Information SecurityGlobal

ISO 27001 compliance

ISO/IEC 27001:2022

ISO/IEC 27001 is the international standard for an Information Security Management System (ISMS). Certification signals a risk-driven security program that you operate and improve over time. Pelta helps you build and run the ISMS, treat risk, and keep Annex A controls mapped to live evidence.

Who it's for

Does ISO 27001 apply to you?

  • Organisations selling internationally that need recognised certification
  • Teams formalising an information security management system
  • Companies maintaining ISO 27001 alongside other frameworks

What ISO 27001 requires

ISO/IEC 27001 is the international standard for an Information Security Management System — an ISMS. The distinction that trips teams up is this: ISO 27001 is not primarily a checklist of security controls. It is a standard for the management system that decides which controls you need, implements them, measures whether they work, and improves them over time.

The main clauses (4 to 10) define that management system: understanding your context, leadership commitment, planning and risk treatment, support and resources, operation, performance evaluation, and continual improvement. Annex A then provides the catalogue of controls you select from, justified by your risk assessment.

The ISO 27001 certification journey

Scope

Define the ISMS

Risk assess

Identify & evaluate

Treat

Select Annex A controls

Operate

Run & evidence

Internal audit

Plus management review

Certify

Stage 1 & Stage 2

What changed in ISO 27001:2022

The 2022 revision restructured Annex A from 114 controls across 14 domains into 93 controls across four themes, merging overlapping controls and introducing new ones that reflect how organisations actually operate today — including threat intelligence, cloud services, and data leakage prevention.

Annex A structure in ISO 27001:2022
ThemeFocus
OrganizationalPolicies, roles, supplier and cloud relationships, incident planning
PeopleScreening, awareness, responsibilities during and after employment
PhysicalSecure areas, equipment, physical entry and environmental controls
TechnologicalAccess, cryptography, secure development, logging, monitoring
If you certified against the 2013 version, transition to the 2022 revision on the timeline set by your certification body. Most of the work is re-mapping existing controls rather than building new ones.

The Statement of Applicability

The Statement of Applicability (SoA) is the document auditors reach for first. It lists every Annex A control, states whether it applies to you, and justifies each inclusion or exclusion against your risk assessment. A vague or unjustified SoA is one of the most common sources of audit findings — it signals that risk treatment was not genuinely driven by risk.

How certification works

  1. 1Stage 1 audit: the certification body reviews your documentation and readiness, including scope, policies and the SoA.
  2. 2Stage 2 audit: a deeper examination of whether the ISMS is genuinely implemented and effective in practice.
  3. 3Certification: valid for three years, subject to ongoing surveillance.
  4. 4Surveillance audits: typically annual, checking the ISMS continues to operate and improve.
  5. 5Recertification: a full reassessment at the end of the three-year cycle.

Common pitfalls to avoid

  • Treating Annex A as a checklist and skipping the risk assessment that is supposed to drive control selection.
  • Writing policies nobody follows — auditors look for evidence of operation, not just documents.
  • Scoping too broadly at first certification, which multiplies effort without commercial benefit.
  • Neglecting internal audit and management review, which are explicit requirements and frequent finding sources.
  • Rebuilding from scratch for SOC 2 instead of reusing the substantial overlap.
How Pelta helps

Run ISO 27001 on one connected platform

ISMS you actually run

Manage the management system — scope, risk treatment, controls and improvement — in one place.

Annex A mapped to evidence

Every control links to the artefact that demonstrates it, so surveillance audits are painless.

AI-assisted policies

Pelta GPT drafts and tailors the policies ISO 27001 expects, mapped to the controls they satisfy.

Risk-driven

Run risk assessments whose residual scores flow straight into your dashboards.

ISO 27001 FAQs

What changed in ISO 27001:2022?+

The 2022 revision restructured Annex A from 114 controls across 14 domains into 93 controls across four themes — Organizational, People, Physical and Technological — merging overlapping controls and adding new ones covering threat intelligence, cloud services and data leakage prevention.

How long does ISO 27001 certification take?+

It varies by scope and maturity. The pace is usually set by how long risk treatment and evidence collection take, so keeping controls continuously mapped to evidence shortens both initial certification and every surveillance cycle.

What is the Statement of Applicability?+

The SoA lists every Annex A control, states whether it applies to your organisation, and justifies each inclusion or exclusion against your risk assessment. Auditors typically review it first, and a poorly justified SoA is a common source of findings.

How long is ISO 27001 certification valid?+

Certification runs on a three-year cycle with surveillance audits in between — typically annual — followed by a full recertification assessment at the end of the cycle.

Is ISO 27001 a legal requirement?+

No. ISO 27001 is a voluntary international standard. It is usually pursued because customers, partners or tenders require recognised certification, though some regulated contexts reference it.

How does ISO 27001 differ from SOC 2?+

ISO 27001 certifies a management system and is recognised globally; SOC 2 is an auditor attestation against the Trust Services Criteria and is most requested by North American buyers. Their controls overlap heavily, so evidence can be reused across both.

See ISO 27001 compliance on Pelta

Implement and maintain ISO/IEC 27001:2022 on Pelta — run your ISMS, treat risk, map Annex A controls to evidence, and stay certification-ready year round.