Suspect a breach? Report it immediately — response within 1 hour.Report an incident

ISO/IEC 27001:2022

The international reference standard for establishing an information security management system (ISMS).

Last updatedAugust 22, 2026

Who's affected

Any organization seeking to structure its security governance and formally demonstrate it to clients, partners, or procurement authorities, particularly in tenders or supplier relationships.

What the framework requires

Defining the ISMS scope, risk assessment and treatment, implementation of relevant Annex A controls, a formalized security policy, management review, internal audit, and continual improvement of the system.

Compliance steps

01

Gap analysis against the standard's requirements

02

Define the ISMS scope and conduct a risk assessment

03

Select and implement the applicable Annex A controls

04

Draft the documentation set (policies, procedures, registers)

05

Internal audit, management review, then certification audit

Common mistakes

  • Producing compliant documentation without actually applying the controls in practice
  • Under-sizing the risk assessment or reducing it to a formal exercise
  • Defining a certification scope too narrow to be commercially credible
  • Failing to keep the ISMS alive between audits (no management review, risks not updated)

Cross-mapping to other frameworks (UCM)

FrameworkCovered
nis2
loi-05-20-dgssi
soc-2

Downloadable resource

Get the checklist by email.

Frequently asked questions

How long does ISO 27001 certification take?

Typically 6 to 12 months, depending on the organization's starting maturity and the scope selected.

Is ISO 27001 mandatory?

No, it is a voluntary process. It can nonetheless become a contractual prerequisite imposed by certain clients or tenders.

How does it differ from a simple security audit?

A security audit assesses a point-in-time state; ISO 27001 certifies a full management system, with governance, continual improvement, and ongoing oversight.

Does ISO 27001 automatically cover other frameworks like NIS2?

It provides a solid, largely overlapping foundation, but does not remove the need for a specific analysis of each applicable regulatory framework's own requirements.