What the standard requires
ISO 27001 asks an organisation to define the scope of its ISMS, assess its information security risks, decide how to treat each one and run the controls that follow from that decision. The current version is ISO 27001:2022. Its Annex A lists 93 reference controls grouped in four themes: organisational, people, physical and technological. The organisation documents which controls apply in a Statement of Applicability.
How certification works
An accredited certification body audits the ISMS in two stages: a documentation review (Stage 1) and an audit of how the system works in practice (Stage 2). Certificates last three years, with surveillance audits in the years in between.
ISO 27001 vs SOC 2
ISO 27001 is an international certification of a management system. SOC 2 is an attestation report issued by a CPA firm, more common with customers in the United States. Many controls overlap, so one programme can support both.
Why companies get certified
Most companies pursue ISO 27001 because customers ask for it during procurement, and because it gives a structured way to manage security that also supports ENS, NIS2 and DORA requirements.




