Compliance · Certifiable standard
The international standard your global customers recognize.
ISO/IEC 27001 certifies that you run a working information security management system (ISMS) — not just a pile of controls, but a governed cycle of risk assessment, treatment, measurement, and improvement. It's the security credential most recognized outside the US.
93
Annex A controls (2022)
3 yr
Certification cycle
Stage 1+2
Audit structure
The controls get the attention, but auditors certify the management system. Most first-time failures are governance gaps, not missing tools.
Scope, leadership commitment, objectives, risk assessment and treatment, internal audit, and management review. The clauses are the standard; Annex A is the control menu you select from.
The 2022 revision restructured controls into 93 across four themes — organizational, people, physical, and technological — including cloud services, threat intelligence, and data masking.
The SoA documents which Annex A controls apply, which don't, and why. It's the spine of the audit, and the document auditors read first.
Anyone selling internationally, or into industries where it's table stakes.
We do the readiness, build and run the controls, and support you through the audit — we are not the auditor, and we keep that separation deliberate.
We measure your current state against the clauses and Annex A, and tell you honestly how far certification is.
We stand up the management system — scope, roles, objectives, and the cadence that keeps it alive after the auditor leaves.
We run a defensible risk methodology and produce a treatment plan that drives control selection, rather than the reverse.
We build the SoA with justifications that hold up under questioning.
We close technical and organizational gaps across identity, logging, change, vendors, and physical security.
We prepare you for Stage 1 and Stage 2, run internal audit and management review, and support surveillance audits.
Define the ISMS boundary and assess against clauses + Annex A.
Run the risk assessment, choose controls, write the SoA.
Close gaps and put the governance cadence into operation.
Audit yourself and hold management review — both are mandatory.
Stage 1 documentation review, Stage 2 effectiveness audit, then surveillance.
For most mid-sized organizations, 4–9 months from kickoff to Stage 2 — driven mostly by how much of the management system already exists. The ISMS also needs to have actually operated (internal audit and management review completed) before certification.
No. Certification must come from an accredited certification body, which has to be independent of the people who built your ISMS. intSignal builds and runs the ISMS, closes the gaps, and prepares you for audit — and we help you select an accredited body.
Follow your buyers. US-centric B2B usually asks for SOC 2; international and enterprise RFPs ask for ISO 27001. If you'll eventually need both, ISO 27001 makes a strong backbone because its ISMS governance carries most of SOC 2's requirements.
Annex A was restructured from 114 controls into 93 across four themes, with new controls covering areas like cloud services, threat intelligence, secure coding, and data masking. Existing certificates transitioned to the 2022 revision, and new certifications use it.
Certificates run on a three-year cycle with annual surveillance audits, then recertification. Skipping the governance cadence between audits is the most common way organizations lose certification.
Most of the work transfers. Once controls are mapped and evidenced, a second framework costs a fraction of the first.
Tell us where you are and who’s asking for it — we’ll come back with scope, gaps, and a realistic timeline.