What Is ISO 27001? The Plain-English Guide to ISMS Certification
ISO 27001 is the international standard for building an information security management system, or ISMS. An ISMS is the actual system a business runs to protect its data. It covers risk assessment, security controls, and ongoing review, not just paperwork. ISO/IEC 27001:2022 spells out exactly what that system has to include.
ISO and the International Electrotechnical Commission, IEC, publish and jointly maintain the standard. No US or Illinois law requires a business to hold ISO 27001. In practice, more and more contracts and vendor questionnaires require it anyway.
This guide covers who publishes it, who needs it, and what certification actually costs. It also breaks down how the certification process works and how ISO 27001 differs from SOC 2, a standard people often confuse with it.
Who Publishes ISO 27001, and Why the 2022 Edition Matters
ISO and IEC publish ISO/IEC 27001 together. ISO is the International Organization for Standardization. IEC is the International Electrotechnical Commission. The two organizations jointly maintain the standard and periodically update it.
The current version is the third edition, published in 2022. It replaces the 2013 second edition. It also lines the standard up with ISO’s shared structure for management-system standards.
| Edition | Published | Status |
|---|---|---|
| Second edition | 2013 | Superseded |
| Third edition | 2022 | Current |
NIST’s own cybersecurity framework crosswalk lists ISO/IEC 27001:2022 as a recognized standard. That confirms it’s the current edition security teams should reference.
Adoption backs this up. That number is tracked in the International Accreditation Forum’s public certificate registry, the global database certification bodies report into. China leads all countries by certificate count.
A Voluntary Standard That Acts Like a Mandate
ISO 27001 certification is voluntary. No federal or Illinois law requires it, unlike HIPAA or GLBA, which are federal statutes. In practice, it works like a mandate anyway.
Enterprise customers, especially in SaaS, fintech, and defense-adjacent supply chains, increasingly won’t sign a contract without it. They use it to screen vendors before a deal even gets discussed. A vendor-risk questionnaire will often ask outright: do you hold a valid ISO 27001 certificate?
If the answer is no, the deal can stall before it starts. That’s the real-world force behind an otherwise voluntary standard. Nobody is required to certify. Plenty of businesses find they can’t compete for certain contracts without it.
Who Actually Needs ISO 27001
The requirements are generic on purpose. They’re built to apply to any organization, regardless of size or industry.
Most small and mid-size businesses go after it for one reason: it helps close bigger deals. A larger client’s security questionnaire, or their own compliance requirements, can make ISO 27001 a condition of doing business. Losing a contract over a missing certificate is a common trigger for starting the process.
Certification also doesn’t have to cover your whole company. You choose the scope, whether that’s one business unit, one office, or the entire organization. A growing Chicagoland firm might scope its first certification narrowly, then expand it as the business grows.
For a Chicagoland business heading toward certification, LeadingIT’s ISO 27001 compliance support handles the technical groundwork. That way, the certification body finds a system that’s actually ready, not one still catching up on basics like access control and logging.
The Two Halves of the Standard: Clauses and Annex A
ISO 27001 has two distinct halves. Clauses 4 through 10 set the management-system requirements. Annex A supplies the actual security controls you put in place.
Clauses 1 through 3 just cover scope, references, and definitions. They aren’t directly audited. The seven auditable clauses run from Clause 4 to Clause 10.
| Clause | Covers |
|---|---|
| 4. Context of the organization | Defining scope and stakeholders |
| 5. Leadership | Top-management commitment, security policy |
| 6. Planning | Risk assessment and risk treatment |
| 7. Support | Resources, competence, awareness, documentation |
| 8. Operation | Running the ISMS day to day |
| 9. Performance evaluation | Monitoring, internal audit, management review |
| 10. Improvement | Nonconformity handling, corrective action |
This is ISO’s harmonized structure.
Annex A is the control catalog.
| Theme | Controls | Examples |
|---|---|---|
| People | 8 | HR screening, training, awareness |
| Physical | 14 | Facility and equipment protection |
Not every control has to apply. Each one gets tracked in the Statement of Applicability, a mandatory document that links your risk treatment decisions to the actual Annex A list. Every control gets marked included or excluded, with a reason either way.
Auditors treat the Statement of Applicability as core evidence. It’s the document that shows your risk decisions actually map to real controls. For the full requirement-by-requirement breakdown, see ISO 27001 certification requirements, and for a working checklist to track each control, see the ISO 27001 checklist.
How ISO 27001 Certification Actually Works
Certification isn’t one audit. It’s a sequence, and skipping steps is how businesses end up unprepared when the auditor shows up.

- Gap assessment. Benchmark current practices against Clauses 4-10 and the 93 Annex A controls. This produces a prioritized list of what’s missing before any remediation starts.
- Remediation. Close the gaps: write policies, implement controls, build the Statement of Applicability.
- Readiness check. Confirm the gaps identified in step 1 are actually closed and evidence is ready.
- Stage 1 audit. An accredited certification body reviews your documentation: ISMS scope, policies, risk methodology, the Statement of Applicability.
- Stage 2 audit. A deeper operational audit, typically about twice the length of Stage 1. The auditor tests whether the controls you documented are actually implemented.
- Certificate issued. A successful Stage 1 and Stage 2 result in a certificate valid for three years.
- Annual surveillance audits. In Years 1 and 2, the certification body runs shorter audits sampling a subset of controls.
- Recertification. At the end of year three, a full audit comparable to Stage 2 renews the certificate. Let it lapse, and you lose the certificate entirely, not just a grace period.
A certificate from an unaccredited body doesn’t carry the same weight.
Steps 1 and 3 are where most businesses need outside help. If you want a structured read on where your organization stands before committing to an auditor, the ISO 27001 gap assessment walks through exactly what that process looks like.
ISO 27001 vs SOC 2: The Real Difference
These two get confused constantly. They’re not interchangeable, and they’re not scored the same way.
ISO 27001 is a certification issued by an accredited certification body against a published international standard. SOC 2 is an attestation report issued by a licensed CPA firm against the AICPA’s Trust Services Criteria, the framework common in the US SaaS market.
| ISO 27001 | SOC 2 | |
|---|---|---|
| Issued by | Accredited certification body | Licensed CPA firm |
| What you get | A certificate, valid 3 years | A report, requested fresh each cycle |
| Control basis | Fixed 93-control Annex A list | Principles-based Trust Services Criteria |
| Typical market | International, especially EU/APAC | US SaaS and vendor-risk market |
A business can hold one, both, or neither. It depends on what a given customer’s contract actually requires. Because the underlying control intent overlaps heavily, many organizations that pursue both reuse a large share of the same evidence.
LeadingIT does not hold either certification itself. Certification and attestation both have to come from an independent, accredited body or firm, not from a managed IT provider.
What ISO 27001 Certification Costs
Cost scales with company size, number of locations, how much remediation the gap assessment turns up, and whether you bring in outside consulting help.
These are market-rate ranges, not a fixed ISO price. For a full breakdown of what drives cost up or down for a Chicagoland business, see how much ISO 27001 certification costs.
See Where You Stand
Not sure where your organization actually stands against the 93 controls? Answer 8 plain-English questions and get your readiness level plus the gaps to close first, no sign-up required to see your result.
Take the free 2-minute ISO 27001 Risk-Check
Related Guides
- ISO 27001 Certification Requirements: What You Actually Need
- ISO 27001 Checklist: Every Requirement in One Place
- ISO 27001 Gap Assessment: Find Out What’s Missing Before You Commit
- How Much Does ISO 27001 Certification Cost in 2026?
Frequently Asked Questions
What does ISMS stand for?
ISMS stands for information security management system. It’s not a piece of software or a single document. It’s the whole system of policies, risk processes, assigned responsibilities, and controls an organization runs to protect its data. ISO 27001 is the standard you get certified against; the ISMS is the actual operating system running inside your business.
Is ISO 27001 certification mandatory?
No. No US or Illinois law requires it, unlike HIPAA or GLBA. In practice it acts like a mandate anyway, since enterprise customers in SaaS, fintech, and defense-adjacent supply chains increasingly won’t sign a contract without it.
What is a gap assessment in ISO 27001?
A gap assessment is a structured review done before implementation starts. It benchmarks your current practices against the Clause 4-10 requirements and the 93 Annex A controls, producing a prioritized list of what’s missing. It’s different from a readiness assessment, which happens later to confirm those gaps are actually closed before Stage 1.
How long is an ISO 27001 certificate valid?
Three years. During that cycle, accredited certification bodies run shorter annual surveillance audits in Years 1 and 2, sampling a subset of controls. At the end of year three, a full recertification audit renews the certificate. Let it lapse and you lose the certificate, not just a grace period.
Cost depends on company size, number of locations, and how much remediation work the gap assessment finds.</p> </details>
What’s the difference between ISO 27001 and SOC 2?
ISO 27001 is a certification issued by an accredited certification body against a published international standard. SOC 2 is an attestation report issued by a licensed CPA firm against the AICPA’s Trust Services Criteria. ISO 27001 gives you a 3-year certificate; SOC 2 gives you a report customers request fresh each cycle. Many organizations pursue both since the underlying controls overlap.
Ready to Close the Gap?
Getting ISO 27001-ready isn’t a paperwork exercise. It’s building the actual technical backbone an auditor will test in Stage 2. That’s where LeadingIT’s ISO 27001 compliance support comes in, handling the access controls, logging, and documentation trail a Stage 2 auditor expects to see.
Want our cybersecurity insights first? Add LeadingIT as a preferred source on Google and see more of our guidance in your results.
