knowledge base

ISO 27001 Compliance in 2026

This guide covers what ISO 27001 actually requires, how certification works, what changed in the 2022 revision, and why it matters not just to the organizations being certified, but to the customers and consumers relying on them.

ISO 27001 Compliance in 2026: What Organizations and Their Customers Need to Know

If SOC 2 is the compliance report North American buyers tend to ask for, ISO 27001 is its global counterpart — the internationally recognized certification that procurement teams, regulators, and partners around the world look for as proof that an organization takes information security seriously. Unlike a SOC 2 attestation report, ISO 27001 results in an actual certification, issued by an accredited certification body, that an organization can display, renew, and lose.

With the mandatory transition to the 2022 edition of the standard now complete and certification bodies enforcing it strictly, 2026 is a year where “we’re ISO 27001 compliant” finally has to mean something very specific. This guide covers what ISO 27001 actually requires, how certification works, what changed in the 2022 revision, and why it matters not just to the organizations being certified, but to the customers and consumers relying on them.

What Is ISO 27001?

ISO/IEC 27001 is an international standard, jointly published by the International Organization for Standardization (ISO) and the International Electrotechnical Commission (IEC), that specifies the requirements for establishing, implementing, maintaining, and continually improving an Information Security Management System (ISMS).

Unlike SOC 2, which produces a narrative attestation report describing controls during a specific period, ISO 27001 certification confirms that an organization has built a functioning, risk-based management system for information security — one that’s audited, certified, and subject to ongoing surveillance, not just assessed once and forgotten.

ISO 27001 has gone through several major revisions:

  • ISO/IEC 27001:2005 — the original edition, building on the earlier BS 7799 standard.
  • ISO/IEC 27001:2013 — a significant restructuring that introduced the risk-based approach most security professionals associate with the standard today.
  • ISO/IEC 27001:2022 — published on October 25, 2022, this is the current edition and the one all active certifications must now reference.

A 2024 amendment, often called the “climate action amendment,” added language requiring organizations to consider whether climate change and environmental conditions are relevant to their ISMS context — a small but notable addition reflecting how broadly the standard’s risk lens has expanded.

The Core Idea: A Risk-Based Management System

ISO 27001 isn’t primarily a checklist of technical controls — it’s a management system standard. That means it requires an organization to:

  1. Understand its internal and external context and the needs of interested parties (customers, regulators, employees).
  2. Define the scope of its ISMS.
  3. Conduct a formal information security risk assessment.
  4. Select and implement controls to treat identified risks.
  5. Monitor, measure, and continually improve the system over time.

This structure follows the ISO Harmonized Structure (formerly the “High Level Structure”), shared across many ISO management system standards, which is why organizations that already hold certifications like ISO 9001 (quality) or ISO 22301 (business continuity) often find it more efficient to integrate ISO 27001 into an existing management system rather than building one from scratch.

The standard’s core requirements live in Clauses 4 through 10 — covering context, leadership, planning, support, operation, performance evaluation, and improvement. These clauses changed only modestly in the 2022 revision. The much bigger overhaul happened in Annex A.

Annex A: The 93 Controls

Annex A lists the reference controls organizations can draw on to treat identified risks. The 2022 revision reorganized and consolidated the previous 114 controls into 93 controls grouped under four themes, aligning with the parallel revision of ISO/IEC 27002:2022:

  • Organizational controls (37 controls) — policies, roles and responsibilities, supplier relationships, incident management, and compliance.
  • People controls (8 controls) — screening, terms of employment, security awareness training, and disciplinary processes.
  • Physical controls (14 controls) — secure areas, equipment protection, clear desk/clear screen practices, and physical entry controls.
  • Technological controls (34 controls) — access control, cryptography, secure configuration, network security, and application security.

Eleven of these controls have no direct equivalent in the 2013 edition and were added to address gaps the standard hadn’t previously covered explicitly, including:

  • Threat intelligence (A.5.7) — collecting and analyzing information about emerging threats and feeding it into risk assessments.
  • Information security for use of cloud services (A.5.23) — formal processes for acquiring, managing, and exiting cloud service relationships securely.
  • ICT readiness for business continuity (A.5.30) — ensuring technology infrastructure specifically (not just business processes generally) can withstand and recover from disruption.
  • Configuration management (A.8.9) and secure coding (A.8.28) — addressing modern software development and infrastructure-as-code practices.
  • Data masking (A.8.11) and data leakage prevention (A.8.12) — controls reflecting the realities of cloud data sharing and remote work.

Importantly, an organization doesn’t need to implement every Annex A control. Each is selected — or formally excluded with justification — based on the organization’s risk assessment, and the resulting decisions are documented in the Statement of Applicability (SoA), one of the most heavily scrutinized documents in any ISO 27001 audit.

How ISO 27001 Certification Works

Achieving and maintaining ISO 27001 certification follows a structured path:

  1. Gap analysis — Comparing the organization’s current security posture against ISO 27001’s clauses and the Annex A control set.
  2. ISMS design and implementation — Defining scope, conducting a formal risk assessment, selecting controls, and building the Statement of Applicability.
  3. Internal audit — A required self-assessment of the ISMS before the external audit, used to catch and fix gaps proactively.
  4. Management review — Leadership formally reviews ISMS performance, risk treatment progress, and audit findings.
  5. Stage 1 audit — The certification body reviews documentation and readiness.
  6. Stage 2 audit — The certification body assesses whether the ISMS is actually implemented and operating effectively, often through interviews, evidence sampling, and site visits.
  7. Certification issuance — Valid for three years, assuming successful surveillance audits — typically conducted annually — confirm the ISMS remains effective.
  8. Recertification audit — A more comprehensive audit at the end of the three-year cycle to renew the certificate.

Only accredited certification bodies — accredited under ISO/IEC 17021-1 by a recognized national accreditation body — can issue valid ISO 27001 certificates. A “certification” from an unaccredited provider carries little weight with sophisticated customers or auditors.

The 2022 Transition: Where Things Stand in 2026

For organizations that held ISO 27001:2013 certification, the transition to the 2022 edition wasn’t optional — and the deadline has now passed.

The transition timeline ran as follows:

  • October 2022 — ISO/IEC 27001:2022 published; the transition period begins.
  • April 30, 2024 — Certification bodies were required to stop issuing new certifications against the 2013 edition; all new and recertification audits had to use the 2022 edition from this point forward.
  • October 31, 2025 — The transition deadline. Any ISO 27001:2013 certificate not transitioned by this date automatically expired or was withdrawn.

As of 2026, any organization still holding or claiming a 2013-edition certificate is not validly certified. Organizations that missed the deadline can’t simply pick up where they left off — they must pursue a full Stage 1 and Stage 2 certification audit against the 2022 edition, a more time-consuming and costly path than the transition audits that were available before the deadline closed.

This has real commercial consequences: lapsed certification can mean lost contracts, failed vendor risk reviews, and reputational friction with customers who specifically require an active, accredited ISO 27001 certificate as a condition of doing business.

Adding to the regulatory housekeeping, Global Accreditation Cooperation Incorporated began operating on January 1, 2026, taking over the international accreditation functions previously split between the IAF and ILAC — a structural change worth knowing about even though it doesn’t alter certification requirements directly.

Who Pursues ISO 27001, and Why

ISO 27001 is relevant well beyond the technology sector — the standard is explicitly designed to apply to organizations of any size and industry. In practice, it’s most commonly pursued by:

  • Technology and SaaS companies selling internationally, especially into Europe, the Middle East, and Asia-Pacific
  • Organizations responding to customer or government tender requirements that explicitly require ISO 27001 certification
  • Companies in regulated or security-sensitive sectors — finance, healthcare technology, defense supply chains, and critical infrastructure
  • Multinational organizations seeking a single, globally recognized security standard rather than navigating multiple regional frameworks

ISO 27001 vs. SOC 2

These two frameworks are often confused, but they serve different purposes:

  • ISO 27001 results in a certification against a management system standard, valid for three years with annual surveillance audits, and is the standard most widely recognized outside North America.
  • SOC 2 results in an attestation report, typically renewed annually, and is most commonly requested by North American buyers, particularly in SaaS procurement.

There’s substantial control overlap between the two — access control, risk assessment, incident response, vendor management — which is why many organizations selling globally eventually pursue both. Because of that overlap, tackling ISO 27001 and SOC 2 in parallel, with a shared control library and evidence base, is typically far more efficient than treating them as two unrelated projects.

Common ISO 27001 Implementation Challenges

  • Treating the 2022 transition as a renumbering exercise. Simply remapping old control numbers to new ones misses the intent behind the new themes and controls, and auditors notice the difference between genuine implementation and cosmetic mapping.
  • A weak or outdated risk assessment. The risk assessment drives every other decision in the ISMS; a generic or rarely updated one undermines the credibility of the whole system.
  • An incomplete or poorly justified Statement of Applicability. Excluding a control without a clear, risk-based rationale is one of the most common audit findings.
  • Documentation without operation. Auditors increasingly focus on outcomes — patch times, access review frequency, incident detection times — rather than whether a policy document simply exists.
  • Underestimating ongoing maintenance. Certification isn’t a one-time achievement; annual surveillance audits and a genuine continual-improvement cycle are part of the deal, not optional extras.
  • Missing the cloud and supplier controls. The newer Annex A controls around cloud services and supplier relationships catch organizations that haven’t formally documented how they vet and monitor vendors.

A Practical ISO 27001 Compliance Checklist

  1. Define the scope of your ISMS — which business units, locations, and systems are included.
  2. Conduct a formal, documented information security risk assessment.
  3. Select Annex A controls (or document justified exclusions) based on that risk assessment, and build your Statement of Applicability.
  4. Implement the selected controls across organizational, people, physical, and technological domains.
  5. Establish a cloud services security process and formal supplier/vendor oversight program.
  6. Train staff on their specific ISMS responsibilities — developers on secure coding, operations on configuration management, procurement on supplier oversight.
  7. Conduct a thorough internal audit and management review before scheduling your external audit.
  8. Engage an accredited certification body early, particularly around recertification or transition deadlines, since auditor availability tightens as deadlines approach.
  9. Treat surveillance audits as checkpoints for continual improvement, not just compliance hurdles to clear.
  10. Reassess your risk register and Statement of Applicability whenever your business, technology, or threat environment changes materially.

Why ISO 27001 Matters to Customers and Consumers

Like SOC 2, ISO 27001 is fundamentally a B2B trust mechanism — but its protections extend to the people whose data ultimately flows through certified organizations’ systems.

  • It gives global buyers a consistent way to evaluate vendors. A customer in Singapore, Germany, or Brazil can rely on the same accredited certification standard rather than navigating unfamiliar, region-specific frameworks.
  • It requires genuine risk management, not just technical controls. Because ISO 27001 mandates an ongoing risk assessment process, certified organizations are structurally more likely to identify and address emerging threats — including those affecting customer and consumer data — before they become incidents.
  • It creates accountability through independent, accredited audits. Certification isn’t self-declared; it’s issued and periodically re-verified by an independent body, giving customers a level of assurance that internal claims alone can’t provide.
  • It pushes security obligations through the supply chain. The 2022 revision’s stronger supplier and cloud-service controls mean certified organizations are expected to vet and monitor their own vendors more rigorously — extending data protection further down the chain than any single customer contract could achieve alone.
  • It’s a legitimate, fair question to ask a vendor. Any customer or partner evaluating an organization that will handle sensitive data is entitled to ask for proof of active, accredited ISO 27001 certification — and in 2026, given the transition deadline, it’s worth specifically confirming the certificate references the 2022 edition rather than a lapsed 2013 one.

The Bottom Line

ISO 27001 in 2026 is no longer a standard in transition — the 2022 edition is simply the standard, full stop, and organizations still claiming certification against the 2013 version are not validly certified at all. For organizations pursuing or maintaining certification, that means a genuine, risk-driven ISMS, a defensible Statement of Applicability, and a real commitment to the ongoing surveillance and improvement cycle the standard requires. For the customers and consumers on the other side of that relationship, a current, accredited ISO 27001 certificate remains one of the clearest, most internationally consistent signals that an organization has built information security into how it actually operates — not just into what it claims.


This article is intended for general informational purposes and does not constitute legal, audit, or certification advice. Organizations evaluating their ISO 27001 scope, transition status, or certification readiness should consult an accredited certification body or qualified information security advisor.

Ready to build on Stratosphere?

Build once. Scale securely. Stay compliant.