ISO 27001:2022 is now mandatory for many enterprise vendor questionnaires — non-compliance = lost deals
ISO 27001:2022 Compliance Consulting

ISO 27001:2022 is the
global security currency.

Every enterprise procurement questionnaire asks for it. Every global supply chain requires it. ISO 27001 certification signals that your ISMS has been independently audited against the international standard — and increasingly, it's a precondition for the deals your business depends on.

Compliance scope
ISO 27001:2022 Annex A Controls ISMS Build SOC 2 Mapping Gap Analysis Remediation
The standard

93 Annex A controls. 4 themes. One globally recognized ISMS.

ISO/IEC 27001:2022 reorganized Annex A from 114 controls across 14 domains into 93 controls across 4 themes. Understanding how the themes map to your existing security program is the first step in scope and readiness.

Theme 1 · Organizational
Organizational Controls
37 controls · A.5
Information security policies, roles, supplier relationships, incident management
Theme 2 · People
People Controls
8 controls · A.6
Screening, awareness, training, disciplinary process, post-employment
Theme 3 · Physical
Physical Controls
14 controls · A.7
Physical perimeters, entry controls, securing offices, equipment
Theme 4 · Technological
Technological Controls
34 controls · A.8
Access rights, cryptography, malware, backup, logging, development
ISO 27001:2022 changes

What's new. What you're likely missing.

ISO/IEC 27001:2022 was published in October 2022 and replaced the 2013 standard. Organizations already certified had a three-year transition window — that expired in October 2025. If your certificate is still on the 2013 version, it is no longer valid for new enterprise procurement cycles.

Check Your Posture →
New

Annex A Reduced from 114 to 93 Controls

The 2022 revision consolidated 14 control domains into 4 themes and merged overlapping controls. 11 new controls were added. Net reduction of 21 controls, but the new control set is more demanding — particularly in cloud, threat intelligence, and data lifecycle management.

New

Threat Intelligence (A.5.7)

Organizations must now collect and analyze threat intelligence relevant to their ISMS and use it to inform risk assessments and controls. Reactive-only security programs are no longer sufficient — proactive threat-informed defense is now a baseline requirement.

New

Cloud Services Security (A.5.23–A.5.30)

Seven new cloud-specific controls covering information security for use of cloud services, including shared responsibility, supplier agreements, and ongoing monitoring. Organizations that treat cloud as "the vendor's problem" no longer pass an audit.

New

Data Masking, Classification & Leakage Prevention (A.8.10–A.8.12)

Three new controls explicitly require data masking techniques, a documented data classification scheme, and data leakage prevention measures. These were implicit in the 2013 standard — now they are auditable requirements.

New

Information Deletion (A.8.10)

Formalized requirement to securely delete information when no longer needed, including from cloud services, portable devices, and third-party systems. The 2013 standard addressed disposal — 2022 requires demonstrable deletion processes.

Applicability

If you sell to enterprise or operate globally, ISO 27001 is in your future.

ISO 27001 is technically voluntary — no regulator mandates it. But in practice it has become a de facto requirement for enterprise vendor onboarding, global supply chain participation, and certain M&A transactions. These are the buyer profiles driving certification demand today.

Procurement

Enterprise Vendor Onboarding

Large enterprise procurement teams now require ISO 27001 certification as a standard gating criterion in vendor security questionnaires. Without it, SaaS deals stall in InfoSec review or get rejected outright — regardless of the quality of your actual security program.

EMEA / APAC

Global Supply Chain

Multinational customers — particularly in the EU, UK, and Asia-Pacific — routinely require ISO 27001 certification rather than accepting U.S.-centric frameworks like SOC 2. For SaaS companies targeting EMEA enterprise customers, ISO 27001 is effectively required to compete.

FinHealth

SaaS Serving Regulated Industries

Software vendors serving financial services, healthcare, and insurance customers face overlapping certification pressure. ISO 27001 satisfies procurement at the parent enterprise level even where sector-specific frameworks (SOC 2, PCI-DSS, HIPAA) handle the regulated workload.

Capital Mkts

Pre-IPO / M&A Targets

Companies preparing for IPO or considering acquisition routinely pursue ISO 27001 certification pre-event to strengthen their security posture, accelerate due diligence, and increase enterprise valuation. Buyers pay for the operational maturity a certified ISMS represents.

Public Sector

Public Sector & Critical Infrastructure

Government contractors, critical infrastructure operators, and vendors to regulated utilities frequently need ISO 27001 alongside frameworks like NIST SP 800-53 or FedRAMP. Certification supports both commercial and government-sector tenders.

Niche

Cert Bodies and Auditors

Certification bodies, training providers, and security audit firms certify their own ISMS to ISO 27001 as both a marketing signal and a baseline credential requirement. Standard practice in the assurance industry.

Cross-framework mapping

Already working on NIST CSF? You're partway there.

NIST CSF and ISO 27001 share significant conceptual overlap. Organizations with an implemented NIST CSF program frequently find that 50–70% of ISO 27001 Annex A controls are already addressed by their existing controls. Here's how the frameworks map.

NIST CSF Function Description Primary ISO 27001 Annex A Controls Est. Coverage
GV — Govern Organizational context, risk management strategy, supply chain Clause 5 (Context), Clause 6 (Leadership), A.5.19–A.5.23 (Supplier)
~55%
ID — Identify Asset management, risk assessment, improvement planning A.5.9 (Inventory), A.5.12 (Information Classification), A.8.1 (User Endpoint)
~60%
PR — Protect Access control, awareness, data security, platform security A.8.2–A.8.5 (Access), A.8.24 (Cryptography), A.8.9 (Configuration Mgmt)
~70%
DE — Detect Continuous monitoring, anomaly detection A.8.16 (Monitoring Activities), A.8.20 (Networks Security), A.5.7 (Threat Intel)
~60%
RS — Respond Incident management, analysis, communication, mitigation A.5.24–A.5.28 (Information Security Incident Management)
~65%
RC — Recover Recovery planning, communications A.8.13 (Information Backup), A.5.30 (ICT Readiness for Business Continuity)
~50%

What this means for you: If you've already invested in a NIST CSF program — or purchased a Rhodigital NIST Policy Package — a meaningful portion of your ISO 27001 ISMS build is already done. A cross-mapping assessment identifies exactly which Annex A controls your existing program satisfies and which still need dedicated attention, saving weeks of redundant documentation work. See the NIST Policy Package →

How we work

Scoping to certification. A defined process with no surprises.

ISO 27001 certification isn't a single event — it's a structured sequence. We follow a phased engagement model that ends with a Stage 2 certification audit and an issued certificate, not an open-ended consulting relationship.

01
Phase 1 · Week 1–2
Scoping & Gap Analysis

Define the ISMS scope: which business units, systems, processes, and locations are in scope for certification. Interview key stakeholders, review existing policies and controls, document the Statement of Applicability (SoA) baseline. Scope decisions drive audit cost, timeline, and ongoing operational burden — getting them right up front is the most consequential decision in the engagement.

02
Phase 2 · Week 3–10
ISMS Build & Risk Treatment

Build the Information Security Management System: policies, risk assessment methodology, risk treatment plan, controls implementation, monitoring infrastructure, and management review process. For organizations with existing NIST CSF or SOC 2 documentation, this phase is significantly shorter — we adapt existing materials to ISO 27001's specific evidence requirements rather than authoring from scratch.

03
Phase 3 · Week 11–16
Statement of Applicability & Internal Audit

Finalize the SoA documenting applicability and implementation status for all 93 Annex A controls. Conduct internal audits against ISO 27001 clauses 4–10 and the controls in scope. Address nonconformities identified. This phase prepares the organization for the external audit and surfaces any residual gaps before the certification body arrives.

04
Phase 4 · Week 17+
Stage 1 & Stage 2 Certification Audit

The certification body conducts a Stage 1 documentation review (typically remote, 1–3 days) followed by a Stage 2 on-site audit (3–10 days depending on scope). On successful completion, the certification body issues the ISO 27001 certificate — typically valid for 3 years with annual surveillance audits. We support you through both stages and the post-certification maintenance cadence.

ISO 27001 gaps don't close themselves.

Start with a free security posture check. Understand where you stand before your next enterprise procurement cycle.

Frequently asked

Common ISO 27001 questions.

What is ISO 27001 and what changed in the 2022 revision? +
ISO/IEC 27001 is the international standard for Information Security Management Systems. It specifies the requirements for establishing, implementing, maintaining, and continually improving an ISMS. The 2022 revision reorganized Annex A from 114 controls across 14 domains to 93 controls across 4 themes (Organizational 37, People 8, Physical 14, Technological 34). Eleven new controls were added covering threat intelligence, cloud services security, data masking, data leakage prevention, and information deletion. Organizations certified under the 2013 standard had until October 2025 to transition.
Who needs ISO 27001 certification? +
ISO 27001 is typically required for enterprise vendors onboarding to large procurement programs, SaaS companies serving EU/UK/Asia-Pacific regulated customers, suppliers in global supply chains, organizations pursuing pre-IPO or M&A readiness where security certification increases enterprise value, and any business where enterprise customers explicitly require a certified ISMS. Unlike PCI-DSS or HIPAA, ISO 27001 is voluntary — but in many enterprise vendor contexts it has effectively become a de facto requirement to do business.
How long does ISO 27001 certification take? +
A typical first-time ISO 27001 certification engagement runs 6–12 months end to end: scoping and gap analysis (1–2 weeks), ISMS build and risk treatment (4–8 weeks), Statement of Applicability and internal audit (4–6 weeks), Stage 1 documentation audit by the certification body, Stage 2 on-site certification audit, then issuance of the certificate. Organizations with an existing NIST CSF or SOC 2 program typically compress the ISMS build phase by 30–50%.
How does ISO 27001 pair with SOC 2? +
ISO 27001 and SOC 2 are complementary. ISO 27001 is a management-system standard (certification proves your ISMS conforms); SOC 2 is an attestation report (an auditor opines on the design and operating effectiveness of your controls). Roughly 60–80% of SOC 2 Trust Services Criteria map to ISO 27001 Annex A controls. Many organizations pursue SOC 2 first for U.S. enterprise customers and then add ISO 27001 for global/EMEA customers — or run both in parallel using a unified control set. A cross-mapping assessment identifies the shared controls and the framework-specific gaps for each.