ISO 27001:2022

The standard your enterprise customers keep asking for.

ISO 27001 is the international standard for an Information Security Management System. Unlike DPDP it is voluntary — but it is the certificate that unblocks enterprise procurement, and it is the only one on this page you can actually be certified against.

security Check your exposure free See pricing

ISO 27001:2022 is included from the Shield plan.

Scope

When it is worth doing

ISO 27001 is not a legal obligation. It is a commercial one — you pursue it because it removes friction from deals, not because a regulator requires it.

01

Enterprise buyers are asking

Procurement gates increasingly treat the certificate as the price of entry.

02

You sell internationally

Recognised globally — the better first certificate if your customers are abroad.

03

You want a system, not a checklist

It certifies the management system — risk, treatment, review — not a list of tools.

04

It takes months, not weeks

A realistic first certification runs 6–12 months, including Stage 1 and Stage 2 audits.

The structure

What the standard is made of

ISO 27001:2022 has two halves. Clauses 4–10 define the management system and are mandatory. Annex A lists 93 controls in four themes, which you select from and justify in a Statement of Applicability.

ISO 27001:2022 Annex A: 93 controls in four themes - 37 organisational, 8 people, 14 physical and 34 technological.37A.5 Organisational8A.6People14A.7 Physical34A.8 Technological93 controls in Annex A - you pick which apply and justify the rest in a Statement of Applicability

Annex A of ISO 27001:2022 lists 93 controls in four themes: A.5 Organisational (37), A.6 People (8), A.7 Physical (14) and A.8 Technological (34). You select which apply and justify the rest in a Statement of Applicability.

Clause / Theme Requirement What it means in practice
Cl. 4 Context of the organisation Define what the ISMS covers, who the interested parties are, and what they require. The scope statement you write here appears on your certificate.
Cl. 5 Leadership Top management must demonstrate commitment, set an information security policy, and assign roles and responsibilities. Auditors test this, and it is a common first-audit failure.
Cl. 6 Planning Information security risk assessment and risk treatment, plus measurable security objectives. The risk register is the engine of the whole standard.
Cl. 7 Support Resources, competence, awareness, communication, and control of documented information.
Cl. 8 Operation Actually run the risk assessment and treatment plan you designed, and keep records that you did.
Cl. 9 Performance evaluation Monitoring and measurement, internal audit, and management review. You must have run at least one internal audit and one management review before certification.
Cl. 10 Improvement Nonconformity handling, corrective action, and continual improvement.
A.5 Organizational controls (37) Policies, roles, supplier relationships, incident management, business continuity, legal and contractual requirements.
A.6 People controls (8) Screening, terms of employment, awareness and training, disciplinary process, remote working, and reporting of events.
A.7 Physical controls (14) Secure areas, equipment siting and protection, clear desk and screen, secure disposal, and physical monitoring.
A.8 Technological controls (34) Endpoint protection, access rights, cryptography, logging and monitoring, network security, secure development, and configuration management.
SoA Statement of Applicability For each of the 93 Annex A controls, state whether it applies, why, and its implementation status. This is the single most scrutinised document in the audit.

The path

What certification actually involves

ISO 27001 is certified by an accredited certification body, not by a software vendor. The cycle is three years, with surveillance audits in between.

Stage 1

Documentation review — is the ISMS designed and documented?

Stage 2

Implementation audit — is it actually operating, with records?

3 years

Certificate validity, with annual surveillance audits

93

Annex A controls to assess and justify in the SoA

6–12 mo

Typical time to first certification for an SME

How CyberLetics helps

The evidence trail an auditor asks for, built as you go

CyberLetics ships 30 ISO 27001:2022 Annex A controls across all four themes — organizational, people, physical and technological — with the risk register, policy set and evidence history the clauses require.

How CyberLetics keeps you compliant: connect your systems, signals are collected every six hours, each becomes an immutable SHA-256 evidence snapshot, controls are evaluated against it, and your live score and a read-only auditor view update automatically.Connectyour systemsAWS, M365, devicesSignalscollectedevery six hoursEvidencesnapshotSHA-256, immutableControlevaluatedpass or fail, with proofLivescoreread-only auditor view

Connect your systems (AWS, Microsoft 365, devices). Signals are collected every six hours. Each becomes an evidence snapshot with a SHA-256 checksum that cannot be edited. Controls are evaluated as pass or fail with that proof attached. Your score updates live and your auditor gets a read-only view of the controls, evidence and history.

inventory_2

A pre-loaded control library

30 Annex A controls across all four themes, each with an owner and an evidence history.

verified_user

Evidence that cannot be quietly edited

Every item is snapshotted with a SHA-256 checksum. Nothing changes after the fact.

sync

Evidence collected for you

Connect Microsoft 365 or AWS. Re-checked every six hours, written to the trail.

monitoring

A live score, not an annual scramble

Every control has a status and a history. Watch the number move.

assignment

Policies, risks and remediation in one place

Policy templates, a risk register and remediation tasks tied to controls.

group

Read-only access for your auditor

A scoped read-only view for your assessor. No screenshots by email.

info What CyberLetics does not do

CyberLetics is not a certification body and cannot certify you against ISO 27001. Certification is issued only by an accredited certification body after Stage 1 and Stage 2 audits. We are also not your internal auditor — Clause 9.2 requires an internal audit that is objective and impartial. What we do is hold the control set, the risk register, the policies and the evidence in one place so those audits are a review rather than an excavation.

Start the ISMS before the questionnaire arrives

Open a 14-day trial and work the Annex A control set, or run a free scan to see where your technical controls stand today.

security Scan my site free Start 14-day trial

Also covered

SOC 2 Type II →

The attestation US buyers ask for. Often pursued alongside ISO 27001.

DPDP Act 2023 →

India’s data protection law. Mandatory, not optional — unlike ISO 27001.