ISO 27001 turns security from a claim into a certificate
The world's leading information security standard certifies a management system, not a product — proof that your organisation identifies, treats and governs its risks in a way an independent auditor has verified.
- Current edition
- ISO/IEC 27001:2022
- Annex A
- 93 controls across 4 themes
- Certification cycle
- 3 years, with annual surveillance
- Typical timeline
- 4–6 months to audit-ready
The highlights
Certification is increasingly the ticket to enterprise deals, and the 2022 edition is leaner and more relevant than what came before.
A management system, not a toolsetClauses 4–10
The ISMS core covers context, leadership, risk assessment, objectives, competence, operation and improvement. Technology features in it, but the standard certifies how you run security — governance first.
Risk-based by designClause 6
You choose controls because your risk assessment justifies them, recorded in the Statement of Applicability. This is why a 40-person SaaS firm and a hospital trust can hold the same certificate honestly.
93 controls, 4 themesAnnex A
The 2022 restructure consolidated 114 controls into 93 across organisational, people, physical and technological themes — adding modern controls for cloud security, threat intelligence, data leakage prevention and secure coding.
Independent certificationStage 1 & 2
An accredited body audits documentation, then implementation, then returns annually. It is the difference between saying you are secure and having a UKAS-accredited auditor agree.
The commercial payoffWhy bother
Certification collapses security questionnaires, accelerates enterprise procurement, satisfies NIS2's measure list almost line-for-line, and provides the scaffolding SOC 2, DORA and ISO 42001 can all hang from. One system, many answers.

Where to start
- Define scope deliberately — a tight, honest scope certifies faster and means more to customers than a vague one.
- Run the risk assessment early — it drives the SoA, which drives everything else. Start here, not with policy templates.
- Operate before you audit — auditors want evidence of the system running — management reviews held, internal audits done, incidents logged.
- Choose the certification body carefully — UKAS accreditation matters. A cheap certificate from an unaccredited mill is worthless in enterprise procurement.
First certification, or a recertification you want to stop dreading?
Sentinel42 takes organisations from zero to certificate — gap analysis, ISMS build, internal audit and audit-day support — led by a qualified ISO 27001 Lead Auditor.