Home/Services/Certification/ISO/IEC 27001:2022

ISO/IEC 27001:2022

International standard for Information Security Management Systems (ISMS).

Overview
What is ISO/IEC 27001?

ISO/IEC 27001 is an internationally recognized Information Security Management System standard designed to help organizations protect information assets and manage information security risks systematically. It establishes a framework for identifying, assessing, treating, monitoring, and continually improving information security risks affecting information, systems, services, and business operations, irrespective of the technology platform or format in which information is held.

The standard requires organizations to assess information security risks, define risk treatment options, select and implement appropriate controls from the Annex A control set, and demonstrate ongoing management of information security through internal audit and management review. The 2022 revision updated the Annex A control set to 93 controls organized into four themes: organizational, people, physical, and technological. New controls address threat intelligence, cloud service security, data masking, web filtering, and ICT readiness for business continuity.

ISO/IEC 27001 certification is recognized globally as the benchmark for information security governance. It is increasingly required by customers in financial services, government, healthcare, and technology sectors as a baseline assurance for information security management — providing independently verified evidence that an organization's information security posture meets a rigorous and internationally accepted standard.

Key Themes
What does the standard focus on?
Confidentiality
Information must be accessible only to those authorized to have access. Controls address access management, encryption, data classification, and the prevention of unauthorized disclosure of sensitive information assets.
Integrity
The accuracy and completeness of information and processing methods must be maintained. Controls address change management, audit logging, software integrity, and the detection and prevention of unauthorized modification of information.
Availability
Information and associated systems must be accessible and usable when required by authorized users. Controls address redundancy, incident response, capacity management, and ICT readiness for business continuity.
Risk Management
The standard requires a systematic process for identifying and assessing information security risks, selecting risk treatment options including acceptance, avoidance, transfer, or control, and maintaining a statement of applicability for the selected control set.
Security Controls
Annex A provides 93 controls across organizational, people, physical, and technological themes. Organizations select controls proportionate to their risk assessment and document the rationale for inclusions and exclusions in the statement of applicability.
Continual Improvement
The ISMS must be continually improved through performance monitoring, internal audit, management review, and corrective action. Improvement obligations cover both the management system itself and the underlying information security posture of the organization.
Applicability
Who typically implements ISO/IEC 27001?
Technology Companies
Software developers, SaaS providers, and systems integrators managing customer data and platform security under contractual and regulatory expectations.
Cloud Service Providers
IaaS, PaaS, and SaaS operators providing independently verified assurance of information security governance to enterprise and public sector customers.
Data Centers
Colocation and managed infrastructure providers managing physical and logical security of customer systems and data across shared facilities.
Financial Institutions
Banks, insurers, and payment processors subject to regulatory information security requirements and customer expectations for data protection governance.
Fintech Organizations
Digital financial services providers handling payment data, account credentials, and transaction records under heightened regulatory and customer scrutiny.
Healthcare Organizations
Providers and health IT organizations managing sensitive patient data under strict confidentiality, integrity, and availability requirements.
Government Agencies
Public bodies handling sensitive citizen data, national security information, and critical infrastructure systems with information security obligations.
Telecommunications Providers
Network operators and service providers managing communications infrastructure, subscriber data, and interconnect security at scale.
Professional Services Firms
Law firms, accountancies, and consultancies holding sensitive and privileged client information subject to confidentiality and data protection obligations.
Organizations Processing Sensitive Information
Any organization whose operations involve the collection, processing, storage, or transmission of information that is commercially sensitive, personally identifiable, or subject to regulatory protection.
Benefits
Why organizations pursue certification
Improved Information Security
Systematic risk assessment and control selection strengthens the organization's overall information security posture across people, processes, and technology.
Reduced Cybersecurity Risk
Structured identification and treatment of information security risks reduces the likelihood and potential impact of security incidents, breaches, and data loss events.
Improved Regulatory Confidence
Demonstrable compliance with data protection and information security regulatory requirements, including GDPR and sector-specific security obligations.
Enhanced Customer Trust
Internationally recognized certification provides independently verified assurance to customers that information assets are adequately protected.
Improved Security Governance
Defined roles, responsibilities, and accountability structures for information security management across all levels of the organization.
Stronger Risk Management
A repeatable, documented process for identifying, assessing, and treating information security risks provides a defensible basis for investment and prioritisation decisions.
Supply Chain Confidence
Provides customers with independently verified assurance that third-party data handling and system access meets a recognized baseline for information security governance.
Continual Improvement
Built-in monitoring, audit, and review mechanisms ensure the ISMS and information security controls are regularly assessed and strengthened over time.
Regulatory Context
Is ISO/IEC 27001 certification required?

ISO/IEC 27001 certification is generally voluntary. However, information security requirements are increasingly driven by regulations, contractual obligations, customer due diligence activities, cybersecurity expectations, privacy requirements, and industry-specific obligations. Data protection legislation in major jurisdictions — including the GDPR in the European Union and equivalent privacy and data security frameworks globally — imposes obligations relating to the security of personal data. ISO/IEC 27001 certification is widely accepted as evidence of appropriate technical and organizational security measures.

Sector-specific regulatory frameworks in financial services, healthcare, and telecommunications frequently include information security requirements that reference or align with ISO/IEC 27001. In some cases, certification is formally recognized or required by regulators as part of licensing or authorisation conditions. Organizations providing services to government bodies or critical infrastructure operators may find certification required under applicable procurement frameworks or national security standards.

Customer-driven requirements are a primary driver of certification, particularly in B2B technology and professional services markets. Organizations seeking to contract with large enterprises, government bodies, and regulated organizations are increasingly expected to demonstrate ISO/IEC 27001 certification as a baseline security assurance — and in many cases, certification is a prerequisite for completing security due diligence questionnaires or qualifying for preferred supplier status.

Certification Journey
The certification lifecycle
01
Application
The organization submits an application for certification. Exelera reviews the scope of activities, sites, applicable standard, and certification requirements.
02
Application Review
Exelera evaluates the application, confirms scope boundaries, identifies any specific requirements, and prepares the certification proposal and audit program.
03
Stage 1 Audit
Review of the ISMS documentation, scope definition, risk assessment methodology, statement of applicability, and organizational readiness for the Stage 2 conformance assessment.
04
Stage 2 Audit
On-site evaluation of the implementation and effectiveness of the information security management system and selected controls against all applicable standard requirements.
05
Certification Decision
Independent review of the audit report and findings by a Certification Decision Maker not involved in the audit, followed by a formal certification decision.
06
Certificate Issuance
Following a positive certification decision, Exelera issues the certificate and publishes the organization on the public certification register.
07
Surveillance Audit — Year 1
Scheduled surveillance visit conducted no later than 12 months after the certification decision to verify continued conformance and system effectiveness.
08
Surveillance Audit — Year 2
Continued verification of ISMS implementation, control effectiveness, and the adequacy of corrective actions from prior audits.
09
Recertification Audit
Comprehensive reassessment of the full ISMS scope before renewal of the certification cycle at the end of year three.
10
Certification Renewal
Following a successful recertification audit and positive certification decision, a new three-year certification cycle commences.
FAQ
Common questions
Implementing an information security management system means developing and operating a system that meets the requirements of ISO/IEC 27001. Certification is the independent verification by an accredited certification body — such as Exelera — that the system conforms to the standard. An organization may implement an ISMS without pursuing certification, but certification provides formal, third-party assurance to customers, regulators, and other stakeholders regarding the adequacy of information security governance.
The 2022 revision updated the Annex A control set from 114 controls in 14 domains to 93 controls in four themes: organizational, people, physical, and technological. Eleven new controls were introduced covering areas including threat intelligence, cloud security, data masking, web filtering, physical security monitoring, and ICT readiness for business continuity. The structure of Annex A changed but the management system requirements in the main body of the standard remained substantially unchanged. Organizations certified to ISO/IEC 27001:2013 were required to transition to the 2022 version by October 2025.
The statement of applicability is a required document that lists all Annex A controls, indicates which are applicable to the organization, and provides justification for both inclusions and exclusions. It is one of the key documents reviewed during Stage 1 and Stage 2 audits. The statement of applicability must be kept current and reflect the outputs of the organization’s risk assessment and risk treatment process.
The time required depends on the size of the organization, the complexity of its information systems and security environment, and the maturity of its existing security practices. For a small to medium-sized organization with a reasonably developed ISMS, the process from initial application to certificate issuance typically takes between three and six months. Organizations with large, complex, or distributed information environments may require a longer program.
The scope of ISO/IEC 27001 certification is defined by the organization and must reflect the information assets, systems, and environments that are within the boundary of the ISMS. Cloud services, remote working arrangements, and third-party processing can be included within scope where the organization has sufficient control to demonstrate conformance. The 2022 revision introduced new controls specifically addressing cloud service security, which are available for inclusion in the statement of applicability.
Nonconformities identified during an audit are documented formally. Major nonconformities must be closed — through verified corrective action — before certification can be granted or maintained. Minor nonconformities require a corrective action plan to be submitted within an agreed timeframe, with verification of effectiveness at the next scheduled audit. Exelera auditors assess the quality of the corrective action as well as its effectiveness when verifying closure.
ISO/IEC 27001 is not a legal compliance framework and does not in itself demonstrate GDPR compliance. However, certification provides independently verified evidence that appropriate technical and organizational security measures are in place for the protection of personal data — one of the core obligations under the GDPR and equivalent legislation. The European Data Protection Board has recognized ISO/IEC 27701 (an extension to ISO/IEC 27001) as a candidate certification mechanism under the GDPR, further reinforcing the relationship between the standards and data protection accountability.
Following initial certification, surveillance audits are conducted annually — with the first surveillance no later than 12 months after the certification decision and the second no later than 24 months. A full recertification audit is required at the end of the three-year certification cycle before the certificate can be renewed.
Applications can be submitted through the Exelera website or by contacting the certification team directly. The application process involves providing information about the organization’s scope of activities, number of sites, employee headcount, and existing ISMS documentation. Exelera will review the application and prepare a certification proposal for consideration.
Related Standards
Standards commonly pursued alongside ISO/IEC 27001