ISO 27001 seeks to secure the confidentiality, integrity, and availability of an organization’s data. It requires a Statement of Applicability, which lists the security controls and measures an organization intends to implement.
The standard splits into two halves that people constantly confuse.
The clauses define the management system: how you scope it, who owns it, how you assess risk, how you measure it, and how you improve it. Clauses 4 through 10 are what an auditor tests, and every requirement in them is mandatory. You can't pick and choose at the clause level.
Annex A is the control catalog you select from, driven by your risk assessment. You can exclude controls, but every exclusion needs a documented reason.
| Annex A theme | Clause | Controls | Representative controls |
|---|---|---|---|
| Organizational | A.5 | 37 | Policies, threat intelligence, supplier relationships, cloud service security |
| People | A.6 | 8 | Screening, terms of employment, awareness, disciplinary process |
| Physical | A.7 | 14 | Secure areas, physical security monitoring, equipment siting, clear desk |
| Technological | A.8 | 34 | Access rights, cryptography, configuration management, secure coding, data masking |
The 2022 edition reorganized the control set rather than expanding it. Fifty-seven controls were consolidated into 24, one was split into two, 11 were added, and the remaining 58 were revised or carried forward.
| ISO 27001:2013 | ISO 27001:2022 | |
|---|---|---|
| Annex A controls | 114 | 93 |
| Grouping | 14 domains | 4 themes |
| New controls | — | 11 |
| Control attributes | None | 5 attribute types (defined in ISO 27002:2022) |
| Certificate status | Expired October 31, 2025 | Current |
The 11 new controls track where enterprise risk actually moved: threat intelligence (A.5.7), information security for use of cloud services (A.5.23), ICT readiness for business continuity (A.5.30), physical security monitoring (A.7.4), configuration management (A.8.9), information deletion (A.8.10), data masking (A.8.11), data leakage prevention (A.8.12), monitoring activities (A.8.16), web filtering (A.8.23), and secure coding (A.8.28).
Amendment 1:2024 added a requirement to clause 4.1 to determine whether climate change is a relevant issue, and a note to clause 4.2 acknowledging that interested parties may have climate-related requirements. It is a small change with real audit consequences: it must be addressed in your context analysis.
The Statement of Applicability (SoA) is a mandatory document, required by clause 6.1.3(d). It lists all 93 Annex A controls and records, for each one, whether it applies, why, and its implementation status. Controls excluded from scope need a stated justification. Auditors read the SoA before anything else because it defines what they are actually assessing, making it the single document most worth getting right.
Certification is a two-stage audit followed by ongoing surveillance.
Stage 1 reviews documentation and ISMS design, scope, policies, risk assessment method, and SoA, and surfaces gaps before they become findings. Stage 2 tests whether the ISMS operates as documented, through evidence and interviews. Surveillance audits follow in years one and two, with recertification in year three.
Timeline depends on starting maturity. An organization with documented controls and existing evidence can reach Stage 2 in three to six months; building an ISMS from nothing typically takes nine to twelve. The binding constraint is that Stage 2 auditors expect several months of operating records, including a completed internal audit and management review. Cost follows scope, headcount, and number of sites — but certification body fees are usually the smaller line. Internal effort spent collecting evidence and reconciling it against controls is the larger one, and it recurs every cycle.
| ISO 27001 | ISO 27002 | SOC 2 | NIST CSF 2.0 | |
|---|---|---|---|---|
| What it is | Certifiable ISMS standard | Implementation guidance for Annex A controls | Attestation on control effectiveness | Voluntary risk management framework |
| Output | Certificate from an accredited body | None — guidance only | Auditor's report (Type I or Type II) | Self-assessed profile |
| Scope | Whole management system | Control detail | Selected Trust Services Criteria | Six functions, including Govern |
| Prescribes controls | Yes, via Annex A | Explains them | Criteria, not controls | No |
| Recognized | Globally | Globally | Primarily US | Globally, US-anchored |
The practical distinction: ISO 27002 tells you how to implement a control; ISO 27001 certifies that you run a system to choose and manage them. SOC 2 attests to control operation over a period, for a customer audience. NIST CSF organizes risk without certifying anything.
Few enterprise programs maintain ISO 27001 in isolation. It sits alongside SOC 2, NIST CSF, PCI DSS, and customer-specific requirements, and the same control evidence answers to several of them. Kept in separate spreadsheets and portals, one control gets assessed four times and produces four different answers.
CyberSaint built CyberStrong to assess a control once and map it across every framework in scope, connecting posture to risk and risk to financial impact. Evidence stays current because it comes from the tools already generating it, so a surveillance audit confirms what the program already tracks.
Want to see your ISO 27001 posture mapped against the rest of your framework set? Request a demo.
How many controls are in ISO 27001?
ISO 27001:2022 has 93 controls in Annex A, split into 37 organizational, 8 people, 14 physical, and 34 technological. The earlier 2013 edition had 114 controls across 14 domains. If a source still cites 114, it is describing a version whose certificates expired in October 2025.
How many clauses does ISO 27001 have?
Eleven numbered clauses, 0 through 10, but only clauses 4 through 10 contain auditable requirements: context of the organization, leadership, planning, support, operation, performance evaluation, and improvement. Clauses 0 through 3 cover the introduction, scope, normative references, and terms and definitions.
What are the four themes of ISO 27001 Annex A?
Organizational (A.5, 37 controls), people (A.6, 8), physical (A.7, 14), and technological (A.8, 34). The 2022 edition replaced the 14 domains of the 2013 edition with these four themes. ISO 27002:2022 also assigns each control five attribute types, which makes cross-framework mapping practical.
Is ISO 27001:2013 still valid?
No. The transition period closed on October 31, 2025, and all ISO 27001:2013 certificates expired then. Any valid certificate today is against ISO 27001:2022, including Amendment 1:2024.
What is the difference between ISO 27001 and ISO 27002?
ISO 27001 is the certifiable standard defining the management system and the Annex A control set. ISO 27002 is a guidance document that explains how to implement each control, with purpose statements and implementation guidance. You certify against 27001; you consult 27002 while building. No organization is certified to ISO 27002.
What is a Statement of Applicability in ISO 27001?
A required document listing every Annex A control with a decision on whether it applies, the justification for that decision, and its implementation status. Clause 6.1.3(d) mandates it, and auditors use it to define audit scope. Exclusions are permitted, but each needs a documented reason tied to the risk assessment.
Is ISO 27001 mandatory?
Not by law in most jurisdictions. It becomes effectively mandatory through contracts — enterprise procurement, EU customers, and regulated supply chains commonly require it.
How long does ISO 27001 certification take?
Three to six months for an organization with documented controls and existing evidence; nine to twelve when building an ISMS from scratch. The constraint isn't audit scheduling—it is that Stage 2 auditors expect several months of ISMS operating records, including at least one completed internal audit and management review.
Learn More:
Copyright © 2026 CyberSaint Security. All Rights Reserved. Privacy Policy.