC 27701:2025 — This privacy extension can complement an ISO/IEC 27001 ISMS where personal-data processing is central, but it does not replace the ISMS requirements.
- ISO/IEC 27002:2022 — This is the control guidance companion to ISO/IEC 27001 and is often used to interpret Annex A implementation choices.
FAQ
Does ISO/IEC 27001 apply to companies outside Europe?
Yes. ISO/IEC 27001 is an international standard and can be used by organizations anywhere in the world. It is not limited to the EU or any single jurisdiction. [1][3]
Is ISO/IEC 27001:2022 still the current standard in 2026?
Yes. ISO lists ISO/IEC 27001:2022 as the current edition, with Amd 1:2024 published in February 2024. There is no published ISO/IEC 27001:2026 edition as of 2026-09-06. [1][2]
Did the 2024 amendment change the whole standard?
No. The amendment is narrow and adds climate-change relevance checks in clauses 4.1 and 4.2. It does not create a new edition or rewrite the full ISMS structure. [2]
What happened to ISO/IEC 27001:2013 certificates?
They had to transition to the 2022 edition by 31 October 2025. After the transition period, certification bodies no longer treat the 2013 edition as current for certification. [4][5]
Does ISO/IEC 27001 guarantee legal compliance?
No. It is a management-system standard, not a blanket legal compliance instrument. It can support legal compliance by improving governance and controls, but organizations still need to meet applicable privacy, cybersecurity, sectoral, and contract-specific laws. [1][3]
Can a small company get certified?
Yes. The standard applies to organizations of any size, and ISO provides a practical guide for SMEs in the 27000 family. Scope and control selection should be proportionate to risk and operational reality. [1]
Sources
- ISO/IEC 27001:2022 — ISO standard page
- ISO/IEC 27001:2022/Amd 1:2024 — ISO standard page
- ISO/IEC 27000 family — Information security management
- ISO/IEC 27001:2013 — ISO withdrawal page
- UK National Cyber Security Centre guidance on ISO/IEC 27001
- BSI overview of ISO/IEC 27001
- A-LIGN guide to ISO 27001 transition from 2013 to 2022
Put it into practice
- Generate the policy: ISO 27001 policy generator (generatepolicy.com)
- Buy the policy pack: ISO 27001 Complete Bundle (cyberpolicy.shop)
- Build it yourself: ISO 27001:2022 Readiness Accelerator (ciso.diy)