What Is ISO 27001? A Plain-English Guide for 2026

Last updated: 07/29/2026
Compliance
what-is-iso-27001

ISO 27001 is the international standard for an information security management system, or ISMS. It certifies that a company manages information risk through a documented, audited, continuously improved system, not a list of tools. The current version is ISO/IEC 27001:2022.

Most people hear ISO 27001 and picture a security checklist. Buy the tools, tick the boxes, frame the certificate. That's not what it is. And that one misunderstanding is why so many projects stall around month four, and why building a real compliance program takes longer than a software purchase.

Here's the part that trips everyone up. You don't get certified on a list of controls. You get certified on the system that decides which controls you need, proves you actually run them, and forces you to keep improving them. The controls are downstream. The system is the point.

The standard matters more every year. According to the ISO Survey 2024, there were 96,709 valid ISO 27001 certificates worldwide, up roughly 2.7 times in five years. Your customers are the reason. When a prospect's procurement team asks for your certificate and you can't produce one, you're not in the conversation anymore. This guide covers what ISO 27001 actually is, what changed in 2022, and what getting certified really takes, minus the auditor jargon.

What Is ISO 27001, Exactly?

ISO 27001 is the globally recognized standard for building and running an information security management system. It sets the requirements for protecting the confidentiality, integrity, and availability of your information, and it lets an accredited body certify that you meet them.

An ISMS isn't software. It's the whole set of policies, processes, roles, and decisions that govern how your business handles information risk. The International Organization for Standardization and the International Electrotechnical Commission published the first version in 2005, then revised it in 2013 and again in 2022.

Break down those three words and it gets concrete. Confidentiality means the right people see the data and the wrong ones don't. Integrity means the data is accurate and nobody tampered with it. Availability means you can get to it when you need it, ransomware attack or not. A good ISMS protects all three at once. Skip one and the other two stop mattering.

Think of it less like a firewall and more like an operating manual for how your company treats sensitive information. Who can access the customer database. What happens when a laptop goes missing. How you vet a new vendor before handing them data. The certificate says an independent auditor checked that manual, watched you follow it, and signed off.

What Changed in the 2022 Version, and Why 2013 Is Now Dead

The 2022 revision cut Annex A from 114 controls down to 93, reorganized them into four themes, and added 11 new controls for modern risks. As of October 31, 2025, the 2013 version is officially retired. Every valid certificate now sits on 2022.

If someone hands you an ISO 27001 certificate today, it should reference ISO/IEC 27001:2022. A 2013 badge means expired. That's not a technicality. It's the difference between a certificate that passes a procurement review and one that gets your deal flagged.

The 11 new controls tell you where the risk moved. Threat intelligence. Information security for cloud services. Data leakage prevention. Data masking. ICT readiness for business continuity. Configuration management. According to ISMS.online, these additions pulled the standard toward how companies actually operate now, cloud-first, distributed, and a lot more exposed than they were in 2013. The old version didn't say a word about cloud. The new one had to.

What's Actually Inside the Standard, Clauses vs. Controls

ISO 27001 has two halves. Clauses 4 through 10 are the mandatory requirements, the ISMS itself, and you can't skip any of them. Annex A is a menu of 93 security controls you pick from based on your risk assessment. You get certified on the clauses. You choose the controls.

This is the piece nearly every explainer glosses over, and it's the piece that decides whether your project works. The clauses cover the unglamorous management work. Understanding your business context. Leadership commitment. Running a security risk assessment. Measuring performance. Fixing what's broken. There are seven mandatory clauses, and an auditor tests all seven.

The risk assessment is the engine. Everything flows from it. You work through what could go wrong, how badly it would hurt, and how likely it really is, and only then do you decide which of the 93 Annex A controls actually address the risks you found, which is exactly why two certified companies can end up with very different control sets. That decision goes into a document called the Statement of Applicability, which lists every control, whether you're using it, and why. Sprinto notes the Statement of Applicability is the document that links your risk assessment to your controls, and auditors read it closely.

ISO 27001 mandatory clauses driving selection of Annex A controls via the risk assessment

Annex A's 93 controls split into four themes.

  • Organizational, 37 controls covering policies, supplier relationships, and how you handle incidents
  • People, just 8 controls, and they're about the humans, screening, training, what happens when someone leaves
  • Physical security gets 14, from locked server rooms to clean-desk rules
  • Technological, the biggest bucket at 34, where access control, encryption, and logging live

The four ISO 27001 2022 Annex A control themes

Here's why copy-paste kills projects. Teams download a template Statement of Applicability, mark all 93 controls as implemented, and walk into the audit. The auditor asks to see the risk assessment behind three of those choices. There isn't one. Nonconformity. Now you're paying for a second audit visit. The controls were never the hard part. Justifying them was.

ISO 27001 vs. SOC 2, Which One Do You Actually Need?

ISO 27001 certifies an information security management system and is recognized globally. SOC 2 is an attestation report, common in North America, that shows how well your controls protected customer data at a point in time or over a period. Which one you need comes down to your customers and where they are.

The two overlap a lot under the hood. Same core idea, prove you take security seriously. But buyers ask for different proof depending on the market. European and international clients tend to want the ISO certificate. US software buyers usually ask for a SOC 2 report first. If you sell to both, you may end up doing both, and the good news is the control work overlaps by more than half.

  • What it is. ISO 27001 certifies a management system. SOC 2 is an attestation report from a CPA firm.
  • Where it's asked for. ISO 27001 is global, strong in Europe and Asia. SOC 2 is mostly North America.
  • Structure. ISO 27001 is more prescriptive, clauses plus controls. SOC 2 is flexible, you pick the trust criteria.
  • Result. ISO 27001 gives a pass or fail certificate, valid three years. SOC 2 gives a detailed report auditors and clients read.
  • Renewal. ISO 27001 uses annual surveillance audits. SOC 2 is usually renewed every year.

Cherry Bekaert points out that ISO leans prescriptive while SOC 2 lets you tailor which criteria apply. We wrote a full breakdown of how SOC 2 and ISO 27001 compare if you're weighing the two against a specific deal.

How Do You Actually Get Certified?

Certification runs through a gap analysis, a two-stage external audit, and then annual surveillance. A small or mid-sized company can usually be audit-ready in about four months and certified in roughly six. The certificate then stays valid for three years, as long as you pass the yearly check-ins.

Stage 1 is the documentation review. The auditor reads your ISMS on paper and confirms it exists and makes sense. Stage 2 is where they test whether you actually do what the documents say, and it runs about twice as long as Stage 1. Secureframe's process guide lays out the same sequence most certification bodies follow.

  • Gap analysis, 2 to 4 weeks. Find what's missing before you build.
  • Implementation, 3 to 4 months. Build the ISMS, run the risk assessment, write policies.
  • Stage 1 audit, 1 to 2 days. The auditor reviews your documentation.
  • Stage 2 audit, 2 to 5 days. The auditor tests your controls in practice.
  • Surveillance, yearly. Annual audits in years one and two, a full recertification in year three.

ISO 27001 certification timeline from gap analysis through Stage 1, Stage 2, and surveillance audits

Cost is the question everyone actually wants answered. For a small organization, external audit fees usually land between $5,000 and $15,000, and StrongDM's breakdown puts the full three-year cycle anywhere from $10,000 to $75,000 or more once you count preparation and surveillance. The number that surprises people isn't the auditor invoice. It's the staff time. Someone on your team spends months building the ISMS, and that internal cost dwarfs the audit fee. Budget for the people, not just the paperwork.

Who Needs ISO 27001, and Who Doesn't

ISO 27001 is worth it when customers demand it, when you sell internationally, or when security is part of what you're selling. It's often overkill when your buyers only ask for a SOC 2 report, or when a US framework like NIST 800-171 already governs your contracts.

The clearest signal is your sales pipeline. If prospects keep sending security questionnaires and vendor risk assessments, certification pays for itself fast. Secureframe reports that many RFPs flat-out require it, and no certificate means no seat at the table. Hicomply cites one software company that saw a 50% jump in enterprise conversion after certifying, because procurement stopped demanding lengthy assessments. That's the real return. Fewer stalled deals.

Decision graphic mapping ISO 27001, SOC 2, and NIST 800-171 or CMMC to buyer type

Now the honest part. Bias disclosed, we help companies get certified, so take this with that in mind. If your customers have never once asked about security certifications, you probably don't need ISO 27001 yet. If you're a defense contractor, the standard that applies to your business is more likely NIST 800-171 or CMMC than ISO. And if all your buyers are US SaaS companies, start with SOC 2 and add ISO later if you expand overseas. Getting certified on the wrong framework is an expensive way to impress nobody.

Why ISO 27001 Projects Fail

Most failed ISO 27001 projects share the same root cause. The company started building documents before it understood its own risks, treated certification as a one-time event, and leaned on copy-paste templates that auditors spot in minutes.

According to NQA, a common failure is underestimating the effort, thin staffing, unrealistic timelines, and no real expertise on the team. We've watched it happen. A company assigns the ISMS to one already-overloaded IT manager as a side project, sets a three-month deadline, and acts surprised when Stage 2 turns up nonconformities. The certificate isn't the problem. The system underneath it was never built to hold weight.

The other quiet killer is treating certification as a finish line, because the moment the audit passes, the pressure evaporates, the risk assessment stops getting updated, the surveillance dates slide, and the whole system quietly rots until the recert year arrives and everyone panics. An ISMS is a living thing. Skip the surveillance audits or let the risk assessment go stale, and the certificate lapses. This is where a virtual CISO to run the ISMS earns its keep, keeping the system alive between audits instead of scrambling to rebuild it every three years. Certification is a habit, not an event.

The Short Version

ISO 27001 isn't a security product you buy. It's a management system you build, run, and prove. Three things worth remembering. You get certified on the clauses, not the 93 controls, so the risk assessment is where the real work lives. The 2013 version is dead as of October 31, 2025, so any certificate you rely on should say 2022. And the biggest cost isn't the auditor, it's the staff time to build the system right the first time.

If a customer or a stalled deal just put ISO 27001 on your radar and you're not sure whether it's the right framework or where to start, speak to a compliance expert before you spend a dollar on tooling. The cheapest mistake to fix is the one you catch before the project starts.

Not Sure ISO 27001 Is Even the Right Framework?

Consilien helps mid-market teams of 20 to 500 users, nationwide, figure out whether ISO 27001, SOC 2, or a US framework like NIST 800-171 is what your buyers actually require, then build and run the system that gets you there. Compliance is a standalone service here, not a line item hidden inside managed IT. Start with a gap assessment against real customer requirements, then take the shortest honest path to the certificate that closes deals.

Questions People Actually Ask About ISO 27001

Is ISO 27001 required by law?
No. ISO 27001 is voluntary, not a law. Nobody from the government fines you for skipping it. The pressure comes from customers, partners, and RFPs that require it before they'll sign. In practice, a market requirement can feel just as binding as a legal one, especially when a deal depends on it.
ISO 27001 vs. ISO 27002, what's the difference?
Two different documents. ISO 27001 is the standard you get certified against, the requirements and the audit. ISO 27002 is the companion guidance that explains how to implement each Annex A control in detail. You certify to 27001. You use 27002 as the instruction manual. Auditors check 27001. They don't certify anyone to 27002.
How long does an ISO 27001 certificate last?
Three years, with strings attached. The certificate is valid for a three-year cycle, but you have to pass annual surveillance audits in years one and two to keep it, then a full recertification in year three. Miss a surveillance audit and you can lose it early. It's less set-it-and-forget-it and more prove-it-again-every-year.
Can a small company actually get certified?
Absolutely, and small companies often certify faster than big ones. A firm with under 50 employees and one location can sometimes get through the audit in a handful of days and land in the $5,000 to $10,000 range for external fees. Fewer systems and simpler operations mean a smaller scope. The standard scales down on purpose.
Is ISO 27001 worth the cost?
Depends entirely on your buyers. If enterprise or international customers keep asking for it, the certificate usually pays for itself by shortening sales cycles and killing repetitive security questionnaires. If nobody's asking, it's premature. Let demand, not fear of missing out, drive the timing.
Do we need SOC 2 as well?
Sometimes, yes. If you sell to both US and international customers, you may need SOC 2 for the American buyers and ISO 27001 for everyone else. The upside is that the underlying control work overlaps by more than half, so doing the second one is a lot cheaper than doing the first. Plenty of companies run both once they scale.