ISO/IEC 27001:2022: Information security management system
The most internationally recognised standard for information security management systems (ISMS) — voluntarily certifiable, but in practice often a market requirement and a regulatory-recognised proof point, including against NIS2.
A management-system standard, not EU legislation.
ISO/IEC 27001 is a standard from the International Organization for Standardization (ISO) and the International Electrotechnical Commission (IEC) — not EU legislation, but a voluntarily certifiable management system for information security. Certification is carried out by accredited, independent certification bodies, not by a public authority.
The current edition, ISO/IEC 27001:2022, replaces the 2013 version. Its core is the management-system clauses 4 to 10 (context of the organisation, leadership, planning, support, operation, evaluation, improvement, among others) plus the Annex A control catalogue, closely aligned with ISO/IEC 27002:2022.
Annex A of the 2022 edition comprises 93 controls, grouped into four themes: organisational, people, physical, and technological — a significant streamlining and restructuring compared with 114 controls across 14 categories in the 2013 edition.
Key deadlines
ISO/IEC 27001:2022 replaces the 2013 edition
New structure: 93 Annex A controls across four themes instead of 114 controls across 14 categories.
ISO/IEC 27001:2013 certificates are invalid
The three-year transition window set by the International Accreditation Forum (IAF) for migrating 2013 certificates to the 2022 edition has ended; existing 2013 certificates have lost their validity.
Recertification every three years, annual surveillance audits
After initial certification, accredited certification bodies conduct annual surveillance audits and a full recertification every three years.
What ISO/IEC 27001:2022 structurally requires.
Management-system clauses 4–10
The mandatory core: context of the organisation, leadership and commitment, planning including risk treatment, support, operation, performance evaluation, and continual improvement.
Statement of Applicability (SoA)
Documented justification of which of the 93 Annex A controls are applied and which are excluded with reasoning — a central audit object.
Risk assessment per ISO/IEC 27005
Systematic identification, analysis, and treatment of information-security risks as the basis for control selection.
Four themes in Annex A
Organisational, people, physical, and technological controls — from access control and supplier relationships to cryptography.
An SoA, sealed and reusable across regimes.
The ReportAct ISO/IEC 27001 Framework Pack maps all 93 Annex A controls as a complete Statement of Applicability, including an asset register and a risk register per ISO 27005 — every assessment cryptographically sealed.
Because ISO/IEC 27001 covers much of NIS2's requirements in substance, ReportAct automatically credits controls maintained once toward every active framework pack, instead of capturing evidence multiple times.
For customers and auditors, every control is available via a public verify URL — checkable without ReportAct access.
Product/positioning statement, not legal advice.
Read the originals
ReportAct is not a consultancy. This page does not constitute legal advice. The text of ISO/IEC 27001 is copyrighted and available for purchase from ISO or the relevant national standards body — this page describes structure and deadlines but does not replace reading the original text. Our Terms of Service apply.
An SoA that counts across regimes.
Start right away with your Statement of Applicability — including cross-mapping to NIS2 and DORA.