GuideGlobalISO/IEC 27001

ISO/IEC 27001 Compliance

Demonstrating ISO/IEC 27001:2022 conformity means showing that the scoped ISMS meets every applicable requirement in Clauses 4-10 and that selected controls and management processes operate as planned.

Certification is a separate, optional third-party assessment of that scoped ISMS. Neither conformity nor certification automatically proves compliance with every law or contract, or that no security incident can occur.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 25, 2026
Sections
5

Structured answer sets in this page tree.

Primary sources
5

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 25, 2026
Overview

Start with the October 2022 third edition and its February 2024 climate-action amendment; the accredited-certification transition from the 2013 edition ended on 31 October 2025. Define the ISMS scope and required processes before collecting evidence. Then connect leadership, risk assessment, treatment, the (SoA), operational records, monitoring, internal audit, management review, and corrective action. Annex A is a completeness reference during treatment, not a universal checklist.

Section 1

Start with ISMS scope, context, and leadership

First establish what the ISMS covers and who is accountable. Clause 4.3 requires a documented scope that considers internal and external issues, relevant interested-party requirements, and interfaces and dependencies with other organizations. The standard does not prescribe a list of products, sites, or technologies to include, but the boundary must be clear enough to apply and evaluate the ISMS.

ISO/IEC 27001:2022/Amd 1:2024 also requires the organization to determine whether climate change is a relevant issue and notes that relevant interested parties can have climate-change requirements. Record the conclusion and its effect on the ISMS when relevant; the amendment does not make a climate control universally mandatory.

Leadership evidence should show that top management established the information security policy, assigned and communicated relevant responsibilities and authorities, made needed resources available, and integrated ISMS requirements into organizational processes.

  • Keep the documented scope, context analysis, interested-party requirements, interface and dependency map, and climate-relevance decision consistent with each other.
  • Retain the information security policy, objectives, competence evidence, assigned authorities, and communications required by the organization's ISMS.
  • Review context and scope when significant organizational, service, supplier, legal, contractual, or technology changes could alter the ISMS boundary or requirements.
Section 2

Connect risk assessment to treatment

Clause 6.1.2 requires maintained risk criteria, including acceptance criteria and criteria for performing assessments. The process must produce consistent, valid, and comparable results; identify risks associated with loss of confidentiality, integrity, and availability within scope; identify risk owners; analyze consequences and realistic likelihood; determine risk levels; and evaluate priorities. Retain both the process and its results.

Clause 6.1.3 then requires appropriate treatment options, all controls needed to implement them, an Annex A comparison, the SoA, and a treatment plan. Risk owners must approve the plan and accept the residual information security risks. Clause 8 requires the plan to be implemented and the treatment results retained.

  • Keep the risk process, criteria, assessment results, risk owners, priorities, treatment plan, approvals, and retained treatment results traceable.
  • For each treatment, record the option selected, necessary controls, implementation owner, resources, target, dependencies, and how the result will be evaluated.
  • Perform assessments at planned intervals and when significant changes are proposed or occur; update treatment when the assessed risk, controls, or acceptance decision changes.
Section 3

Keep the Statement of Applicability current

The SoA is a required output of risk treatment. It must contain the necessary controls, justification for including them, whether they are implemented, and justification for excluding any Annex A control. Necessary controls can be designed by the organization or selected from any source; Annex A is used to check that none were overlooked.

Keep the SoA aligned with the treatment plan and actual implementation. Owner and evidence-location fields are useful governance additions, but ISO/IEC 27001 does not prescribe a particular SoA template or require those fields by name.

  • For necessary controls, record inclusion justification and implementation status; for every excluded Annex A control, record the exclusion justification.
  • Add risk links, owners, evidence locations, and review dates when they help the organization control and maintain the SoA.
  • Use ISO/IEC 27002 as guidance where useful, but assess conformity against ISO/IEC 27001 and the organization's own ISMS requirements.
Section 4

Collect operating evidence, not just policy text

Evidence must match the applicable requirement and the scoped process. Clause 8.1 requires enough documented information to provide confidence that operational processes ran as planned. Clause 9.1 requires evidence of monitoring and measurement results. Evidence for selected controls depends on the control design; access reviews, supplier assessments, training records, test results, logs, tickets, and approvals are examples, not a mandatory universal set.

Clause 7.5 requires ISMS documented information to be suitable, available when needed, and protected. As applicable, the organization must address distribution, access, retrieval, use, storage, preservation, change control, retention, and disposition.

  • Identify which clause, organizational requirement, risk treatment, or selected control each record demonstrates.
  • Record the owner, date or period, scoped system or process, result, and approval when those attributes are needed to interpret the evidence.
  • Classify a gap according to the facts: it may be a nonconformity, a failed or incomplete treatment action, a changed risk, or another issue requiring review. Risk acceptance does not erase a conformity failure.
Recommended next step

Operate the ISMS and keep the evidence connected

Track the scoped requirements, risks, treatments, SoA status, operating records, monitoring, audits, management-review decisions, and corrective actions without treating one checklist as proof of conformity.

Section 5

Evaluate the ISMS and correct nonconformities

Internal audits at planned intervals must determine whether the ISMS conforms to the organization's own requirements and ISO/IEC 27001, and whether it is effectively implemented and maintained. The audit program must cover frequency, methods, responsibilities, planning, and reporting; each audit needs criteria and scope, and auditor selection must protect objectivity and impartiality.

Top management must review the ISMS at planned intervals. Required inputs include previous actions, relevant context and interested-party changes, performance feedback, interested-party feedback, risk-assessment results, treatment-plan status, and improvement opportunities. Retain the resulting decisions on improvement opportunities and needed ISMS changes.

When a nonconformity occurs, react to it, address consequences as applicable, evaluate and address causes, review corrective-action effectiveness, and change the ISMS if needed. Retain the nature of the nonconformity, actions taken, and corrective-action results.

  • Keep an internal audit plan, audit criteria, audit reports, findings, evidence sampled, and closure status.
  • Use management review to record the decisions required by the evidence presented; resource, scope, objective, or treatment changes depend on those results.
  • Track corrective action from the nonconformity and cause evaluation through action, effectiveness review, and any resulting ISMS change.
Primary sources

References and citations

iso.org
Referenced sections
  • Clauses 9.2, 9.3, 10.1, and 10.2 establish internal audit, management review, continual improvement, and nonconformity and corrective-action requirements.
"effectively implemented and maintained"
iso.org
Referenced sections
  • Official amendment listing. The February 2024 amendment applies to ISO/IEC 27001:2022 and adds climate-change text to Clauses 4.1 and 4.2.
"This amendment applies to ISO/IEC 27001:2022"
iso.org
Referenced sections
  • ISO/IEC 27002 helps teams understand control implementation practices that may support selected Annex A controls.
"Information security controls"
iso.org
Referenced sections
  • ISO/IEC 27005 provides optional guidance for designing and operating information-security risk management in support of an ISO/IEC 27001 ISMS.
"Guidance on managing information security risks"
Related guides

Explore more topics

ISO/IEC 27001 Annex A Control Evidence Guide
Build useful ISO/IEC 27001:2022 Annex A control evidence: selected controls, SoA rationale, owners, implementation proof, effectiveness checks, audit records, and improvement actions.
ISO/IEC 27001 Annex A Control Ownership FAQ
How to assign practical owners for ISO/IEC 27001 Annex A controls without confusing control ownership with the standard's required risk-owner accountability.
ISO/IEC 27001 Audit Readiness Guide
Prepare ISO/IEC 27001 audit evidence across ISMS scope, risk assessment, risk treatment, Statement of Applicability, Annex A controls, internal audit, management review, and corrective actions.
ISO/IEC 27001 Certification Body Evidence FAQ
What ISO/IEC 27001 certification auditors may sample, how to connect requirements to operating evidence, and what the certification body does not own.
ISO/IEC 27001 Certification Stage Workflow
Plan optional ISO/IEC 27001 certification from scope readiness through Stage 1, Stage 2, findings, certification decision, surveillance, and recertification.
ISO/IEC 27001 FAQ: ISMS Scope, Risk and SoA
Practical ISO/IEC 27001 FAQ covering ISMS scope, risk assessment, risk treatment, Statement of Applicability, Annex A controls, certification evidence, audits, management review, and surveillance readiness.
ISO/IEC 27001 Implementation Roadmap Guide
A practical ISO/IEC 27001:2022 roadmap from context and scope through risk treatment, the SoA, control operation, internal audit, management review, corrective action, and optional certification.
ISO/IEC 27001 Internal Audit and Management Review Guide
Keep ISO/IEC 27001 internal audit and management review distinct and connected: independent audit evidence, top-management decisions, corrective actions, resources, and improvement records.
ISO/IEC 27001 Internal Audit FAQ
How should teams run ISO/IEC 27001 internal audits: who should own each step, what evidence is expected, and how findings are resolved.
ISO/IEC 27001 Management Review FAQ
What ISO/IEC 27001 management review must consider, what top management must decide, what evidence to retain, and how to set the cadence.
ISO/IEC 27001 Requirements Guide
Plain-language guide to ISO/IEC 27001:2022 Clauses 4-10: context, leadership, planning, support, operation, performance evaluation, improvement, and Annex A control selection.
ISO/IEC 27001 Risk Acceptance FAQ
How ISO/IEC 27001 risk acceptance works: criteria, risk-owner approval, residual-risk evidence, external obligations, and reassessment triggers.
ISO/IEC 27001 Risk Treatment and Residual Risk Guide
Connect ISO/IEC 27001 risk-treatment choices, necessary controls, the treatment plan, Statement of Applicability, residual-risk acceptance, owners, evidence, and review triggers.
ISO/IEC 27001 Risk Treatment Register Workflow
Build an ISO/IEC 27001 risk-treatment register that links assessed risks to treatment options, controls, SoA entries, actions, owners, residual-risk approval, evidence, and review triggers.
ISO/IEC 27001 SoA Exclusions FAQ
How should teams justify Statement of Applicability exclusions under ISO/IEC 27001? Practical answer with owners, evidence, review triggers, and external source references.
ISO/IEC 27001 SoA: workflow for gathering and documenting control evidence
Operate the ISO/IEC 27001 Statement of Applicability as a live evidence index linking necessary controls, Annex A inclusion and exclusion rationale, implementation status, owners, and proof.
ISO/IEC 27001 Statement of Applicability template: Annex A control selection and justification
Practical ISO/IEC 27001:2022 Statement of Applicability template fields for necessary controls, Annex A applicability, inclusion and exclusion rationale, status, owners, evidence, and review history.
ISO/IEC 27001 Surveillance Audits FAQ
What ISO/IEC 27001 surveillance audits check, how they differ from internal audit and recertification, and what evidence to maintain between audits.
ISO/IEC 27001 vs NIS2 Comparison
Compare voluntary ISO/IEC 27001 ISMS conformity and optional certification with NIS2 legal duties, entity scope, management accountability, incident reporting, supervision, and penalties.
ISO/IEC 27001 vs NIST CSF 2.0 Comparison
Compare ISO/IEC 27001:2022's certifiable ISMS requirements with NIST CSF 2.0's cybersecurity outcomes, Profiles, Tiers, Functions, evidence uses, and adoption choices.
ISO/IEC 27001 vs SOC 2 Comparison
Compare ISO/IEC 27001 certification with SOC 2 examination reports: criteria, scope, assurance period, auditor and certification-body roles, deliverables, evidence reuse, and claim limits.