ISO 27001:2022
The standard your enterprise customers keep asking for.
ISO 27001 is the international standard for an Information Security Management System. Unlike DPDP it is voluntary — but it is the certificate that unblocks enterprise procurement, and it is the only one on this page you can actually be certified against.
ISO 27001:2022 is included from the Shield plan.
Scope
When it is worth doing
ISO 27001 is not a legal obligation. It is a commercial one — you pursue it because it removes friction from deals, not because a regulator requires it.
Enterprise buyers are asking
Procurement gates increasingly treat the certificate as the price of entry.
You sell internationally
Recognised globally — the better first certificate if your customers are abroad.
You want a system, not a checklist
It certifies the management system — risk, treatment, review — not a list of tools.
It takes months, not weeks
A realistic first certification runs 6–12 months, including Stage 1 and Stage 2 audits.
The structure
What the standard is made of
ISO 27001:2022 has two halves. Clauses 4–10 define the management system and are mandatory. Annex A lists 93 controls in four themes, which you select from and justify in a Statement of Applicability.
Annex A of ISO 27001:2022 lists 93 controls in four themes: A.5 Organisational (37), A.6 People (8), A.7 Physical (14) and A.8 Technological (34). You select which apply and justify the rest in a Statement of Applicability.
| Clause / Theme | Requirement | What it means in practice |
|---|---|---|
Cl. 4 |
Context of the organisation | Define what the ISMS covers, who the interested parties are, and what they require. The scope statement you write here appears on your certificate. |
Cl. 5 |
Leadership | Top management must demonstrate commitment, set an information security policy, and assign roles and responsibilities. Auditors test this, and it is a common first-audit failure. |
Cl. 6 |
Planning | Information security risk assessment and risk treatment, plus measurable security objectives. The risk register is the engine of the whole standard. |
Cl. 7 |
Support | Resources, competence, awareness, communication, and control of documented information. |
Cl. 8 |
Operation | Actually run the risk assessment and treatment plan you designed, and keep records that you did. |
Cl. 9 |
Performance evaluation | Monitoring and measurement, internal audit, and management review. You must have run at least one internal audit and one management review before certification. |
Cl. 10 |
Improvement | Nonconformity handling, corrective action, and continual improvement. |
A.5 |
Organizational controls (37) | Policies, roles, supplier relationships, incident management, business continuity, legal and contractual requirements. |
A.6 |
People controls (8) | Screening, terms of employment, awareness and training, disciplinary process, remote working, and reporting of events. |
A.7 |
Physical controls (14) | Secure areas, equipment siting and protection, clear desk and screen, secure disposal, and physical monitoring. |
A.8 |
Technological controls (34) | Endpoint protection, access rights, cryptography, logging and monitoring, network security, secure development, and configuration management. |
SoA |
Statement of Applicability | For each of the 93 Annex A controls, state whether it applies, why, and its implementation status. This is the single most scrutinised document in the audit. |
The path
What certification actually involves
ISO 27001 is certified by an accredited certification body, not by a software vendor. The cycle is three years, with surveillance audits in between.
Documentation review — is the ISMS designed and documented?
Implementation audit — is it actually operating, with records?
Certificate validity, with annual surveillance audits
Annex A controls to assess and justify in the SoA
Typical time to first certification for an SME
How CyberLetics helps
The evidence trail an auditor asks for, built as you go
CyberLetics ships 30 ISO 27001:2022 Annex A controls across all four themes — organizational, people, physical and technological — with the risk register, policy set and evidence history the clauses require.
Connect your systems (AWS, Microsoft 365, devices). Signals are collected every six hours. Each becomes an evidence snapshot with a SHA-256 checksum that cannot be edited. Controls are evaluated as pass or fail with that proof attached. Your score updates live and your auditor gets a read-only view of the controls, evidence and history.
A pre-loaded control library
30 Annex A controls across all four themes, each with an owner and an evidence history.
Evidence that cannot be quietly edited
Every item is snapshotted with a SHA-256 checksum. Nothing changes after the fact.
Evidence collected for you
Connect Microsoft 365 or AWS. Re-checked every six hours, written to the trail.
A live score, not an annual scramble
Every control has a status and a history. Watch the number move.
Policies, risks and remediation in one place
Policy templates, a risk register and remediation tasks tied to controls.
Read-only access for your auditor
A scoped read-only view for your assessor. No screenshots by email.
info What CyberLetics does not do
CyberLetics is not a certification body and cannot certify you against ISO 27001. Certification is issued only by an accredited certification body after Stage 1 and Stage 2 audits. We are also not your internal auditor — Clause 9.2 requires an internal audit that is objective and impartial. What we do is hold the control set, the risk register, the policies and the evidence in one place so those audits are a review rather than an excavation.
Start the ISMS before the questionnaire arrives
Open a 14-day trial and work the Annex A control set, or run a free scan to see where your technical controls stand today.
Also covered