The complete guide

ISO 27001,
explained
clause-by-clause.

ISO/IEC 27001 is the international standard for Information Security Management Systems (ISMS), the framework companies use to identify, treat, and continuously manage information security risk. This guide walks through its requirements, the 93 Annex A controls, the certification process, and what it costs in 2026.

ISO 27001 Compliance

What is ISO 27001?

ISO/IEC 27001:2022 is the international standard for Information Security Management Systems (ISMS), a structured way to identify information security risks, decide how to treat them, and prove that those decisions are actually being followed day to day. It’s published jointly by ISO and IEC, and it’s the most widely certified security standard in the world.

It applies to any organization that handles sensitive data, whether that’s a five-person SaaS startup, a fintech processing card data, or a global enterprise with dozens of subsidiaries. The standard doesn’t prescribe specific tools or technologies — it defines outcomes your security program needs to achieve, and lets you choose how to get there.

A few things worth knowing upfront:

  1. ISO 27001 is voluntary, but it’s routinely a contractual requirement — enterprise and government buyers ask for it before they’ll sign, especially outside North America.
  2. The current version is ISO/IEC 27001:2022. The 2013 version was formally retired on October 31, 2025, and every certificate issued against it has since expired or been withdrawn.
  3. The standard has 10 clauses; the first 3 cover scope, references, and terminology, while Clauses 4–10 contain the auditable requirements, plus Annex A, which contains 93 controls grouped under 4 themes.
  4. Certification is granted by accredited third-party certification bodies and is valid for 3 years, with annual surveillance audits in between.
  5. ISO 27001 shares a large portion of its control logic with SOC 2, so organizations already SOC 2–compliant typically move faster toward ISO 27001 certification.
💡Note

ISO 27001 doesn’t exist in isolation; it’s the certifiable centerpiece of the wider ISO/IEC 27000 family of standards, which includes companion standards like ISO 27002 (implementation guidance for the same controls) and ISO 27017 (cloud-specific security guidance). ISO 27001 is the only one of these you can actually get certified against — more on that distinction below.

Who needs ISO 27001 (and who doesn’t)

ISO 27001 isn’t relevant for every business, but if your product touches customer data, or your buyers are enterprises, the question is usually “when,” not “if.”

You probably need ISO 27001 if:

  • You sell to enterprise or government buyers who require it before signing (a very common deal-blocker outside the US)
  • You’re a SaaS company storing or processing customer data in the cloud
  • You’re a startup trying to shorten security review cycles and close enterprise deals faster
  • You operate in a regulated or high-trust sector such as fintech, healthtech, or B2B infrastructure
  • You’re fielding repeated, lengthy security questionnaires from prospects and want a credential that answers most of it upfront
  • You already hold SOC 2 or are pursuing it, and want a globally recognized credential to go with it
  • You’re a small business that wants a structured security program without hiring a full security team

You probably don’t need ISO 27001 (yet) if:

  • You’re pre-revenue with no customer data in scope and no buyer asking for it
  • Your market is exclusively US based SMBs, where SOC 2 alone typically satisfies buyer requirements
  • No prospect, regulator, or partner has ever asked about your security posture

If you’re on the fence, it usually comes down to what certification actually buys you commercially: shorter sales cycles, fewer security questionnaires, and access to enterprise and government RFPs.

CTA-logo
Full breakdown of what ISO 27001 certification gets you →

How ISO 27001 connects to SOC 2, GDPR, NIS2, and other frameworks

If you’re evaluating security frameworks, ISO 27001 rarely stands alone — it shares control logic with almost every other major standard your buyers or regulators might ask about.

Framework / regulationHow it relates to ISO 27001What this means for you
SOC 2Roughly 70% control overlap; SOC 2 is a US-centric attestation report, and ISO 27001 is a global certificationMany companies build one control set and map it to both, rather than running two separate programs
GDPRISO 27001’s risk management and access control requirements support (but don’t replace) GDPR’s technical and organizational measuresISO 27001 certification is strong supporting evidence in a GDPR data processing agreement
NIS2 (EU)Article 21 references risk-management measures that closely mirror ISO 27001’s Annex A controlsOrganizations in-scope for NIS2 often use ISO 27001 as their baseline compliance structure
PCI DSSNarrower and more prescriptive (cardholder data only) vs. ISO 27001’s broad ISMS approachCard-data businesses typically need both — PCI DSS for card data, ISO 27001 for the rest of the environment
ISO 42001Same 10-clause management-system structure; ISO 42001 governs AI systems specificallyOrganizations already ISO 27001 certified typically reach ISO 42001 certification faster by reusing the management system

ISO 27001 vs. ISO 27002 — a distinction worth getting right

These two get confused constantly, and the mix-up matters. ISO 27001 is the certifiable standard — the one your certification body actually audits and certifies you against. ISO 27002 covers the exact same 93 controls but is never certifiable; it exists purely to explain how to implement each control in practice, which ISO 27001 itself doesn’t spell out.

In practice, this means your Statement of Applicability is built against ISO 27001, but when you’re deciding how to actually implement a specific control — encryption key management, or supplier security reviews, for instance, ISO 27002’s control-by-control implementation guidance is usually the better reference to work from.

The 10 Clauses, decoded

ISO 27001 follows the same 10-clause skeleton used across modern ISO management-system standards — ISO 42001 and ISO 9001 included. Clauses 1 through 3 just define scope, references, and terminology; there’s nothing to action there. Everything an auditor will actually test sits in Clauses 4 through 10.

Clause 1 – Scope

Defines what ISO 27001 covers. No action items.

Clause 2 – Normative references

Points to ISO/IEC 27000 for terms and definitions. No action items.

Clause 3 – Terms and definitions

Glossary. No action items.

Clause 4 – Context of the organization

Identify internal/external issues, interested parties, and define your ISMS scope in a formal scope statement.

Clause 5 – Leadership

Top management owns the information security policy, roles, and accountability.

Clause 6 – Planning

Run a risk assessment across your information assets, build a risk treatment plan, and set security objectives.

Clause 7 – Support

Provide the people, competence, security awareness training, and documented information the ISMS needs.

Clause 8 – Operation

Operationalize risk treatment and control implementation day to day.

Clause 9 – Performance evaluation

Monitor, run internal audits, and conduct management review of the ISMS.

Clause 10 – Improvement

Address nonconformities and continually improve the ISMS.

ISO 27001 Requirements — mandatory documents and the SoA

The 10 clauses tell you what your ISMS must do. Meeting them means producing a specific set of mandatory documents auditors will always ask for, regardless of your size or industry:

  • ISMS scope statement
  • Information security policy and objectives
  • Risk assessment and risk treatment methodology
  • Statement of Applicability (SoA) — the single most-scrutinized document in any ISO 27001 audit
  • Risk treatment plan
  • Evidence of employee competence and training
  • Internal audit program and results
  • Management review records
  • Nonconformity and corrective action records


Most organizations end up maintaining somewhere between 20 and 25 documented policies to support these requirements — from an acceptable use policy to a data retention policy. See the full list of ISO 27001 policies →, or start from ready-made policy templates →

None of this has to start from a blank page. Sprinto ships with every mandatory document pre-drafted, pre-fills your SoA against the controls your actual tech stack needs, and keeps every policy version-controlled as your environment changes.

CTA-logo-img
Keep reading: ISO 27001 Requirements Every mandatory document is explained, with what auditors actually check for.

ISO 27001 Controls (Annex A)

Clauses 4–10 define what your ISMS must do. Annex A defines the specific controls you select and implement to actually do it. ISO/IEC 27001:2022’s Annex A contains 93 controls organized under 4 themes; a significant restructure from the 2013 version’s 114 controls across 14 domains.

The 4 Annex A themes at a glance:

ThemeControlsFocus
A.5 — Organizational37 controlsGovernance, policies, supplier and cloud security, incident response, and business continuity — including vendor management for third-party risk
A.6 — People8 controlsScreening, security awareness, remote working policy, disciplinary process
A.7 — Physical14 controlsFacilities, equipment, media handling, physical and environmental security
A.8 — Technological34 controlsAccess control, encryption, logging and monitoringmalware defensesecure developmentvulnerability management

Annex A is a reference menu, not a mandatory checklist; you select applicable controls based on your risk assessment, and justify every inclusion or exclusion in your Statement of Applicability. Asset management is a good example of a control area almost every organization includes regardless of scope, since some form of asset inventory underpins nearly every other control that follows.

Sprinto pre-builds the full Annex A control set against your actual tech stack, maps each control to the tools you already run, and collects evidence for every applicable one automatically — so implementation starts well past a blank slate.

CTA-check-img
Keep reading: ISO 27001 Controls Full breakdown of all 93 Annex A controls and how Sprinto maps each one.

ISO 27001 Checklist — turning the standard into a step-by-step plan

Reading the standard clause by clause is one thing. Actually sequencing the work is another. Most teams find it easier to work off a checklist grouped into practical stages rather than the standard’s own structure:

  • Foundations & scoping: define ISMS scope, appoint an ISMS owner, secure leadership sign-off
  • Risk & vendor management: complete risk assessment, risk treatment plan, and vendor risk reviews
  • Policies & documentation: publish mandatory policies and the SoA
  • Access & identity: enforce least-privilege access, MFA, and offboarding controls
  • Monitoring & logging: stand up continuous monitoring across infrastructure
  • Incident response: document and test your incident response plan
  • Internal audit & management review: run both before you ever see an external auditor
  • Audit prep & evidence: assemble evidence, brief stakeholders, schedule Stage 1 and Stage 2
CTA-check-img
Keep reading: ISO 27001 Checklist The complete stage-by-stage checklist, from scoping to certificate.

Picking the right ISO 27001 auditor

Your certification is only as credible as the body that issues it. Not every “ISO 27001 auditor” is accredited the same way, and the wrong choice can mean delays, re-audits, or a certificate that carries less weight with your buyers.

What to look for in an ISO 27001 certification body:

  • IAF MLA accreditation through a recognized national body (ANAB, UKAS, NABCB, DAkkS, etc.)
  • ISO/IEC 27001:2022 specifically in their accreditation scope
  • Auditor familiarity with your industry (a SaaS auditor understands cloud environments differently than a manufacturing auditor)
  • Reasonable scheduling availability and transparent pricing
  • Clear support for remote or hybrid audits, if that matters to your team

Questions to ask before signing with a certification body:

  • Are you currently accredited for ISO/IEC 27001:2022?
  • What’s your typical Stage 1-to-certificate turnaround?
  • Can you share references from companies our size?
  • Do you offer remote audits, and for which parts of the process?

If you’d rather not run this search yourself, compare Sprinto’s vetted list of ISO 27001 certification companies, or see when it’s worth bringing in an ISO 27001 consultant instead of or alongside an auditor. If you’re the one leading internal audits, it’s worth checking what ISO 27001 lead auditor training actually covers.

CTA-check-img
Keep reading: ISO 27001 Auditors How to evaluate and choose the right certification body.

What actually happens during an ISO 27001 audit?

ISO 27001 audits follow the standard ISO management-system audit cycle:

  • Stage 1 – Documentation review: the auditor checks your ISMS scope, policies, and SoA are in place and coherent (typically 1–2 days)
  • Stage 2 – Implementation assessment: the auditor tests whether controls are actually operating, sampling evidence and interviewing staff (typically 2–10+ days, usually scheduled 4–8 weeks after Stage 1)
  • Certification decision: certificate issued, valid for 3 years
  • Years 1 & 2 – Surveillance audits: shorter audits sampling a subset of controls to confirm the ISMS is still operating, not just point-in-time
  • Year 3 – Recertification audit: a full audit to renew the certificate for another 3-year cycle

What auditors specifically look for:

  • A Statement of Applicability that clearly justifies every included and excluded control
  • Evidence that controls have been operating continuously, not assembled just before the audit
  • A completed internal audit and management review, with documented outputs
  • Incident logs and evidence that the incident management process has actually been used
  • Consistent access control records: onboarding, offboarding, and periodic access reviews

Common audit findings:

  • Policies that exist on paper but aren’t reflected in day-to-day practice
  • Thin or missing risk treatment rationale in the SoA
  • Internal audits that were skipped or under-documented
  • Evidence gaps between the Stage 1 review and the Stage 2 assessment months later

For the internal groundwork that should happen before external auditors ever show up, see how an ISO 27001 internal audit should actually run, and for what the lighter, ongoing check looks like once you’re certified, see how ISO 27001 surveillance audits work.

CTA-check-img
More on ISO 27001 Audit What auditors look for, stage by stage, and how to prepare.

The ISO 27001 Certification roadmap

Most organizations move from kickoff to certificate in 3 to 12 months, depending on how much of the internal work is automated; though a meaningful chunk of that calendar time is actually your certification body’s scheduling, not your own prep.

The journey breaks down into six phases:

  1. Scoping & gap analysis (Week 1): define ISMS boundaries, run a gap analysis, shortlist a certification body
  2. Risk assessment & documentation (Weeks 2–4): risk assessment, risk treatment plan, Statement of Applicability, core policies
  3. Control implementation (Weeks 3–6): roll out Annex A controls and embed them into daily operations
  4. Internal audit & management review (Weeks 6–8): run your internal audit, hold management review, close any gaps; this is typically where “audit-ready” starts
  5. Stage 1 & Stage 2 external audit (Weeks 8–16+): Stage 1 reviews your documentation, followed by a 4–8 week gap before Stage 2 assesses whether controls are actually operating; certificate issued after Stage 2
  6. Surveillance & recertification (Years 1–3): annual surveillance audits, full recertification in year 3

Organizations coming from a 2013 certificate should note the transition window closed on October 31, 2025. Any lapsed 2013 certificate now needs a full initial audit against the 2022 version rather than a lighter transition assessment, so it’s worth reviewing what changed between ISO 27001:2013 and ISO 27001:2022 before you scope the program.

CTA-check-img
More on ISO 27001 Certification The full roadmap from kickoff to certificate, phase by phase.

What does an ISO 27001 report actually contain?

Unlike a SOC 2 report, ISO 27001 doesn’t produce one single “report” that gets handed to prospects. ISO 27001 certification results in a 1–2 page certificate, backed by internal documentation most buyers never see directly. But “report” comes up in a few different ISO 27001 contexts, and it’s worth being clear on which one you mean:

  • The audit report: the certification body’s internal findings from Stage 1 and Stage 2, including any nonconformities raised
  • The management review report: the output of your Clause 9.3 management review, evidencing that leadership is actively overseeing the ISMS
  • The internal audit report: findings from your own internal audit function ahead of the external audit
  • The compliance/status report: an internal summary (often generated automatically inside a platform like Sprinto) showing control health, open risks, and audit readiness at any point in time


Buyers who ask “can we see your ISO 27001 report” are usually asking for the certificate plus a summary of scope; not the full audit file, which stays between you and your certification body.

CTA-check-img
More on ISO 27001 Report What each type of ISO 27001 report contains, and what to actually share with buyers.

What does ISO 27001 really cost?

ISO 27001 costs vary widely based on company size, scope, the certification body you choose, and whether you bring in a consultant, a compliance platform, or run it fully in-house.

$15K–$50K+

Total program cost (small to mid-size)

6–8 weeks

Typical time to be audit-ready, with automation

60–150 hours

Internal effort with Sprinto

Estimated cost by organization profile:

Organization profileEstimated costWith Sprinto
Small team, single product (under 50 people)$15K–$25K$15K–$18K
Mid-size, multiple products (50–250 people)$25K–$60K$18K–$30K
Large mid-market (250–1,000 people)$60K–$150K$30K–$60K
Enterprise, multi-entity (1,000+ people)$150K–$250K+$60K–$100K

Where the money goes:

  • Certification body fees: Stage 1 + Stage 2 audit, typically $8,000–$16,000 for a small SaaS company; annual surveillance audits run roughly $6,000–$7,500 each
  • Gap analysis: $5,000–$8,000 if outsourced
  • Internal effort: security, engineering, and ISMS-owner time; the single largest hidden cost in a manual program
  • Consultant or software: a consultant reduces internal effort but not calendar time; automation platforms reduce both
CTA-check-img
More on ISO 27001 Certification Cost The full cost breakdown by company size, certification body, and approach.

Common ISO 27001 mistakes (and how to dodge them)

  1. Treating Annex A as a checklist. The 93 controls need to be implemented proportionately to your actual risks, not blindly applied. Document what you’ve included, excluded, and why, in your SoA.
  2. Skipping the asset and risk inventory. You can’t scope an ISMS around assets you haven’t cataloged. Build the inventory first.
  3. Treating it as an IT-only project. ISO 27001 is a management-system standard; it needs leadership sign-off, HR involvement, and cross-team ownership, not just engineering.
  4. Letting policies exist only on paper. Auditors sample real behavior, not just documents. A remote working policy nobody follows will surface in Stage 2.
  5. Underestimating evidence collection. Manually gathering screenshots and logs across 90+ controls is where most timelines slip; this is the single biggest reason manual programs take 6–12 months instead of 6–8 weeks.
  6. Ignoring vendor risk. If third parties touch your in-scope systems, vendor management controls apply, and auditors will ask for evidence of vendor due diligence.
  7. Assuming certification is “done” after the audit. Surveillance audits require continuous evidence, not a one-time push; the ISMS has to keep running, not just pass once.

How Sprinto helps with ISO 27001

ISO 27001 is documentation-heavy, evidence-heavy, and continuous by design. As an autonomous trust and compliance platform, Sprinto turns it from a multi-quarter manual project into a continuously monitored, mostly automated workflow.

  • Pre-built ISMS framework: all 93 Annex A controls pre-mapped to policies, evidence requirements, and ownership, tailored to your tech stack from day one
  • Automated evidence collection: 300+ integrations — AWS, GCP, Azure, Okta, Google Workspace, GitHub, and more; pull evidence continuously instead of once before an audit
  • Continuous monitoring: real-time alerts on control drift or failing checks, so evidence doesn’t go stale between audits
  • Built-in policy management: ready-to-use, auditor-approved policy templates, kept current automatically
  • Credible auditor options, if you need them: a vetted directory of certification bodies — you stay in control of who you work with
  • Auditor-facing dashboard: cuts audit duration by giving your certification body direct, read-only access to evidence
  • Scale beyond ISO instantly: map controls once, extend to SOC 2, GDPR, HIPAA, PCI, and 200+ other frameworks without repeating the work

The result: audit-readiness in weeks instead of months, internal effort cut significantly, and an ISMS that keeps working after the certificate is issued — not just in the weeks before the audit.

CTA-logo-img
See ISO 27001 inside Sprinto

Frequently asked questions

No, it’s voluntary. But it’s routinely a contractual requirement from enterprise and government buyers, especially outside North America. If your deals are stalling on security review, treat it as effectively mandatory.

Manually, 6–12 months. With a consultant, 3–6 months. With automation, well-prepared companies can be audit-ready in 6–8 weeks.

ISO 27001 is a global certification of your entire ISMS, issued after a two-stage audit; SOC 2 is a US-centric attestation report written by a CPA firm against the Trust Services Criteria. Roughly 70% of the underlying controls overlap. Many companies build one program and map it to both.

Annex A was restructured from 114 controls across 14 domains to 93 controls across 4 themes, with 11 new controls added (covering areas like cloud security, threat intelligence, and data leakage prevention). The 2013 version was formally retired on October 31, 2025.

Annually, in years 1 and 2 of your 3-year certification cycle, with a full recertification audit in year 3.

If you’re selling to enterprise or government buyers, increasingly yes — it’s one of the fastest ways to shorten or bypass lengthy security questionnaires. For very early-stage teams with no enterprise pipeline, it’s often premature.

For small to mid-size companies, total program cost typically ranges from $15,000 to $50,000+, depending on scope, certification body, and how much of the work is automated.

No. The transition period ended October 31, 2025. Any certificate still on the 2013 version has expired and requires a full initial audit against ISO/IEC 27001:2022.

Read enough. See it working.

A live walkthrough of ISO 27001 inside Sprinto — 30 minutes.

Frameworks-logos-bg
Frameworks-logos-mob-bg