ISO 27001:2022 FAQ
Everything you need to know about ISO 27001 certification, the 2022 transition, and information security management systems.
ISO 27001:2022 is the latest version of the international standard for information security management systems. It replaces ISO 27001:2013 and includes updated controls in Annex A, reorganised into four themes: Organisational, People, Physical, and Technological controls.
The transition period ended on 31 October 2025. All ISO 27001:2013 certificates are now invalid. If your organisation has not yet transitioned to ISO 27001:2022, you will need to pursue certification under the 2022 version directly. Contact us for guidance on your transition path.
The main changes include a restructured Annex A with 93 controls (down from 114) organised into four themes, 11 new controls addressing areas like threat intelligence, cloud security, and data masking, and enhanced requirements for understanding interested parties' requirements.
The cost varies significantly based on organisation size, scope, and current security maturity. It includes consulting fees, implementation costs, internal audit costs, and certification body fees. Contact us for a tailored quote based on your specific situation.
While there is significant overlap between SOC 2 and ISO 27001, they serve different purposes and audiences. ISO 27001 is internationally recognised, while SOC 2 is more prevalent in North America. Many organisations pursue both to satisfy global customer requirements.
The scope defines which parts of your organisation, information assets, processes, and locations are covered by the ISMS. Defining the right scope is critical — too narrow and it may not satisfy customer requirements, too broad and it becomes unnecessarily complex and costly.
The SoA is a key document in ISO 27001 that lists all Annex A controls, states whether each is applicable, provides justification for inclusion or exclusion, and describes how applicable controls are implemented. It is one of the most important documents reviewed during certification audits.
After initial certification, surveillance audits are conducted annually (typically at 12 and 24 months). A full re-certification audit is conducted every three years. These audits ensure your ISMS remains effective and continuously improved.
Risk assessment is fundamental to ISO 27001. It involves identifying information security risks, analysing their likelihood and impact, evaluating them against your risk criteria, and determining appropriate treatment options. The risk assessment drives your selection of controls and your overall security strategy.
Yes, ISO 27001 is designed to be integrated with other ISO management system standards such as ISO 9001 (Quality), ISO 22301 (Business Continuity), and ISO 42001 (AI). The common high-level structure makes integration straightforward and reduces audit burden.