What category of standard this is
ISO/IEC 27001 is a requirements standard for an information security management system (ISMS). The IEC abstract says the document specifies requirements for establishing, implementing, maintaining, and continually improving an ISMS within the context of the organization. It also includes requirements for the assessment and treatment of information security risks tailored to the needs of the organization.
The same abstract says the requirements are generic, and intended for organizations of any type, size, or nature. Excluding any of the requirements in Clauses 4 to 10 is not acceptable when an organization claims conformity. Who it commonly frames: GRC and management-system owners, and buyers who are handed a logo. It is not a statute, and it is not a product feature list.
What security people most often confuse: they treat an ISO logo, a SOC 2 report, a CSF profile, and a CIS Implementation Group as one compliance badge. This page keeps those objects apart. The Reference card at /reference/frameworks/iso-iec-27001-2022/ remains the framework summary. This explainer does not replace it.
Edition pin
ISO/IEC 27001:2022 is Edition 3. ISO lists the publication date as 2022-10. Stage 60.60 (International Standard published) is stamped 2022-10-25, the same date as the IEC webstore publication date (Edition 3.0). The ISO life cycle lists the 2013 edition as withdrawn.
Read that edition with ISO/IEC 27001:2022/Amd 1:2024, Amendment 1: Climate action changes. ISO lists the amendment as Edition 3, publication date 2024-02, stage 60.60 on 2024-02-23. It applies to ISO/IEC 27001:2022. The same page notes a French corrected version dated 2024-08. The English publication pin stays 2024-02. The amendment adds a climate-change relevance determination to the clause 4.1 theme, and a note that interested parties can have climate-related requirements in the clause 4.2 theme. That clause placement was read on the French Online Browsing Platform text of the same amendment. This page does not reprint the amendment. The Atlas Reference string is ISO/IEC 27001:2022 + Amd 1:2024. Re-open the ISO and IEC pages when you cite this. If a newer edition appears, update the pin and treat the older claim as UNKNOWN.
An ISMS is a management system
An ISMS is the management system those requirements describe. The clause themes, at slogan depth, are context, leadership, planning, support, operation, performance evaluation, and improvement. Those are the Clause 4 to 10 families. This page does not walk the requirements inside each clause. A management-system requirement is not a shipping feature.
Annex A is a reference control set the organization considers through risk treatment and a Statement of Applicability. The statement records which reference controls are included or excluded, and why. A photocopy of Annex A, with no risk treatment and no Statement of Applicability, is folklore. An Annex A control count is UNKNOWN on this page. This page does not list controls.
A scoped certificate is a defined ISMS
Accredited certification, when an organization chooses to seek it, is evidence that a certification body assessed a defined ISMS scope against the 27001 requirements. The ISO catalog page says organizations can implement the standard without certifying, and that a certificate from an accredited conformity assessment body is one way to show that commitment. It also says to use the full reference (for example, certified to ISO/IEC 27001:2022) and to ask the certification body that issued the certificate before using a logo.
Buyers should ask which organizational units, locations, processes, and information types are in scope, what is carved out, which edition string is on the certificate, and when surveillance or recertification applies. The certificate covers a defined ISMS. It does not mean the whole company is safe forever. The length of a surveillance or recertification cycle is UNKNOWN on this page (it is not stated on the 27001 pages opened here). Read the certificate. Whether Harborline, Riverstone, or any named organization holds a certificate is UNKNOWN until that certificate is in hand. Do not paste a real certificate that contains customer data into Atlas.
The scope box on this page is the same reading habit as a SOC 2 system description (what is in, what is out, which document, which time bounds). The logos are not the same object. The SOC 2 explainer is /learn/explainers/soc-2/.
What this card is not
Not a do-it-yourself certification project plan. Not an Annex A encyclopedia. Not a replacement for the Reference card at /reference/frameworks/iso-iec-27001-2022/. Not legal advice on whether a named organization must certify. Not a rewrite of the SOC 2 explainer.
Not a CSF profile, and not a CIS Implementation Group. CIS Implementation Groups literacy is /learn/explainers/cis-implementation-groups/. The CIS Controls reference card stays at /reference/frameworks/cis-controls-8-1/. CSF outcomes live on /learn/topics/outcomes-then-controls/ and on the CSF 2.0 card at /reference/frameworks/nist-csf-2-0/. Govern-as-cadence (R3) stays the calendar habit at /learn/topics/govern-as-cadence/.
Rewrite the one-line claim
Replace the blob "they are ISO, SOC 2, CSF, and CIS compliant" with a reading sentence. They hold or claim ISO/IEC 27001:2022 assurance, with Amd 1:2024 (Climate action changes) in view, for ISMS scope X. That is different from a SOC 2 report for system Y, from CSF 2.0 outcomes, and from a CIS Implementation Group starting discipline.
When a logo appears, privately ask the scope, the edition string, and the carve-outs before you treat it as product assurance. Do not paste a real certificate that contains customer data into Atlas.
An ISO certificate is not product immunity, SOC 2, CSF, or CIS IG1
Teaching table only. It does not assign a certificate, a SOC 2 opinion, a CSF profile, or a CIS alignment.
| Phrase people say | Literacy correction |
|---|---|
| They have ISO 27001, so the product is immune / safe | A scoped ISMS certificate is management-system assurance for a defined scope. It is not a product immunity badge. |
| ISO certificate = SOC 2 done | SOC 2 is a CPA attestation report on controls relevant to Trust Services Criteria for a described system. Different assurance family. Atlas card: /learn/explainers/soc-2/. |
| ISO certificate = CSF profile done | CSF 2.0 is outcomes and function language. An ISMS certificate is not automatic proof that a CSF profile is complete. Atlas card: /reference/frameworks/nist-csf-2-0/. Lesson: /learn/topics/outcomes-then-controls/. |
| ISO certificate = CIS IG1 done | CIS Implementation Groups are a hygiene prioritization discipline. They are not an ISO certificate. Atlas card: /reference/frameworks/cis-controls-8-1/. IG literacy: /learn/explainers/cis-implementation-groups/. |
| Annex A checklist without SoA thinking | Selecting controls without risk treatment and Statement of Applicability thinking is folklore. This page does not dump Annex A. |
| Atlas lesson = ISO certified | Atlas does not issue certificates. Completing a lesson is not certified. |
Claims to retire
An ISO 27001 certificate means the product cannot be breached.
A scoped ISMS certificate is management-system assurance for a defined scope. It is not a product immunity badge.
ISO, SOC 2, CSF, and CIS IG1 are interchangeable compliance badges.
They are different objects. SOC 2 is a CPA attestation report. CSF 2.0 is outcomes language. CIS Implementation Groups are a hygiene starting discipline. An ISMS certificate does not finish the others.
Annex A is a mandatory photocopy checklist, and a Statement of Applicability is optional.
Annex A is a reference control set considered through risk treatment and a Statement of Applicability. This page does not reprint Annex A.
This explainer replaces the Reference framework card.
The card at /reference/frameworks/iso-iec-27001-2022/ stays the framework summary. This page is certificate and ISMS literacy beside that card.
Atlas, or a vendor homepage shield, issues ISO certificates.
A certification body issues a certificate, when an organization seeks one. Atlas does not. Finishing this lesson is not certified.
What to read on the certificate
Static scope box only. It does not decide that a real organization is certified, and it does not name a surveillance interval.
| Ask | What a buyer reads | What it does not prove |
|---|---|---|
| Scope boundary | Which organizational units, locations, processes, and information types are inside the ISMS | Not proof that the whole company is safe forever. |
| Carve-outs | What the certificate leaves outside the scope | Not a silent claim that everything is covered. |
| Edition string | ISO/IEC 27001:2022 on the certificate, and whether Amd 1:2024 is in view | Not a bare ISO 27001 logo with no edition. |
| Surveillance and recertification | The dates the certification body states. The cycle length is UNKNOWN on this page | Not a one-time badge that never needs another look. |
CHECK THE CATEGORY
Which sentence matches this page?
Glossary and nearby pages
- ISO/IEC 27001 Reference card (framework summary, not replaced by this page)
- SOC 2 explainer (attestation report, different assurance family)
- Outcomes first, then controls (F8a, CSF outcomes)
- Govern is a calendar (R3)
- NIST CSF 2.0 framework card
- CIS Controls framework card (framework summary, not this page)
- CIS Implementation Groups explainer (hygiene prioritization, not an ISO certificate)
- GRC practice path
- Technology/SaaS industry path (a logo is not tenant safety)
- Privacy is not a CIA checkbox
Use the agency page in the sources for the authoritative text. This page has no figure.