The question of what separates ISO/IECÂ 27001 from ISO/IECÂ 27002 almost always arises at the same point: a tender, a customer or your own management asks for a certificate, and a look at the standards family turns up two documents side by side that appear, at first glance, to cover the same ground. Both talk about 93 controls, both date from 2022, both carry similar-sounding titles.
The confusion is costly in both directions. Buy only ISO/IECÂ 27002 and you have a detailed catalogue of controls but no basis for certification. Buy only ISO/IECÂ 27001 and you have the binding requirements, but Annex A offers no more than a short sentence per control and leaves you to interpret its intended scope yourself.
The short answer: ISO/IECÂ 27001 is the requirements standard for the management system and the only one of the two you can be certified against. ISO/IECÂ 27002 is the guidance document that explains the Annex A controls in full. The two standards are not competitors; they divide the work between them.
Side by side
| Criterion | ISO/IEC 27001 | ISO/IEC 27002 |
|---|---|---|
| Purpose | Sets out the requirements for establishing, operating, monitoring and improving an information security management system. It describes what an organisation has to be able to demonstrate. | Describes the information security controls in detail, with purpose, effect and implementation guidance. It describes how an individual control is meant. |
| Legal character and binding force | A requirements standard. Clauses 4 to 10 are binding once conformity is claimed. The standard is not legally mandatory; it becomes binding through contracts, tenders or a decision by top management. | A guidance document with recommendations. Its wording is deliberately not cast as requirements. Conformity with ISO/IEC 27002 therefore cannot be claimed. |
| Certifiability | Certifiable. Certification is carried out by an accredited certification body; in Germany, accreditation is granted by DAkkS. | Not certifiable, because the standard contains no requirements for a management system. Personal certificates relating to ISO/IEC 27002 do exist, but they concern an individual's qualification, not the organisation. |
| What is covered, and how it is laid out | Covers the entire management system: context of the organisation, leadership, planning, support, operation, performance evaluation and improvement. Clauses 4 to 10 follow the harmonised structure for ISO management system standards, plus Annex A with 93 reference controls in short form. | Covers the level of the controls only; scope, internal audit and management review do not appear in the standard at all. Four themes hold the 93 controls: 37 organisational, 8 people, 14 physical and 34 technological, supplemented by a system of attributes allowing alternative ways of sorting them. |
| Level of detail on the controls | Annex A gives only the title and one short sentence per control. The annex serves as a cross-check on whether a necessary control has been overlooked. | Describes the same controls across several paragraphs, with purpose and implementation guidance. This is the version people actually work with day to day. |
| How they work together | Sets the framework and points, via Annex A, to the catalogue of controls. Without the explanations it often remains open how far a control is meant to reach. | Is the commentary on Annex A of ISO/IEC 27001. It does not replace the requirements standard but supplements it with the substantive interpretation. |
| Role in the audit | The basis for the audit. Auditors examine conformity with the requirements of clauses 4 to 10 and with the controls set out in the Statement of Applicability. | Not a basis for the audit; it is consulted to interpret a control, but is not itself the object of examination. |
| What has to be evidenced | Requires documented information, including the policy, the scope, risk assessment and risk treatment, the Statement of Applicability, internal audits and the management review. | Requires no evidence. Evidence only arises where a control is implemented and substantiated within an ISO/IEC 27001 management system. |
| Effort | The effort sits in building and running the management system: roles, processes, documentation and the recurring audit cycle. | No separate effort for a management system. Time goes into reading, interpreting and translating the controls to your own organisation. |
| Who needs it | Organisations that need a certificate, or that want to demonstrate a defensible ISMS to customers, insurers and supervisory authorities. | Everyone who implements controls in concrete terms: security officers, IT operations and the business functions. Usable as a structured catalogue even without any intention to certify. |
| Edition and availability | Current edition ISO/IEC 27001:2022, supplemented by Amendment 1:2024 on the consideration of climate change. Available for a fee from the standards bodies. | Current edition ISO/IEC 27002:2022. Likewise available for a fee from the standards bodies, and usually purchased together with ISO/IEC 27001. |
Our verdict
For a certification you need ISO/IECÂ 27001. There is no route to a certificate via ISO/IECÂ 27002, because that standard places no requirements on a management system. Without a scope, an internal audit and a management review there is simply nothing for a certification body to examine.
For day-to-day work you will as a rule need both. Annex A of ISO/IECÂ 27001 is deliberately terse. A control such as configuration management cannot sensibly be turned into an internal rule on the strength of a single sentence. That is precisely what ISO/IECÂ 27002 exists for: it supplies purpose and implementation guidance, and so makes it defensible why your rule looks the way it does.
More decisive than the question of which standard to buy is the order of work in the project. What has proven itself: define the scope, assess the risks, derive controls from risk treatment, then use Annex A as a cross-check, look up in ISO/IECÂ 27002 how the control in question is meant, and record the result in the Statement of Applicability. Anyone who instead works through the 93 controls from top to bottom produces documentation but cannot explain in the audit why the ISMS has taken this particular shape.
There is one legitimate case in which ISO/IEC 27002 on its own is enough: you are looking for a structured, internationally agreed catalogue of controls, but you do not want to build a management system and are not pursuing certification. That happens more often than the certification debate suggests — as a reference for an internal security policy, for instance, or as a grid for assessing a service provider.
The reverse also holds: when a customer asks for certification to ISOÂ 27002, what is almost always meant is a certificate to ISO/IECÂ 27001. It is worth settling that early in the conversation rather than hunting for a piece of evidence that does not exist.