Back to blog
ISO 27001

What is ISO 27001? ISMS Standard & Compliance Explained

ISO 27001 is the international standard for managing information security risk through a formal management system. Here's what it covers, and how certification actually works.

20.08.26
12'
Person typing on a laptop, with an overlay showing the three pillars of information security: confidentiality, integrity, and availability.
Maurice Müller

Maurice Müller

Senior Content Manager

Maurice Müller is a journalist and content strategist with experience across print and digital media. At Formalize, he translates complex compliance and regulatory topics into clear, practical content for compliance, risk, and security professionals across Europe.

Key takeaways:

  • ISO 27001 is the international standard for building and running an Information Security Management System (ISMS).

  • It's built around the CIA triad: confidentiality, integrity, and availability.

  • Annex A of the 2022 revision defines 93 controls across four themes: organizational, people, physical, and technological.

  • Compliance means aligning with the standard; certification means passing an independent audit.

  • Certification typically takes 6 to 12 months, depending on company size and tooling.

The average cost of a data breach reached $4.99 million globally in 2026. That's an all-time high, according to IBM's Cost of a Data Breach Report. Regulatory pressure has climbed just as fast: fines under the GDPR alone have passed €6 billion since 2018, per the CMS GDPR Enforcement Tracker. Customers, partners, and regulators increasingly expect proof that an organization takes information security seriously, not just a claim on a sales page. ISO 27001 gives organizations a proven, globally recognized framework to systematically safeguard critical information assets. It replaces ad hoc fixes and scattered spreadsheets with a structured process. It's also the standard most often requested in vendor security questionnaires and enterprise procurement, which makes understanding it useful well beyond security teams.

What is ISO 27001?

ISO/IEC 27001 is the international standard for information security management systems (ISMS). It provides a framework to manage and protect sensitive data through systematic risk management. The standard sets out the requirements an organization must meet to identify, treat, and continuously monitor information security risks.

The standard is published jointly by the International Organization for Standardization (ISO) and the International Electrotechnical Commission (IEC). That's why it's written as "ISO/IEC 27001." The current version, ISO/IEC 27001:2022, restructured the standard's control set. It also introduced updated terminology to reflect modern security challenges such as cloud services and threat intelligence.

ISO 27001 is deliberately industry-agnostic. It applies equally to a five-person startup and a multinational enterprise. That's because the standard defines a process for managing risk, not a fixed list of technologies to deploy. This is also why it pairs well with sector-specific requirements. An organization can build one ISMS and map it to ISO 27001, plus other frameworks such as SOC 2 or industry-specific regulation, instead of managing each in isolation. That flexibility is also why the standard matters to such different readers. Compliance managers scoping a certification project, CISOs deciding where to prioritize investment, and business leaders evaluating a vendor's security posture all end up asking, at some point, what ISO 27001 actually requires.

For a closer look at the standard's full requirements, see Formalize's ISO 27001 guide.

The core pillars: The CIA triad in ISO 27001

ISO 27001 is built around the protection of three core information security principles, together known as the CIA triad. The standard doesn't treat security as a single goal. Instead, it asks organizations to weigh three distinct, and sometimes competing, objectives for every information asset:

Confidentiality

Ensuring only authorized personnel can access sensitive information.

Integrity

Protecting data accuracy and preventing unauthorized alterations or tampering.

Availability

Ensuring systems and data are accessible to authorized users when needed.

An effective ISMS balances all three. Overinvesting in one undermines the others. For example, locking data down so tightly that authorized users can't do their jobs defeats the purpose. A risk assessment under ISO 27001 asks, for each asset, which of the three matters most and what could compromise it. That question is what turns the CIA triad from an abstract concept into a practical prioritization tool.

What is an Information Security Management System (ISMS)?

An ISMS is the practical mechanism behind ISO 27001. It's a management framework that connects people, processes, technology, and organizational risk management into a single, auditable system. It isn't a one-time IT project.

An ISMS defines how an organization identifies risks to its information assets. It also determines which controls to apply, who owns them, and how performance is reviewed over time. That's a meaningfully different challenge than deploying a firewall or an access control policy in isolation. In practice, an ISMS touches areas as varied as HR onboarding and offboarding, vendor contracts, physical office access, software development practices, and incident response. It reaches anywhere information flows through the organization.

Because the scope spans the entire organization, ISO 27001 requires clear ownership. Someone needs to be accountable for the risk register. Someone needs to sign off on the Statement of Applicability. And someone needs to review whether controls are still working as new risks emerge. Without that structure, security work tends to concentrate in IT. Yet many of the highest-impact risks, such as phishing or vendor breaches, sit outside it.

This is also where spreadsheet-based approaches tend to fail. A spreadsheet can hold a risk register or a control list. But it can't enforce ownership, trigger reviews, or link evidence to controls automatically. As the ISMS grows to cover more risks, controls, evidence, and stakeholders, spreadsheets become a liability rather than a system of record.

Key components of the ISO 27001 standard

The standard has two main parts. The first is the set of mandatory clauses that define how the ISMS itself must operate. The second is Annex A, the reference list of security controls an organization draws on. Auditors check every mandatory clause. But they only check the Annex A controls an organization has actually selected as relevant.

Clauses 4–10 (the ISMS framework)

Clauses 4 through 10 are mandatory for certification. They cover the context of the organization, leadership commitment, planning, support, operation, performance evaluation, and continual improvement. Practitioners commonly map this structure to the Plan-Do-Check-Act (PDCA) cycle:

  • Plan: Define the ISMS scope, assess risks, and set objectives.

  • Do: Implement the risk treatment plan and selected controls.

  • Check: Monitor, measure, and internally audit the ISMS.

  • Act: Address nonconformities and continually improve.

This cycle repeats continuously rather than running once. A risk identified during the "Check" phase, say a new vendor with access to customer data, feeds back into planning. That feedback loop is what keeps an ISMS current as the organization and its threat landscape change. It's not a one-time snapshot from the initial certification.

Annex A controls

Annex A of ISO/IEC 27001:2022 lists 93 controls, organized into four themes:

  1. Organizational controls (37): policies, roles, supplier relationships, and incident management.

  2. People controls (8): screening, awareness, and terms of employment.

  3. Physical controls (14): protecting facilities, equipment, and media.

  4. Technological controls (34): access control, cryptography, and monitoring.

ISO/IEC 27001:2022 update: The 2022 revision consolidated the previous 114 controls from 14 domains (in the 2013 version) into these 93 controls under four themes. The change reflects current risks like cloud security and threat intelligence. Organizations don't need to implement every control. They select the ones relevant to their risk assessment and document exclusions in a Statement of Applicability (SoA). The transition window for existing ISO 27001:2013 certificates closed on October 31, 2025. ISO/IEC 27001:2022 is now the only valid version; any certificate still referencing the 2013 edition is no longer recognized.

Annex A works as a reference list, not a checklist to complete in full. During certification, auditors don't expect all 93 controls in place. They expect the SoA to justify each exclusion and confirm that the controls the organization did select are actually operating, not just documented on paper. A common gap is implementing controls simply because they appear in the annex, rather than because a specific identified risk calls for them.

What is the difference between ISO 27001 compliance and certification?

These two terms are often used interchangeably, but they describe different stages:

  • Compliance means an organization has aligned its internal security practices and policies with the ISO 27001 standard.

  • Certification means an accredited third-party certification body has formally audited the organization and issued an official ISO 27001 certificate.

An organization can be compliant without being certified. But certification always requires demonstrated compliance, verified by an external auditor. Some organizations operate a compliant ISMS without pursuing formal certification, for example while preparing internally. Most customer and procurement requirements, though, specifically ask for the certificate itself, since it confirms an independent party has verified the claim.

How to achieve ISO 27001 certification: 5 steps

  1. Scope definition and gap analysis. Identify which assets, systems, teams, and locations the ISMS will cover. Then evaluate existing security controls against the standard to see where the gaps are. Getting the scope right early avoids costly rework later. Too narrow, and the certificate won't cover what customers actually ask about. Too broad, and the project stalls under its own weight.

  2. Risk assessment and treatment. Identify threats to each in-scope asset and score risks by likelihood and impact. Decide how to treat each one (accept, mitigate, transfer, or avoid). Then draft a Statement of Applicability (SoA) documenting which Annex A controls apply.

  3. Control implementation. Put the selected Annex A controls into practice: policies, access controls, vendor due diligence, and other safeguards. Capture evidence as controls are rolled out, not after the fact.

  4. Internal audit and management review. Test the ISMS internally, ideally by someone independent of day-to-day operation of the controls. This confirms it's operating as intended and ready for external review. Management then formally reviews the results and signs off.

  5. Stage 1 and Stage 2 external audits. An accredited ISO registrar first reviews documentation and readiness (Stage 1). It then evaluates real-world implementation and evidence (Stage 2) before issuing certification. Annual surveillance audits follow to maintain it.

Most organizations complete this process in 6 to 12 months. The timeline depends on company size, complexity, and how much of the work is manual versus supported by dedicated tooling. Recertification happens on a three-year cycle, with lighter surveillance audits in between.

What are the benefits of ISO 27001?

ISO 27001 can help organizations:

  • Identify and manage information security risks systematically, instead of reacting to incidents after they happen.

  • Demonstrate security maturity to customers and partners, particularly in vendor security reviews and enterprise procurement.

  • Reduce the cost and frequency of security incidents, backed by controls that are tested, not just documented.

  • Get a head start toward other frameworks. A working ISMS already covers much of what NIS2 and DORA also require.

  • Give leadership and staff a consistent process for security decisions, instead of judgment calls that vary by person.

Streamlining ISO 27001 compliance with Formalize

Formalize embeds the official ISO/IEC 27001:2022 standard directly into the platform, through a collaboration with UNE, Spain's national standards body, formalized in April 2026. Teams work from the current, licensed content itself, instead of a separately purchased PDF. Formalize is the first GRC provider in Spain, and among the earliest in Europe, to secure this kind of direct collaboration with ISO/IEC representatives.

Formalize is also part of an official AI pilot with ISO and UNE. The pilot is developing an AI capability called Formalize IQ, intended to turn static ISO requirements into actionable, native workflows once it ships.

Formalize's ISMS software centralizes evidence collection and maps controls to risks, instead of tracking them across disconnected files. It keeps the organization continuously audit-ready, with visibility that stays current between certification cycles, not just in the weeks before an audit. That matters most at exactly the point spreadsheets tend to break down: when ownership needs to be clear, evidence needs to be traceable to a specific control, and reviewers need an up-to-date picture without chasing down the latest version of a file.

Information security risk rarely exists in isolation. That's why Formalize also connects ISO 27001 work to the organization's broader risk management framework. A phishing incident, for instance, can flow directly into updated risk scoring instead of staying siloed in an incident log.

ISO 27001 rarely stands alone in an organization's compliance stack either. Formalize maps its Annex A controls directly to other frameworks, including NIS2, and to national standards such as Spain's ENS, Belgium's CyFun, and Germany's BSI IT-Grundschutz. Update a control once, and that update carries through to every framework it's mapped to. That replaces re-proving the same control separately for each regulator, which is where most duplicate audit work actually comes from.

Formalize's pricing isn't seat-based either. Security teams can invite legal, operations, and outside auditors directly into the platform without paying per additional login. ISO 27001 work touches legal and operations regularly, and seat costs are a common reason those functions get left out of the tooling entirely.

Explore how Formalize can help you build and maintain an audit-ready ISO 27001 management system.

Frequently asked questions

Book a demo