Tutorials  /  Security

ISO 27001: Requirements, Process and Effort

LLudwig · August 2026 ·14 min read ·Security, Tutorial

ISO/IEC 27001 is the standard your customers name when they ask for proof that information security is under control. It is also the standard most often misread as a checklist of technical measures, when it is in fact a requirement set for a management system. This guide explains what it demands, how certification works, and where the effort actually goes.

What is ISO/IEC 27001?

ISO/IEC 27001 is the international standard specifying requirements for an information security management system (ISMS): a documented set of processes for determining information security risks, deciding how to treat them, and proving that those decisions are reviewed and kept current. The current edition is ISO/IEC 27001:2022, published jointly by ISO and IEC and extended by Amendment 1:2024, which added the requirement to consider whether climate change is a relevant issue for the organisation.

Two distinctions matter before anything else:

  • 27001 vs. 27002: ISO/IEC 27001 contains the auditable requirements. ISO/IEC 27002:2022 is guidance on how to implement the controls and is not certifiable.
  • Certificate vs. attestation: ISO/IEC 27001 leads to a certificate issued by a certification body. Schemes such as BSI C5 or SOC 2 lead to an auditor's report instead. The formats are not interchangeable, even where the underlying measures overlap.

The standard is deliberately technology-neutral. It does not tell you which firewall to run, which key length to use or how often to patch. It requires you to decide those things on the basis of a risk assessment, write the decision down, and be able to show it was applied.

Who needs ISO 27001 certification?

No EU or German statute requires ISO/IEC 27001 certification as such — the pressure to certify comes from customers, public tenders and regulated supply chains rather than from a law naming the standard. Whether it applies to you is therefore a commercial and contractual question, not a legal one.

The usual drivers:

  • Customer and tender requirements: Large enterprises and public buyers frequently make a valid certificate a hard criterion for admission to a procurement process.
  • Supply chain position: If your customers are themselves regulated, their obligation to manage supplier risk propagates down to you as a contractual clause.
  • Regulatory context: Frameworks such as NIS2 and DORA require appropriate risk-management measures and governance, without mandating a particular certificate. An ISMS built to ISO/IEC 27001 is a common way to evidence them, but it is not a legal substitute for the specific duties in those regimes. The German transposition of NIS2 and its scope thresholds should be checked against the current BSI publications rather than against secondary sources.
  • Internal need: Organisations with distributed responsibility for security often adopt the standard for its structure alone and postpone certification.
graph TD
    A["Do customers, tenders or contracts ask for a security certificate?"] -->|Yes| B["Certification is likely to pay for itself"]
    A -->|No| C["Are you in scope of NIS2, DORA or a comparable regime?"]
    C -->|Yes| D["An ISMS is expected; certification is one way to evidence it"]
    C -->|No| E["Do you handle third-party data under contractual security duties?"]
    E -->|Yes| F["Build the ISMS first, decide on certification later"]
    E -->|No| G["No external driver; ISO 27001 stays optional"]

What does ISO 27001 actually require?

ISO/IEC 27001:2022 requires two things at once: a functioning management system described in Clauses 4 to 10, and a documented decision on every control in Annex A — either implemented, or excluded with a stated justification. Clauses 1 to 3 cover scope, normative references and terms and contain no auditable requirements.

The management system: Clauses 4 to 10

Clause Theme What it demands
4 Context Scope boundaries, interested parties and their requirements
5 Leadership Security policy, top-management commitment, assigned roles
6 Planning Risk assessment and treatment, objectives, Statement of Applicability
7 Support Resources, competence, awareness, communication, documentation
8 Operation Running the planned processes, keeping risk assessments current
9 Performance evaluation Monitoring, internal audit, management review
10 Improvement Nonconformities, corrective action, continual improvement

The artefact auditors reach for first is the Statement of Applicability (SoA), required by the risk-treatment provisions in Clause 6. It lists every Annex A control, states whether it applies, and gives the reason. An SoA that excludes controls without a defensible justification is the most reliable way to fail an audit.

The second most common finding concerns Clause 9. Internal audit and management review are not paperwork appended at the end; they are the evidence that the system runs. A certification body will look for records covering a real period of operation, not a single review held the week before the audit.

Annex A: 93 controls in four themes

Theme Controls Examples
Organizational 37 Policies, supplier relationships, cloud service usage, incident management
People 8 Screening, terms of employment, awareness, remote working
Physical 14 Secure areas, equipment siting, cabling, media disposal
Technological 34 Access control, cryptography, logging, backup, secure development

Annex A is a reference set, not a mandatory implementation list. You derive your controls from your risk treatment and then compare that set against Annex A to confirm nothing necessary was overlooked. In practice most organisations find that the majority of controls apply, and that exclusions cluster in a few areas — typically software development, if you build nothing yourself.

What changed in the 2022 revision?

The 2022 revision restructured Annex A from 114 controls in 14 categories into 93 controls in four themes and introduced eleven new controls addressing threat intelligence, cloud service usage, ICT readiness for business continuity, physical security monitoring, configuration management, information deletion, data masking, data leakage prevention, monitoring activities, web filtering and secure coding.

ISO/IEC 27001:2013 ISO/IEC 27001:2022
Annex A structure 14 categories 4 themes
Control count 114 93
Cloud-specific control none yes
Certificate status expired at end of transition current

The transition period for accredited certificates ran until 31 October 2025 under the relevant IAF mandatory document; after that date, accredited certificates against the 2013 edition ceased to be valid. If a supplier presents a certificate referencing the 2013 edition today, treat it as expired and ask for the current one.

How does ISO 27001 certification work?

ISO 27001 certification is carried out by an accredited certification body in a two-stage initial audit followed by a three-year cycle of surveillance audits and one recertification audit. In Germany, accreditation of those bodies is granted by the DAkkS; the requirements the bodies themselves must meet are set out in the ISO/IEC 17021-1 and ISO/IEC 27006 documents.

Step What happens Typical timing
Stage 1 Documentation and readiness review, scope confirmation Weeks before Stage 2
Stage 2 Audit of implementation and effectiveness on site or remote Certificate issued on success
Surveillance 1 and 2 Sampled re-audit of parts of the system Roughly annual
Recertification Full re-audit of the whole system Before the certificate expires

Two practical points. First, certification bodies expect at least one completed internal audit and one management review before Stage 2 — which sets a floor on how quickly a project can finish, regardless of budget. Second, the scope statement printed on the certificate is what the certificate is worth. A certificate covering one product line or one location says nothing about the rest of the organisation.

What does ISO 27001 certification cost?

The cost of ISO 27001 certification splits into external audit fees, which follow a day-count derived from the number of persons doing work under the organisation's control and the complexity of the scope, and internal effort — which is usually the larger share and depends mainly on how much documentation already exists.

We do not quote figures here, because they vary too widely by scope, country and certification body to be stated responsibly. The drivers you can estimate yourself:

  • Audit days: Determined by the certification body according to the tables in the applicable ISO/IEC 27006 and IAF documents, not negotiated freely. Ask for the calculation in writing.
  • Internal staff time: Risk assessment, policy writing, evidence collection and the internal audit. This is where multi-month projects consume their budget.
  • Consulting: Optional, and worth weighing against the fact that a consultant cannot operate the system for you afterwards.
  • Ongoing operation: Surveillance audits, annual reviews and continual maintenance of documentation recur every year. Budget for the cycle, not just the first certificate.

One cost is easy to underestimate: gaps found in Stage 1 that require remediation before Stage 2 can push the timeline by a quarter or more.

SEC

Matching infrastructure at centron

Security by default: cloud firewalls filter traffic before it reaches the instance, managed centrally. Explore cloud firewalls →

What does ISO 27001 mean for cloud infrastructure?

A cloud provider's ISO 27001 certificate covers the provider's own management system — it does not extend to your ISMS, and it does not remove your obligation to assess the provider as a supplier. What it does is let you satisfy the supplier-related controls in Annex A with a recognised document instead of a bespoke questionnaire.

When you evaluate a provider's certificate, the useful questions are: which entity and which services does the scope statement name, which edition of the standard is referenced, when does it expire, and does the provider also publish an SoA summary or an audit report covering the services you actually consume. ISO/IEC 27017 and ISO/IEC 27018 add cloud-specific and personal-data-specific control guidance on top of 27001 and are sometimes offered alongside it.

centron holds ISO/IEC 27001, ISO 9001 and ISO 14001 certification and a BSI C5:2020 Type 1 attestation (unrestricted) for ccloud³ / Managed Cloud. The relevant documents are available through the Trust Center resources; for supplier assessment, the documents themselves are the only reliable source — marketing statements are not.

How does ISO 27001 relate to C5, SOC 2 and NIS2?

ISO/IEC 27001 BSI C5 SOC 2 NIS2
Nature International standard German criteria catalogue US attestation framework EU directive
Output Certificate Auditor's attestation Auditor's report Legal obligation
Focus Management system Cloud service controls plus transparency Trust Services Criteria Risk management and reporting duties
Certifiable Yes Attested, not certified Attested, not certified No

They overlap in substance and differ in form. An operating ISMS covers a large share of the groundwork for a C5 attestation, and it is a defensible basis for the risk-management measures NIS2 requires — but it does not automatically satisfy either. NIS2 in particular carries duties, such as incident reporting to national authorities within prescribed deadlines, that no certificate discharges on your behalf.

Where the binding information is

The only authoritative text is the standard itself, ISO/IEC 27001:2022 including Amd 1:2024, which is sold by ISO and the national standards bodies and is not published free of charge. For the certification framework and the list of accredited bodies in Germany, the DAkkS is the source; for transition rules and mandatory documents, the IAF; for NIS2 scope and reporting obligations in Germany, the BSI. This page explains the standard and does not constitute legal advice — whether a specific obligation applies to your organisation is a question for your own legal review against the current text.

More on compliance

Jetzt 200 € Guthaben sichern

Testen Sie Ihr Setup auf ccloud³

Registrieren Sie sich in der ccloud³ und erhalten Sie 200 € Startguthaben für Ihr Projekt – z. B. für eine PostgreSQL-VM mit automatischen Backups.

Ludwig Technische Redaktion

Schreibt bei centron über Linux-Administration, Container und Datenbanken – mit Fokus auf Anleitungen, die im Betrieb tatsächlich funktionieren.

Kategorie Security
Teilen
Noch offene Fragen?

Our team will help you with your specific setup - in German or English, by people who run the platform themselves.

War dieses Tutorial hilfreich?

Your answer is stored anonymously and helps us improve our tutorials.

Kommentare

No comments yet - be the first to ask a question about this tutorial.

Sign in to comment

Comments are open to centron customers. Sign in to your account to ask a question about this tutorial.

Weiterlesen

Das könnte Sie auch interessieren

Jetzt kostenlos anfangen

Melden Sie sich an und erhalten Sie in den ersten 60 Tagen ein Guthaben von 200 € bei centron.

Dieses Werbeangebot gilt nur für neue Konten. Angebot ausschließlich für Gewerbetreibende.

Jetzt loslegen Sales kontaktieren