AQC Group regional partnerIraq

ISO/IEC 27001:2022Information security management systems

ISO/IEC 27001 sets out how an organization decides what information it must protect, assesses the risks to it and puts controls in place that match those risks. It covers people, premises and suppliers as well as technology. It does not give you a list of products to buy. You choose the controls, justify the choice and show that they work.

A corridor between glass-fronted server racks in a data centre

01At a glance

Standard
ISO/IEC 27001:2022
Subject
Information security management systems
Certificate
Issued by AQC Group. Valid for three years, with a surveillance audit each year.
Often combined with
ISO/IEC 20000-1, ISO 9001
Facts checked
9 October 2026, against iso.org

Who it is for

  • Software, hosting and cloud service providers
  • IT outsourcing and managed service companies
  • Banks, payment and financial technology firms
  • Telecom and data centre operators
  • Hospitals, laboratories and others that hold patient records
  • Any supplier asked to prove how it protects client data

02What you gain

What certification to ISO/IEC 27001 gives you

Security questionnaires answered sooner

Clients and their procurement teams send long security questionnaires. A certificate with a clear scope, and the statement of applicability behind it, answers many of the questions before they are asked.

Tenders that name the standard

Tenders for IT, telecom and financial services often list ISO/IEC 27001 certification as a condition. Holding the certificate keeps you eligible to bid.

Risks decided on purpose

You end up with a written list of what could go wrong, who owns each risk and what was decided about it. Spending on security follows that list.

Fewer incidents, handled better

Access reviews, tested backups, patching and trained staff remove common causes of incidents. When one does happen, there is a practised way to contain it, record it and learn from it.

Suppliers brought into view

The standard makes you look at the suppliers who hold or can reach your information, and put security terms into their contracts.

03What it asks of you

What ISO/IEC 27001 asks you to have in place

In plain terms and in our words, not the standard's. The standard itself is the authority, and you will need a copy.

  1. Scope and context

    Decide what the system covers: which services, locations, teams and information. Identify who has a stake in your security, such as clients, regulators and partners, and what they expect. The scope appears on the certificate, so it has to describe something a client would recognize. Since the 2024 amendment you also consider whether climate change is a relevant issue for the system.

  2. Leadership and roles

    Top management approves an information security policy, sets objectives and assigns responsibility for the system. An auditor interviews management as well as the IT team, so this cannot be handed over entirely.

  3. Risk assessment

    Define a method for assessing risk and use it consistently. For each risk you record what could harm the confidentiality, integrity or availability of your information, how likely that is, how serious it would be and who owns the risk. The method has to give comparable results when it is repeated. Reassess at planned intervals and when something significant changes.

  4. Risk treatment and the statement of applicability

    For each risk above the level you accept, decide what to do and which controls to apply. Then compare your choice with the reference list of controls in Annex A, so that nothing necessary has been overlooked. The result is the statement of applicability: a document that lists the controls you have chosen and, for every control in Annex A, says whether you apply it and why or why not. Risk owners approve the treatment plan and accept the risk that remains.

  5. The controls themselves

    Annex A groups its 93 controls into four themes. Organizational controls cover policies, asset inventories, access rules, supplier agreements, incident handling and continuity. People controls cover screening, awareness training, confidentiality terms and remote working. Physical controls cover secure areas, equipment and storage media. Technological controls cover authentication, malware protection, backup, logging, network security, secure development and encryption. You implement the ones your risks call for.

  6. Competence, awareness and documents

    People who work within the scope need to know the policy, what is expected of them and what to do when they notice an incident. Keep the documents the system depends on under control: who approved each one, which version is current and who may change it.

  7. Operation and evidence

    Carry out the risk treatment plan and keep evidence that the controls run: access reviews, backup restore tests, patch records, supplier reviews, incident records. Control changes to systems and processes that affect security. An auditor looks for the record, not only for the policy.

  8. Monitoring, internal audit and improvement

    Decide what you will measure to know whether security is working, and measure it. Run internal audits across the whole scope, hold management reviews, and correct nonconformities by finding their cause.

04The audit

How certification to ISO/IEC 27001 works

  1. Application and quotation

    You tell us your scope, sites and headcount. We quote the audit days the standard's rules require.

  2. Stage 1 audit

    A review of your documented system and your readiness. You get a list of anything to settle before stage 2.

  3. Stage 2 audit

    The auditor follows your processes on site and samples records, to see that the system is in use and works.

  4. Decision

    Nonconformities are answered, the file is reviewed independently of the audit team, and AQC Group issues the certificate.

  5. Surveillance and recertification

    A shorter audit in each of the next two years, then a full recertification audit in the third.

What the auditor looks at

  • The scope, and whether its boundaries with the rest of the organization and with suppliers are clear
  • The risk assessment method, the risk register and whether risk owners have accepted the remaining risk
  • The statement of applicability: the reason given for each control, and evidence on a sample of controls that they operate as described
  • Incident records: how events were reported, handled and learned from
  • Arrangements with suppliers and cloud services that hold or can reach your information
  • Awareness among ordinary staff, tested by interview, together with internal audit and management review

What affects audit time

  • The number of people working within the scope
  • The number of sites, and whether they do the same work or different work
  • The complexity of the technology: in-house software development, several platforms, your own data centre or a cloud provider's
  • The sensitivity of the information and how much of the work is outsourced

How certification works, step by step

05Often combined with

06Questions

Questions about ISO/IEC 27001

Is ISO/IEC 27001:2022 still the current edition?

Yes. It is the third edition, published in October 2022. ISO published Amendment 1 in February 2024, which asks organizations to consider whether climate change is a relevant issue for their system. The 2022 text and the amendment are read together.

Is a certificate to the 2013 edition still valid?

No. The transition period for moving to the 2022 edition ended on 31 October 2025. That date was set by the International Accreditation Forum, whose work Global Accreditation Cooperation has since taken over. Certificates to ISO/IEC 27001:2013 expired or were withdrawn at that point. If a supplier shows you a 2013 certificate, ask for the current one.

Do we have to implement all 93 controls in Annex A?

No. Annex A is a reference list to check your own choices against. You apply the controls your risk assessment calls for and may leave others out, but every exclusion has to be justified in the statement of applicability. An auditor will question an exclusion that does not fit what your organization does, for example leaving out secure development when you write software.

Can the scope cover only part of the company?

Yes. You can certify one service, one department or one site. The scope must be honest about what is in and what is out, because it is printed on the certificate and clients read it. Anything outside the scope that the scoped service depends on, such as a shared IT team or an office network, has to be controlled in the way a supplier would be.

Does certification mean we comply with data protection law?

No. The standard asks you to identify the legal, regulatory and contractual requirements that apply to your information and to meet them, and a working system makes that easier to show. It is not a certificate of legal compliance. Check the legal requirements that apply to you.

How does ISO/IEC 27002 relate to it?

ISO/IEC 27002 is the companion guidance standard. It explains each of the Annex A controls and how it can be implemented. You are certified to ISO/IEC 27001. ISO/IEC 27002 helps you get there, and there is no certificate for it.

More questions about certification

Ask about ISO/IEC 27001 for your organization.

Tell us your scope, your sites and how many people work in them. We will tell you what the audit involves.