✳ International · ISO/IEC 27001

ISO/IEC 27001: ISMS requirements and scoped certificates (not product immune, not SOC 2)

An educational overview of ISO/IEC 27001:2022 (Edition 3) as requirements for an information security management system, read with Amd 1:2024 (Climate action changes). A scoped certificate is a separate assurance lane. Not product immunity, not a SOC 2 report, and not an Atlas certificate.

International · ISO/IEC 27001Standard explainerLast reviewed

What category of standard this is

ISO/IEC 27001 is a requirements standard for an information security management system (ISMS). The IEC abstract says the document specifies requirements for establishing, implementing, maintaining, and continually improving an ISMS within the context of the organization. It also includes requirements for the assessment and treatment of information security risks tailored to the needs of the organization.

The same abstract says the requirements are generic, and intended for organizations of any type, size, or nature. Excluding any of the requirements in Clauses 4 to 10 is not acceptable when an organization claims conformity. Who it commonly frames: GRC and management-system owners, and buyers who are handed a logo. It is not a statute, and it is not a product feature list.

What security people most often confuse: they treat an ISO logo, a SOC 2 report, a CSF profile, and a CIS Implementation Group as one compliance badge. This page keeps those objects apart. The Reference card at /reference/frameworks/iso-iec-27001-2022/ remains the framework summary. This explainer does not replace it.

Edition pin

ISO/IEC 27001:2022 is Edition 3. ISO lists the publication date as 2022-10. Stage 60.60 (International Standard published) is stamped 2022-10-25, the same date as the IEC webstore publication date (Edition 3.0). The ISO life cycle lists the 2013 edition as withdrawn.

Read that edition with ISO/IEC 27001:2022/Amd 1:2024, Amendment 1: Climate action changes. ISO lists the amendment as Edition 3, publication date 2024-02, stage 60.60 on 2024-02-23. It applies to ISO/IEC 27001:2022. The same page notes a French corrected version dated 2024-08. The English publication pin stays 2024-02. The amendment adds a climate-change relevance determination to the clause 4.1 theme, and a note that interested parties can have climate-related requirements in the clause 4.2 theme. That clause placement was read on the French Online Browsing Platform text of the same amendment. This page does not reprint the amendment. The Atlas Reference string is ISO/IEC 27001:2022 + Amd 1:2024. Re-open the ISO and IEC pages when you cite this. If a newer edition appears, update the pin and treat the older claim as UNKNOWN.

An ISMS is a management system

An ISMS is the management system those requirements describe. The clause themes, at slogan depth, are context, leadership, planning, support, operation, performance evaluation, and improvement. Those are the Clause 4 to 10 families. This page does not walk the requirements inside each clause. A management-system requirement is not a shipping feature.

Annex A is a reference control set the organization considers through risk treatment and a Statement of Applicability. The statement records which reference controls are included or excluded, and why. A photocopy of Annex A, with no risk treatment and no Statement of Applicability, is folklore. An Annex A control count is UNKNOWN on this page. This page does not list controls.

A scoped certificate is a defined ISMS

Accredited certification, when an organization chooses to seek it, is evidence that a certification body assessed a defined ISMS scope against the 27001 requirements. The ISO catalog page says organizations can implement the standard without certifying, and that a certificate from an accredited conformity assessment body is one way to show that commitment. It also says to use the full reference (for example, certified to ISO/IEC 27001:2022) and to ask the certification body that issued the certificate before using a logo.

Buyers should ask which organizational units, locations, processes, and information types are in scope, what is carved out, which edition string is on the certificate, and when surveillance or recertification applies. The certificate covers a defined ISMS. It does not mean the whole company is safe forever. The length of a surveillance or recertification cycle is UNKNOWN on this page (it is not stated on the 27001 pages opened here). Read the certificate. Whether Harborline, Riverstone, or any named organization holds a certificate is UNKNOWN until that certificate is in hand. Do not paste a real certificate that contains customer data into Atlas.

The scope box on this page is the same reading habit as a SOC 2 system description (what is in, what is out, which document, which time bounds). The logos are not the same object. The SOC 2 explainer is /learn/explainers/soc-2/.

What this card is not

Not a do-it-yourself certification project plan. Not an Annex A encyclopedia. Not a replacement for the Reference card at /reference/frameworks/iso-iec-27001-2022/. Not legal advice on whether a named organization must certify. Not a rewrite of the SOC 2 explainer.

Not a CSF profile, and not a CIS Implementation Group. CIS Implementation Groups literacy is /learn/explainers/cis-implementation-groups/. The CIS Controls reference card stays at /reference/frameworks/cis-controls-8-1/. CSF outcomes live on /learn/topics/outcomes-then-controls/ and on the CSF 2.0 card at /reference/frameworks/nist-csf-2-0/. Govern-as-cadence (R3) stays the calendar habit at /learn/topics/govern-as-cadence/.

Rewrite the one-line claim

Replace the blob "they are ISO, SOC 2, CSF, and CIS compliant" with a reading sentence. They hold or claim ISO/IEC 27001:2022 assurance, with Amd 1:2024 (Climate action changes) in view, for ISMS scope X. That is different from a SOC 2 report for system Y, from CSF 2.0 outcomes, and from a CIS Implementation Group starting discipline.

When a logo appears, privately ask the scope, the edition string, and the carve-outs before you treat it as product assurance. Do not paste a real certificate that contains customer data into Atlas.

An ISO certificate is not product immunity, SOC 2, CSF, or CIS IG1

Teaching table only. It does not assign a certificate, a SOC 2 opinion, a CSF profile, or a CIS alignment.

Six phrases people fold into one ISO logo. Not a certificate, and not a seal.
Phrase people sayLiteracy correction
They have ISO 27001, so the product is immune / safeA scoped ISMS certificate is management-system assurance for a defined scope. It is not a product immunity badge.
ISO certificate = SOC 2 doneSOC 2 is a CPA attestation report on controls relevant to Trust Services Criteria for a described system. Different assurance family. Atlas card: /learn/explainers/soc-2/.
ISO certificate = CSF profile doneCSF 2.0 is outcomes and function language. An ISMS certificate is not automatic proof that a CSF profile is complete. Atlas card: /reference/frameworks/nist-csf-2-0/. Lesson: /learn/topics/outcomes-then-controls/.
ISO certificate = CIS IG1 doneCIS Implementation Groups are a hygiene prioritization discipline. They are not an ISO certificate. Atlas card: /reference/frameworks/cis-controls-8-1/. IG literacy: /learn/explainers/cis-implementation-groups/.
Annex A checklist without SoA thinkingSelecting controls without risk treatment and Statement of Applicability thinking is folklore. This page does not dump Annex A.
Atlas lesson = ISO certifiedAtlas does not issue certificates. Completing a lesson is not certified.

Claims to retire

An ISO 27001 certificate means the product cannot be breached.

A scoped ISMS certificate is management-system assurance for a defined scope. It is not a product immunity badge.

ISO, SOC 2, CSF, and CIS IG1 are interchangeable compliance badges.

They are different objects. SOC 2 is a CPA attestation report. CSF 2.0 is outcomes language. CIS Implementation Groups are a hygiene starting discipline. An ISMS certificate does not finish the others.

Annex A is a mandatory photocopy checklist, and a Statement of Applicability is optional.

Annex A is a reference control set considered through risk treatment and a Statement of Applicability. This page does not reprint Annex A.

This explainer replaces the Reference framework card.

The card at /reference/frameworks/iso-iec-27001-2022/ stays the framework summary. This page is certificate and ISMS literacy beside that card.

Atlas, or a vendor homepage shield, issues ISO certificates.

A certification body issues a certificate, when an organization seeks one. Atlas does not. Finishing this lesson is not certified.

What to read on the certificate

Static scope box only. It does not decide that a real organization is certified, and it does not name a surveillance interval.

Four questions for a scoped ISMS certificate. Not product assurance.
AskWhat a buyer readsWhat it does not prove
Scope boundaryWhich organizational units, locations, processes, and information types are inside the ISMSNot proof that the whole company is safe forever.
Carve-outsWhat the certificate leaves outside the scopeNot a silent claim that everything is covered.
Edition stringISO/IEC 27001:2022 on the certificate, and whether Amd 1:2024 is in viewNot a bare ISO 27001 logo with no edition.
Surveillance and recertificationThe dates the certification body states. The cycle length is UNKNOWN on this pageNot a one-time badge that never needs another look.

CHECK THE CATEGORY

Which sentence matches this page?

Glossary and nearby pages

Use the agency page in the sources for the authoritative text. This page has no figure.

Find your next idea.

Tip: press / to open search. Escape closes this window.