International standard · certifiable

ISO/IEC 27001:2022 The management system for information security.

ISO/IEC 27001 describes how an organisation manages information security with a plan: identify risks, choose controls, check that they work, improve. An accredited certification body confirms this after an audit.

At a glance

Current edition
ISO/IEC 27001:2022; the transition period from the 2013 edition ended on 31 October 2025
Structure
Clauses 4 to 10 (management system) and Annex A with 93 controls
Annex A
37 organisational, 8 people, 14 physical and 34 technological controls
Certificate
Valid for three years, with annual surveillance audits

Who ISO 27001 suits

  • Any organisation, regardless of size or sector, that wants to manage information security in a traceable way.
  • Companies whose customers ask for evidence, for example in tenders or supplier assessments.
  • Entities under NIS2 that want to build their risk management on a proven framework.
Audit conversation with documents on the table

What ISO 27001 requires

  • 01

    Context and scope

    Define and justify interested parties, requirements and the boundaries of the ISMS.

  • 02

    Risk assessment and treatment

    A documented method, a risk register and a treatment plan with named owners.

  • 03

    Statement of Applicability

    For each of the 93 controls: applicable or not, with justification and implementation status.

  • 04

    Evaluation and improvement

    Metrics, internal audits, management review and corrective action, year after year.

Deadlines and dates

  1. ISO/IEC 27001:2022 published

  2. Certificates to the 2013 edition have expired

318testable requirements in UniqSuite

How UniqSuite helps

UniqSuite takes you through clauses 4 to 10 and the 93 controls in Annex A and builds your Statement of Applicability from them. Where another framework asks for the same thing, your answer counts there too.

Frequently asked questions

Do all 93 controls have to be implemented?

No. You decide based on your risks which apply, and justify exclusions in the Statement of Applicability.

How long does certification take?

It depends on size and prior work. What matters is that the ISMS has been operated for some months before the certification audit.

Is ISO 27001 required by law?

No, the standard is voluntary. The BSI Act requires NIS2 entities to take relevant European and international standards into account, but it does not prescribe a particular standard (Section 30(2) BSIG).

How does it differ from the BSI’s IT-Grundschutz?

IT-Grundschutz is the BSI’s methodology, and it also meets the requirements of ISO 27001. For ISO 27001 certification on the basis of IT-Grundschutz, an auditor certified by the BSI carries out the audit and the BSI issues the certificate.

What does the 2024 climate amendment change?

Under ISO/IEC 27001:2022/Amd 1:2024, you must determine whether climate change is a relevant issue when you establish your context (clause 4.1). A note in clause 4.2 adds that interested parties can have requirements related to climate change.

See what is still open for you.

In half an hour we show you how UniqSuite organises the requirements, makes gaps visible and produces evidence.

→Demo request

Show us your questions.

We will get back to you within two working days and arrange a demo of about 30 minutes – built around your own requirements.

Please fill in.

Please fill in.

Please fill in.

Please enter a valid email address.

Please use digits, spaces and + ( ) / - only.

We use your details solely to answer your request. Details in our privacy policy.