ISO/IECĀ 27001 is the governing international standard for information security management systems. The current edition dates from 2022, supplemented by the Amendment 1:2024. Certification is carried out exclusively against that edition: under IAF MD 26, the transition window for already-certified organisations closed on 31 October 2025; older ISO/IECĀ 27001:2013 certificates have since expired or are being withdrawn. Anyone reading a source today that describes Annex A as "114 controls in 14 sections" is reading the 2013 edition. For CISOs and managing directors the standard matters above all because the certificate is the widely recognised piece of evidence that customers, insurers and auditors all accept.
How the standard is structured
Clauses 4 to 10 are the binding part. They follow the harmonised structure ISO uses for all management system standards.
| Clause | Subject | Core question |
|---|---|---|
| 4 | Context of the organisation | Who are the interested parties, and how is the scope delimited? |
| 5 | Leadership | Does top management stand behind it, is there a policy and are roles clear? |
| 6 | Planning | How are risks assessed and treated, and which objectives apply? |
| 7 | Support | Resources, competence, awareness, communication, documented information |
| 8 | Operation | Are the planned processes actually carried out and controlled? |
| 9 | Performance evaluation | Measurement, internal audit, management review |
| 10 | Improvement | Handling nonconformities and corrective actions |
The Amendment 1:2024, officially titled "Amendment 1: Climate action changes", added the consideration of climate change to clauses 4.1 and 4.2. Substantively this changes little, but it has to be traceable in the context analysis and the documentation.
Annex A and the 93 controls
Annex A contains 93 reference controls across four themes: 37 organisational, 8 people, 14 physical and 34 technological controls. Annex A is deliberately terse: each control consists of a title and one short sentence. The full description with purpose and implementation guidance sits in ISO/IECĀ 27002.
The order matters. Controls follow from risk treatment. Annex A then serves as a cross-check on whether a necessary control was overlooked. Anyone who instead works through the 93 controls from top to bottom cannot explain in the audit why the ISMS looks the way it does.
Clause 6.1.3 and the Statement of Applicability
The Statement of Applicability is the document the standard requires by name in clause 6.1.3 d) as an output of risk treatment. It lists the Annex A controls, justifies inclusion and exclusion, and records the state of implementation. Auditors almost always begin there and draw their sample from it.
The route to certification
The process is standardised. In stage 1 the certification body reviews the documentation, the scope and audit readiness; in stage 2 it reviews actual implementation and effectiveness; the first surveillance audit follows at the latest twelve months after the certification decision. As a rule the certificate is valid for three years, with surveillance audits in the two following years and recertification in the third. The certification body has to be accredited; in Germany, DAkkS accredits the certification bodies for ISO/IECĀ 27001. The requirements on those bodies sit generally in ISO/IECĀ 17021-1 and, specifically for ISMS certification, in ISO/IECĀ 27006-1:2024, which superseded ISO/IECĀ 27006:2015.
There is no list price, and figures found online are rarely transferable. Effort follows the size of the scope, the number of sites and the complexity; the basis for calculating audit time is set by the accreditation rules, not by the certification body alone. A reliable figure only emerges once the scope is delimited.
Distinction from ISO/IECĀ 27002 and IT-Grundschutz
ISO/IEC 27001 sets requirements, ISO/IEC 27002 gives recommendations; certification is possible only against ISO/IEC 27001. The BSI's IT-Grundschutz describes an alternative, more prescriptive route to the same objective and makes an ISO 27001 certificate on the basis of IT-Grundschutz possible. That second route does not run through DAkkS. The IT-Grundschutz certificate is issued by the BSI and audited by assessors the BSI certifies itself, which § 1(2) AkkStelleG makes room for: it leaves the competence of other authorities to authorise conformity assessment bodies untouched, and names information technology security among the fields where that applies. If a customer contract asks for DAkkS accreditation, the two routes are not interchangeable.
How the standard is modelled in Rizzqo
Rizzqo holds two layers as separate requirement catalogues: ISO/IECĀ 27001 for the management system and ISO/IECĀ 27002 for the controls. Neither is worked through as a list; both are distributed by classification onto the objects they apply to, and every object carries the list of frameworks touching it.
Coverage here is a calculation, not a self-assessment. An object counts as fully covered only once every attached requirement has been closed as fulfilled or as not applicable. The object's own workflow state does not enter that calculation, and neither does an approved risk assessment. What is not implemented stays visible and is consciously carried on the risk side rather than computed away.