What is ISO 27001? The international standard for information security management

By Expel team

Last updated: July 24, 2026

ISO 27001 is an international standard for information security management systems (ISMS), published by the International Organization for Standardization (ISO) and the International Electrotechnical Commission (IEC). It specifies requirements for establishing, implementing, maintaining, and continually improving a systematic approach to managing information security risks across people, processes, and technology.

Expel is certified in ISO 27001:2022 with the ISO 27701:2019 (processor) extension. By certifying Expel’s Information Security Management System (ISMS) and Privacy Information Management System (PIMS), Expel continues to demonstrate its commitment to building trust and transparent security and privacy. (Source: https://expel.com/security-compliance/)

Key takeaways

  • ISO 27001 is an international standard for information security management systems (ISMS) that requires organizations to build a systematic approach to identifying and managing information security risks, not just a checklist of controls.
  • Certification is issued by accredited third-party auditors for a three-year cycle, with annual surveillance audits and a public certificate listed in verifiable online registries.
  • Annex A provides a control catalog—93 controls in the 2022 version, organized into organizational, people, physical, and technological themes—from which organizations select based on their risk assessment.
  • ISO 27001 produces a public certificate; SOC 2 produces a confidential report shared under NDA. Many organizations pursue both to satisfy different buyer audiences across different geographies.
  • Expel holds ISO 27001:2022 certification, making Expel’s security posture independently verifiable without a private report.

 

ISO 27001 is one of the most globally recognized security certifications—and one of the most commonly misunderstood. It’s frequently described as a checklist of security controls, but the standard’s actual requirement is more fundamental: organizations must build and operate a systematic information security management system (ISMS) that identifies risks and manages them consistently over time.

ISO 27001 sits within the broader cybersecurity compliance landscape as the dominant international framework. This page describes the standard’s requirements, how it differs from SOC 2, what the certification process may look like, and what pursuing it can involve.

 

What does ISO 27001 require?

ISO 27001 requires organizations to build an information security management system (ISMS). It’s a documented, systematic approach to identifying information security risks and implementing controls to address them.

The ISMS framework has three core components. 

  1. Context and risk assessment: The organization identifies ISMS scope, documents the internal and external context affecting information security, and conducts a formal risk assessment on a defined cycle.
  2. Controls and treatment: Based on the risk assessment, the organization selects controls to mitigate identified risks. Controls can come from Annex A, third-party control sets, or be designed in-house. The selection is justified in a Statement of Applicability (SoA).
  3. Continual improvement: ISO 27001 requires ongoing monitoring, internal audit, and management review. Certification requires demonstrating that the ISMS operates and improves over time, not just that it exists on paper.

 

ISO 27001 vs. SOC 2: How they compare

ISO 27001 and SOC 2 are the two most common security certifications global enterprise buyers expect. They overlap significantly but aren’t interchangeable.

ISO 27001 is international (published by ISO/IEC) and produces a public certificate listed in verifiable registries. SOC 2 is US-specific (published by the AICPA) and produces an audit report shared under NDA. ISO 27001 certification runs on a three-year cycle with annual surveillance audits; SOC 2 Type 2 requires a minimum 6-month observation window per annual audit.

The most practical difference is that ISO 27001 typically satisfies procurement requirements in European, APAC, and global enterprise sales cycles where a public certificate matters. SOC 2 Type 2 is typically the baseline expectation for US enterprise vendor risk programs.

Many organizations choose to pursue both—the ISMS discipline from ISO 27001 strengthens the control environment that SOC 2 auditors test.

A table comparing ISO 27001 to SOC 2.

 

ISO 27001 Annex A controls

Annex A is the control catalog that accompanies ISO 27001. In the 2022 version, it contains 93 controls across four themes: organizational controls (37), people controls (8), physical controls (14), and technological controls (34).

Organizational controls cover policies, roles, threat intelligence, supplier relationships, incident management, business continuity, and legal compliance. People controls address workforce security: screening, employment terms, awareness training, and disciplinary processes. Physical controls cover access perimeters, equipment protection, clean desk policies, and secure disposal. Technological controls address endpoint devices, privileged access management, authentication, cryptography, network security, application security, and security event logging and monitoring.

Not all 93 controls are mandatory to complete a certification. Controls can be excluded if they’re not applicable, provided the exclusions are documented in a Statement of Applicability (SoA) that the auditor reviews.

 

How does ISO 27001 certification work?

ISO 27001 certification is issued by accredited independent third-party auditors registered with national accreditation bodies. The certification lifecycle runs on a three-year cycle.

Stage 1: Documentation review: The auditor examines ISMS documentation to confirm it meets the standard’s requirements. 

Stage 2: Operational assessment: The auditor verifies that the ISMS is implemented and running as documented, through interviews, evidence review, and controls testing. If no major nonconformities are found, certification is recommended and issued for three years.

Surveillance audits in years 1 and 2 verify continued compliance. In year 3, a full recertification audit resets the cycle. Most organizations need 6–12 months from ISMS build to certification, depending on starting maturity.

 

Who needs ISO 27001 certification?

ISO 27001 is voluntary. In practice, it’s recommended for technology and SaaS companies where data security is core to the service.

ISO 27001 certification also may surface in supplier questionnaires from large enterprises regardless of geography. It’s a recognized global baseline that procurement teams across regions understand.

Unlike SOC 2, ISO 27001 produces a public certificate that can be shared without restriction. If customers ask for a security certification they can verify independently, ISO 27001 is typically the answer.

 

How does Expel support ISO 27001?

Expel holds its own ISO 27001:2022 certification.. You can read all about our Compliance program here: https://expel.com/security-compliance/ and  find all our compliance documentation within our Trust Center here: https://security.expel.com

For customers pursuing their own ISO 27001 certification, Expel’s MDR service may support several Annex A requirements. Continuous 24×7 monitoring maps to the technological controls cluster—specifically security event monitoring, intrusion detection, and incident management. Expel’s 2.41-minute median time to detect (MTTD) and 14-minute mean time to remediate (MTTR) for fully automated high/critical incidents can produce the operational evidence auditors look for when testing whether monitoring controls are functioning.

 

Frequently asked questions

What is ISO 27001 certification?

ISO 27001 certification means an accredited third-party auditor has verified that an organization’s ISMS meets the requirements of the ISO/IEC 27001 standard. Certification is issued for a three-year cycle with annual surveillance audits. Unlike SOC 2, ISO 27001 certification is publicly verifiable—certificates are listed in online registries operated by accreditation bodies.

What is the difference between ISO 27001 and SOC 2?

ISO 27001 is an international standard requiring an information security management system (ISMS); it produces a public certificate. SOC 2 is a US-based auditing framework evaluating whether system controls operated effectively during an audit period; it produces a report shared under NDA. ISO 27001 is common in international enterprise sales; SOC 2 Type 2 is the typical baseline for US enterprise vendor risk programs. Many organizations choose to pursue both for customer trust.

How long does ISO 27001 certification take?

Most first-time implementations take 6–12 months from starting the ISMS build to achieving certification, including time to document the ISMS, conduct a risk assessment, implement and operate controls, and complete the two-stage certification audit. Organizations with a mature existing security program often move faster; organizations building from scratch should plan for 9–12 months minimum.

What does ISO 27001 Annex A contain?

Annex A is the control catalog in the ISO 27001 standard. In ISO 27001:2022, it contains 93 controls across four themes: organizational controls, people controls, physical controls, and technological controls. Organizations don’t have to implement every control. Those deemed not applicable can be excluded, provided the exclusions are documented in a Statement of Applicability (SoA) that the auditor reviews.