A data breach today is no longer a remote risk: it is a matter of when, not if. For a company handling client data, contracts, know-how or financial information, the question what ISO 27001 is sooner or later lands on the desk, often pushed by an enterprise client that requires certification as a contractual condition. ISO 27001 is the international standard defining how to build an Information Security Management System (ISMS) that is solid, measurable and verifiable by third parties. It is not a technical manual to leave to IT: it is a governance model involving processes, people and technology. This guide answers, pragmatically, the questions founders, CISOs and quality managers ask: what the standard requires, how the 93 Annex A controls work in the 2022 version, which steps lead to certification and which concrete benefits it brings.
What ISO 27001 is and what it is really for
ISO 27001 is the international standard that sets the requirements to implement, maintain and improve an Information Security Management System. Published jointly by ISO and IEC, it is today the global reference standard for organisational information security. Its logic is not prescriptive about which technologies to use, but about which processes to govern: it asks the company to identify which information is critical, which threats affect it and which countermeasures are reasonable given the risk.
Unlike a purely technical framework, ISO 27001 can be certified by an accredited third-party body. That means a company can obtain a certificate recognised worldwide and usable in tenders, B2B contracts and relationships with international clients. The version currently in force is ISO/IEC 27001:2022, which substantially updated the list of security controls compared with the previous 2013 edition.
The standard protects three fundamental properties of information, often summarised by the acronym CIA:
Confidentiality: information is accessible only to those who are authorised
Integrity: information is accurate, complete and not altered without authorisation
Availability: information is accessible when authorised users need it
Every requirement of the standard and every Annex A control exists to protect at least one of these three properties. Grasping this principle is the first step to stop treating ISO 27001 as paperwork and turn it into a real lever for reducing risk.
The structure of the standard: mandatory clauses 4 to 10
The main body of ISO 27001 consists of seven mandatory clauses, from 4 to 10, describing the management system requirements. These clauses follow the High Level Structure shared by all ISO management standards (9001, 14001, 45001, 27001, 42001), which makes integrating several certifications easier. No clause can be excluded: they are all mandatory requirements for obtaining the certificate.
The underlying logic is the Plan-Do-Check-Act cycle. You plan the system (clauses 4, 5, 6), put it into practice (clauses 7 and 8), evaluate it (clause 9) and continuously improve it (clause 10). Let us look at each clause in detail.
Clause 4: context of the organisation
Clause 4 asks the company to define who it is, what it does and in which ecosystem it operates. This is not a philosophical exercise: it is the basis for establishing the scope of the management system, that is which sites, processes, services and information the certification will cover. A scope that is too broad makes the project unmanageable; one that is too narrow risks lacking credibility with clients.
The organisation must identify the internal and external factors relevant to information security: reliance on cloud providers, sector regulatory obligations, client expectations, supply chain complexity. It must then map interested parties, that is everyone with a legitimate expectation about information security: clients, employees, supervisory authorities, shareholders, partners. Every expectation becomes an input for designing the system. The resulting document is the partial Statement of Applicability, which declares the boundaries of the ISMS.
Clause 5: leadership and policy
Clause 5 is where many projects win or lose. It requires real, demonstrable and ongoing commitment from management. Signing a policy is not enough: leadership must allocate resources, define roles, communicate the importance of security and embed security objectives into business strategy.
The standard requires formal definition of the management system owner (often a CISO or Information Security Manager), the Information Security Policy signed by top management, and roles with their responsibilities and authority. In small companies these roles can be combined, but they cannot be ambiguous. An experienced auditor understands within the first minutes of conversation whether management has genuinely understood and sponsored the project, or delegated it to IT as if it were a firewall configuration.
Clause 6: planning and risk assessment
Clause 6 is the methodological heart of the standard. It requires a structured, repeatable risk assessment across all relevant information assets. The company must define a methodology (qualitative, quantitative or hybrid), identify risks, analyse them in terms of likelihood and impact, evaluate them against an acceptance threshold and treat them with defined options: mitigate, transfer, avoid or accept.
This is where the Statement of Applicability (SoA) comes in, the most important document of the certification. The SoA lists all 93 Annex A controls and declares, for each one, whether it is applicable, whether it is implemented and on what grounds. It is the document the auditor uses to understand what must be verified. Clause 6 also requires measurable security objectives, consistent with the policy and with the outcome of the risk assessment.
Annex A of ISO 27001:2022 and its 93 controls
Annex A is the list of security controls a company can select to treat the risks it has identified. In the 2022 version the controls were deeply reorganised: from 114 controls spread over 14 sections in the old 2013 edition to 93 controls grouped into just 4 thematic areas. Fewer controls does not mean less security: many were consolidated to remove overlaps, and 11 completely new controls were added to address emerging threats such as cloud computing, threat intelligence and data leakage.
Each Annex A control carries five attributes that make filtering and reporting easier: control type (preventive, detective, corrective), the security property protected (confidentiality, integrity, availability), the cybersecurity concept (identify, protect, detect, respond, recover), the operational capability and the security domain. These attributes are optional but very useful for building governance dashboards management can actually read.
A.5 Organisational controls (37 controls)
This is the largest section, with 37 controls dedicated to security governance. It covers security policies, the definition of roles and responsibilities, information asset management, access control at conceptual level, supplier relationships, incident management and business continuity. It also hosts the new controls on threat intelligence (A.5.7), security in cloud services (A.5.23) and ICT readiness for business continuity (A.5.30), which reflect how threat scenarios have evolved.
It is the section requiring the most documentation work, because each control translates into policies, procedures or records. For example, control A.5.19 on security in supplier relationships requires you to set contractual requirements, monitor suppliers’ security performance and manage changes. Writing it in a policy is not enough: you must show the auditor that those requirements really appear in active contracts and that suppliers are assessed periodically.
A.6 People controls (8 controls)
The 8 people controls address the human factor, statistically the leading cause of security incidents. They cover screening during hiring, terms of employment with confidentiality clauses, security awareness and training, the disciplinary process in case of violations, the management of employment termination and the rules for remote working (A.6.7), a topic that became central after the pandemic.
Control A.6.3 on training and awareness is the one auditors dwell on most. An annual e-learning course is not enough: you need a structured programme with content differentiated by role, effectiveness checks and periodic phishing simulations. One employee clicking a malicious link can undo technology investments worth hundreds of thousands of euro.
A.7 Physical controls (14 controls)
The 14 physical controls concern the protection of the places and physical assets hosting information. They include defining secure areas, controlling physical access to offices and data centres, protection from environmental threats (flooding, fire, power outages), cabling security, equipment maintenance, protection of mobile devices and the clear desk rule.
Even in an era of widespread cloud adoption, physical controls remain essential. A laptop stolen at the airport, a server in a room without access control, a paper archive left unattended are still among the most frequent causes of data breaches in SMEs. Control A.7.10 on storage media requires formal procedures for classifying, transporting and securely destroying media, an area often overlooked by companies that rely on cloud alone.
A.8 Technological controls (34 controls)
The 34 technological controls are the most familiar part for IT teams. They cover endpoint management, access privileges, authentication, cryptography, malware protection, backup, logging and monitoring, technical vulnerability management, network security, security in software development and data protection.
The 2022 version introduces long-awaited new controls: A.8.9 on secure configuration, A.8.10 on information deletion, A.8.11 on data masking, A.8.12 on data leakage prevention (DLP), A.8.16 on monitoring activities, A.8.23 on web filtering and A.8.28 on secure coding. These all reflect good practices already widely adopted in modern cybersecurity, but which now formally enter the certification perimeter.
ISO 27001:2013 vs ISO 27001:2022: what changed
Companies already certified against the old 2013 edition had a transition window until 31 October 2025 to move to the new version. Anyone certifying today does so directly on the 2022 edition. The main differences concern the structure and content of Annex A, while the main body of the standard (clauses 4-10) has remained substantially stable.
Here is a concise comparison of the key points:
Number of controls: from 114 in 2013 to 93 in 2022, thanks to consolidation and rationalisation
Annex A sections: from 14 domains in 2013 to 4 thematic areas in 2022 (organisational, people, physical, technological)
New controls: 11 completely new controls introduced in 2022, including threat intelligence, cloud security, DLP, data masking, web filtering, secure coding and secure configuration
Control attributes: in 2022 every control has 5 attributes that make classification and reporting easier
Updated references: alignment with ISO 27002:2022 as the implementation guidance
High Level Structure: already present in 2013, kept and refined in 2022 for integration with other management standards
For a company starting from scratch today, the comparison is of historical interest. For those certified under 2013 who completed the transition, the main work was updating the Statement of Applicability, adding the 11 new controls where applicable and refreshing the documentation. Anyone who has not completed the transition has already lost the validity of the original certificate.
The concrete benefits of ISO 27001 certification
Obtaining ISO 27001 certification is not a formality: it has measurable business effects. In many sectors it has become a precondition for bidding in tenders or signing contracts with large clients, especially when those clients are themselves certified or subject to regulations such as DORA, NIS2 or sector requirements in finance and healthcare.
The benefits can be grouped into five main areas:
Market access: many public tenders and private RFPs require ISO 27001, without which a company cannot even submit a bid
Fewer incidents: a well-implemented ISMS reduces the frequency and impact of security incidents thanks to preventive controls and structured response processes
Client trust: certification is objective evidence verified by a third party, far more credible than any self-declaration
Regulatory compliance: implementing ISO 27001 significantly accelerates compliance with GDPR, NIS2, DORA and other regulations sharing information risk management principles
Operational efficiency: formalising processes reduces ambiguity, rework and dependence on individuals holding tacit knowledge
There are insurance benefits too: many cyber policies offer lower premiums or better terms to ISO 27001 certified companies, because the residual risk is considered lower and more manageable.
How to get ISO 27001 certified: the steps of the journey
The certification path follows a well-defined logical sequence, from the initial decision to the issue of the certificate by an accredited body. The phases cannot be skipped, but their duration can vary significantly depending on the chosen method: a traditional approach with generalist consultants can take many months, while a structured, digital approach like Complaion’s shortens timelines considerably thanks to pre-built templates, dedicated auditors and a document management platform.
These are the typical phases:
Initial gap analysis: a snapshot of the current state against the requirements of the standard, to see where the gaps are
Scope definition: choosing the sites, processes and services covered by the ISMS
Risk assessment and Statement of Applicability: identifying assets, assessing risks, selecting applicable controls
Control implementation: adopting the technical, organisational and physical measures needed to cover the risks
Staff training: awareness of the policy and of the expected behaviours
Internal audit: independent verification before the certification audit
Management review: formal evaluation of the system by company leadership
Stage 1 and Stage 2 certification audits: documentary review and operational verification by the accredited certification body
Certificate issue: valid for three years, with annual surveillance audits
Every phase requires documented evidence and consistent behaviour. A common mistake is arriving at the audit with perfect documentation but day-to-day practices that do not reflect the written procedures: the auditor notices immediately and a nonconformity is certain.
Mandatory management system documents
The standard requires a minimum set of documents that must always be available and kept up to date. It is not an exhaustive list, since further documents may be needed depending on the controls selected, but it is the starting point for any audit.
Mandatory documents include the ISMS scope, the Information Security Policy signed by top management, the risk assessment methodology, the risk assessment report, the Statement of Applicability, the risk treatment plan, measurable security objectives, evidence of staff competence, internal audit results, management review decisions and corrective action records. To these you add the documents required by the specific controls selected, such as access control policies, incident management procedures, training records and contractual clauses for suppliers.
The most common mistakes during implementation
Even companies with competent IT teams make recurring mistakes that stretch timelines and increase costs. Recognising them in advance is the best way to avoid them and reach the certification audit with confidence.
The most frequent mistakes are:
Defining a scope that is too broad, leading to an unmanageable and unfundable project
Underestimating management commitment, delegating everything to the IT department
Copying generic documentation found online without adapting it to the real context
Treating ISO 27001 as a technology project rather than a management one
Neglecting training and awareness for non-technical staff
Failing to align written procedures with actual day-to-day practice
Postponing the internal audit to the last minute, leaving no time to fix nonconformities
Choosing the certification body on price alone, without checking its accreditation and sector reputation
An approach guided by sector experts drastically reduces the risk of falling into these traps and lets you focus resources on the activities that truly create value.
Who should get ISO 27001 certified, and when
ISO 27001 is not a sector-specific standard: it applies to any organisation handling valuable information. Still, there are situations where certification becomes practically mandatory, driven by the market or by regulation. Understanding which scenario you are in helps you decide when to start the project.
The most frequent cases where certification is recommended or necessary:
IT and cloud service providers: SaaS, MSPs, data centres, software development; certification is now a minimum entry requirement in the B2B market
Suppliers in large enterprise supply chains: banks, insurers, public administration and telcos require certification from critical suppliers
NIS2 entities: ISO 27001 is the most efficient way to demonstrate the adoption of adequate risk management measures
Professional firms and B2B services: law firms, consultants and auditors handling confidential client information
Healthcare and regulated sectors: where the data processed is subject to strict regulatory constraints
Companies expanding internationally: the certificate is recognised in more than 160 countries and simplifies entry into new markets
The right moment to certify is typically when the first strategic client formally requires it, when the company passes a certain size threshold, or when specific regulatory obligations appear. Waiting too long risks losing commercial opportunities already on the table.
Maintaining certification over time: surveillance audits and recertification
Obtaining the certificate is not the end of the journey: it is the start of a continuous improvement cycle. The certificate is valid for three years, but every year the certification body carries out a surveillance audit to verify that the management system is still active and effective. At the end of the three years a broader recertification audit renews the certificate for another three-year cycle.
The recurring activities the company must guarantee every year include updating the risk assessment, the management review, running at least one full cycle of internal audits, documented management of security incidents, periodic staff training, monitoring of critical suppliers and verification of measurable security objectives.
One of the costliest mistakes is treating the surveillance audit as a formality. External auditors expect evidence of real activity over the past year: incident records, meeting minutes, monitoring logs, vulnerability management tickets. A system that looks frozen at the year of initial certification generates nonconformities and, in serious cases, suspension of the certificate. A structured approach with a dedicated platform and reference auditors greatly reduces the risk of arriving unprepared at surveillance audits.
ISO 27001 and integration with other certifications and regulations
ISO 27001 does not live in isolation. Thanks to the High Level Structure shared by all ISO management standards, it integrates naturally with ISO 9001 (quality), ISO 14001 (environment), ISO 45001 (occupational health and safety), ISO 37001 (anti-bribery) and ISO 42001 (artificial intelligence management). A company with several certifications can run a single Integrated Management System, with shared policies, audits and reviews.
On the regulatory side, ISO 27001 is the most solid technical basis for demonstrating compliance with several European rules. With GDPR it shares the principles of accountability, risk assessment, data protection by design and breach management: many Annex A controls directly support privacy obligations. With NIS2 the overlap is even stronger on the risk management measures required from essential and important entities. With DORA, for the financial sector, ISO 27001 provides the backbone of the ICT risk management framework.
This interoperability is a major strategic advantage: investing in a good Information Security Management System means building a foundation that serves several obligations at once, cutting duplicated cost and effort.
Frequently asked questions about ISO 27001
How long does it take to obtain ISO 27001 certification?
It depends on the company’s starting point, the chosen scope and the implementation method. A traditional path with generalist consultants can take many months. With a structured, digital approach guided by dedicated auditors such as Complaion’s, timelines shorten noticeably, because documentation, risk assessment and audit management are handled in a platform with pre-configured templates.
Is ISO 27001 required by law?
Generally no, ISO 27001 is a voluntary certification. There are, however, situations where it becomes mandatory in practice: public tenders that require it, B2B contracts with large clients that impose it on critical suppliers, or regulations such as NIS2 and DORA which, while not naming ISO 27001 explicitly, require risk management measures the standard implements naturally.
What is the difference between ISO 27001 and ISO 27002?
ISO 27001 is the certifiable standard containing the mandatory management system requirements plus the concise list of controls in Annex A. ISO 27002 is the implementation guidance explaining in detail how to implement each control, with examples and good practices. It is not certifiable: it is used as an operational manual during implementation.
Does ISO 27001 replace the GDPR?
No. They are two different instruments with different logic. The GDPR is binding European legislation on personal data protection. ISO 27001 is a voluntary standard on the security of all information, personal or not. Implementing ISO 27001 helps a lot with GDPR compliance, but it does not replace it: specific privacy obligations remain, such as privacy notices, the record of processing activities, the DPO and the management of data subject rights.
How much does ISO 27001 certification cost?
The cost depends on many variables: company size, chosen scope, number of sites, process complexity, the starting maturity of controls and the certification body selected. There is no standard price. Complaion prepares a tailored quote after a free initial assessment of your context, so you get clear visibility on the investment required.
Do I need an in-house CISO to get certified?
Having a CISO with that formal title is not mandatory. What is mandatory is appointing an owner of the Information Security Management System with adequate authority and competence. In SMEs this role can be held by an IT manager, a trained quality manager or an external professional. What matters is that the role is defined, recognised and given the resources to operate.
What happens if a surveillance audit finds nonconformities?
Nonconformities are classified as minor or major. Minor ones require a corrective action plan to be submitted to the auditor within a defined timeframe, without suspending the certificate. Major ones can lead to suspension if they are not resolved quickly with concrete evidence. Orderly management of corrective actions is itself a requirement of the standard (clause 10).
Are all certification bodies the same?
No. It is essential to choose a body accredited by Accredia in Italy or by an equivalent internationally recognised body in another member state. A certificate issued by a non-accredited body has limited market value and may not be accepted by clients or tenders. The body’s sector reputation also affects how credible the certificate looks to your end clients.
Next steps: building your ISO 27001 with Complaion
Understanding what ISO 27001 is only the first step. The real value arrives when a company turns the standard into a management system that is genuinely lived, reducing information risk and opening new markets. The journey requires method, experience and the right tools: without these three, projects drag on for months and costs escalate. Complaion supports Italian and Spanish SMEs with a digital platform, dedicated auditors and pre-validated templates, cutting timelines compared with traditional routes and taking the company from gap analysis to certificate through a clear, predictable process. Every project is calibrated on the company’s specific reality, with a tailored quote prepared after an initial analysis of the context. Request a consultation with Complaion and get your personalised quote to start your ISO 27001 certification journey with a partner that has already taken dozens of companies like yours to the certificate.









