ISO/IEC 27001 — Information Security Management

ISO 27001, evidence-driven.

The de-facto international standard for information security. 93 controls in Annex A. Continuous improvement. The Agency keeps your evidence trail live and your control-mapping current — not just at audit time.

What is ISO 27001?

ISO/IEC 27001 is the international standard for an information security management system — an ISMS. It does not prescribe a fixed set of security controls so much as require a governed system for deciding which controls you need, applying them, checking they work, and improving them. Certification is issued by an accredited body against that system, not against any single technology.

The current version, ISO/IEC 27001:2022, carries 93 controls in Annex A, reorganised into four themes — organisational, people, physical and technological. That is down from 114 in the 2013 revision, though the reduction came mostly from merging overlapping controls rather than dropping requirements, and eleven controls are genuinely new.

Two artefacts do most of the work in practice. The Statement of Applicability records which Annex A controls apply, which do not, and why — and it has to stay in lockstep with reality, not with the version you submitted at certification. And the certificate runs on a three-year cycle with annual surveillance audits, so an ISMS that only comes alive before an audit will be found out in year two.

For third-party risk, the relevant clauses are the supplier controls in Annex A theme 5 — supplier relationships, security within supplier agreements, and monitoring and review of supplier services. They are the reason a vendor's ISO 27001 certificate is evidence about their suppliers as well as about them.

The numbers your team already knows.

ISO 27001 isn't a one-time certification — it's a system you maintain, with annual surveillance audits and a Statement of Applicability that has to stay in lockstep with the controls actually in place.

93 controls
Annex A control set in ISO 27001:2022
Down from 114 in 2013
Annual
Surveillance audits between three-year recertifications
Living evidence
SoA
The Statement of Applicability — a living document, not a one-shot
Continuous attestation

ARIA, TARA, VANCE — your living SoA.

Three of The Agency's leads keep ISO 27001 evidence current, controls mapped, and the audit pack composed from live data instead of last quarter's.

ARIA avatar
ARIA
Evidence & Document Intelligence

All 93 controls, evidenced and mapped. ARIA structures every piece of evidence against the Annex A controls and the 157 Universal Controls — your Statement of Applicability stays in lockstep with what's actually in place.

What you get
  • Annex A 2022 control mapping kept current
  • Documents structured against the 157 Universal Controls
  • Trust-centre and contract evidence ingested automatically
TARA avatar
TARA
Compliance & Remediation

Risk treatment plans tracked between audits. TARA continuously assesses control posture across your vendor portfolio and tracks treatment plans with deadlines — so surveillance audits stop being a quarterly scramble.

What you get
  • Continuous control gap analysis across the portfolio
  • Risk treatment plans with deadlines and SLA tracking
  • Surveillance-ready evidence at any moment
VANCE avatar
VANCE
Audit Composition

Audit packs composed, not assembled. VANCE generates ISO 27001 evidence bundles from current data — Statement of Applicability, control evidence, treatment plans — formatted for your certification body.

What you get
  • Statement of Applicability composed from live evidence
  • Audit packs generated, not hand-assembled
  • Tamper-evident audit trail per output

Four shifts you'll feel at the next surveillance audit.

ISO 27001 stops being a sprint to the audit window and becomes a continuous evidence layer the certification body can review at any moment.

Statement of Applicability stays live

Mapped to evidence. When a control changes or a vendor changes, the SoA updates the same week — not at the next surveillance.

Surveillance audits stop being a scramble

Continuous evidence means the auditor sees current state, not assembled state. Less archaeology, less prep.

All 93 Annex A controls covered concurrently

Not in waves. Each control has live evidence, mapped to the right artefact, ready for review.

Treatment plans tracked, not lost

TARA tracks risk treatment plans against deadlines between audits. Nothing falls through the gap year.

We replaced two analysts' worth of questionnaire chasing with The Agency in eight weeks. The risk team is finally doing risk work.

JM
CISO
FTSE 250 Insurance

What teams ask about ISO 27001.

Certification mechanics, what changed in the 2022 revision, and how it relates to the other frameworks you are probably being asked about.

How long does ISO 27001 certification take, and how long does it last?
The certificate runs a three-year cycle. Certification itself is a two-stage audit — a documentation review, then an implementation audit — after which you are audited annually by surveillance audit and recertified in full at year three. How long you need before stage one depends almost entirely on whether the ISMS already exists in practice; the usual constraint is having enough operating history for the internal audit and management review to have actually happened, because an auditor is checking that the system ran, not that it was written down.
What changed between ISO 27001:2013 and ISO 27001:2022?
Annex A was restructured from 14 domains into four themes and the control count fell from 114 to 93 — mostly by merging overlapping controls rather than removing obligations. Eleven controls are new, and they are the ones that catch people out: threat intelligence, information security for cloud services, ICT readiness for business continuity, physical security monitoring, configuration management, information deletion, data masking, data leakage prevention, monitoring activities, web filtering and secure coding. Existing certificates transitioned to the 2022 version by 31 October 2025.
Is ISO 27001 the same as SOC 2?
No, and they are not substitutes. ISO 27001 certifies a management system against an international standard, issued by an accredited body, and the output is a certificate. SOC 2 is an attestation report written by a CPA firm under AICPA standards, describing controls against the Trust Services Criteria and, for Type II, testing them over a period. ISO is more common outside the US, SOC 2 within it. Many vendors hold both because their customers are split. As evidence they answer different questions: ISO tells you a system exists and is governed; a SOC 2 Type II tells you specific controls were tested and what the auditor found.
Does a vendor's ISO 27001 certificate cover my data?
Only if the scope statement says so, and this is the single most common mistake in reading one. The certificate applies to a defined scope — named services, locations, and sometimes only a subsidiary or one product line. A vendor can hold a genuine ISO 27001 certificate whose scope excludes the exact service you are buying. Always read the scope statement and the Statement of Applicability alongside the certificate, and check the certificate number against the accreditation body's register rather than accepting a PDF.
What does ISO 27001 require for supplier and third-party risk?
The supplier controls in Annex A theme 5 require you to agree security requirements with suppliers, address them in the agreements themselves, manage risk in the ICT supply chain, and monitor, review and audit supplier service delivery on an ongoing basis. That last one is where certification and reality most often part company: the control asks for continuous review of supplier services, and an annual questionnaire is a weak answer to it. It is also why an auditor will ask how you knew about a supplier's posture between assessments.

See it on your vendors.

Book a 30-minute call and we'll have NOVA, ARIA and REX produce a complete posture report on one of your live vendors inside 24 hours.