ISO/IEC 27001:2022 · ISMSSecurity management system

    ISO/IEC 27001: information security management system

    ISO/IEC 27001 is the international standard for an information security management system (ISMS) and the foundation NIS2, DORA and TISAX all build on. The certificate opens doors to contracts and reassures customers. We build it on real security, not shelf-ware policies.

    Security management system

    What ISO/IEC 27001 involves

    Risk-based security management, evidenced by audit. Verify exact requirements against the standard and your certification body.

    • 01

      Current version

      ISO/IEC 27001:2022 is the current revision; versus 2013 it restructures Annex A into 93 controls across 4 themes.

    • 02

      Risk-based approach

      The core is risk management: assessment, treatment and a Statement of Applicability (SoA) justifying the selected controls.

    • 03

      Controls (Annex A)

      93 controls across four themes: organizational, people, physical and technological.

    • 04

      Certification

      Issued by an accredited certification body after a successful audit; valid on a three-year cycle with surveillance audits.

    • 05

      Management ownership

      The ISMS requires management commitment, measurable objectives and continual improvement.

    • 06

      Foundation for other frameworks

      An established ISMS greatly simplifies NIS2 / the Act and DORA compliance and TISAX preparation.

    FAQ

    Frequently asked questions

    Straight answers to what clients ask us most.

    The 2022 revision restructures Annex A into 93 controls across four themes (organizational, people, physical, technological) and adds newer areas such as threat intelligence and cloud security. The transition period to the 2022 version ended on 31 October 2025; certificates to the 2013 version are no longer valid.

    For small and mid-sized organisations it's typically several months, depending on your starting point, the ISMS scope and how fast controls are implemented. Design and implementation are followed by a two-stage certification audit.

    It isn't mandatory, but an ISO 27001 ISMS covers a large share of NIS2 / the Act's requirements and makes meeting and evidencing them much easier. That's why we often recommend it as the common foundation.

    Yes. An ISMS isn't a one-off. It needs operation, measurement and surveillance audits. Operationally (SOC/MDR, security engineering) we keep the controls working between audits, not just on audit day.

    Certification built on real security

    We design the ISMS, run the risk analysis, prepare the SoA and implement controls so you pass the audit and stay secure afterwards.