Compliance · Information security
ISO 27001, certified, then kept.
The international standard for an information-security management system, and its privacy extension — the certificate enterprise customers ask for first.
- 93Annex A controls
- 2022current edition
- 3 yrscertification cycle
ISO/IEC 27001:2022 Information Security Management and ISO/IEC 27701 Privacy Information Management
ISO/IEC 27001 specifies how to establish, run and continually improve an information-security management system (ISMS): leadership commitment, a defined scope, a risk-assessment method, a treatment plan, and the controls chosen from Annex A to address the risks. Certification is issued by an accredited body after a two-stage audit and maintained through annual surveillance audits over a three-year cycle.
The 2022 edition reorganised Annex A into 93 controls across four themes — organisational, people, physical and technological — and added controls for threat intelligence, cloud services, ICT readiness for business continuity, data masking, data-leakage prevention, monitoring, web filtering and secure coding. Certificates against the 2013 edition expired at the end of October 2025.
ISO/IEC 27701 extends the ISMS into a privacy information management system (PIMS), with specific controls for controllers and processors that map to GDPR articles. Certifying against both lets you answer security and privacy due diligence with one audited framework.
What the framework demands
The obligations an auditor or supervisor will test, in plain language.
Context, scope and leadership (Clauses 4–5)
Define what the ISMS covers and who the interested parties are, and secure documented leadership commitment, roles and an information-security policy.
Risk assessment and treatment (Clause 6)
A repeatable method to identify, analyse and evaluate information-security risks, a treatment plan, and a Statement of Applicability justifying every included or excluded Annex A control.
Organisational controls (A.5)
Policies, roles, asset inventory, classification, access-control rules, supplier relationships, cloud-service security, incident management and legal compliance — 37 controls.
Technological controls (A.8)
Endpoint protection, privileged access, authentication, malware protection, vulnerability management, logging and monitoring, backup, cryptography, secure development and change management — 34 controls.
Performance evaluation and improvement (Clauses 9–10)
Metrics, internal audits and management reviews, with nonconformities tracked to closure and the ISMS improved on evidence.
People controls (A.6)
Screening, terms of employment, awareness training, disciplinary process, remote working and confidentiality agreements.
Physical controls (A.7)
Secure areas, entry controls, equipment protection, clear desk and screen, secure disposal and cabling security.
Privacy extension — ISO 27701
Additional controls for PII controllers and processors: purpose and consent, privacy notices, data-subject rights, records, sub-processor management and privacy by design, mapped to GDPR obligations.
The cost of getting it wrong
- Lost or delayed enterprise and public-sector contracts that require the certificate at tender stage
- Long security questionnaires and audits from every customer instead of one shared certificate
- Uncontrolled risk: incidents that a functioning ISMS would have caught in review
- A lapsed certificate if surveillance audits are missed
From gap to evidence
Assessment, remediation, documentation and audit support — run as one programme.
- 01
Scoping and gap analysis
We define the ISMS boundary, run a clause-by-clause and control-by-control gap analysis against 27001:2022 (and 27701 where in scope) and set the certification roadmap.
- 02
Risk methodology and Statement of Applicability
We design the risk method, run the first assessment with your teams and produce the SoA and treatment plan an auditor expects.
- 03
Controls implementation
Our security team implements the technological controls and works with HR, facilities and legal on the organisational, people and physical ones.
- 04
Documentation and internal audit
Policies and procedures written to be used, an internal audit programme, and a management review with real metrics.
- 05
Certification and surveillance
We prepare you for Stage 1 and Stage 2, handle findings, and run the annual surveillance cycle so the certificate never lapses.
Deliverables
- ISMS scope statement, policy and roles
- Risk register, risk-treatment plan and Statement of Applicability
- Complete policy and procedure set mapped to Annex A
- Implemented technical controls with evidence
- Internal audit report and management-review minutes
- Stage 1 / Stage 2 audit preparation and findings closure
- Optional ISO 27701 PIMS extension for GDPR alignment
Questions we hear most
How long does ISO 27001 certification take?
Typically three to six months for an organisation starting with reasonable security practices, driven mostly by how quickly policies can be adopted and evidence accumulated. The certification body then needs a Stage 1 and a Stage 2 audit.
Do we have to implement all 93 controls?
No. You implement the controls your risk assessment justifies and document the exclusions in the Statement of Applicability. In practice most organisations apply the large majority.
ISO 27001 or SOC 2?
ISO 27001 is a certification of your management system, recognised globally and preferred in Europe; SOC 2 is an auditor's report on your controls, preferred by US customers. They overlap heavily, and we frequently run both from one control set.
What does ISO 27701 add?
Privacy-specific controls for controllers and processors that map to GDPR obligations. It extends an ISO 27001 certificate and is the closest thing to a GDPR certification available today.
Often pursued together
Ready to Transform Your Business?
Let's discuss how our expertise in IT security, development, and DevOps can help you achieve your goals.