ISO/IEC 27001:2022
ISO 27001 Information Security Management Systems
Protect the data your customers trust you with, and prove it to their security teams.
Information assets
Customer data in
In scope
Access control
Least privilege
Encryption
In transit and at rest
Supplier security
Vendors monitored
Risk treatment
SoA selects controls
Incident response
Detect and learn
Learn returns to Risk treatment
Threats
External and internal
Deflected returns to Incident response
Trusted information
Deals unblocked
SYS/04 · Control gates
Information assets pass risk-selected gates in the ISMS; incident response deflects threats, evidence earns trust.
What ISO 27001 is
ISO/IEC 27001 defines an information security management system: risk assessment, a statement of applicability across the Annex A controls, and the governance that keeps security decisions current as threats change. The 2022 edition restructured the controls into organizational, people, physical and technological themes.
CORE audits ISO 27001 by testing whether the Statement of Applicability describes a system that exists. Your auditor works from the risk assessment outward: does the scope match the services and data flows you claim, is each Annex A inclusion and exclusion justified by assessed risk, and does the operating evidence support the control as written. Access reviews, change records, log and monitoring output, supplier assessments, incident tickets and awareness records are sampled at source. The findings raised most often concern a Statement of Applicability drafted once and never revisited, risk treatment plans without owners or dates, and access reviews that were signed but not performed.
Who it is for
- Software, SaaS and technology companies whose enterprise customers require an ISO 27001 certificate
- Organizations whose contracts or regulators require independently audited information security
- Suppliers to government and regulated industries with certification written into the tender
- Certified organizations transferring an active ISO 27001 certificate from another certification body
- Organizations that certified to the 2013 edition and need the 2022 transition assessed
Business outcomes
What leadership should expect the system to change, in operational terms.
Sales acceleration
A certificate of registration gives enterprise procurement a third-party answer to the questions a security questionnaire asks, so vendor review turns on evidence rather than assertion.
Risk-based spending
Controls are selected and justified against assessed risk, so budget follows exposure.
Incident readiness
Defined detection, response and learning processes reduce the cost and chaos of security events.
Regulatory alignment
The ISMS provides the organizational measures data-protection regulation expects to see.
Benefits beyond the certificate
One security narrative
Policies, risk register and statement of applicability tell a consistent story to every stakeholder.
Supplier chain assurance
Supplier security requirements and monitoring extend protection to your critical vendors.
Board-level ownership
Governance requirements put information risk where it belongs, with leadership.
Culture of care
Awareness, screening and acceptable-use controls make people part of the defense.
Compatibility
Integrates with ISO 9001 governance and pairs naturally with ISO 22301 for resilience.

The main requirements
The themes your auditor will examine, in plain language. The full clause detail is worked through at Stage 2.
01
Context and scope (Clause 4)
Define the ISMS boundary: services, locations, data flows and interested parties.
02
Leadership and policy (Clause 5)
Information security policy, roles and top-management commitment.
03
Risk assessment and treatment (Clause 6)
A repeatable risk methodology, risk treatment plan and the Statement of Applicability across Annex A.
04
Support (Clause 7)
Competence, awareness, communication and documented information control.
05
Operation (Clause 8)
Execute the risk treatment plan and control operational security processes.
06
Annex A control themes
93 controls across organizational, people, physical and technological themes, applied as risk requires.
07
Evaluation and improvement (Clauses 9 and 10)
Monitoring, internal ISMS audits, management review and corrective action.
What each requirement buys you
Select a requirement theme to see the business outcomes it chiefly drives. The mapping reflects where audit sampling concentrates, not a normative ISO table.
Requirement themes
Context and scope (Clause 4) chiefly drives 2 of 4 ISO 27001 outcomes.
Outcomes it drives
Sales acceleration
A certificate of registration gives enterprise procurement a third-party answer to the questions a security questionnaire asks, so vendor review turns on evidence rather than assertion.
Risk-based spending
Controls are selected and justified against assessed risk, so budget follows exposure.
Incident readiness
Defined detection, response and learning processes reduce the cost and chaos of security events.
Regulatory alignment
The ISMS provides the organizational measures data-protection regulation expects to see.
How CORE audits ISO 27001
Step 1
Stage 1 reviews scope, risk method and the Statement of Applicability
Your auditor confirms the ISMS boundary against the services, locations and data flows you have declared, reads the risk assessment methodology and results, examines the Statement of Applicability for justified inclusions and exclusions, and checks that an internal ISMS audit and management review have taken place.
Step 2
Stage 2 tests the controls against evidence
The audit samples the applicable Annex A controls across the organizational, people, physical and technological themes: access provisioning and review, change and vulnerability management, logging and monitoring, cryptography and key handling, supplier security, physical access, incident handling, and the execution of the risk treatment plan.
Step 3
Surveillance samples risk and change
Year 1 and Year 2 audits sample changes to scope, services and infrastructure, updates to the risk assessment and Statement of Applicability, security incidents and their handling, access reviews and supplier assessments performed since the last visit, and the closure of previous findings.
Step 4
Recertification revisits the whole cycle
In Year 3 the audit reviews three years of the ISMS: whether risk assessment has genuinely been repeated, whether treatment plans completed, whether incidents changed the control set, whether the scope still matches what customers are told, and whether governance has held through changes of personnel.
What your auditor expects to see
Before Stage 2 can proceed, the system needs to have run long enough to have produced its own evidence.
01Internal ISMS audit completed
A full internal audit of the clauses and applicable Annex A controls, performed by auditors independent of the systems and teams they audited, with reports available.
02Management review held
Minuted review covering risk status, incidents, control performance, audit results, supplier and interested-party feedback, and improvement, with decisions recorded.
03Records covering a meaningful period
Access reviews, change approvals, vulnerability remediation, backup and restore tests, monitoring output and awareness completion spanning enough time to show the controls running rather than being configured.
04Corrective actions closed
Nonconformities and incidents showing root-cause analysis, the control change made, and evidence that the change is operating.
05Competence demonstrable
Records connecting named people to defined security responsibilities, including risk owners, control owners and anyone with privileged access.
06Scope and Statement of Applicability defined
A written scope naming services, locations and data flows, and a current Statement of Applicability whose justifications trace back to the risk assessment.
Certification decision
With that evidence in place, Stage 1 and Stage 2 can run. The decision that follows is taken by a reviewer who was not on your audit team.
CORE is the certification body. We assess and certify management systems. We do not build them — that separation is what makes the certificate worth holding. We do not design, document or implement the systems we audit, and we do not run your internal audits. If you need that work done, our directory of independent consultants is a starting point, and engaging one has no bearing on the decision. More on how we keep the audit and the decision separate.
The optional pre-assessment
Before Stage 1 you can ask for an optional pre-assessment: an audit-style review of the governance clauses and the applicable Annex A themes of ISO/IEC 27001:2022. It samples evidence the way a Stage 2 audit does and returns a written report identifying where the ISMS would not currently satisfy an auditor, including any gap between the Statement of Applicability and the controls in operation.
The report describes findings only. It does not draft your Statement of Applicability, choose your controls or design your risk methodology, because authoring that work would disqualify CORE from auditing it under ISO/IEC 17021-1. Organizations moving from the 2013 edition often use the pre-assessment to see the effect of the restructured control set before Stage 1; where implementation help is needed, see /resources/find-a-consultant.
What you receive
- Findings against each clause of the standard
- Where the evidence is missing or incomplete
- Whether Stage 2 could proceed on today's records
- The same sampling method a certification audit uses
Training for ISO 27001
Courses that teach how the standard is written and how it is audited.
ISO 27001 questions, answered straight
Related standards
Ready to certify to ISO 27001?
Tell us your standards, scope, effective headcount and sites. You will get a scope statement and a fixed quotation, with audit duration calculated from the accreditation body's mandatory formula.
