What Is the ISO/IEC 27001 Standard?

Also called: ISO 27001, ISO/IEC 27001

Related problems: International customers ask whether we are ISO 27001 certified; Need a recognized way to show our security program is managed, not ad hoc; Unsure whether a vendor's certificate covers the service we buy; Choosing between ISO 27001 and SOC 2

ISO/IEC 27001 is the international standard that sets requirements for an information security management system (ISMS): the policies, processes, people and controls an organization uses to manage security risk and keep improving. It is published jointly by two international standards bodies, ISO and the IEC. Organizations can be audited and certified against it by an independent certification body, which makes it one of the most widely recognized ways to show customers that security is run as a managed program.

At a glance

  • ISO/IEC 27001 specifies how to run an ISMS: leadership, risk assessment, risk treatment, monitoring, internal audit and continual improvement.
  • It includes a reference set of security controls; the organization decides which apply and records the reasons in a Statement of Applicability.
  • Certification is issued by an independent certification body after an external audit and covers a defined scope.
  • A certificate typically runs on a multi-year cycle with periodic surveillance audits.
  • The scope on the certificate may cover only part of an organization, so check that it includes the service you buy.

What problem it solves

Customers want to know that a supplier handles their information safely, and they want a shortcut that doesn’t involve auditing every supplier themselves. A one-off security project or a list of tools doesn’t answer that, because security degrades without someone managing it.

ISO/IEC 27001 addresses this by focusing on the management system. It requires leadership commitment, a repeatable way to assess and treat risks, defined responsibilities, measurement and regular review. A certificate gives customers, partners and regulators a recognized signal that this system exists and has been independently checked. It is especially common in Europe, Asia and in international supply chains.

How it works

Scope. The organization defines what the ISMS covers: which business units, locations, systems and services. A narrow scope is easier to certify but tells customers less.

Risk assessment and treatment. The organization runs a structured risk assessment, then decides how to treat each risk. Controls are chosen from the standard’s reference annex (detailed guidance on them is in the companion standard ISO/IEC 27002) or from elsewhere where needed.

Statement of Applicability. This document lists each reference control, whether it applies, whether it is in place, and why any are excluded. Auditors and informed customers read it closely.

Operation and improvement. The organization runs its controls, monitors them, conducts internal audits and management reviews, and fixes nonconformities. This cycle is what keeps the system alive between audits.

Certification. An accredited certification body audits the ISMS, typically in stages: a documentation review, then a full audit of how it operates. A certificate follows if the audit is passed, with surveillance audits during the cycle and a recertification audit at the end.

When it matters for buyers

  • When selling to international or enterprise customers. Certification is frequently a requirement in procurement or supplier onboarding.
  • When evaluating a provider. A current certificate with a relevant scope is a strong starting point for vendor due diligence, and can answer parts of a security questionnaire.
  • When building a security program from scratch. The standard provides a structure that other frameworks, such as the NIST Cybersecurity Framework (NIST CSF), can map onto.
  • When expanding abroad. It is widely recognized across regions, which helps when local requirements differ.

Our governance, risk and compliance overview covers advisors and platforms that help with readiness and audits.

Questions to ask vendors

  • Can you share your current certificate, and which certification body issued it?
  • Is the certification body accredited, and by which accreditation body?
  • What is the scope on the certificate, and does it include the service, systems and locations we will use?
  • Can we see your Statement of Applicability, or at least a summary of excluded controls?
  • When was your last surveillance audit, and were any major nonconformities raised?
  • Which of your own suppliers, such as cloud hosts, fall outside your scope?
  • Do you also hold related certifications or reports, such as SOC 2 or cloud-specific extensions?

How it differs from SOC 2

SOC 2 is an attestation report from a CPA firm, built on AICPA criteria and most common in North America. It gives an opinion on specific controls and, in a Type II report, detailed test results over a period. ISO/IEC 27001 is a certifiable international standard for the management system as a whole; the output is a certificate with a scope rather than a detailed report. The controls overlap heavily, and many providers hold both. Both feed into the broader data security compliance and governance, risk and compliance (GRC) work that maps one set of controls to many requirements.

Frequently Asked Questions

Is ISO 27001 the same as ISO/IEC 27001?
Yes. The standard is published jointly by the international standards bodies ISO and IEC, so its full designation is ISO/IEC 27001. ISO 27001 is the common shorthand.
What is an ISMS?
An information security management system is the set of policies, processes, roles and controls an organization uses to manage information security risk and keep improving. ISO/IEC 27001 sets the requirements for one; the ISMS is what the organization actually runs.
What is a Statement of Applicability?
It is the document that lists the reference controls in the standard's annex, says which ones the organization applies and why, and justifies any it excludes. Together with the certificate's scope, it tells you what the certification really covers.
How long is an ISO 27001 certificate valid?
Certification typically runs on a multi-year cycle, commonly three years, with surveillance audits in between and a recertification audit at the end. Check the dates on the certificate and ask when the last surveillance audit took place.
Should we get ISO 27001 or SOC 2?
It depends on who is asking. SOC 2 is most commonly requested in North America, while ISO/IEC 27001 is widely recognized internationally. Many providers end up with both, since the controls overlap heavily. Start with whichever your customers ask for most.

You Don’t Need Another Sales Call. You Need an Answer.

30 minutes. No pitch. Just an honest conversation about where you are, what you need, and whether working together makes sense.

We use your details to set up and prepare for the call, and send the newsletter only if you ask for it. Privacy policy.