What Is ISO 27001? A Clear Guide for Business Leaders

ISO/IEC 27001 is the international standard for information security. It sets the rules for an information security management system, known as an ISMS. ISO/IEC 27001 certification implies your firm builds and runs an Information Security Management System according to worldwide standards. Thousands of businesses in the UK use it to gain customers' trust. An accredited body, such as one approved by UKAS, can then audit your ISMS and issue a certificate.

What does ISO 27001 mean?

ISO 27001 compliance is the process by which your organization adheres to the internationally recognized requirements of the ISO/IEC 27001 standard to establish and operate an Information Security Management System (ISMS). It tells you how to run an information security management system, or ISMS. An ISO 27001 ISMS is a set of rules, roles and checks that protect your data. ISO says it suits organisations of any size and sector.

The name has a British story. BSI published BS 7799 in 1995. That standard grew into ISO/IEC 27001 in 2005. The UK adoption now reads BS EN ISO/IEC 27001:2023+A1:2024.

Which three locks does ISO 27001 place on your data?

Every control in the standard serves one of three goals. Confidentiality keeps data away from the wrong people. Integrity keeps data correct. Availability keeps data ready when staff need it.

‍

CIA triad · 3 locks

You can imagine an accountancy firm. A leaked client list breaks confidentiality. A wrong figure on an invoice breaks integrity. A server outage on payday breaks availability.

What are the benefits of ISO 27001 for your business?

ISO 27001 is an international standard that gives businesses a structured way to protect sensitive data, reduce breach risk, speed growth, and give your buyers proof instead of promises. The government's Cyber Security Breaches Survey 2025/2026 found that 43% of businesses in the United Kingdom, about 612,000 firms, faced a breach or attack in a year. Your customers know that risk. They now ask suppliers for proof.

A certified ISMS helps you in four ways.

  • Win tenders and pass supplier security checks
  • Spot risks before they turn into incidents
  • Give every role clear security duties
  • Back up your UK GDPR security duties with written evidence

Which benefit would your board value most? You should rank the four before you plan any work.

How does ISO 27001 work, from first risk to final audit?

ISO 27001 builds and audits an Information Security Management System (ISMS) by following a set path from figuring out the risks to getting it certified by an outside body while maintaining it up to date.

ISO 27001 works as a loop. You find your risks, pick controls, record your choices and then check the result. Each pass makes your ISMS stronger.

ISMS cycle · 4 steps, 1 loop

A risk assessment always comes first. You list what could go wrong with each asset, such as laptops, client files or cloud accounts. Then you rate each risk by chance and harm. The risk treatment plan says what you will do about each one.

Annex A supplies the controls you can choose. You do not need all of them. You pick the ones that fit your risks and explain each choice.

What are the requirements for ISO 27001, clause by clause?

ISO 27001 compliance means you meet every rule in clauses 4 to 10. Clauses 0 to 3 only introduce the standard. The table shows you what to prove for each clause.

Clause What you must show
4 Context You know your business, your legal duties and your scope
5 Leadership Top managers back the ISMS and sign the policy
6 Risk and goals You assess risks and set security goals
7 Support You supply people, skills, awareness and records
8 Operation You run the risk process you wrote
9 Evaluation You measure, audit and review the results
10 Improvement You fix gaps and get better each year

Which documents does ISO 27001 make mandatory?

ISO 27001 needs certain "documented information" and records in all of its main clauses (Clauses 4–10) in order to be certified and make sure that it is followed. ISO 27001 compliance needs written proof. So if you have these nine kinds of records, then that is good for you.

  • ISMS scope
  • Information security policy
  • Risk assessment and risk treatment process
  • Risk assessment and treatment results
  • Statement of Applicability (SOA) 
  • Security objectives
  • Proof of staff competence
  • Internal audit and management review records
  • Records of problems and fixes

The Statement of Applicability matters most. It lists all 93 Annex A controls and says which ones apply to you and why. You should keep every record current, because an auditor will ask to see them.

What are the ISO 27001 Annex A controls, and which four doors do they lock?

Annex A from ISO/IEC 27001 contains 93 information security measures, grouped into four themes. These controls protect a company across four main pillars, or "doors" or "domains," of security operations: Controls over organisations, people, technology controls and Physical. The table shows each door and how many controls it holds.

Door Controls What it covers
Organisational (A.5) 37 Policies, supplier rules, access and incident plans
People (A.6) 8 Staff checks, awareness and remote work
Physical (A.7) 14 Offices, locks and equipment
Technological (A.8) 34 Backups, malware defence, activity logs and secure code

ISO/IEC 27002 explains how to apply each control. It is guidance, so you cannot certify against it.

What changed in ISO 27001:2022, and why does it matter now?

The 2022 edition cut Annex A from 114 controls to 93. It grouped them into four pillars. It also added 11 new controls, such as threat intelligence, cloud service security or information deletion. ISO then issued Amendment 1 in 2024, which adds climate action wording.

BSI confirms that every 2013 certificate had to expire or end by 31 October 2025. A 2013 certificate no longer counts. You should ask each supplier for a 2022 certificate.

Is ISO 27001 mandatory, and does your company need it?

The certification of ISO 27001 is not mandatory by law in any of the world's most important jurisdictions, although it is frequently functionally required when faced with demands from large enterprises or certain contracts.

Cyber Essentials is a government backed UK scheme for basic technical controls. ISO 27001 covers your whole management system. ISO says IT firms hold the most certificates. Every sector can still use the standard.

Who needs it most? You should expect the question when you sell to large buyers like Large banks and financial institutions, Insurance companies, Large hospitals and healthcare organizations, Telecommunications companies, Multinational corporations, Large retailers and e-commerce companies and Organizations outsourcing IT, software, or data-processing services. Or managing client data.

What is ISO 27001 certification, and what does it prove?

ISO 27001 certification is a well-known mark that shows a company has created and keeps up a strict system to handle and safeguard private information. An accredited certification body issues the certificate when your ISMS meets ISO/IEC 27001. ISO itself does not certify anyone.

The ISO Survey 2024 counted 96,709 valid ISO/IEC 27001 certificates across 179,877 sites worldwide. The certificate proves that your ISMS works. It does not prove that you will never suffer an incident.

What it shows

  1. The CIA Triad: Ensure that core principles of Confidentiality (only authorised access), Integrity (correct, unaltered data), and Availability (systems available when needed) are followed.
  2. Holistic Safeguards: Rules that cover more than just technology. They also cover people (training), physical protection, and the way the company works.
  3. Systematic Risk Management: The company finds, analyses, and deals with security threats proactively, rather than depending on quick fixes.
  4. Legal and compliance: Shows a basic dedication to following data protection rules like GDPR.
  5. Continuous Improvement: Annual monitoring reviews confirm that security measures are regularly checked, updated, and kept up to date.

What is the gap between ISO 27001 compliant and ISO 27001 certified?

Being ISO 27001 compliant is different from being ISO 27001 certified because compliance is based on internal self-evaluation, while certification needs to be officially confirmed by a third-party inspector who is independent and has been instructed to do so.

How does an ISO 27001 audit run, step by step?

certification path · 3 phases

Step Who leads What happens What you get
1 Agree the scope You Pick the sites, teams and systems your ISMS covers A written scope
2 Close the gaps You Compare your controls with ISO/IEC 27001 and fix the weak spots A gap list that you clear
3 Run an internal audit You Test your own ISMS and hold a management review Audit and review records
4 Stage 1 audit Certification body The auditor reads your documents and checks you are ready Findings to fix before Stage 2
5 Stage 2 audit Certification body The auditor tests whether your people follow the controls Audit findings
6 Certificate Certification body A pass earns the ISO/IEC 27001 certificate Proof valid for three years
7 Surveillance audits Certification body The auditor returns each year to check your ISMS A certificate that stays valid
8 Renewal audit Certification body The auditor repeats a full audit in year three A new three year certificate

How can you check that a company really holds an ISO 27001 certificate?

A logo on a website proves little. If you want to be sure that a company really has an ISO 27001 certificate, you can search official global and state accreditation sources or call the company that issued the certificate. UKAS explains how to confirm that a certification body holds accreditation and that its certificate is valid.

  1. The version, which must read ISO/IEC 27001:2022
  2. The expiry date, because certificates run for three years
  3. The scope, which names the sites, teams and systems covered
  4. The certification body, which UKAS should accredit
  5. The certificate number, which you can confirm with the issuer

The scope deserves extra care. A certificate may cover one office or one product, not the whole company. UKAS also notes that certification bodies do not have to upload every certificate to the IAF CertSearch database. A missing search result therefore does not prove a fake, so you should ask the issuer.

How does the GRC Index show your ISO 27001 status to buyers?

Buyers need a quick way to compare suppliers. The GRC Index lists organisations with a GRC score and shows their frameworks. You can filter the list by framework, such as ISO27001, and by country, such as the United Kingdom, Germany, France, Spain and all europ. The index listed 1,232 organisations in October 2026.

Your own entry works as a public proof point. The team verifies your documents first. Your organisation then receives a score and joins the index. You can start your assessment today.

What is the one point every leader should keep?

ISO 27001 is proof in writing, not just simple paperwork. The standard turns a security claim into evidence that a buyer can check. You should ask for the 2022 certificate, read its scope and confirm the issuer.

Do you want your own proof on show? You can make an account on GRCI.net website and add your organisation to the GRC Index and let buyers find you.

Questions Related to ISO/IEC 27001.

Is ISO 27001 the same as ISO/IEC 27001?

Yes, ISO 27001 and ISO/IEC 27001 both refer to the same standard for keeping information safe. Most people shorten it to ISO 27001.

What is the difference between ISO 27001 and ISO 27002?

ISO/IEC 27001 specifies the mandatory standards for the development and certification of an Information Security Management System (ISMS), While ISO/IEC 27002 presents a non-certifiable, practical manual on how to apply such security measures.

How long does an ISO 27001 certificate last?

A certificate lasts three years. An auditor returns every year to check your ISMS..

Is ISO 27001 the same as SOC 2?

ISO 27001 is a formal international standard for managing an Information Security Management System (ISMS) for an entire company. SOC 2 is a flexible North American (NA) report that focuses on specific service rules and user information.