ISO 27001 requirements explained

Your complete guide to ISO 27001:2022 requirements. Understand the mandatory clauses, Annex A controls, and documentation your business needs to achieve information security certification.

Introduction

ISO 27001 is the international Standard for information security management. For UK businesses handling sensitive data, facing rising cyber threats and tighter supply chain expectations, ISO 27001 provides a structured framework to protect information assets, demonstrate compliance with regulations like UK GDPR and the Data Protection Act 2018, and build trust with clients and partners.

The Standard outlines specific requirements for establishing, implementing, maintaining, and continually improving an Information Security Management System (ISMS). These requirements are detailed across Clauses 4 to 10 of ISO 27001:2022, supported by a comprehensive set of security controls in Annex A.

Whether you’re bidding for public sector contracts, meeting client due diligence requirements, or proactively managing cyber risks, understanding these requirements is your first step towards certification.

ISO certification woman in data centre server room, quality management system compliance, professional auditor, certification process, IT security standards, quality assurance, compliance audit, data centre standards, business quality improvement, professional certification.

ISO 27001 requirements at a glance

  • Standard: ISO/IEC 27001:2022
  • Core structure: Clauses 4-10 (mandatory) + Annex A (controls)
  • Key focus: Context, leadership, planning, support, operation, evaluation, improvement
  • UK relevance: Supports UK GDPR Article 32 and NIS Regulations
  • Certification: External audit required
  • Documentation: Policies, risk assessments, Statement of Applicability

What are the ISO 27001 requirements?

ISO 27001 requirements are split into two key parts: mandatory clauses and applicable controls.

Clauses 4 to 10 are mandatory for all organisations seeking certification. These clauses define how you establish, document, implement, and maintain your information security management system.

Annex A contains 93 security controls organised into four domains. Unlike the mandatory clauses, you select which controls apply to your organisation based on your risk assessment. This selection is documented in your Statement of Applicability (SoA), where you justify why each control is included or excluded.

 

What changed in ISO 27001:2022?

The 2022 revision streamlined the controls from 114 to 93, reorganising them into four clear themes rather than 14 categories. The update emphasises risk-based thinking and gives organisations more flexibility in how they implement controls. It also aligns the structure more closely with other ISO management system Standards. 

For UK businesses, the 2022 version better aligns with contemporary threats and regulatory expectations, particularly around cloud security, supply chain risks, and data protection requirements under UK GDPR. 

Aspect ISO 27001:2013 ISO 27001:2022
Number of controls 114 controls 93 controls
Structure 14 control categories 4 thematic domains
New controls N/A 11 new controls (threat intelligence, cloud security, etc.)
Emphasis Prescriptive approach Risk-based, flexible implementation
UK context Pre-GDPR alignment Enhanced alignment with modern regulatory expectations, including GDPR and risk-based security regimes such as NIS2.

UK-specific considerations

UK organisations need to consider additional regulatory requirements alongside ISO 27001:

UK GDPR and Data Protection Act 2018

ISO 27001 helps demonstrate compliance with Article 32 (security of processing) but doesn’t replace your obligation to appoint a Data Protection Officer (DPO) where required, or report data breaches to the ICO within 72 hours.

NIS Regulations (and recently NIS2 if operating in EU supply chains)

Operators of essential services and relevant digital service providers must implement appropriate security measures. ISO 27001 certification is widely recognised as helping to meet many of these requirements.

Cyber Essentials and Cyber Essentials Plus

While separate schemes, many UK organisations pair these with ISO 27001, particularly when bidding for government contracts.

Clause 4: Context of the organisation

Clause 4 requires you to understand the environment in which your organisation operates. This includes both internal and external factors that could affect your ability to achieve information security objectives.

You need to identify your industry’s regulatory landscape, competitive pressures, emerging cyber threats, your organisation’s risk appetite, and the expectations of interested parties like customers, regulators, and partners.

Checklist:

  • Document internal and external issues
  • Identify interested parties and their requirements
  • Define and approve ISMS scope

UK‑specific considerations:

  • Data flows between the UK, EU and third countries post‑Brexit
  • Regulatory stakeholders such as the ICO
  • Contractual security requirements from public‑sector or regulated clients

Clause 5: Leadership

ISO 27001 requires demonstrable commitment from top management. This means active leadership in establishing, resourcing, and championing your information security programme.

Your senior leadership team needs to establish an information security policy, assign roles and responsibilities, and make sure the ISMS aligns with your organisation’s strategic direction. They’re also accountable for making sure it works.

What this means in practice

  • Establish the information security policy – A high-level statement of your organisation’s commitment to information security, signed by a director or equivalent.
  • Assign roles and responsibilities – Clearly define who’s responsible for what.
  • Allocating resources – Provide the budget, people, time, and tools needed to implement and maintain the ISMS.
  • Communicating the importance – Leadership must communicate why information security matters to your organisation’s success.
  • Promoting continual improvement – Give active direction and support to achieve information security objectives.

UK relevance: Directors and senior leaders are increasingly expected to demonstrate accountability for cyber risk, aligning with governance duties under UK company law.

Clause 6: Planning

Clause 6 is where risk-based thinking becomes concrete. You need to identify risks and opportunities related to information security, then plan how you’ll address them.

The risk assessment and risk treatment process sit at the heart of ISO 27001. Your risk assessment identifies what could go wrong with your information assets. Your risk treatment plan documents how you’ll mitigate those risks—typically by implementing controls from Annex A.

Risk assessment process

  • Establish risk criteria – Define how you’ll measure likelihood and impact. Keep it proportionate to your business size and complexity.
  • Identify information security risks – What threats exist to your confidentiality, integrity, and availability of information?
  • Analyse risks – Assess likelihood and potential impact. Prioritise risks based on your criteria.
  • Evaluate risks – Which risks require treatment? Which can be accepted?

Risk treatment and the Statement of Applicability 

Your risk treatment plan identifies which Annex A controls you’ll implement to address identified risks. This feeds directly into your Statement of Applicability (SoA)—a critical document that lists all 93 Annex A controls and states whether each is applicable to your organisation, with justification.

Link to UK risk frameworks

Many UK organisations align their ISO 27001 risk assessment with the NCSC Cyber Assessment Framework (CAF), particularly if they’re in scope for NIS or working with central government. The CAF’s 14 principles map well to ISO 27001 requirements.

For financial services firms, aligning with FCA requirements on operational resilience and cyber security alongside ISO 27001 creates a comprehensive risk management approach.

Planning steps:

  1. Conduct a risk assessment
  2. Evaluate and prioritise risks
  3. Select appropriate Annex A controls
  4. Document the SoA

Clause 7: Support

Your information security management system can only work if it’s properly supported. Clause 7 is about making sure you have the right resources, skills, awareness and documentation in place to keep your information security programme effective and sustainable.

Key support requirements

  • Resources – Adequate people, budget, technology, and infrastructure to establish and maintain the ISMS.
  • Competence – Make sure employees (and relevant contractors) have the necessary skills and knowledge for their information security responsibilities. Define competence requirements and provide training or support where gaps are identified.
  • Awareness – Everyone in your organisation should understand the information security policy, how they contribute to the ISMS, and the implications of not conforming.
  • Communication – Establish what needs to be communicated about information security, when, to whom, and by whom.
  • Documented information – Create and maintain the documents and records required by ISO 27001, such as policies, procedures and risk assessments.

GDPR training requirements

UK GDPR requires organisations to ensure staff who handle personal data receive appropriate training. Your ISO 27001 competence and awareness activities should support this obligation.

In practice, many UK organisations integrate data protection training into their broader information security awareness programme. This can include guidance on handling personal data securely, recognising phishing attempts and knowing how to report suspected data breaches.

The ICO expects organisations to be able to demonstrate that staff understand their responsibilities. Keep training records and evidence of completion so you can clearly show accountability if required.

Documentation essentials

ISO 27001 requires specific documented information (see Documentation requirements further down). The key is to keep it proportionate. Smaller organisations don’t need extensive document libraries. A concise, well-maintained set of core documents is far more valuable than a collection of lengthy, outdated policies.

Clause 8: Operation

This is where your planning turns into action. Clause 8 requires you to implement the risk treatment decisions you developed in Clause 6.

In simple terms, this is where your ISMS becomes operational. You’re expected to implement your risk treatment plan, apply the Annex A controls identified in your Statement of Applicability, and manage the day-to-day activities that protect your information.

What this looks like operationally

  • Implement your selected Annex A controls – This may include physical security, access management, encryption, logging and monitoring, incident response procedures, and supplier security measures.
  • Control outsourced processes – If third parties are involved in security-relevant activities (such as cloud hosting, managed IT services or payroll processing), you need to make sure those activities are appropriately governed and controlled.
  • Carry out your risk treatment plan – Put the agreed risk treatments into action and retain evidence that they have been implemented.
  • Work towards your information security objectives – Work towards the specific, measurable objectives you set.

UK example: Supply chain security

Supply chain attacks are a growing threat. Recent incidents have shown how compromised suppliers can become attack vectors. For UK businesses, particularly those operating in regulated sectors or government supply chains, supplier security is paramount.

Annex A controls 5.19 to 5.23 address supplier relationships. In practice, this means conducting supplier due diligence, including contractual security requirements (particularly for data processors under GDPR), monitoring supplier security practices, and having clear processes for managing supply chain risk.

Clause 9: Performance evaluation

How do you know your ISMS is working? Clause 9 is about making sure your ISMS is doing what it’s designed to do. It requires you to monitor, measure, analyse, and evaluate your information security performance. This includes internal audits and management reviews.

Performance monitoring

You need to determine what to monitor and measure, the methods you’ll use, when you’ll analyse results, and who’s responsible. Common metrics include:

  • Number of security incidents and response times
  • Completion rates for security awareness training
  • Vulnerability scan results and remediation times
  • Compliance with specific controls (e.g., access reviews completed on time)
  • Effectiveness of key controls through testing

The Standard doesn’t prescribe specific metrics. What matters is that your monitoring is relevant to your risks and objectives, and that you act on what you learn.

Internal audit requirements

ISO 27001 requires planned internal audits at regular intervals to confirm that your ISMS:

  • Conforms to ISO 27001 requirements and your own information security management system requirements
  • Is effectively implemented and maintained

Your internal auditor must be independent of the area being audited. In smaller organisations, this may mean training someone from a different function or using an external consultant to maintain independence.

Management review

Top management must review the information security management system at planned intervals (typically annually, though more frequent reviews are common). The management review considers:

  • Previous management review actions
  • Changes in external and internal issues
  • Feedback on information security performance
  • Nonconformities and corrective actions
  • Monitoring and measurement results
  • Audit results
  • Opportunities for continual improvement

Aligning with ICO audit expectations

The ICO can audit your data protection practices. While ISO 27001 certification isn’t a substitute for GDPR compliance, a mature ISMS with robust internal audit practices demonstrates accountability—a key GDPR principle.

If your organisation is subject to regulatory scrutiny, documented internal audits, management reviews and monitoring results can provide clear evidence that information security is being actively managed, reviewed and improved.

Clause 10: Improvement

ISO 27001 requires continual improvement. When nonconformities occur – instances where your ISMS doesn’t meet requirements – you must react, investigate root causes, take corrective action, and prevent recurrence.ear improvement plans.

Managing nonconformities

When you identify a nonconformity (through internal audits, incidents, or other means):

  1. React – Take immediate action to control and correct the issue.
  2. Evaluate – Determine if similar nonconformities exist or could occur elsewhere.
  3. Implement corrective action – Address the root cause, not just the symptom.
  4. Review effectiveness – Did your corrective action work?
  5. Update your ISMS if needed – If systemic issues emerge, update your processes.

Continual improvement in practice

Beyond fixing problems, look for opportunities to enhance your ISMS:

  • Implement lessons learned from security incidents
  • Update controls as threats evolve
  • Refine processes based on internal audit findings
  • Incorporate new security technologies or practices
  • Respond to changes in your organisation or external environment

UK relevance: Post-breach improvements

If you suffer a personal data breach reportable to the ICO, they’ll expect to see a credible action plan to prevent recurrence. Your ISO 27001 Clause 10 processes—nonconformity management and corrective action—provide a structured approach.

The ICO’s post-breach guidance emphasises learning and improvement. Organisations that can demonstrate they’ve systematically addressed root causes and strengthened controls tend to receive a more favourable ICO response than those without clear improvement plans.

Annex A controls

Annex A contains 93 information security controls organised into four themes. Unlike the mandatory clauses, you select which controls to implement based on your risk assessment and business needs.

Every control must be considered. If you decide a control isn’t applicable, you document why in your Statement of Applicability. If a control is applicable, you state whether it’s implemented and reference supporting evidence.

 

Domain Number of controls What they cover Example controls
Organisational controls 37 Governance framework, policies, roles and responsibilities, asset management, information classification, supplier relationships, incident management and business continuity-related security requirements Information security policy, defined security roles, asset inventory, supplier security requirements, information security incident management
People controls 8 Security responsibilities before, during and after employment, including awareness, training and disciplinary processes Security awareness training, terms and conditions of employment, confidentiality agreements.
Physical controls 14 Physical and environmental protection of facilities, equipment and information Secure areas, physical entry controls, protection against environmental threats, equipment security, clear desk and clear screen policies.
Technological controls 34 Technical measures to protect systems and data, including access control, cryptography, secure configuration, monitoring and secure development Access control policy, secure authentication, encryption, malware protection, logging and monitoring, network security, secure development practices

UK priorities: GDPR-related controls

For UK organisations processing personal data, certain Annex A controls directly support GDPR compliance:

  • 5.10 Acceptable use of information – Supports responsible use of information and governance controls
  • 5.33 Protection of records – Supports record retention requirements
  • 5.34 Privacy and protection of personal information – Direct GDPR alignment
  • 8.9 Configuration management – Demonstrates security by design
  • 8.10 Information deletion – Supports right to erasure
  • 8.11 Data masking – Helps implement data minimisation
  • 8.12 Data leakage prevention – Mitigates breach risks
  • 5.26 Response to information security incidents – Aligns with breach notification obligations

The key principle is that control selection must be risk-based. Certification auditors will expect to see a clear link between your risk assessment, your chosen controls and your documented Statement of Applicability.

Documentation requirements

ISO 27001 requires certain documented information to make sure your ISMS is clearly defined, implemented and evidenced effectively.

Mandatory documented information

  • Scope of the ISMS – What’s in and what’s out
  • Information security policy – Your high-level commitment statement
  • Information security objectives – Specific, measurable targets
  • Risk assessment process – How you identify and analyse risks
  • Risk assessment results – The actual risks you’ve found
  • Risk treatment process and results – What you’re doing about those risks
  • Statement of Applicability (SoA) – All Annex A controls with applicability justification
  • Evidence that processes are carried out as planned – Policies, procedures and records needed to make sure processes are carried out as planned
  • Monitoring and measurement results – Performance data
  • Internal audit programme and results – Audit plans and findings
  • Management review results – What came out of management reviews
  • Evidence of corrective actions – What you did to fix problems

Other commonly required documents

While ISO 27001 doesn’t explicitly ask for these by name, you’ll typically need them to prove compliance:

  • Asset register
  • Access control procedures
  • Incident response procedures
  • Business continuity and disaster recovery plans
  • Supplier agreements with security requirements
  • Security awareness training materials and attendance records
  • Change management procedures
  • Backup and recovery procedures

Documentation tips for UK SMEs

Keep it proportionate. A 10-person business doesn’t need the same documentation library as a 1,000-person enterprise. Focus on:

  • Clarity – Write documents in plain language so they are easy to follow.
  • Accessibility – Store documents where relevant staff can easily access them.
  • Version control – Maintain revision histories so you can demonstrate control of documented information.
  • Review cycles – Schedule regular reviews to ensure documents remain current.
  • Integration – Where possible, integrate ISO 27001 documentation with existing policies (data protection policy, IT acceptable use policy, etc.) rather than creating parallel document sets.

Example documentation structure

Many UK organisations structure their documentation library like this:

Level 1: Policy
Information Security Policy (the what and why)

Level 2: Procedures
How to implement controls (incident response procedure, access control procedure, etc.)

Level 3: Work instructions
Step-by-step guides for specific tasks

Level 4: Records
Evidence that procedures were followed (audit logs, training records, incident reports)

Who needs ISO 27001?

ISO 27001 is voluntary—there’s no legal requirement to be certified. But many UK organisations find they need it to win work or meet expectations.

You likely need ISO 27001 if you’re:

  • Bidding for public sector contracts – Many UK government tenders require or strongly prefer ISO 27001 certification, particularly for digital services or contracts involving sensitive data.
  • Working with regulated sectors – Financial services, healthcare, defence, and energy sectors frequently require suppliers to hold ISO 27001.
  • Processing significant volumes of personal data – While GDPR doesn’t mandate ISO 27001, certification demonstrates robust security measures and strengthens your accountability.
  • Handling client or patient data – Professional services firms, healthcare providers, and others processing sensitive client information increasingly pursue ISO 27001 to demonstrate trust and reduce client risk concerns.
  • Operating in competitive markets – Where multiple suppliers compete for business, ISO 27001 can differentiate you from competitors without certification.
  • Looking to strengthen your cyber insurance position – Certification can demonstrate strong risk management, which insurers often view positively. This can make it easier to get cover and may help reduce your premiums.

Sectors where ISO 27001 is particularly common in the UK:

  • IT services and software development
  • Professional services (legal, accounting, consulting)
  • Healthcare (private hospitals, diagnostic services, care providers)
  • Financial services (particularly fintech)
  • Telecommunications and managed service providers
  • Education (particularly universities handling research data)
  • Manufacturing
  • Construction
ISO certification document with the QMSUK logo, symbolising quality management standards adherence and professional accreditation in compliance with international standards.

Common Questions

About ISO 27001

ISO 27001:2022 has 10 clauses, but Clauses 4 to 10 contain the mandatory requirements:

  • Clause 4 – Context of the organisation
  • Clause 5 – Leadership
  • Clause 6 – Planning
  • Clause 7 – Support
  • Clause 8 – Operation
  • Clause 9 – Performance evaluation
  • Clause 10 – Improvement

Clauses 1-3 provide introductory information about scope, normative references, and terms and definitions. All organisations must comply with all requirements in Clauses 4-10 to achieve certification.

No, ISO 27001 certification is not a legal requirement under UK GDPR. However, it can support your GDPR compliance efforts.

UK GDPR Article 32 requires organisations to implement “appropriate technical and organisational measures” to ensure security of personal data. ISO 27001 provides a structured framework for implementing many of these measures, particularly around access controls, encryption, incident management, and security testing.

Think of ISO 27001 as good evidence of GDPR compliance efforts, not a replacement for data protection obligations like having a lawful basis for processing, respecting individual rights, and maintaining accurate records of processing activities.

ISO 27001:2022 Annex A contains 93 controls, down from 114 in the 2013 version. These controls are organised into four domains:

  • Organisational controls – 37 controls
  • People controls – 8 controls
  • Physical controls – 14 controls
  • Technological controls – 34 controls

You don’t need to implement all 93 controls. Organisations select relevant controls based on risk and document their decisions in a Statement of Applicability.

ISO 27001 requires certain documented information including:

  • ISMS scope
  • Information security policy
  • Risk assessment process and results
  • Risk treatment process and results
  • Statement of Applicability
  • Internal audit records
  • Management review outputs
  • Evidence of corrective actions

The documentation required will vary depending on the size, complexity and risk profile of your organisation.

Implementation timelines vary based on your starting point and resources. The average timeline for UK SMEs is around 3-6 months. With Citation ISO Certification’s consultancy support, many UK SMEs achieve certification within 45 days.

Our expert consultants guide UK businesses through every stage of ISO 27001 implementation. From gap analysis to successful certification, we make information security management straightforward.