International standard · certifiable
ISO/IEC 27001:2022 The management system for information security.
ISO/IEC 27001 describes how an organisation manages information security with a plan: identify risks, choose controls, check that they work, improve. An accredited certification body confirms this after an audit.
At a glance
- Current edition
- ISO/IEC 27001:2022; the transition period from the 2013 edition ended on 31 October 2025
- Structure
- Clauses 4 to 10 (management system) and Annex A with 93 controls
- Annex A
- 37 organisational, 8 people, 14 physical and 34 technological controls
- Certificate
- Valid for three years, with annual surveillance audits
Who ISO 27001 suits
- Any organisation, regardless of size or sector, that wants to manage information security in a traceable way.
- Companies whose customers ask for evidence, for example in tenders or supplier assessments.
- Entities under NIS2 that want to build their risk management on a proven framework.

What ISO 27001 requires
- 01
Context and scope
Define and justify interested parties, requirements and the boundaries of the ISMS.
- 02
Risk assessment and treatment
A documented method, a risk register and a treatment plan with named owners.
- 03
Statement of Applicability
For each of the 93 controls: applicable or not, with justification and implementation status.
- 04
Evaluation and improvement
Metrics, internal audits, management review and corrective action, year after year.
Deadlines and dates
ISO/IEC 27001:2022 published
Certificates to the 2013 edition have expired
How UniqSuite helps
UniqSuite takes you through clauses 4 to 10 and the 93 controls in Annex A and builds your Statement of Applicability from them. Where another framework asks for the same thing, your answer counts there too.
Frequently asked questions
Do all 93 controls have to be implemented?
No. You decide based on your risks which apply, and justify exclusions in the Statement of Applicability.
How long does certification take?
It depends on size and prior work. What matters is that the ISMS has been operated for some months before the certification audit.
Is ISO 27001 required by law?
No, the standard is voluntary. The BSI Act requires NIS2 entities to take relevant European and international standards into account, but it does not prescribe a particular standard (Section 30(2) BSIG).
How does it differ from the BSI’s IT-Grundschutz?
IT-Grundschutz is the BSI’s methodology, and it also meets the requirements of ISO 27001. For ISO 27001 certification on the basis of IT-Grundschutz, an auditor certified by the BSI carries out the audit and the BSI issues the certificate.
What does the 2024 climate amendment change?
Under ISO/IEC 27001:2022/Amd 1:2024, you must determine whether climate change is a relevant issue when you establish your context (clause 4.1). A note in clause 4.2 adds that interested parties can have requirements related to climate change.
See what is still open for you.
In half an hour we show you how UniqSuite organises the requirements, makes gaps visible and produces evidence.
