ISO/IEC 27001:2022

ISO 27001 turns security from a claim into a certificate

The world's leading information security standard certifies a management system, not a product — proof that your organisation identifies, treats and governs its risks in a way an independent auditor has verified.

Current edition
ISO/IEC 27001:2022
Annex A
93 controls across 4 themes
Certification cycle
3 years, with annual surveillance
Typical timeline
4–6 months to audit-ready

The highlights

Certification is increasingly the ticket to enterprise deals, and the 2022 edition is leaner and more relevant than what came before.

A management system, not a toolsetClauses 4–10

The ISMS core covers context, leadership, risk assessment, objectives, competence, operation and improvement. Technology features in it, but the standard certifies how you run security — governance first.

Risk-based by designClause 6

You choose controls because your risk assessment justifies them, recorded in the Statement of Applicability. This is why a 40-person SaaS firm and a hospital trust can hold the same certificate honestly.

93 controls, 4 themesAnnex A

The 2022 restructure consolidated 114 controls into 93 across organisational, people, physical and technological themes — adding modern controls for cloud security, threat intelligence, data leakage prevention and secure coding.

Independent certificationStage 1 & 2

An accredited body audits documentation, then implementation, then returns annually. It is the difference between saying you are secure and having a UKAS-accredited auditor agree.

The commercial payoffWhy bother

Certification collapses security questionnaires, accelerates enterprise procurement, satisfies NIS2's measure list almost line-for-line, and provides the scaffolding SOC 2, DORA and ISO 42001 can all hang from. One system, many answers.

Sentinel42 ISO 27001 Statement of Applicability listing Annex A controls with applicability toggles and compliance status
The Statement of Applicability in Sentinel42 — all 93 Annex A controls with applicability, justification and live status. Illustrative representation of the interface; figures shown are examples, not real customer data.

Where to start

  • Define scope deliberately — a tight, honest scope certifies faster and means more to customers than a vague one.
  • Run the risk assessment early — it drives the SoA, which drives everything else. Start here, not with policy templates.
  • Operate before you audit — auditors want evidence of the system running — management reviews held, internal audits done, incidents logged.
  • Choose the certification body carefully — UKAS accreditation matters. A cheap certificate from an unaccredited mill is worthless in enterprise procurement.

First certification, or a recertification you want to stop dreading?

Sentinel42 takes organisations from zero to certificate — gap analysis, ISMS build, internal audit and audit-day support — led by a qualified ISO 27001 Lead Auditor.