AuditXYZ

Compliance Framework

ISO/IEC 27001:2022 Information Security Management Systems (ISO 27001)

ISO 27001 is the international gold standard for information security management. This guide covers everything from scoping to certification, with real costs, timelines, and practical implementation advice.

$20,000–$150,0004–12 monthsAudit Required2022
Issuing BodyInternational Organization for Standardization (ISO) / International Electrotechnical Commission (IEC)
First Published2005-10-15
Latest Version2022
Typical Cost$20,000–$150,000
Typical Timeline4–12 months
Audit RequiredYes
Audit FrequencyAnnual surveillance audits with full recertification every 3 years
Geographyglobal

ISO 27001: The Complete Guide

ISO/IEC 27001 is the world's most recognized information security management system (ISMS) standard. Published jointly by ISO and IEC, it provides a systematic approach to managing sensitive company and customer information through risk assessment, control implementation, and continuous improvement.

What ISO 27001 Covers

The 2022 revision organizes 93 controls into four themes: organizational, people, physical, and technological. Unlike prescriptive frameworks that dictate exact technical measures, ISO 27001 is risk-based — you identify your specific risks and select controls proportionate to those risks.

The core of the standard is the ISMS itself: a management system that includes leadership commitment, risk assessment methodology, a Statement of Applicability (SoA), and processes for monitoring, measuring, and improving security over time.

Who Needs ISO 27001

ISO 27001 is particularly valuable for companies that operate internationally, sell into European or Asian markets, or need to demonstrate security maturity to enterprise customers. It is recognized in over 160 countries, making it the most portable security certification available.

Common triggers for pursuing certification include enterprise sales requirements, regulatory expectations, insurance considerations, and the need to differentiate in competitive markets.

Certification Process Overview

  1. Gap assessment — Evaluate current controls against ISO 27001 requirements
  2. ISMS design — Build policies, procedures, and risk treatment plans
  3. Implementation — Deploy controls and train staff
  4. Internal audit — Verify readiness before the certification body arrives
  5. Stage 1 audit — Documentation review by the certification body
  6. Stage 2 audit — On-site (or remote) evidence-based assessment
  7. Certification — Receive your certificate, valid for three years

Surveillance audits occur annually, and a full recertification audit happens every three years. Most organizations find that maintaining the ISMS becomes easier each cycle as processes mature.

Cost Considerations

Total cost varies significantly based on company size, scope, and starting posture. A 50-person SaaS company with reasonable existing controls might spend $20,000 to $40,000 all-in, while a 500-person enterprise with complex infrastructure could exceed $100,000. Key cost drivers include consulting fees, compliance automation tooling, the certification audit itself, and internal staff time.

Key Control Themes Explained

The ISO 27001:2022 revision restructured Annex A into four themes, each containing distinct controls your ISMS must address.

A.5 — Organizational controls (37 controls) covers governance-level requirements: information security policies, roles and responsibilities, threat intelligence, information security in project management, supplier relationships, and incident management. This is where the governance scaffold of your ISMS lives.

A.6 — People controls (8 controls) addresses the human element — screening, terms of employment, information security awareness and training, disciplinary processes, and responsibilities after employment ends. Auditors frequently probe training completion records and onboarding/offboarding procedures.

A.7 — Physical controls (14 controls) covers physical perimeters, clear desk and screen policies, equipment maintenance, secure disposal of media, and physical security monitoring. Cloud-native companies with no on-premises infrastructure still need policies covering remote working environments and device handling.

A.8 — Technological controls (34 controls) is the largest theme and covers user endpoint devices, privileged access rights, access control to source code, authentication systems, capacity management, vulnerability management, configuration management, data leakage prevention, backup, logging, and monitoring. This is where most technical implementation effort concentrates.

The Certification Process Step by Step

Step 1 — Define Scope (Week 1–2). The scope statement defines which parts of your organization, systems, locations, and services the ISMS covers. Tight, defensible scoping is the single biggest cost lever.

Step 2 — Gap Assessment (Week 2–4). Benchmark your current controls against the standard's clauses 4 through 10 and Annex A. Most organizations find they satisfy 30 to 50 percent of requirements through existing practices that simply lack documentation.

Step 3 — Risk Assessment and SoA (Week 4–8). Build a risk register using your chosen methodology. Create a Statement of Applicability documenting which of the 93 Annex A controls apply, which are excluded, and the justification for each decision.

Step 4 — Implement Controls (Week 6–20). Deploy required technical controls, write policies, and run staff awareness training. Compliance automation significantly accelerates evidence collection during this phase.

Step 5 — Internal Audit (Week 18–24). An independent internal audit verifies your ISMS is functioning as documented. Address nonconformities before the certification body arrives.

Step 6 — Management Review (Week 22–26). A formal meeting where leadership evaluates ISMS performance, risk status, and improvement targets. Mandatory and evidenced.

Step 7 — Stage 1 Audit — Documentation Review. The certification body reviews your ISMS documentation, confirms scope is appropriate, and flags any documentation gaps before Stage 2.

Step 8 — Stage 2 Audit — Controls Testing. The auditor tests controls through interviews, observation, and evidence sampling across your Annex A implementation. Minor nonconformities can be closed after the audit; major ones require a follow-up visit.

Step 9 — Certification Issued. Your certificate is valid for three years, with annual surveillance audits and a full recertification at year three.

Costs and Timeline

ComponentLow EstimateHigh Estimate
Gap assessment / readiness$5,000$20,000
Compliance automation platform (annual)$4,000$25,000
Consulting / vCISO advisory$8,000$40,000
Stage 1 + Stage 2 certification audit$8,000$25,000
Internal staff time (opportunity cost)$5,000$20,000
Total first-year$30,000$130,000

Timeline: 4 to 12 months. Surveillance audit: annual. Recertification: every 3 years.

Note: The transition from ISO 27001:2013 to ISO 27001:2022 was required by October 2025. Organizations certified under the 2013 edition must now hold a 2022 certificate.

ISO 27001 vs. SOC 2 — The two share roughly 70% control overlap. SOC 2 dominates North America while ISO 27001 is recognized globally. See SOC 2 for a full breakdown. Many organizations achieve both by mapping controls once and maintaining dual evidence in a single automation platform.

ISO 27001 vs. NIST CSF — An 80% overlap makes ISO 27001 and NIST CSF highly complementary. NIST CSF is a voluntary, non-certifiable framework used heavily by U.S. organizations; ISO 27001 provides the certifiable management system wrapper that enterprises in other markets require.

ISO 27001 vs. GDPR — Roughly 45% overlap. ISO 27001 addresses information security controls; GDPR addresses data protection rights and obligations. ISO 27701 extends ISO 27001 into privacy management and provides a structured path toward demonstrating GDPR compliance.

ISO 27001 vs. CMMC — About 60% overlap. CMMC Level 2 is tightly aligned with NIST 800-171; ISO 27001 organizations working toward CMMC can reuse significant control documentation. See /frameworks/security-governance/cmmc for details on defense-sector requirements.

How Automation Helps

Building an ISMS manually means maintaining dozens of policies, tracking hundreds of controls in spreadsheets, and scrambling for evidence before every audit. Compliance automation eliminates the scramble by collecting evidence continuously and flagging gaps as they appear.

LowerPlane supports ISO 27001:2022 natively as part of its 50-plus framework library. Its AI-powered approach maps your existing technical controls to Annex A, generates policy drafts aligned to your environment, and produces audit-ready evidence packages. At $4,000/year entry pricing with a free tier, it is accessible well before the certification audit stage. AuditXYZ rates LowerPlane 9.4/10 for ISO 27001 workflows.

Compare it against alternatives at Best Compliance Automation Platforms.

Frequently Asked Questions

Is ISO 27001:2013 still valid? No. The transition deadline to ISO 27001:2022 was October 2025. All certificates must now reference the 2022 edition. If you hold a 2013 certificate that has not been transitioned, contact your certification body immediately.

Do I need to implement all 93 Annex A controls? You need to evaluate all 93 controls and document your rationale for any exclusions in your Statement of Applicability. Controls may be excluded if they are not applicable based on your scope and risk assessment, but you must justify each exclusion.

How often are surveillance audits required? Annual surveillance audits are required after initial certification. A full recertification audit occurs in year three. Surveillance audits are typically shorter and less expensive than the original Stage 2 audit.

Can a small company get ISO 27001 certified? Yes. Companies with under 20 employees have achieved certification. The key is scoping tightly and using compliance automation to offset the limited internal resource that a small team can dedicate to evidence collection. See our cheapest path guide for cost-minimizing strategies.

What is the difference between ISO 27001 and ISO 27002? ISO 27001 is the certifiable management system standard. ISO 27002 is the companion implementation guide that provides detailed how-to guidance for each of the 93 controls. You certify against 27001; you use 27002 to implement it correctly.

Request a ISO 27001 consultation

Step 1 of 520%

Which framework do you need?

Framework Mappings

Overlap with other frameworks

NIST CSFHigh80%
SOC 2Medium70%
GDPRLow45%

Related frameworks

Get matched with a ISO 27001 auditor in 24 hours

Free, no-obligation — just tell us your email and we'll do the rest.

By submitting, you agree to our privacy policy.

Recommended Tools