When it comes to protecting your business from data breaches, cyber threats, and compliance risks, ISO 27001 is the gold standard. But what exactly is it?
ISO/IEC 27001 is the internationally recognised Standard for managing information security. Certification means your organisation has been formally audited and approved as compliant. Published by the International Organization for Standardization (ISO), the ISO 27001 provides a best-practice framework for putting the right policies, procedures, and controls in place to manage information security risks effectively.
As ISO.org explains: “The ISO/IEC 27001 standard provides companies of any size and from all sectors of activity with guidance for establishing, implementing, maintaining and continually improving an information security management system.”
What sets ISO 27001 apart is its holistic approach. This isn’t just about IT. ISO 27001 is a whole-business approach to information security, helping you manage risks across people, processes, and technology. The Standard helps you prevent, detect, and respond to threats in a structured and proactive way, while also supporting compliance with data protection laws and industry regulations.
Achieving ISO 27001 certification demonstrates a clear commitment to protecting sensitive information, reducing the risk of breaches, and meeting both legal and contractual obligations.
Every organisation handles valuable information – whether it’s customer data, employee records, financial details, or intellectual property. And with 43% of UK businesses hit by a cyber attack in 2024 and ransomware demands averaging £4m (gov.uk), the risks are clear. As cyber threats grow more sophisticated and data protection laws tighten, ISO 27001 has become essential for businesses of all sizes.
This Standard helps:
From SMEs to multinationals, any organisation that collects, stores, or processes data can benefit. It’s especially valuable for:
Whether you’re a startup or a global enterprise, ISO 27001 shows that you take information security seriously.
92% of our clients feel their business is more secure with ISO 27001 in place.
(Based on Client Feedback Survey).
ISO 27001 is built around ten core clauses, covering everything from setting the right leadership direction to managing risk and measuring performance.
The ten clauses of ISO 27001:
Each clause plays a critical role in creating a compliant, strong, and sustainable ISMS. On top of that, ISO 27001 includes Annex A —a detailed list of 93 security controls grouped under four themes: People, Organisational, Physical, Technological. These controls act as a toolbox. You don’t have to use all of them—but you’ll need to assess which ones apply to your business and implement what’s relevant.
Want to explore all 93 controls in more detail? See our full Annex A breakdown here.
In October 2022, the ISO 27001 Standard was updated with several changes to the structure. ISO 27001:2022 is the latest version of the Standard, which replaced the previous version – ISO 27001:2013
The 2022 update streamlined the Annex A controls, reducing the total from 114 to 93 controls, reorganised into four themes:
Use our simple comparison table to see what’s changed.
This modernisation helps businesses stay aligned with emerging cyber risks and cloud-native environments.
| ISO/IEC 27001:2013 | ISO/IEC 27001:2022 | |
|---|---|---|
| Number of controls | 114 | 93 |
| Groupings | 14 categories | 4 themes |
| New controls | Training plans and register including any documentary evidence that training has taken place e.g. a training matrix – Section 4.4.2 | 11 new controls. Includes: Threat intelligence Cloud services ICT readiness for business continuity Physical security Configurations management Information deletion Data masking Data leakage protection Monitoring activities Web filtering Secure coding |
| Use of attributes | Not used | Introduced to help organisations classify and filter controls (e.g. by purpose or type) |
Implementing ISO 27001 typically involves the following steps:
To achieve certification, your organisation must elect an accredited certification body. Certification typically involves:
The certification process typically takes 3–6 months, depending on the size and complexity of your organisation. But with our expert support certification can often be achieved in as little as 45 days.
With over 33,000 certifications issued and a team of 60+ auditors nationwide, we make 27001 certification faster, simpler, and more cost-effective. Here’s why 30,000+ UK businesses trust us:
On average, businesses can achieve certification within 3–6 months, depending on size, complexity, and readiness. Smaller organisations with simpler systems may achieve it faster. With Citation ISO Certification you can achieve certification in as little as 45 days.
Any organisation handling sensitive data — from SMEs to large enterprises — benefits from ISO 27001. It’s especially valuable in sectors like tech, finance, healthcare, legal, and professional services.
Three years, with annual surveillance audits.
Yes. A recertification audit is required every 3 years.
GDPR is a legal requirement that governs how personal data is collected, stored, and processed, while ISO 27001 is a voluntary standard that provides a framework for managing all types of information securely. Achieving ISO 27001 helps demonstrate GDPR compliance, but it goes further by addressing broader information security risks.
No, ISO 27001 isn’t legally required, but it’s often demanded in tenders, contracts, and by regulated industries. Certification proves your commitment to robust information security.
Costs depend on your company’s size, scope, and current security practices. Expenses typically cover consultancy, training, internal resources, and certification audits.
No, ISO 27001 is an organisational certification.
Not at all. It’s about securing information across the whole organisation.