Service
Policies, controls & evidence
A security program you can repeat and prove
Compliance readiness
Design and tune an information security management system (ISMS) that's ready for a certification audit by an independent, accredited certification body.
ISO/IEC 27001:2022, including Amendment 1:2024
Published October 25, 2022; Amendment 1 published February 23, 2024
As of 2026-09-26 this is the only edition used for accredited certification. Every certificate based on ISO/IEC 27001:2013 expired or was withdrawn at the end of October 31, 2025. Amendment 1 adds a climate-change consideration to clauses 4.1 and 4.2.
ISO/IEC 27001 is an international standard that sets requirements for establishing, implementing, maintaining, and continually improving an information security management system (ISMS).
The 2022 edition's Annex A references 93 controls drawn from ISO/IEC 27002:2022, down from 114 in the 2013 edition. It also added a clause on planning for changes.
ISO doesn't certify anyone. Certificates come from certification bodies. Accreditation is voluntary, but accredited certification means the certification body is accredited to ISO/IEC 17021-1 and ISO/IEC 27006-1 by an accreditation body that belongs to the Global ACI MRA (formerly the IAF MLA). Accredited certificates can be checked in IAF CertSearch.
ISO/IEC 27001 certification follows the process rules in ISO/IEC 17021-1:2015, which accredited certification bodies must meet. The initial certification audit has two stages. Stage 1 reviews your management system documentation, evaluates your readiness for stage 2, and gathers what the certification body needs to plan it. Stage 2 evaluates the implementation, including the effectiveness, of your ISMS.
A certification cycle runs three years from the certification decision. Surveillance audits take place in the first and second years, and a recertification audit in the third year, before the certificate expires. Surveillance audits happen at least once a calendar year except in recertification years, and the first one comes no more than 12 months after the certification decision (clause 9.1.3).
European Accreditation's FAQ on that clause states that every calendar year needs at least one audit, whether surveillance or recertification. The certification body plans and performs all of these audits; your part is to keep the ISMS running and producing records between them.
Sources: IAS: ISO/IEC 17021-1:2015 section 9, process requirements (training summary); European Accreditation FAQ 37.12: ISO/IEC 17021-1 clause 9.1.3
Read the full guide: The ISO/IEC 27001 certification process, step by step
Annex A of ISO/IEC 27001:2022 is a reference list of information security controls drawn from ISO/IEC 27002:2022. It has 93 controls in four groups, down from 114 controls in 14 groups in the previous edition. The four groups, or themes, are organizational, people, physical, and technological controls.
IAF's transition document for the 2022 edition notes that 11 controls are new, 24 were merged from existing controls, and 58 were updated, and that each control now carries attributes and a purpose instead of sitting under a control objective.
Annex A isn't a checklist to adopt wholesale. The standard asks you to determine the controls your risk treatment needs, from any source, then compare them with Annex A to check that nothing necessary has been left out (clause 6.1.3). The standard also notes that Annex A isn't exhaustive, so you can add controls it doesn't list.
The result of that comparison is recorded in the Statement of Applicability, described in the next section.
Sources: IAF MD 26: transition requirements for ISO/IEC 27001:2022; ISO/IEC 27001:2022, clauses 4.3 and 6.1.3 (publisher-authorized preview); ISO/IEC 27002:2022 table of contents, as adopted by SIST (publisher-authorized preview)
Two documents anchor an ISO/IEC 27001 certification: the ISMS scope and the Statement of Applicability.
The scope (clause 4.3) sets the boundaries and applicability of your ISMS. When you determine it, the standard asks you to consider the internal and external issues that affect the organization, the requirements of interested parties, and the interfaces and dependencies between your activities and those performed by other organizations. The scope must be available as documented information, and a certificate applies only to what it covers.
The Statement of Applicability (clause 6.1.3 d)) lists the necessary controls and why each is included, whether each is implemented, and the justification for excluding any Annex A control. It ties your risk treatment decisions to your controls. Risk owners then approve the risk treatment plan and accept the residual information security risks (clause 6.1.3 f)).
Source: ISO/IEC 27001:2022, clauses 4.3 and 6.1.3 (publisher-authorized preview)
Both answer a customer's question about how you manage security, but they produce different things, issued by different kinds of organization. Ask your customers and prospects which one they expect before you choose; nothing stops an organization from pursuing both, and a single control set can support each.
| Question | ISO/IEC 27001 | SOC 2 |
|---|---|---|
| What you receive | A certificate that your ISMS conforms to the standard | An attestation report with a CPA firm's opinion, your system description and, for Type 2, test results |
| Who issues it | A certification body; for accredited certification, one accredited to ISO/IEC 17021-1 and ISO/IEC 27006-1 | A licensed CPA firm acting as service auditor |
| What it measures against | The requirements of ISO/IEC 27001:2022, with Annex A as the control reference | The AICPA Trust Services Criteria for the categories in scope |
| How it stays current | Surveillance audits in years one and two of a three-year cycle, then recertification | Each report covers only its date (Type 1) or period (Type 2) |
Sources: ISO: ISO/IEC 27001:2022; AICPA: 2018 SOC 2 Description Criteria (With Revised Implementation Guidance – 2022); IAS: ISO/IEC 17021-1:2015 section 9, process requirements (training summary)
Read the full guide: ISO 27001 vs SOC 2: differences and which to pursue
Readiness work prepares you. The formal outcome below comes only from the organization the program authorizes.
Security Inspect is not a law firm, a CPA firm, or an ISO/IEC 27001 certification body. We don't give legal opinions, issue SOC 2 reports or ISO/IEC 27001 certificates, or guarantee that a client will pass an assessment.
ISO/IEC 27001 readiness — preparation for certification by an independent accredited certification body.
ISO/IEC 17021-1 bars an accredited certification body, its legal entity, and any entity it controls from providing management system consultancy at all (5.2.5). If a body related to the certification body consulted for you, the recognized mitigation is that the certification body waits at least two years after the consultancy ends before certifying you (5.2.7), and people who consulted for you stay off your audits for two years (5.2.10). ISO/IEC 27006-1:2024 also requires the certification body to be independent of whoever performs your internal ISMS audit (5.2.2).
When a program requires a formal assessment, audit, or certification, it's performed by an independent, authorized assessor. We keep advisory work and formal assessment apart: a practitioner never assesses controls they designed, developed, or implemented.
Every engagement begins with a written scope and proposal.
Agree the ISMS scope: the parts of the organization, locations, systems, and interested parties it covers.
Compare your current practices with the standard's requirements and Annex A, including the climate-change consideration Amendment 1 added to clauses 4.1 and 4.2.
Set up the risk assessment and treatment method, the Statement of Applicability, and the policies your team will run. You make the decisions and own the system.
Run the ISMS long enough to produce records, then prepare for your clause 9.2 internal audit.
You choose and engage an accredited certification body directly. It plans and performs its own stage 1 and stage 2 audits.
From $15,000
Typical scoped range: $15,000 to $35,000
One-time project
Non-binding. Final pricing follows a written scope and proposal.
Pricing depends on environment size, complexity, testing depth, locations, applications, accounts, user roles, compliance objectives, and delivery timeline. Every engagement begins with a written scope and proposal. Taxes, travel, remediation, third-party audit or certification fees, licensing, and emergency work are separate. Readiness services do not include independent certification, attestation, legal advice, or a guarantee of passing.
Certification bodies do, not ISO and not consultants. ISO states that it doesn't perform certification or issue certificates. For an accredited certificate, choose a certification body accredited for ISO/IEC 27001 by an accreditation body in the Global ACI MRA (formerly the IAF MLA). Accredited certification bodies may not provide consultancy, which is why readiness help and certification come from different organizations.
No. Under the accreditation transition rules in IAF MD 26, every certificate based on ISO/IEC 27001:2013 expired or was withdrawn at the end of October 31, 2025. Organizations now certify to ISO/IEC 27001:2022, which includes Amendment 1:2024. If your certificate lapsed, ask your certification body how it will handle your next audit.
It added one requirement and one note about climate change. Clause 4.1 now says the organization shall determine whether climate change is a relevant issue, and a note in clause 4.2 says relevant interested parties can have requirements related to climate change. ISO and the IAF describe the overall intent of clauses 4.1 and 4.2 as unchanged.
Search IAF CertSearch by company name or certificate number. It contains only accredited management system certifications and shows the issuing certification body and its accreditation body. You can also confirm the certification body's accreditation and scope with its accreditation body. IAF CertSearch doesn't cover certificates held by individuals, such as lead auditor credentials.
ISO/IEC 17021-1 (5.2.10) says people who provided management system consultancy to a client shouldn't take part in that client's audits or certification activities, with two years after the consultancy ends as the recognized mitigation. The certification body also can't outsource audits to a consultancy organization (5.2.8).
Information on this website is general and educational. It isn't legal advice, and it doesn't create a client relationship.
Tell us what’s driving the work and who’s asking for it, and we’ll help you judge where you stand and whether readiness support makes sense.