AuditXYZ

Lesson 1 of 5

What Is ISO 27001? A Plain-English Introduction

12 min readBeginner

What Is ISO 27001?

ISO 27001 is an international standard that describes how to manage information security systematically. Published jointly by the International Organization for Standardization (ISO) and the International Electrotechnical Commission (IEC) — its formal name is ISO/IEC 27001:2022 — it provides a framework for establishing, implementing, maintaining, and continually improving an Information Security Management System, known as an ISMS.

Think of the ISMS as your organization's master plan for keeping data safe. It is not a checklist of technical controls (though it includes those). It is a management system — a set of policies, processes, roles, and practices that ensure security is considered deliberately, at every level of the organization, and improved over time. That management-system framing is the single most important thing to understand: ISO 27001 certifies how you manage security, not merely which safeguards you deployed.

For founders and compliance leads, the practical significance is commercial: an ISO 27001 certificate is the security credential enterprise buyers in Europe, Asia, and increasingly worldwide expect from vendors. It is the international counterpart to SOC 2 — and for companies selling globally, often the more valuable of the two.

A Brief History

The standard traces its roots to BS 7799, a British Standard first published in 1995. It became an international standard as ISO/IEC 27001 in 2005 and has been revised twice since — in 2013 and most recently in October 2022. The 2022 revision reorganized the Annex A controls from 14 categories into 4 themes and consolidated the total from 114 to 93 controls, while adding 11 new ones covering modern topics like threat intelligence, cloud security, and data leakage prevention.

The transition window matters for anyone reading older material: organizations certified against the 2013 edition had until October 2025 to transition, and that deadline has passed. Every valid certificate today is against the 2022 edition. If a consultant, template, or tool still references 14 control domains or 114 controls, it is describing a retired version of the standard.

What an ISMS Actually Is

"Management system" sounds abstract, so here is what it means concretely. An ISMS is the combination of:

  • Defined scope — which parts of the organization, systems, locations, and services are covered
  • Leadership commitment — a security policy set by top management, with assigned roles and resources
  • Risk management — a documented, repeatable process for identifying, analyzing, evaluating, and treating information security risks
  • Selected controls — the safeguards you implement, chosen because they treat your identified risks, documented in your Statement of Applicability
  • Supporting machinery — competence and training, documentation control, internal communications
  • Measurement and review — monitoring, internal audits, and management reviews that check whether the system works
  • Improvement — corrective actions and continual refinement based on what those checks find

The underlying logic is the classic Plan-Do-Check-Act cycle. You plan based on risk, implement controls, check via audits and metrics, and act on findings. Auditors certify that this loop genuinely runs — which is why a company with beautiful documents but no evidence of reviews, audits, or corrective actions will not pass.

How ISO 27001 Is Structured

The standard has two main parts:

Clauses 4 through 10 define the management system requirements. These are mandatory — you must satisfy all of them to achieve certification, with no exclusions permitted:

ClauseTitleWhat It Requires
4Context of the OrganizationUnderstand internal/external issues, interested parties, and define ISMS scope
5LeadershipTop management commitment, information security policy, roles and responsibilities
6PlanningRisk assessment and risk treatment methodology, security objectives, planning of changes
7SupportResources, competence, awareness, communication, documented information control
8OperationExecute the risk assessment and treatment; operational planning and control
9Performance EvaluationMonitoring and measurement, internal audit, management review
10ImprovementNonconformities, corrective action, continual improvement

Annex A lists 93 reference controls organized into four themes: organizational (37 controls), people (8), physical (14), and technological (34). You do not need to implement every Annex A control — only those relevant to your identified risks. Your Statement of Applicability (SoA) documents which controls you selected, which you excluded, and why. We cover the controls in the Annex A lesson and the SoA in its own lesson.

A companion standard, ISO 27002:2022, provides implementation guidance for each Annex A control. You certify against 27001; you consult 27002 for the "how." (You cannot be "ISO 27002 certified" — a claim that occasionally appears on vendor sites and is always wrong.)

ISO 27001 vs SOC 2

This is the comparison everyone asks about. The frameworks overlap heavily in substance — most of the underlying controls are the same — but differ in structure and audience:

  • Origin: ISO 27001 is an international standard; SOC 2 is a US-based attestation framework from the AICPA
  • Output: ISO 27001 results in a certificate valid on a three-year cycle; SOC 2 results in a detailed audit report covering a specific period
  • Approach: ISO 27001 is risk-based — you build a risk process and choose controls accordingly; SOC 2 is criteria-based — you address defined Trust Services Criteria
  • Geography: ISO 27001 is recognized globally and expected in Europe and Asia; SOC 2 dominates in North America
  • Auditor: ISO 27001 audits are performed by accredited certification bodies; SOC 2 examinations must be performed by licensed CPA firms
  • Sharing: an ISO certificate is a one-page public document; a SOC 2 report is shared under NDA and contains control-level detail
  • Cadence: ISO runs Stage 1 + Stage 2, then annual surveillance audits and recertification every three years; SOC 2 is re-examined annually

Decision rule: follow your customers. North American pipeline → SOC 2 first. European or Asian pipeline, or buyers explicitly asking for "the certificate" → ISO 27001 first. Many companies eventually hold both; because of control overlap, the second framework typically costs 20 to 40 percent of the effort of the first, especially with a compliance platform that cross-maps controls.

One structural difference deserves emphasis: ISO 27001's mandatory machinery — internal audits, management reviews, corrective action tracking, a formal risk methodology — has no strict SOC 2 equivalent. Teams coming from SOC 2 usually find the controls familiar but the management system new.

Why Companies Pursue Certification

The three most common drivers:

  1. Customer requirements. Enterprise buyers — especially in Europe, the UK, Australia, Singapore, and Japan — require or strongly prefer certified vendors. Some tenders make it a hard prerequisite.
  2. International market access. A certificate travels. It is recognized in every market without translation or NDA logistics, and it shortcuts security questionnaires everywhere.
  3. Operational maturity. The ISMS discipline — risk-driven decisions, scheduled reviews, corrective actions — genuinely improves how organizations run security, and it scales with the company rather than living in one person's head.

Secondary drivers include regulatory alignment (ISO 27001 maps well onto GDPR security obligations and frameworks like NIS2), cyber insurance questionnaires, and M&A due diligence.

What Certification Involves, Briefly

The path, covered in depth in the certification process lesson:

  1. Build and operate the ISMS (typically 3 to 9 months including a few months of operating evidence)
  2. Conduct an internal audit and management review — both mandatory before certification
  3. Stage 1 audit — the certification body reviews documentation and readiness
  4. Stage 2 audit — the full implementation audit; certificate issued on success
  5. Surveillance audits annually in years two and three; recertification in year three

Cost, order of magnitude for a startup or mid-sized company: certification body fees of roughly $6,000–$20,000 for the initial cycle depending on headcount and scope, plus tooling, possible consultant support, and the internal effort — which, as with SOC 2, is the largest line item.

Is ISO 27001 Right for You? A Readiness Checklist

  • Customers or tenders have asked for ISO 27001 (or you sell into markets where it is expected)
  • You can define a sensible scope — a product, business unit, or the whole company
  • Top management will visibly sponsor the program (auditors interview leadership; this is not delegable to a doc)
  • Someone is named as ISMS owner with real time allocated
  • You are prepared to run a genuine risk assessment, not adopt a generic control list
  • You can operate the recurring machinery: internal audits, management reviews, corrective actions
  • Budget exists for a certification body, tooling, and 3 to 9 months of program effort
  • You have checked whether SOC 2 is also needed, and sequenced the two deliberately

Frequently Asked Questions

How long does ISO 27001 certification take?

For a startup with reasonable security hygiene and automation tooling: commonly 4 to 8 months from kickoff to certificate — a few months to build and operate the ISMS, then the Stage 1 and Stage 2 audits. Larger or more complex organizations should plan 9 to 18 months. Certification bodies also expect the ISMS to have operated long enough (typically at least three months) to produce real evidence.

Is ISO 27001 certification legally required?

Almost never by law. It is a market and contractual requirement. That said, regulators and frameworks in some sectors (and EU regimes like NIS2 and DORA) treat certification as strong evidence of adequate security management, and some government procurements require it outright.

Can a small startup get certified?

Yes. The standard explicitly scales — requirements are interpreted relative to your size and risk profile. Companies with 10 to 20 employees certify routinely. The mandatory machinery (risk assessment, internal audit, management review) still applies, but each can be proportionally lightweight.

Does ISO 27001 certify our product is secure?

No. It certifies that your organization operates a conforming management system within a defined scope. It does not test your application for vulnerabilities the way a penetration test does, and a certificate is not a guarantee against breaches. Sophisticated buyers know this — expect certificates to be checked alongside pen test reports and questionnaires, not instead of them.

What is the difference between ISO 27001 and ISO 27002?

ISO 27001 is the requirements standard you certify against; ISO 27002 is the guidance standard explaining how to implement each Annex A control. Buy both, certify against one.

Do we implement all 93 Annex A controls?

No — you implement those your risk assessment and legal/contractual obligations make relevant, and justify any exclusions in your Statement of Applicability. In practice most organizations find the large majority applicable; genuinely excludable controls tend to be physical or development-related ones that do not match your operating model.

In the next lesson, we will dive into the fundamentals of building an ISMS, starting with the Annex A controls.


Choosing tooling and a certification body early shapes the whole project. AuditXYZ helps you compare compliance automation platforms and evaluate auditors and certification partners so your ISO 27001 program starts on the right footing.