ISO 27001 vs ISO 27002: What Is the Difference?

ISO/IEC 27001 sets the requirements for the management system and is certifiable; ISO/IEC 27002 explains the controls in Annex A. The comparison covers purpose, binding force, structure, effort and evidence for both standards — and when you need which.

ISO/IEC 27001 vs. ISO/IEC 27002ISO 27001Last reviewed:

The question of what separates ISO/IEC 27001 from ISO/IEC 27002 almost always arises at the same point: a tender, a customer or your own management asks for a certificate, and a look at the standards family turns up two documents side by side that appear, at first glance, to cover the same ground. Both talk about 93 controls, both date from 2022, both carry similar-sounding titles.

The confusion is costly in both directions. Buy only ISO/IEC 27002 and you have a detailed catalogue of controls but no basis for certification. Buy only ISO/IEC 27001 and you have the binding requirements, but Annex A offers no more than a short sentence per control and leaves you to interpret its intended scope yourself.

The short answer: ISO/IEC 27001 is the requirements standard for the management system and the only one of the two you can be certified against. ISO/IEC 27002 is the guidance document that explains the Annex A controls in full. The two standards are not competitors; they divide the work between them.

Side by side

CriterionISO/IEC 27001ISO/IEC 27002
PurposeSets out the requirements for establishing, operating, monitoring and improving an information security management system. It describes what an organisation has to be able to demonstrate.Describes the information security controls in detail, with purpose, effect and implementation guidance. It describes how an individual control is meant.
Legal character and binding forceA requirements standard. Clauses 4 to 10 are binding once conformity is claimed. The standard is not legally mandatory; it becomes binding through contracts, tenders or a decision by top management.A guidance document with recommendations. Its wording is deliberately not cast as requirements. Conformity with ISO/IEC 27002 therefore cannot be claimed.
CertifiabilityCertifiable. Certification is carried out by an accredited certification body; in Germany, accreditation is granted by DAkkS.Not certifiable, because the standard contains no requirements for a management system. Personal certificates relating to ISO/IEC 27002 do exist, but they concern an individual's qualification, not the organisation.
What is covered, and how it is laid outCovers the entire management system: context of the organisation, leadership, planning, support, operation, performance evaluation and improvement. Clauses 4 to 10 follow the harmonised structure for ISO management system standards, plus Annex A with 93 reference controls in short form.Covers the level of the controls only; scope, internal audit and management review do not appear in the standard at all. Four themes hold the 93 controls: 37 organisational, 8 people, 14 physical and 34 technological, supplemented by a system of attributes allowing alternative ways of sorting them.
Level of detail on the controlsAnnex A gives only the title and one short sentence per control. The annex serves as a cross-check on whether a necessary control has been overlooked.Describes the same controls across several paragraphs, with purpose and implementation guidance. This is the version people actually work with day to day.
How they work togetherSets the framework and points, via Annex A, to the catalogue of controls. Without the explanations it often remains open how far a control is meant to reach.Is the commentary on Annex A of ISO/IEC 27001. It does not replace the requirements standard but supplements it with the substantive interpretation.
Role in the auditThe basis for the audit. Auditors examine conformity with the requirements of clauses 4 to 10 and with the controls set out in the Statement of Applicability.Not a basis for the audit; it is consulted to interpret a control, but is not itself the object of examination.
What has to be evidencedRequires documented information, including the policy, the scope, risk assessment and risk treatment, the Statement of Applicability, internal audits and the management review.Requires no evidence. Evidence only arises where a control is implemented and substantiated within an ISO/IEC 27001 management system.
EffortThe effort sits in building and running the management system: roles, processes, documentation and the recurring audit cycle.No separate effort for a management system. Time goes into reading, interpreting and translating the controls to your own organisation.
Who needs itOrganisations that need a certificate, or that want to demonstrate a defensible ISMS to customers, insurers and supervisory authorities.Everyone who implements controls in concrete terms: security officers, IT operations and the business functions. Usable as a structured catalogue even without any intention to certify.
Edition and availabilityCurrent edition ISO/IEC 27001:2022, supplemented by Amendment 1:2024 on the consideration of climate change. Available for a fee from the standards bodies.Current edition ISO/IEC 27002:2022. Likewise available for a fee from the standards bodies, and usually purchased together with ISO/IEC 27001.

Our verdict

For a certification you need ISO/IEC 27001. There is no route to a certificate via ISO/IEC 27002, because that standard places no requirements on a management system. Without a scope, an internal audit and a management review there is simply nothing for a certification body to examine.

For day-to-day work you will as a rule need both. Annex A of ISO/IEC 27001 is deliberately terse. A control such as configuration management cannot sensibly be turned into an internal rule on the strength of a single sentence. That is precisely what ISO/IEC 27002 exists for: it supplies purpose and implementation guidance, and so makes it defensible why your rule looks the way it does.

More decisive than the question of which standard to buy is the order of work in the project. What has proven itself: define the scope, assess the risks, derive controls from risk treatment, then use Annex A as a cross-check, look up in ISO/IEC 27002 how the control in question is meant, and record the result in the Statement of Applicability. Anyone who instead works through the 93 controls from top to bottom produces documentation but cannot explain in the audit why the ISMS has taken this particular shape.

There is one legitimate case in which ISO/IEC 27002 on its own is enough: you are looking for a structured, internationally agreed catalogue of controls, but you do not want to build a management system and are not pursuing certification. That happens more often than the certification debate suggests — as a reference for an internal security policy, for instance, or as a grid for assessing a service provider.

The reverse also holds: when a customer asks for certification to ISO 27002, what is almost always meant is a certificate to ISO/IEC 27001. It is worth settling that early in the conversation rather than hunting for a piece of evidence that does not exist.

Browse all entriesBack to top

Frequently asked questions

See compliance run on your real assets

Rizzqo turns framework requirements into owned tasks on the assets you already have, and prices the risk in real money.

Made in GermanyEU-hostedMulti-framework