An independent overview from DQS, an accredited certification body.

ISO 27001 is the leading international standard for information security management systems (ISMS). It specifies the requirements an organization must meet to systematically identify, assess, and treat information security risks — covering people, processes, and technology rather than any single technical control. The standard is relevant to organizations of every size and sector, from financial institutions, healthcare providers, and public authorities to cloud service providers, manufacturers, and software companies that handle sensitive information on behalf of customers, employees, or partners. The current edition is ISO/IEC 27001:2022, which replaced the 2013 version; the three-year transition period for previously certified organizations ended on 31 October 2025, and an amendment published in 2024 (Amendment 1:2024) added explicit requirements relating to climate action.

Already have an information security management system in place?

If your organization has implemented an ISMS based on ISO 27001 and you’re looking for a certification partner, our dedicated certification page has everything you need — from process overview to a personalized quote.

Go to ISO 27001 Cer­ti­fic­a­tion with DQS

Key Facts about ISO 27001 at a Glance

Full TitleISO/IEC 27001:2022 Information security, cybersecurity and privacy protection — Information security management systems — Requirements
Published byInternational Organization for Standardization (ISO) and International Electrotechnical Commission (IEC), jointly through subcommittee ISO/IEC JTC 1/SC 27
First Published2005 (BS 7799-2 was the predecessor, dating to 1999)
Current VersionISO/IEC 27001:2022, including Amendment 1:2024 (Climate action changes).
Management System TypeInformation security management system (ISMS)
Applicable toOrganizations of any size, sector, or geography that process, store, or transmit information assets
CertifiableYes. Independent third-party certification by an accredited certification body is the most widely recognized form of demonstrating conformance.
StructureAnnex SL Harmonized Structure with management system requirements in Clauses 4–10, supplemented by Annex A, which references 93 controls grouped into four themes: Organizational, People, Physical, and Technological.
Related StandardsISO/IEC 27002, ISO/IEC 27005, ISO/IEC 27017, ISO/IEC 27018, ISO/IEC 27019, ISO/IEC 22301

 

Context and Drivers for ISO 27001

Regulatory Pressure on Information Security

The regulatory environment for information security has tightened sharply in recent years, particularly in the European Union. The Network and Information Security Directive 2 (NIS2) extend cybersecurity obligations to a significantly broader set of essential and important entities, including medium-sized organizations across sectors such as energy, transport, health, digital infrastructure, and manufacturing. The Digital Operational Resilience Act (DORA), applicable to financial entities and their critical Information and Communications Technology (ICT) third-party providers, sets out detailed requirements for ICT risk management, incident reporting, resilience testing, and oversight of providers. Neither NIS2 nor DORA prescribes ISO 27001 as a mandatory baseline, but both reference internationally recognized information security standards as a reference point, and many organizations use certified ISMS as the structural foundation on which their regulatory programs are built.

Market Expectations and Customer Trust

Beyond formal regulation, information security has become a routine subject in business-to-business contracts, tender procedures, and supplier qualification programs. Enterprise customers increasingly require their suppliers to demonstrate an externally verified ISMS before granting access to systems or data, and certificates issued by accredited certification bodies are widely accepted as evidence of that maturity. For software vendors, cloud providers, and other organizations whose business model rests on customer data, an ISO 27001 certificate has become close to a market entry expectation in many sectors. This trend is reinforced by growing public awareness of data breaches, ransomware, and supply chain attacks, which has raised expectations regarding how organizations protect information across their entire value chain.

Convergence with Resilience, Privacy, and Sustainability

Information security no longer sits in isolation. It increasingly intersects with operational resilience, business continuity, privacy, and — since the publication of Amendment 1:2024 — climate-related considerations. Boards and risk committees are looking at information security as one dimension of a broader picture that includes ICT outages, third-party risk, and disruption caused by extreme weather events affecting critical infrastructure. ISO 27001 provides a structural anchor that allows organizations to integrate these adjacent topics — privacy, continuity, supplier oversight, and physical resilience — into a single management system rather than a patchwork of disconnected initiatives.

 

Core Requirements for ISO 27001

ISO/IEC 27001:2022 follows the Annex SL Harmonized Structure shared by modern ISO management system standards. Clauses 1–3 set out scope, normative references, and terms. Clauses 4–10 contain the auditable management system requirements summarized below. Annex A then references 93 information security controls detailed in ISO 27002, from which an organization selects what is applicable based on its risk assessment.

Clause 4 — Context of the Organization

The organization identifies internal and external issues that affect its ISMS and determines the needs and expectations of interested parties such as customers, regulators, supply chain partners, and shareholders. On this basis, it defines the scope of the ISMS, including locations, business activities, technologies, and information assets that are covered.

Clause 5 — Leadership

Top management demonstrates leadership and commitment to the ISMS, an information security policy is signed, and roles, responsibilities, and authorities assigned. Information security is positioned as a topic of strategic relevance, not a delegated technical function.

Clause 6 — Planning

The organization performs an information security risk assessment, defines criteria for accepting and treating risks, and selects the controls necessary to address those risks. The Statement of Applicability documents which Annex A controls apply, which are excluded, and the justification in each case. Information security objectives are defined and aligned with the policy.

Clause 7 — Support

Resources, competence, awareness, communication, and documented information are addressed. Personnel involved in the ISMS receive appropriate training, and documentation is maintained in a form proportionate to the size and complexity of the organization.

Clause 8 — Operation

The organization plans, implements, and controls the processes needed to meet information security requirements, executes the risk assessment and treatment plans, and manages changes that could affect the ISMS.

Clause 9 — Performance Evaluation

The ISMS is monitored, measured, and analyzed. Internal audits and management reviews provide the basis for evaluating whether the system is effective, conforming, and continually improving. The outputs feed back into planning and operational decisions.

Clause 10 — Improvement

Nonconformities are addressed through corrective action, and the organization is required to continually improve the suitability, adequacy, and effectiveness of the ISMS. Continual improvement is a structural feature of the standard rather than an optional add-on.

Annex A — Reference Control Set

Annex A references 93 controls grouped into four themes: Organizational controls (37), People controls (8), Physical controls (14), and Technological controls (34). The 2022 revision consolidated and reorganized the 114 controls of the 2013 version, introduced 11 new controls (including threat intelligence, information security for cloud services, ICT readiness for business continuity, physical security monitoring, configuration management, information deletion, data masking, data leakage prevention, monitoring activities, web filtering, and secure coding), and applied five attributes to each control (control type, information security properties, cybersecurity concepts, operational capabilities, and security domains) to support filtering and reporting.

 

Target Groups and Application Areas for ISO 27001

ISO 27001 is sector-agnostic by design. Its requirements apply equally to a multinational bank, a regional hospital network, a public agency, and a software start-up that processes customer data on behalf of clients. In practice, certain application areas have become particularly visible.

Information and communications technology providers — including cloud platforms, Software-as-a-Service (SaaS) vendors, managed service providers, and data center operators — frequently treat ISO 27001 as the baseline assurance framework expected by enterprise customers. Financial services organizations use ISO 27001 to structure ICT risk management programs that also support DORA obligations. Healthcare organizations apply it to protect patient information and clinical systems, often alongside sector-specific privacy and security requirements. Public sector bodies and critical infrastructure operators implement ISO 27001 to support obligations under NIS2 and national cybersecurity legislation. Manufacturing organizations adopt it to protect intellectual property, secure operational technology environments, and respond to supply chain security requirements from large customers, including Original Equipment Manufacturers (OEMs).

For any of these organizations, a certified ISMS provides a structured framework for evidence-based decisions on information security investments and priorities. It supports informed decisions by leadership and provides the basis for risk-based conversations with regulators, customers, and supply chain partners, while leaving the substantive decisions to the people accountable for them.

 

Standards Related to ISO 27001

Harmonized Structure and Typical Combinations

ISO 27001 shares the Annex SL Harmonized Structure with other widely used management system standards, including ISO 9001 (quality), ISO 14001 (environment), and ISO 22301 (business continuity). This common structure allows organizations to operate an integrated management system in which information security, quality, environmental, and continuity requirements share leadership commitments, planning processes, internal audits, and management reviews. Combined audits across these schemes are common in practice and tend to reduce duplication.

The ISO 27000 Family 

ISO 27001 sits at the center of the ISO 27000 family of standards, which together address information security management in depth. ISO 27000 provides an overview and vocabulary for the family. ISO 27002 expands each Annex A control with detailed implementation guidance and is the standard most often consulted alongside ISO 27001 in implementation. ISO 27005 provides guidance on information security risk management and is widely used to operationalize the risk-based clauses of ISO 27001. ISO 27017 and ISO 27018 extend the control set to cloud services and to the protection of Personally Identifiable Information (PII) in public cloud environments, respectively. ISO 27019 is a guidance standard for establishing an information security management system for control systems used in energy supply. The standard builds on the information security controls outlined in ISO 27002 and adds sector-specific requirements that go beyond the general measures defined in that standard. ISO 27701 specifies requirements and guidance for a Privacy Information Management System (PIMS).

Sector- and Topic-Specific Extensions

A number of sector-specific standards build on ISO 27001 in a normative sense. ISO/IEC 27011 provides additional guidance for telecommunications organizations. ISO/IEC 27017 and ISO/IEC 27018 address cloud-specific controls. ISO/IEC 27019 provides guidance for the energy utility industry. ISO/IEC 27799 applies the controls of ISO/IEC 27002 to health informatics. These extensions reuse the ISO 27001 management system and add or refine controls relevant to the sector in question.

Differentiation from Similar Frameworks

ISO 27001 is sometimes compared to other information security frameworks, notably SOC 2 and the NIST Cybersecurity Framework. ISO 27001 is an international standard against which an ISMS can be certified by a certification body. SOC 2 is a reporting framework defined by the American Institute of Certified Public Accountants (AICPA), under which assurance professionals issue attestation reports on controls relevant to security, availability, processing integrity, confidentiality, or privacy. The two addresses overlap but cover different scopes and follow different governance models, they should not be described as equivalent. The NIST Cybersecurity Framework is a voluntary framework intended to guide risk management, particularly in the United States; it is not certifiable in the same sense as ISO 27001.

About DQS as a certification body

This article is part of the DQS Knowledge Center, a resource on management system standards and certification processes. For context on who produced it:

  • One of Germany’s first management system certifiers — DQS issued its first ISO 9001 certificate in 1986 and has audited and certified management systems for over 40 years.
  • Operates from more than 80 offices in 60 countries with a worldwide network of more than 3,000 auditors.
  • Accredited for ISO/IEC 27001 alongside related standards such as ISO 9001, ISO 22301, and ISO/IEC 27701 — so integrated management systems can be certified from a single provider.
  • Member of IQNet, the international certification network, supporting cross-border recognition of DQS certificates.

The articles in this Knowledge Center are written and reviewed by DQS specialists working with these standards in audit practice. Where applicable, content is verified against the current version of the standard, the issuing body’s official publications, and recent regulatory or accreditation guidance. This article was last reviewed on 30 June 2026.

Frequently Asked Questions about ISO 27001

Is ISO 27001 mandatory?

ISO 27001 is a voluntary international standard. It is not directly mandated by general law, but it is referenced in many contractual, regulatory, and tender requirements. Organizations subject to NIS2, DORA, sector-specific cybersecurity rules, or major customer requirements often use ISO 27001 as the structural basis for demonstrating conformance with those obligations.

What is the current version of ISO 27001?

The current version is ISO/IEC 27001:2022, published in October 2022, with Amendment 1:2024 (Climate action changes) published in February 2024.

What changed between ISO/IEC 27001:2013 and ISO/IEC 27001:2022?

The 2022 revision restructured and modernized the standard. The management system clauses (4–10) were aligned more closely with the current Annex SL structure, and Annex A was substantially reworked. The previous set of 114 controls in 14 domains was consolidated into 93 controls grouped into four themes (Organizational, People, Physical, Technological). Eleven new controls were introduced, addressing topics such as threat intelligence, cloud services, ICT readiness for business continuity, configuration management, data leakage prevention, monitoring activities, web filtering, and secure coding. Each control now carries five attributes to support filtering and reporting.

What did Amendment 1:2024 add to ISO 27001?

Amendment 1:2024 (Climate action changes) introduced explicit references to climate considerations into the management system clauses. Organizations are required to determine whether climate change is a relevant issue in the context of the ISMS and to consider the climate-related needs and expectations of interested parties where applicable.

What is the difference between ISO 27001 and ISO 27002?

ISO 27001 specifies the requirements for an ISMS and is the standard against which an organization can be certified. ISO 27002 is a companion standard that provides detailed implementation guidance for the controls referenced in Annex A of ISO 27001. ISO 27002 itself is not certifiable; it is used as a reference for designing and implementing controls.

How does ISO 27001 relate to NIS2 and DORA?

Neither NIS2 nor DORA prescribes ISO 27001 as a mandatory baseline, but both address information security and ICT risk management topics that ISO 27001 already cover in structured form. Many organizations subject to NIS2 or DORA use an ISO 27001-based ISMS as the foundation on which their regulatory programs are built, mapping additional regulatory requirements — such as specific incident reporting timelines or oversight of ICT third-party providers — on top of the existing management system.

How does ISO 27001 differ from SOC 2?

ISO 27001 is an international management system standard against which an organization can be certified by a certification body, and the certificate applies to the information security management system (ISMS) described in the scope. SOC 2 is a reporting framework defined by the AICPA, under which assurance professionals issue attestation reports on controls relevant to one or more of five Trust Services Criteria. The two are governed by different bodies, have different scopes and reporting models, and are not formally recognized as equivalent.

Your organization has already established an information security management system based on ISO 27001 — and you’re now considering independent certification? Learn more on our dedicated page about ISO 27001 Certification.