Compyl

The Complete Guide to ISO 27001 Certification

June 03, 2026
Framework · ISO 27001

The Complete Guide to ISO 27001 Certification

By Compyl ResearchUpdated June 20264 min read

ISO/IEC 27001 certification proves your organization runs a working Information Security Management System (ISMS) — a risk-based program for protecting information — verified by an accredited external auditor.

Key takeaways
  • ISO 27001 certifies a management system, not just a checklist — risk assessment drives which controls you apply.
  • The 2022 revision has 93 Annex A controls in four themes: Organizational (37), People (8), Physical (14), and Technological (34).
  • The Statement of Applicability (SoA) documents which controls you include or exclude, and why.
  • Certification is a Stage 1 + Stage 2 audit, followed by annual surveillance and recertification every three years.

The ISMS: the heart of ISO 27001

Unlike a pure control checklist, ISO 27001 requires you to operate an ISMS: define scope and context, set security objectives, run a risk assessment and treatment process, assign roles, train people, and continually improve. The controls support the ISMS — they don’t replace it.

The 93 Annex A controls (2022)

Theme Controls Focus
Organizational 37 Policies, roles, supplier and incident management
People 8 Screening, awareness, responsibilities
Physical 14 Facilities, equipment, secure areas
Technological 34 Access, cryptography, logging, secure development

You don’t necessarily implement all 93 — your risk assessment determines which are applicable, and the SoA records the justification.

The path to certification, step by step

  1. Define scope and context. What information, systems, and locations the ISMS covers.
  2. Run a risk assessment. Identify, analyze, and prioritize information-security risks.
  3. Select controls & write the SoA. Choose applicable Annex A controls and document inclusions/exclusions.
  4. Implement controls and ISMS processes. Policies, training, monitoring, internal audit, management review.
  5. Run an internal audit and management review. Required before certification.
  6. Stage 1 audit. The auditor reviews your ISMS documentation and readiness.
  7. Stage 2 audit. The auditor tests that controls operate effectively, then issues certification.
  8. Surveillance & recertification. Annual surveillance audits; full recertification every three years.

Timing note that matters

The transition from ISO 27001:2013 to the 2022 revision closed on 31 October 2025 — 2013 certificates are no longer valid, so new certifications proceed against the 2022 version. Plan your control set and SoA around the 93 Annex A controls accordingly.

How automation helps

ISO 27001 generates continuous evidence demands — access reviews, logs, training records, supplier checks. Continuous controls monitoring and automated evidence collection keep the ISMS demonstrably effective between surveillance audits, instead of scrambling each year.

Frequently asked questions

How do you get ISO 27001 certified?
Build and operate an ISMS, run a risk assessment, select controls and write a Statement of Applicability, implement and internally audit, then pass a Stage 1 and Stage 2 audit by an accredited certification body.
How many controls are in ISO 27001:2022?
93 Annex A controls across four themes — Organizational (37), People (8), Physical (14), and Technological (34).
What is the Statement of Applicability?
A document that lists which Annex A controls you've included or excluded and the justification for each, based on your risk assessment.
How long is ISO 27001 certification valid?
Three years, with annual surveillance audits in between to confirm the ISMS remains effective.

See ISO 27001 run on your own data

Compyl unifies governance, risk, compliance and audit on one source of truth — built by CISOs, with a human approving every consequential decision.

Request a demo →

About this guide. By Compyl Research. Compyl is an AI-powered, agentic GRC platform built by CISOs that operationalizes ISO 27001 controls and evidence.

Monitoring thousands of environments daily
By clicking “Accept”, you agree to the use of cookies on your device in accordance with our Privacy and Cookie policies