ISO/IEC 27001 certification means two different things. An organization is certified when an accredited certification body confirms that its information security management system (ISMS) meets the standard. A person is certified when they pass an exam and earn a personal credential. This guide covers both kinds of ISO/IEC 27001 certification.
Key points
- ISO/IEC 27001 is the international standard for an information security management system. The current edition is ISO/IEC 27001:2022.
- Clauses 4 to 10 hold the requirements. Annex A lists 93 controls in four themes.
- An organization’s certificate lasts three years, with surveillance audits in between.
- Personal certifications from PECB run from Foundation to Lead Implementer and Lead Auditor.
What ISO/IEC 27001 requires
The standard asks an organization to manage information security as a system, not as a list of tools. The requirements sit in seven clauses:
- Context (clause 4): understand the organization, its interested parties and the scope of the ISMS.
- Leadership (clause 5): commitment from top management, a policy and assigned roles.
- Planning (clause 6): risk assessment, risk treatment and security objectives.
- Support (clause 7): resources, competence, awareness and documented information.
- Operation (clause 8): carry out the risk assessments and treatment plans.
- Performance evaluation (clause 9): monitoring, internal audit and management review.
- Improvement (clause 10): correct nonconformities and improve continually.
Annex A: 93 controls in four themes
| Theme | Controls | Examples |
|---|---|---|
| Organizational | 37 | Policies, supplier relationships, incident management |
| People | 8 | Screening, awareness training, remote working |
| Physical | 14 | Secure areas, equipment protection |
| Technological | 34 | Access rights, cryptography, logging, secure development |
You do not have to implement every control. You choose the controls your risks call for and record the decision, with reasons, in the Statement of Applicability.
How an organization gets ISO/IEC 27001 certification
- Define the scope of the ISMS.
- Run a gap analysis against the requirements.
- Assess and treat risk, and write the Statement of Applicability.
- Implement the controls and the supporting processes.
- Operate the system and keep records.
- Internal audit and management review.
- Stage 1 audit: the certification body reviews the documented system and readiness.
- Stage 2 audit: the certification body checks that the system works in practice.
- Surveillance and recertification: audits in the following years, and recertification after three years.
Horus Academy trains the people who do this work. It does not certify organizations.
ISO/IEC 27001 certification for individuals
| Course | Length | Who it is for |
|---|---|---|
| ISO/IEC 27001 Foundation | 2 days, 14 CPD credits | People new to the standard |
| ISO/IEC 27001 Lead Implementer | 5 days, 31 CPD credits | People who build and run an ISMS |
| ISO/IEC 27001 Lead Auditor | 5 days, 31 CPD credits | People who audit an ISMS |
| ISO/IEC 27001 Transition | 2 days, 14 CPD credits | Holders of 2013-edition credentials |
Passing a Lead exam is the first step. The credential you receive depends on your experience, from Provisional to Senior Lead. Our comparison of Lead Auditor and Lead Implementer explains the difference and shows the experience tables.
What it costs and how to prepare
For individuals, the cost is the course fee, which includes the exam. See ISO/IEC 27001 certification cost for individuals and how to prepare for the Lead Auditor exam.
For organizations, the cost depends on scope and size: internal time, any consulting support, tools and the certification body’s audit fees.
The 2022 edition
ISO/IEC 27001:2022 reorganized Annex A from 114 controls in 14 groups to 93 controls in four themes and added 11 new controls, including threat intelligence, cloud services security and data leakage prevention. The transition period for certified organizations ended on 31 October 2025.
Related standards
- ISO/IEC 27002 gives guidance on implementing the Annex A controls.
- ISO/IEC 27005 gives guidance on information security risk management. See ISO/IEC 27005 vs ISO 31000.
- ISO/IEC 27701 extends the ISMS to privacy.
- ISO/IEC 42001 uses the same structure for AI. See our ISO/IEC 42001 certification guide.
Sources: ISO/IEC 27001:2022, Information security management systems (ISO) and the PECB ISO/IEC 27001 certification scheme.
Frequently asked questions
How long does ISO/IEC 27001 certification take for an organization?
It depends on size, scope and how much is already in place. The standard sets no fixed time. The system has to run long enough to produce records, an internal audit and a management review before the certification audit.
How long is an ISO/IEC 27001 certificate valid?
An organization’s certificate is valid for three years, with surveillance audits in between and a recertification audit at the end of the cycle.
Is the 2013 edition still valid?
No. The transition period ended on 31 October 2025. Certificates are now issued against ISO/IEC 27001:2022.
Which personal ISO/IEC 27001 certification should I take first?
Start with Foundation if you are new to the standard. Take Lead Implementer if you build or run the management system, and Lead Auditor if you assess it.