Skip to main content
New 2026 Ransomware Report: Why Every Year Becomes the Worst Year on RecordRead the Report
BlackKite: Home
Menu
Back to Glossary

ISO 27001

ISO 27001 is an internationally recognized standard for information security management systems, published by the International Organization for Standardization. Certification demonstrates that an organization has implemented a structured, audited approach to managing information security risks and is a common compliance benchmark in vendor due diligence. Black Kite's Compliance Rating maps observed technical controls to ISO 27001 requirements.

The standard doesn't list required technologies. It requires a documented management system, a risk assessment process, and a set of controls a vendor selects and justifies based on its own risk profile. Two ISO 27001-certified vendors can implement very different specific controls and both pass, which is the detail a vendor risk assessment misses if it treats the certificate itself as the finding.

What Does an ISO 27001 Certification Actually Require?

Certification requires an information security management system, plus a documented, risk-based selection of controls from a reference list, not implementation of every possible control. The current version, ISO 27001:2022, organizes its reference controls, known as Annex A, into four themes.

  • Organizational controls, 37 total. Policies, roles, and governance structures around information security.
  • People controls, 8 total. Screening, training, and responsibilities tied to individual staff.
  • Physical controls, 14 total. Facility access, equipment security, and environmental protections.
  • Technological controls, 34 total. Access management, encryption, logging, and other technical safeguards.

A vendor documents which of the 93 controls apply, and why, in a Statement of Applicability. An auditor checks that document against the vendor's actual practice, not against a fixed checklist every certified company must match identically.

How Did the 2022 Revision Change ISO 27001?

The 2022 revision cut the standard's reference controls from 114 to 93 and reorganized them from 14 domains into the four themes used today.

Eleven Controls Are New to This Edition

The 2022 update added controls addressing gaps the 2013 version didn't anticipate, including threat intelligence and cloud services security, reflecting how much the underlying technology environment shifted between revisions.

The 2013 Transition Deadline Has Passed

Organizations had until October 31, 2025 to move from the 2013 version to 2022. A certificate still showing 2013 in its scope statement after that date isn't valid, which makes the certificate's edition and date worth checking, not just its existence.

How Long Does an ISO 27001 Certification Last?

A certification cycle runs three years, with a lighter surveillance audit in between rather than a full re-audit every year.

  • Year one covers the initial Stage 1 and Stage 2 audits and the certificate's issue date.
  • Year two brings a surveillance audit that samples a subset of controls rather than reviewing all 93.
  • Year three combines another surveillance audit with the full recertification audit that renews the cycle.

A vendor's security posture in year two looks very different from what an auditor sampled in year one, which is a gap a risk team relying solely on the original certificate won't see.

What Can an ISO 27001 Certificate Not Tell a Risk Team?

A certificate confirms a management system and a selected set of controls passed an audit; it doesn't confirm every technical exposure in a vendor's environment is closed. Black Kite's 2026 Wholesale & Retail Cyber Risk Report found that 57% of retailers and 53% of wholesalers carried exposure to at least one known exploited vulnerability, a population that plausibly includes vendors holding a current ISO 27001 certificate, since certification audits a documented system and a chosen set of controls rather than scanning for every possible technical gap.

Certification Scope Can Be Narrower Than It Looks

A vendor can certify one business unit or one data center and market the certificate as if it covers the whole company, so the scope statement, not the headline claim, is what a risk team actually needs to read.

How Does ISO 27001 Differ From a SOC 2 Report?

ISO 27001 is a certification against an international management-system standard; a SOC 2 report is an attestation, a CPA firm's opinion on how well specific controls operated over a defined period. A vendor either holds ISO 27001 certification or doesn't, decided against the same global standard regardless of where the vendor operates. A SOC 2 report has no pass or fail; it documents the auditor's findings against trust service criteria the vendor itself selected, and different SOC 2 reports can cover very different scopes even when both say "SOC 2" on the cover. ISO 27001 tends to carry more weight with vendors selling internationally, while SOC 2 remains the more common request from North American buyers. A SIG questionnaire response often references both documents as supporting evidence rather than replacing either one.

What Should a Risk Team Verify Beyond the Certificate Itself?

The organization relying on a vendor's certificate is the one exposed if that certificate turns out to be expired, out of scope, or issued by an unaccredited body, so verification is the risk team's job, not the vendor's claim.

  • Check the scope statement, not just the certificate's existence, to confirm it covers the systems and data actually in scope for the relationship.
  • Confirm the issuing body is accredited and the certificate reflects the current 2022 revision.
  • Pair the certificate with continuous monitoring, an outside-in assessment, or a continuously updated cyber rating, since a certificate reflects the audit date, not today.

A compliance completeness rating captures a related but separate view. It measures how much of a given framework Black Kite was able to evaluate from a vendor's externally facing assets and uploaded documents, which sets the boundary on what any compliance figure can actually speak to.

How Does Black Kite Check ISO 27001 Claims in Practice?

Black Kite automates mapping to ISO 27001 alongside NIST, SOC 2, HIPAA, and PCI DSS, cross-checking those claims against independent, externally observed evidence rather than accepting a certificate at face value. Checking a certificate's scope and currency by hand across hundreds of vendors doesn't scale, which is why that verification runs continuously inside a broader vendor compliance management program, alongside the same questionnaire automation that reads a SIG or a Trust Center document. Technology vendors selling into international markets are often the first to lean on this kind of continuous check, since they're the ones most likely to hold ISO 27001 as their primary credential.

See also: CMMC 2.0: Compliance Made Simpler for DoD Contractors