ISO 27001 requirements explained
Your complete guide to ISO 27001:2022 requirements. Understand the mandatory clauses, Annex A controls, and documentation your business needs to achieve information security certification.
Your complete guide to ISO 27001:2022 requirements. Understand the mandatory clauses, Annex A controls, and documentation your business needs to achieve information security certification.
ISO 27001 is the international Standard for information security management. For UK businesses handling sensitive data, facing rising cyber threats and tighter supply chain expectations, ISO 27001 provides a structured framework to protect information assets, demonstrate compliance with regulations like UK GDPR and the Data Protection Act 2018, and build trust with clients and partners.
The Standard outlines specific requirements for establishing, implementing, maintaining, and continually improving an Information Security Management System (ISMS). These requirements are detailed across Clauses 4 to 10 of ISO 27001:2022, supported by a comprehensive set of security controls in Annex A.
Whether you’re bidding for public sector contracts, meeting client due diligence requirements, or proactively managing cyber risks, understanding these requirements is your first step towards certification.
ISO 27001 requirements are split into two key parts: mandatory clauses and applicable controls.
Clauses 4 to 10 are mandatory for all organisations seeking certification. These clauses define how you establish, document, implement, and maintain your information security management system.
Annex A contains 93 security controls organised into four domains. Unlike the mandatory clauses, you select which controls apply to your organisation based on your risk assessment. This selection is documented in your Statement of Applicability (SoA), where you justify why each control is included or excluded.
The 2022 revision streamlined the controls from 114 to 93, reorganising them into four clear themes rather than 14 categories. The update emphasises risk-based thinking and gives organisations more flexibility in how they implement controls. It also aligns the structure more closely with other ISO management system Standards.
For UK businesses, the 2022 version better aligns with contemporary threats and regulatory expectations, particularly around cloud security, supply chain risks, and data protection requirements under UK GDPR.
| Aspect | ISO 27001:2013 | ISO 27001:2022 |
|---|---|---|
| Number of controls | 114 controls | 93 controls |
| Structure | 14 control categories | 4 thematic domains |
| New controls | N/A | 11 new controls (threat intelligence, cloud security, etc.) |
| Emphasis | Prescriptive approach | Risk-based, flexible implementation |
| UK context | Pre-GDPR alignment | Enhanced alignment with modern regulatory expectations, including GDPR and risk-based security regimes such as NIS2. |
UK organisations need to consider additional regulatory requirements alongside ISO 27001:
Operators of essential services and relevant digital service providers must implement appropriate security measures. ISO 27001 certification is widely recognised as helping to meet many of these requirements.
Clause 4 requires you to understand the environment in which your organisation operates. This includes both internal and external factors that could affect your ability to achieve information security objectives.
You need to identify your industry’s regulatory landscape, competitive pressures, emerging cyber threats, your organisation’s risk appetite, and the expectations of interested parties like customers, regulators, and partners.
Checklist:
UK‑specific considerations:
ISO 27001 requires demonstrable commitment from top management. This means active leadership in establishing, resourcing, and championing your information security programme.
Your senior leadership team needs to establish an information security policy, assign roles and responsibilities, and make sure the ISMS aligns with your organisation’s strategic direction. They’re also accountable for making sure it works.
What this means in practice
UK relevance: Directors and senior leaders are increasingly expected to demonstrate accountability for cyber risk, aligning with governance duties under UK company law.
Clause 6 is where risk-based thinking becomes concrete. You need to identify risks and opportunities related to information security, then plan how you’ll address them.
The risk assessment and risk treatment process sit at the heart of ISO 27001. Your risk assessment identifies what could go wrong with your information assets. Your risk treatment plan documents how you’ll mitigate those risks—typically by implementing controls from Annex A.
Risk assessment process
Risk treatment and the Statement of Applicability
Your risk treatment plan identifies which Annex A controls you’ll implement to address identified risks. This feeds directly into your Statement of Applicability (SoA)—a critical document that lists all 93 Annex A controls and states whether each is applicable to your organisation, with justification.
Link to UK risk frameworks
Many UK organisations align their ISO 27001 risk assessment with the NCSC Cyber Assessment Framework (CAF), particularly if they’re in scope for NIS or working with central government. The CAF’s 14 principles map well to ISO 27001 requirements.
For financial services firms, aligning with FCA requirements on operational resilience and cyber security alongside ISO 27001 creates a comprehensive risk management approach.
Planning steps:
Your information security management system can only work if it’s properly supported. Clause 7 is about making sure you have the right resources, skills, awareness and documentation in place to keep your information security programme effective and sustainable.
Key support requirements
GDPR training requirements
UK GDPR requires organisations to ensure staff who handle personal data receive appropriate training. Your ISO 27001 competence and awareness activities should support this obligation.
In practice, many UK organisations integrate data protection training into their broader information security awareness programme. This can include guidance on handling personal data securely, recognising phishing attempts and knowing how to report suspected data breaches.
The ICO expects organisations to be able to demonstrate that staff understand their responsibilities. Keep training records and evidence of completion so you can clearly show accountability if required.
Documentation essentials
ISO 27001 requires specific documented information (see Documentation requirements further down). The key is to keep it proportionate. Smaller organisations don’t need extensive document libraries. A concise, well-maintained set of core documents is far more valuable than a collection of lengthy, outdated policies.
This is where your planning turns into action. Clause 8 requires you to implement the risk treatment decisions you developed in Clause 6.
In simple terms, this is where your ISMS becomes operational. You’re expected to implement your risk treatment plan, apply the Annex A controls identified in your Statement of Applicability, and manage the day-to-day activities that protect your information.
What this looks like operationally
UK example: Supply chain security
Supply chain attacks are a growing threat. Recent incidents have shown how compromised suppliers can become attack vectors. For UK businesses, particularly those operating in regulated sectors or government supply chains, supplier security is paramount.
Annex A controls 5.19 to 5.23 address supplier relationships. In practice, this means conducting supplier due diligence, including contractual security requirements (particularly for data processors under GDPR), monitoring supplier security practices, and having clear processes for managing supply chain risk.
How do you know your ISMS is working? Clause 9 is about making sure your ISMS is doing what it’s designed to do. It requires you to monitor, measure, analyse, and evaluate your information security performance. This includes internal audits and management reviews.
Performance monitoring
You need to determine what to monitor and measure, the methods you’ll use, when you’ll analyse results, and who’s responsible. Common metrics include:
The Standard doesn’t prescribe specific metrics. What matters is that your monitoring is relevant to your risks and objectives, and that you act on what you learn.
Internal audit requirements
ISO 27001 requires planned internal audits at regular intervals to confirm that your ISMS:
Your internal auditor must be independent of the area being audited. In smaller organisations, this may mean training someone from a different function or using an external consultant to maintain independence.
Management review
Top management must review the information security management system at planned intervals (typically annually, though more frequent reviews are common). The management review considers:
Aligning with ICO audit expectations
The ICO can audit your data protection practices. While ISO 27001 certification isn’t a substitute for GDPR compliance, a mature ISMS with robust internal audit practices demonstrates accountability—a key GDPR principle.
If your organisation is subject to regulatory scrutiny, documented internal audits, management reviews and monitoring results can provide clear evidence that information security is being actively managed, reviewed and improved.
ISO 27001 requires continual improvement. When nonconformities occur – instances where your ISMS doesn’t meet requirements – you must react, investigate root causes, take corrective action, and prevent recurrence.ear improvement plans.
Managing nonconformities
When you identify a nonconformity (through internal audits, incidents, or other means):
Continual improvement in practice
Beyond fixing problems, look for opportunities to enhance your ISMS:
UK relevance: Post-breach improvements
If you suffer a personal data breach reportable to the ICO, they’ll expect to see a credible action plan to prevent recurrence. Your ISO 27001 Clause 10 processes—nonconformity management and corrective action—provide a structured approach.
The ICO’s post-breach guidance emphasises learning and improvement. Organisations that can demonstrate they’ve systematically addressed root causes and strengthened controls tend to receive a more favourable ICO response than those without clear improvement plans.
Annex A contains 93 information security controls organised into four themes. Unlike the mandatory clauses, you select which controls to implement based on your risk assessment and business needs.
Every control must be considered. If you decide a control isn’t applicable, you document why in your Statement of Applicability. If a control is applicable, you state whether it’s implemented and reference supporting evidence.
| Domain | Number of controls | What they cover | Example controls |
|---|---|---|---|
| Organisational controls | 37 | Governance framework, policies, roles and responsibilities, asset management, information classification, supplier relationships, incident management and business continuity-related security requirements | Information security policy, defined security roles, asset inventory, supplier security requirements, information security incident management |
| People controls | 8 | Security responsibilities before, during and after employment, including awareness, training and disciplinary processes | Security awareness training, terms and conditions of employment, confidentiality agreements. |
| Physical controls | 14 | Physical and environmental protection of facilities, equipment and information | Secure areas, physical entry controls, protection against environmental threats, equipment security, clear desk and clear screen policies. |
| Technological controls | 34 | Technical measures to protect systems and data, including access control, cryptography, secure configuration, monitoring and secure development | Access control policy, secure authentication, encryption, malware protection, logging and monitoring, network security, secure development practices |
UK priorities: GDPR-related controls
For UK organisations processing personal data, certain Annex A controls directly support GDPR compliance:
The key principle is that control selection must be risk-based. Certification auditors will expect to see a clear link between your risk assessment, your chosen controls and your documented Statement of Applicability.
ISO 27001 requires certain documented information to make sure your ISMS is clearly defined, implemented and evidenced effectively.
Mandatory documented information
Other commonly required documents
While ISO 27001 doesn’t explicitly ask for these by name, you’ll typically need them to prove compliance:
Documentation tips for UK SMEs
Keep it proportionate. A 10-person business doesn’t need the same documentation library as a 1,000-person enterprise. Focus on:
Example documentation structure
Many UK organisations structure their documentation library like this:
Level 1: Policy
Information Security Policy (the what and why)
Level 2: Procedures
How to implement controls (incident response procedure, access control procedure, etc.)
Level 3: Work instructions
Step-by-step guides for specific tasks
Level 4: Records
Evidence that procedures were followed (audit logs, training records, incident reports)
ISO 27001 is voluntary—there’s no legal requirement to be certified. But many UK organisations find they need it to win work or meet expectations.
You likely need ISO 27001 if you’re:
Sectors where ISO 27001 is particularly common in the UK:
ISO 27001:2022 has 10 clauses, but Clauses 4 to 10 contain the mandatory requirements:
Clauses 1-3 provide introductory information about scope, normative references, and terms and definitions. All organisations must comply with all requirements in Clauses 4-10 to achieve certification.
No, ISO 27001 certification is not a legal requirement under UK GDPR. However, it can support your GDPR compliance efforts.
UK GDPR Article 32 requires organisations to implement “appropriate technical and organisational measures” to ensure security of personal data. ISO 27001 provides a structured framework for implementing many of these measures, particularly around access controls, encryption, incident management, and security testing.
Think of ISO 27001 as good evidence of GDPR compliance efforts, not a replacement for data protection obligations like having a lawful basis for processing, respecting individual rights, and maintaining accurate records of processing activities.
ISO 27001:2022 Annex A contains 93 controls, down from 114 in the 2013 version. These controls are organised into four domains:
You don’t need to implement all 93 controls. Organisations select relevant controls based on risk and document their decisions in a Statement of Applicability.
ISO 27001 requires certain documented information including:
The documentation required will vary depending on the size, complexity and risk profile of your organisation.
Implementation timelines vary based on your starting point and resources. The average timeline for UK SMEs is around 3-6 months. With Citation ISO Certification’s consultancy support, many UK SMEs achieve certification within 45 days.
Our expert consultants guide UK businesses through every stage of ISO 27001 implementation. From gap analysis to successful certification, we make information security management straightforward.