Threat ResQ

Compliance

ISO 27001: The Complete Guide to Information Security Management Certification

ISO/IEC 27001 is the internationally recognized standard for an Information Security Management System (ISMS) — a systematic, risk-based approach to managing an organization's information security. Unlike a checklist of

9 min readLast reviewed September 3, 2026Threat ResQ Technologies

ISO 27001: The Complete Guide to Information Security Management Certification

Executive Summary

ISO/IEC 27001 is the internationally recognized standard for an Information Security Management System (ISMS) — a systematic, risk-based approach to managing an organization's information security. Unlike a checklist of technical controls, ISO 27001 certifies that an organization has a working management system: it identifies risks, selects and implements controls to address them, and continuously reviews and improves the system over time. This guide covers what an ISMS actually requires, the Annex A control domains, how the third-party certification process works, and how getTRAC automates the evidence collection an ongoing ISO 27001 program depends on.

Key Takeaways

  • ISO 27001 certifies a management system, not a fixed technical checklist — the same standard applies to a 10-person startup and a multinational bank, scaled to context.
  • The current edition (ISO/IEC 27001:2022) organizes its Annex A controls into four themes: Organizational, People, Physical, and Technological.
  • Certification requires an accredited, independent third-party certification body — Threat ResQ does not issue ISO 27001 certificates, and no organization can self-certify.
  • Certification follows a two-stage audit (Stage 1 documentation review, Stage 2 implementation audit), then annual surveillance audits and full recertification every three years.
  • A risk assessment and a Statement of Applicability (SoA) — which Annex A controls apply, and why — sit at the center of the entire ISMS.

What ISO 27001 actually certifies {#what-it-certifies}

ISO 27001 certifies that an organization operates a functioning Information Security Management System — a structured, ongoing process for identifying information security risks and managing them, not a one-time technical audit. The standard is deliberately outcome-based rather than prescriptive: it doesn't mandate a specific firewall configuration or password policy, it requires the organization to assess its own risks and select proportionate controls to address them, documented in a Statement of Applicability.

The ISMS core requirements {#core-requirements}

The main body of ISO/IEC 27001 (clauses 4–10) sets out the management-system requirements every certified organization must meet:

  • Context of the organization — understanding internal and external issues, and interested parties' requirements, that shape the ISMS's scope.
  • Leadership — top management commitment, an information security policy, and clearly assigned roles and responsibilities.
  • Planning — a documented risk assessment methodology, risk treatment plan, and Statement of Applicability.
  • Support — resources, competence, awareness, communication, and documented information.
  • Operation — executing the risk treatment plan and operating the selected controls.
  • Performance evaluation — monitoring, internal audits, and management review.
  • Improvement — corrective action and continual improvement of the ISMS.

Annex A control themes {#annex-a}

ISO/IEC 27001:2022's Annex A lists 93 controls, organized into four themes:

  • Organizational controls (37 controls) — policies, roles, asset management, access control, supplier relationships, incident management.
  • People controls (8 controls) — screening, terms of employment, security awareness and training, disciplinary process.
  • Physical controls (14 controls) — secure areas, equipment security, clear desk/clear screen, physical entry controls.
  • Technological controls (34 controls) — access control, cryptography, logging and monitoring, network security, secure development.

An organization doesn't have to implement every Annex A control — it selects the ones relevant to its risk assessment and documents the reasoning (including justified exclusions) in its Statement of Applicability.

The certification process {#certification-process}

  1. Gap assessment — comparing current practices against ISO 27001's requirements to scope the work ahead.
  2. Risk assessment and Statement of Applicability — the foundation the rest of the ISMS is built on.
  3. Implementation — putting the selected controls, policies, and processes into operation, typically over several months.
  4. Internal audit and management review — required before the external audit, confirming the ISMS is actually operating as documented.
  5. Stage 1 audit — an accredited certification body reviews documentation and readiness.
  6. Stage 2 audit — the certification body assesses whether the ISMS is implemented and operating effectively in practice.
  7. Certification, surveillance, and recertification — certificates are typically valid for three years, with annual surveillance audits in between.

Certification bodies must themselves be accredited by a national accreditation body — this is a genuinely independent, third-party process, not something any consultancy (including Threat ResQ) can grant directly.

Who needs ISO 27001 {#who-needs-it}

ISO 27001 is common where an organization needs to demonstrate information security governance to customers, regulators, or partners — SaaS vendors selling into enterprise or regulated customers, IT service providers, financial services technology vendors, and organizations handling sensitive data at scale. It's frequently requested in vendor security questionnaires and RFPs as a baseline trust signal, alongside or instead of SOC 2.

Common implementation mistakes {#common-mistakes}

  • Treating it as a document exercise — writing policies that don't reflect how the organization actually operates is the single most common reason Stage 2 audits fail.
  • A risk assessment that's too generic — a Statement of Applicability copied from a template, rather than derived from the organization's actual risk profile, doesn't hold up to audit scrutiny.
  • No evidence trail — controls that exist but generate no ongoing evidence (log reviews that happen but aren't recorded, access reviews that aren't documented) are difficult to demonstrate a year into certification.
  • Scoping too broadly on day one — a narrower, well-implemented initial scope is usually a stronger starting point than an organization-wide scope implemented shallowly.

How getTRAC helps with ISO 27001 {#how-gettrac-helps}

getTRAC maps ongoing platform activity to ISO 27001 Annex A controls alongside seven other frameworks (SOC 2, GDPR, DPDP, HIPAA, RBI, NIST, PCI DSS), so evidence accumulates continuously instead of being assembled in the weeks before an audit. For organizations building or maturing an ISMS, Compliance Consulting pairs a human consultant with the platform to run the gap assessment, risk assessment, and Statement of Applicability work that certification actually depends on.

FAQ {#faq}

How long does ISO 27001 certification take? It varies significantly by organization size and starting maturity, but a first-time certification typically spans several months from gap assessment through Stage 2 audit — organizations with an existing security program can move faster than those starting from scratch.

Is ISO 27001 the same as SOC 2? No. ISO 27001 certifies a management system against an international standard via an accredited certification body; SOC 2 is an attestation report issued by a licensed CPA firm against the AICPA's Trust Services Criteria. Many organizations pursue both, since they're requested by different customer bases and cover overlapping but distinct ground.

Does ISO 27001 require every Annex A control to be implemented? No — an organization selects controls based on its own risk assessment and documents its reasoning, including any justified exclusions, in the Statement of Applicability.

Can Threat ResQ certify my organization against ISO 27001? No — certification must come from an independently accredited certification body. Threat ResQ's role is helping organizations prepare for that audit and maintain compliance evidence afterward, not issuing the certificate itself.

Frequently asked questions

How long does ISO 27001 certification take?

It varies significantly by organization size and starting maturity, but a first-time certification typically spans several months from gap assessment through Stage 2 audit — organizations with an existing security program can move faster than those starting from scratch.

Is ISO 27001 the same as SOC 2?

No. ISO 27001 certifies a management system against an international standard via an accredited certification body; SOC 2 is an attestation report issued by a licensed CPA firm against the AICPA's Trust Services Criteria. Many organizations pursue both, since they're requested by different customer bases and cover overlapping but distinct ground.

Does ISO 27001 require every Annex A control to be implemented?

No — an organization selects controls based on its own risk assessment and documents its reasoning, including any justified exclusions, in the Statement of Applicability.

Ask TIARA about this article

Get a grounded answer on ISO 27001 compliance, or ask your own question.

Talk to an Expert

We use cookies for essential function and, with consent, analytics. Cookie Policy