ISO 27001
Information security management systems
ISO 27001 provides a framework for establishing, implementing, and continuously improving an information security management system. Thalorin supports ISO 27001 implementation and certification with risk assessment tools, control mapping, and audit preparation features aligned with the standard's requirements.
ISO/IEC 27001 certifies a management system, not a set of controls. The distinction is the whole reason organisations that treat it as a control checklist struggle at audit: what is certified is the Information Security Management System — the governing process by which risks are identified, treated, monitored, and improved. Annex A controls are the treatment options, not the subject of the certificate.
The 2022 revision restructured Annex A from 114 controls in 14 domains to 93 controls in four themes — organisational, people, physical, and technological — and introduced eleven genuinely new controls covering areas such as threat intelligence, cloud services, and secure coding. Organisations certified under the 2013 version have completed transition; new work starts at 2022.
The Statement of Applicability is the document auditors examine most closely. It records which Annex A controls apply, which do not, and why — and an exclusion without a defensible risk-based justification is the most reliable way to generate a nonconformity.
Certification runs a three-year cycle: an initial certification audit in two stages, then surveillance audits in years one and two, then recertification. Thalorin holds the risk register, the treatment decisions, and the control evidence as one connected object, so the Statement of Applicability is derived from the risk assessment rather than maintained alongside it.
Framework compliance requires sustained effort
It certifies a system, not a control set
Auditors test whether the management system functions — that risks are assessed, treatments decided, effectiveness reviewed. An organisation with excellent controls and no working ISMS process fails on the thing being certified.
Statement of Applicability justification
Every Annex A control included or excluded needs a rationale traceable to the risk assessment. Exclusions asserted without that trace are the most common source of nonconformities.
The 2022 control themes
93 controls across four themes replaced 114 across 14 domains, with eleven new controls including threat intelligence, cloud service security, and secure development. Mappings inherited from 2013-era documentation are no longer structurally aligned.
Surveillance keeps the clock running
Certification is a three-year cycle with annual surveillance audits. Management review, internal audit, and continual improvement have to demonstrably happen between audits, not be assembled before them.
How Thalorin helps
ISMS implementation support
Run the ISMS as the management system the standard actually requires — context, leadership, objectives, internal audit and management review as recurring obligations rather than a certification exercise.
Annex A control mapping
Track the 93 Annex A 2022 controls across the four themes, including the eleven controls introduced in the revision.
Risk assessment automation
Maintain the risk register, treatment plans, and residual risk acceptance as connected records rather than separate documents.
Statement of Applicability
Derive the Statement of Applicability from the risk assessment, so every inclusion and exclusion carries its justification by construction.
Internal audit preparation
Plan and evidence the internal audit programme against clause and Annex A coverage, and carry nonconformities and corrective actions through to verified closure.
Certification maintenance
Keep the management system evidenced between surveillance visits, and share control evidence with SOC 2 and other frameworks where the same underlying control satisfies both.
ISO 27001: common questions
How many controls are in ISO 27001:2022?
Annex A of the 2022 revision contains 93 controls organised into four themes: organisational, people, physical, and technological. This replaced the 2013 structure of 114 controls across 14 domains. Eleven controls are new, covering threat intelligence, information security for cloud services, ICT readiness for business continuity, physical security monitoring, configuration management, information deletion, data masking, data leakage prevention, monitoring activities, web filtering, and secure coding.
What is the Statement of Applicability?
A mandatory document recording which Annex A controls apply to your ISMS, which do not, and the justification for each decision, traceable to your risk assessment. It is among the first documents an auditor reads and the most common source of nonconformities, because exclusions are often asserted rather than justified.
How long does ISO 27001 certification take?
The management system must operate long enough to produce evidence — typically at least one full cycle of internal audit and management review — before a Stage 2 audit can succeed. The certification audit itself runs in two stages, with Stage 1 reviewing documentation and readiness and Stage 2 testing implementation. The three-year cycle then continues with annual surveillance audits.
Is ISO 27001 better than SOC 2?
They answer different questions for different audiences. ISO 27001 is an internationally recognised certification of a management system, generally preferred outside the United States and in procurement processes that expect a certificate. SOC 2 is a US-centric attestation report containing an auditor's detailed opinion, generally preferred by US enterprise buyers who want to read the control detail. Organisations selling into both markets commonly hold both.
Do I need to recertify every year?
No. Certification lasts three years, with surveillance audits in years one and two confirming the ISMS continues to operate, then a full recertification audit in year three. Surveillance audits are narrower than the initial certification but can still raise nonconformities that must be closed.
Regulatory state described as of August 2026. Requirements change; verify against the current rule before relying on any date above.
Talk to us about ISO 27001.
See how one evidence artifact satisfies ISO 27001 requirements alongside every other framework you carry.