FRAMEWORKS & CERTIFICATIONS
What Is ISO 27001?
DEFINITION
ISO 27001 is the international standard for information security management systems, published jointly by ISO and IEC as ISO/IEC 27001. It defines requirements for establishing, operating, and continually improving a risk-based ISMS, and organizations can be certified against it by accredited certification bodies. The current edition is ISO/IEC 27001:2022; the transition period from the 2013 edition closed on October 31, 2025.
ISO 27001 is a management system standard, not a control checklist. Certification requires a documented information security management system (ISMS) with risk assessment, leadership involvement, internal audit, and continual improvement, plus a statement of applicability drawn from the Annex A control set. The 2022 edition reorganized Annex A into 93 controls across four themes: organizational, people, physical, and technological. All certificates now rest on the 2022 edition, since the transition window from ISO 27001:2013 closed on October 31, 2025.
ISO 27001 is most often requested by international customers and large enterprise procurement teams, particularly in Europe and Asia-Pacific, where it carries more weight than SOC 2. Many North American mid-market companies end up pursuing both: SOC 2 for domestic buyers and ISO 27001 for global expansion.
The practical implication for a mid-market company is that certification is a multi-stage commitment. An accredited body performs a stage 1 and stage 2 audit, followed by annual surveillance audits on a three-year cycle, so the ISMS has to keep running between audits. Z Cyber's compliance services operate that ongoing program on the client's behalf.
Running a program that has to satisfy this?
A Z Cyber advisor can walk your current posture against the requirement and show you what a running program looks like on Glance.
Meet Your Security Team →