ISO/IEC 27001:2022

ISO 27001 readiness without the spreadsheet maze.

ISO/IEC 27001 certifies that you run an information security management system: a documented, governed, reviewed way of deciding what to protect and proving you do it. Clauses 4 to 10 are the auditable requirements. Annex A is 93 controls in four themes that you compare your risk treatment against. Sentinel holds the requirements, the control mapping, the owners, the evidence, the actions and the Statement of Applicability in one register — instead of six workbooks and a shared drive nobody can defend.

Self-service signup opens shortly — we will set you up in the meantime

FrameworksSentinel interface, reproduced

ISO/IEC 27001:2022

In scope
  • ISO/IEC 27001:202280% ready
    42 controls in the catalogue
Annex A
42
controls mapped
Register
26
controls, four frameworks
Unowned
2
controls

Annex A controls with an owner, a status and the evidence attached to each one. Figures are from the example workspace used throughout this site; Northstar Manufacturing Ltd. is fictional, and 80% ready is a readiness position rather than a certification.

42
Annex A controls, in four themes, mapped onto one control register
7
Clauses (4 to 10) carrying the auditable management-system requirements
11
Controls new in the 2022 edition, from threat intelligence to secure coding
80%
Annex A ready in the example workspace — readiness, not a certificate

Fit

Worth it for some organisations, expensive theatre for others.

ISO 27001 is the most widely recognised information security certificate in the world outside North America. It is also a genuine management system with genuine ongoing cost, and the wrong answer for a company whose real problem is that nobody has patched anything since spring.

ISO 27001 is the right call
Where your buyers are
International — Europe, the UK, the Gulf and much of Asia, where ISO 27001 is the token procurement recognises.
What the document has to be
A tender or a vendor policy asks for a certificate rather than a report.
What is driving the date
One credential to satisfy many customers, instead of a security review per deal.
Your current baseline
The security work already happens; the gap is that none of it is documented, reviewed or owned.
Appetite for the annual cycle
Somebody will own internal audit, management review and surveillance audits every year.
What you actually need to answer
Procurement, with a credential it already recognises.
Choose something else
Where your buyers are
Every buyer asking is a North American software company whose vendor policy names SOC 2. Get the report they asked for.
What the document has to be
A 200-question questionnaire wants control answers. No certificate answers it for you.
What is driving the date
A cyber-insurance renewal. Underwriters ask about controls and evidence, not certificates.
Your current baseline
No asset inventory, no multi-factor authentication, no backup testing. CIS Controls IG1 is the shorter road.
Appetite for the annual cycle
Nobody can commit to that cycle. The certificate lapses and the money is gone.
What you actually need to answer
A board, about risk. NIST CSF 2.0 does that better and costs nothing.

Structure

The clauses are the management system. Annex A is the control set.

Two parts, and the first one is where audits are failed. Clauses 1 to 3 cover scope, normative references and terms, and contain no requirements.

Clauses 4 to 10 — the requirements

  1. Clause 4 — Context of the organisation

    Who has an interest in your information security, what they require, and where the boundary of the management system sits. Clause 4.3 is the scope statement that will be printed on your certificate.

  2. Clause 5 — Leadership

    Top management commitment that is demonstrated rather than asserted, an information security policy, and assigned roles with real authority.

  3. Clause 6 — Planning

    The risk assessment and risk treatment process, information security objectives, and — new in the 2022 edition — planning of changes to the management system.

  4. Clause 7 — Support

    Resources, competence, awareness, communication, and control of documented information. This is where “we know who is trained and can prove it” lives.

  5. Clause 8 — Operation

    Actually doing it: operational planning and control, performing the risk assessment at planned intervals, and implementing the risk treatment plan.

  6. Clause 9 — Performance evaluation

    Monitoring and measurement, an internal audit programme, and management review. The clause that most often fails a Stage 2 audit, because it needs history.

  7. Clause 10 — Improvement

    Continual improvement, and the handling of nonconformities and corrective action. Auditors look for evidence that something went wrong and was dealt with properly.

Amendment 1:2024 added climate change considerations to clauses 4.1 and 4.2. Clause 9 is the one that needs history rather than drafting, which is why it usually sets the real timeline for a first certification.

Annex A

Ninety-three controls, and they are not evenly distributed.

The 2022 edition reorganised the 114 controls of the 2013 edition into 93, merged overlapping ones, and introduced eleven new controls: threat intelligence, information security for use of cloud services, ICT readiness for business continuity, physical security monitoring, configuration management, information deletion, data masking, data leakage prevention, monitoring activities, web filtering and secure coding.

  • A.537

    Organisational

    Policies, roles and segregation of duties, asset and information classification, supplier and cloud service security, incident management, business continuity, and legal and contractual requirements. The largest theme, and the one most often thin in practice.

    88% of Annex A

  • A.68

    People

    Screening, terms of employment, awareness and training, the disciplinary process, responsibilities after employment ends, confidentiality agreements, remote working and event reporting.

    19% of Annex A

  • A.714

    Physical

    Security perimeters and entry, protecting offices and equipment, working in secure areas, clear desk and screen, storage media, cabling, maintenance and secure disposal. Still applicable to a remote-first company, and usually where scope arguments start.

    33% of Annex A

  • A.834

    Technological

    Access to information, privileged access, authentication, malware protection, vulnerability management, configuration management, logging and monitoring, backup, cryptography, network security, secure development, testing and change management.

    81% of Annex A

37 plus 8 plus 14 plus 34 — 42 controls in total. Each control also carries attributes in ISO/IEC 27002:2022, which is the implementation guidance for the same set. Annex A is a reference set you compare your risk treatment against, not a list you must implement in full.

A certificate says the management system exists and is being run. It does not say you are hard to attack.

Which is why the scope statement in clause 4.3 matters more than the logo on the certificate. A careful buyer reads what the certificate covers before they read that it exists.

In Sentinel

Where the programme lives between audits.

The failure mode of a first certification is not the audit. It is month fourteen, when the register is stale, the person who maintained it has left, and the surveillance audit is in three weeks.

Requirements and control mapping

Annex A becomes controls with names against them.

Each Annex A control is a requirement pointing at a control you own, with an inclusion decision and justification recorded beside the risk treatment it came from — which is the Statement of Applicability, kept where it cannot drift out of step.

  • 42 Annex A controlsmapped onto a register of 26 controls shared with SOC 2, NIST CSF 2.0 and CIS v8.1
  • Named owners24 of 26 assigned, and the 2 that are not shown in red rather than averaged away
  • Test schedule and findingsthe date each control was last checked, and what the check found

See the control register

ControlsSentinel interface, reproduced
Control LibraryFramework ReadinessTest ScheduleTest HistoryFindings
Operating
18
Needs evidence
6
Not implemented
2
Owners assigned
24/26
  • A.5.1Policies for information security
    Owner
    Priya Raman
    Status
    Passed
    Evidence
    Accepted
    Last tested
    28 Jul 2026
  • A.5.18Access rights
    Owner
    Priya Raman
    Status
    Passed
    Evidence
    Accepted
    Last tested
    26 Jun 2026
  • A.8.5Secure authentication
    Owner
    Priya Raman
    Status
    Passed
    Evidence
    Accepted
    Last tested
    14 Aug 2026
  • + 5 more in the workspace

Evidence

A certification body asks for proof, and proof expires.

Attach the access review, the training record, the restore test once. Each item carries a status and an expiry date, so you find out something went stale months before a Stage 2 auditor does.

  • Status and expiryon every item: Accepted, Under Review, Pending, Expired, Missing
  • 1 expired, 1 missingsurfaced continuously in the example workspace, not discovered during fieldwork
  • Linked to the controlso the Annex A requirement, the proof and the owner stay connected

See evidence workflows

See evidence workflows

Clause 6 and clause 10

The treatment plan becomes dated, assigned work.

Assessed risks carry an owner, a treatment decision and a target date. Gaps and nonconformities become tracked actions in the product’s own horizons, which is what clause 10 wants evidence of: something went wrong and was dealt with properly.

  • Rating as likelihood × severitywith treatment and target date on the same row
  • Critical Now → Strategic Projectsthe product’s real horizons, not a flat backlog
  • Corrective action with a recordso the internal audit finding and its closure sit together

See risk and actions

See the risk register

See risk and actions

What changes

The same standard, held somewhere it can answer a question.

Nothing here is about doing more security. It is about the difference between having done the work and being able to show it on the day a certification body, a customer or an underwriter asks.

The spreadsheet maze
  • A workbook per Annex A theme, and a seventh for the clauses
  • A Statement of Applicability in its own file, already out of step with the risk treatment
  • Evidence in a shared drive, named by whoever uploaded it
  • The owner of a control is whoever answered the email last
  • Internal audit findings tracked in a mail thread
  • Management review minutes rebuilt from memory the week of the audit
One register in Sentinel
  • Annex A mapped onto one register of 26 controls, shared with three other frameworks
  • An inclusion decision and justification against each of the 42 controls, beside its risk treatment
  • Evidence attached to the control, carrying a status and an expiry date
  • Every control has a named owner, and the unowned ones are visible
  • Findings and corrective actions tracked with owners and dates
  • A management review pack generated from the register

Evidence

What a certification body asks to see.

Not exhaustive, and your risk treatment decides the rest. But these come up in almost every engagement, and the items tagged Time-bound are the ones that quietly expire between the audit you passed and the audit you have next year.

See how the evidence library handles expiry

Scope statement and ISMS policyFoundational
Approved, dated, and owned by a named person.
Risk assessment and treatment recordsFoundational
Method, criteria, assessed risks, owners, treatment decisions.
Statement of ApplicabilityFoundational
All 42 Annex A controls, each with an inclusion decision and justification.
Asset and information inventoryRecurring
Classified, owned, and current — the dependency for a dozen other controls.
User access review recordsRecurring
Who reviewed which accounts, when, and what changed as a result.
Supplier register and agreementsRecurring
Including cloud services, with the security terms actually in the contract.
Incident records and post-incident reviewEvent-driven
Auditors would rather see a handled incident than an empty log.
Continuity and ICT readiness test resultsEvent-driven
A test with a date, a result and a corrective action.
Awareness and competence recordsTime-bound
Completion by person and date. The item most likely to have expired.
Internal audit programme and reportsTime-bound
Independent of the area audited, and covering the whole management system over the cycle.
Management review minutesTime-bound
Inputs, decisions, actions. Missing minutes is a common Stage 2 nonconformity.

Clause 9

Management review needs a pack, not a folder.

Clause 9 wants monitoring results, an internal audit programme and a management review with inputs, decisions and actions recorded. That is the clause most likely to produce a nonconformity, because it cannot be written the night before — it needs a register that has been running.

Same register, read for a different room: where are we, what changed, and what needs a decision.

See executive reporting

See executive reporting

Straight answers

Honest limitations.

Three things worth knowing before you commit budget, and one thing about us.

Scope is everything
A certificate covers only the scope printed on it. A scope drawn around one product and one office says nothing about the rest of the organisation, and sophisticated buyers read it.
It is a recurring commitment
Annual surveillance audits, an internal audit programme and a management review every cycle. A programme nobody owns after certification lapses, publicly.
Readiness is not a result
Being ready means the register is complete, the evidence is current and the gaps are known. The audit outcome is still the certification body’s decision, and Stage 2 findings happen.

Questions

Asked on nearly every first call.

Timelines, the control count, and who is allowed to sign what.

How long does a first certification realistically take?
For a small organisation starting from scratch, plan on six to twelve months to Stage 2. The documentation is rarely the constraint. The constraint is that clause 9 requires monitoring results, an internal audit and a management review, and clause 10 requires evidence that nonconformities were handled — none of which can be produced retroactively. Organisations that already run access reviews, incident management and supplier assessments move much faster, because they are documenting practice rather than inventing it.
Do we have to implement all 93 Annex A controls?
No. Annex A is a reference set you compare your risk treatment against, so that nothing necessary is omitted by accident. You must consider every control and record a decision on each one in the Statement of Applicability, with justification where you exclude. Excluding controls is normal and expected; excluding them without a reason that stands up to questioning is not.
What is the difference between ISO 27001 and ISO 27002?
ISO/IEC 27001 contains the auditable requirements — clauses 4 to 10 and Annex A. ISO/IEC 27002:2022 is implementation guidance for the same 93 controls, with far more detail on what each one means in practice and the attribute tags used to filter them. You are certified against 27001. You read 27002 to work out how.
We hold a certificate against the 2013 edition. Where does that leave us?
The transition period for ISO/IEC 27001:2013 closed on 31 October 2025, so certificates against the 2013 edition are no longer current. If you have not transitioned, the practical work is remapping your controls to the 2022 Annex A structure, addressing the eleven controls that were new in 2022 — including threat intelligence, cloud service security, ICT readiness for continuity, configuration management, data leakage prevention, web filtering and secure coding — and reissuing the Statement of Applicability. Amendment 1:2024 also added climate change considerations to clauses 4.1 and 4.2.
Does the certification body have to be accredited?
Nothing stops an organisation issuing you a document, but a certificate from a body that is not accredited by a recognised national accreditation body carries little weight with the customers you are getting certified for. Check the accreditation mark before you sign, and check that the scope on the certificate is the scope your buyers care about.
Can CyberWave certify us, or act as our auditor?
No. Certification is issued by an accredited certification body after its own audit, and CyberWave is not one. We also cannot be your internal auditor for the parts of the management system we help you build, because clause 9.2 requires independence from the area being audited. Sentinel is where the register, evidence and reporting live so that the external engagement is short and the surprises are small.

Put Annex A next to what you actually have.

An honest first pass usually takes an afternoon and changes the conversation, because the gap you have been guessing at becomes a list with names and dates against it.

Book a walkthrough

Self-service signup opens shortly — we will set you up in the meantime

  • Published pricing — no quote-on-request tier
  • No credit card required for the trial
  • No automatic charge when a trial ends
  • Tenant-isolated architecture, data stored in Canada
  • Clear data-processing terms
  • No compliance guarantee — human judgement still required