Skip to main content
ISO/IEC 27001:2022 · ISMS

Win international tenders with an ISO 27001 audit you are ready for.

Tenders and global buyers increasingly name ISO 27001. Summit runs gap analysis, penetration testing and control validation so your technical controls arrive at the assessor with evidence, and stays with you through audit queries.

Human-led VAPT · NDA first · report in 48h

93
Annex A controls in the 2022 version
4
control themes: organizational, people, physical and technological
3
years a certificate is valid, with yearly surveillance audits
7
mandatory management-system clauses (clauses 4 to 10)
Board and leadership view

Why ISO 27001 matters to your board

The work is technical. The consequences of getting ISO 27001 wrong show up in revenue, liability and reputation, which is why we report on it in the language of the boardroom first.

Access to tenders and contracts

Buyers in Europe, the Middle East and Asia often name ISO 27001 in tenders. Without it you may not be shortlisted.

Regulatory and contractual exposure

A managed risk register and tested controls show leadership has governed information risk, not just delegated it.

Reputation and trust

An independently audited management system tells customers that security is run as a discipline.

Deadlines and ownership

Stage 1 and Stage 2 dates are fixed. Named owners and a dated plan keep the audit on schedule.

Fit

Who usually needs ISO 27001

Companies selling internationally

Buyers in Europe, the Middle East and Asia often name ISO 27001 specifically in tenders.

Regulated and public-sector suppliers

Government and enterprise contracts commonly require an ISMS with an independent certificate from suppliers.

Cloud and software providers

A certificate can answer many security questionnaire lines in one document.

Outsourcing and service firms

If you handle client information, certification shows structured, audited control.

Scope of work

What Summit delivers for ISO 27001

One accountable team takes you from scoping to retest. The people who test your systems are the people who explain the findings to your leadership.

Gap analysis

Your ISMS and Annex A controls compared with the standard, with a prioritised list of what is missing.

Penetration testing

Human-led testing supporting Annex A 8.8 and 8.29 on the systems in scope.

Control validation

Technical checks that configuration, access and logging controls work as documented.

Evidence pack

Test reports and fix records organised for the Statement of Applicability and assessor requests.

Remediation support and retest

Practical fix guidance, then a retest and confirmation letter.

Board-ready report

Risk and progress in language executives can use for management review.

Fixed scope, one team, no hand-offsYou get a named lead, a clear scope document before work starts and a report your leadership, customers and reviewers can read without a translator. We stay with you through your review to answer questions about what we tested and found.
How it works

A realistic ISO 27001 roadmap

Timelines are typical ranges, not promises. Yours depends on scope, team size and how much is already in place.

  1. 1

    Define scope and context

    Weeks 1 to 2

    Decide which products, locations and teams the ISMS covers and who sponsors it at leadership level.

  2. 2

    Assess risk

    Weeks 3 to 6

    Identify assets, threats and weaknesses, then rate and prioritise the risks.

  3. 3

    Select and implement controls

    Months 2 to 5

    Write the Statement of Applicability and put the chosen Annex A controls in place.

  4. 4

    Test your controls

    Month 4 to 5

    Run penetration testing and an internal audit to prove technical controls work.

  5. 5

    Management review

    Month 5 to 6

    Leadership reviews results, risks and resources and signs off.

  6. 6

    Certification audit

    Months 6 to 9

    Stage 1 reviews documents, Stage 2 tests operation, then the certificate is issued.

Deliverables

What your leadership team receives

Every engagement ends with material written for two audiences: a plain-language view for executives and the board, and full technical detail for the engineers who fix things.

  • An executive summary

    Where the ISMS stands and which risks matter most to the business.

  • Management review inputs

    Test results and risk data formatted for the review leadership must hold.

  • A dated audit roadmap

    Milestones from scope to Stage 2 with named owners.

  • Technical evidence for assessors

    Reports, scope notes and retest confirmation ready to share.

  • Support through audit queries

    The same Summit team stays with you while assessors ask follow-ups.

The detail

What ISO 27001 actually is

ISO/IEC 27001 specifies the requirements for an Information Security Management System (ISMS): a structured way to find risks to your information, decide how to treat them and keep improving. Unlike SOC 2, it leads to a certificate issued by an accredited certification body.

The standard has two halves. Clauses 4 to 10 describe the management system itself: context, leadership, planning, support, operation, performance evaluation and improvement. Annex A lists 93 reference controls in four themes. You select the controls that apply based on your risk assessment and record the decision in a Statement of Applicability (SoA).

Certification runs in a three-year cycle. A Stage 1 audit reviews your documentation, Stage 2 tests that the system works, and surveillance audits follow each year. The 2013 edition was withdrawn from certification after the October 2025 transition deadline, so new work should follow the 2022 version.

Key terms in plain English

ISMS
Information Security Management System: the policies, processes and people that manage information security risk.
Statement of Applicability
A document listing every Annex A control, whether it applies, why, and how it is implemented.
Risk treatment plan
How each identified risk will be reduced, accepted, avoided or transferred, with owners and dates.
Surveillance audit
A lighter yearly audit between certification and recertification to confirm the ISMS still works.
Requirements

What the standard asks for

The clauses read like a management system; Annex A reads like a control catalogue. Here is each part in plain language.

4–5

Clauses 4 and 5: context, scope and leadership

You define what is in scope, who your interested parties are and what they expect. Top management must own the ISMS, set an information security policy and assign roles.

What it looks like in practice

  • A clear ISMS scope statement
  • A policy approved by senior management
  • Named roles and responsibilities
6

Clause 6: risk assessment and treatment

This is the engine of the standard. You identify information security risks, rate them with a consistent method, choose treatments and set measurable objectives.

What it looks like in practice

  • A repeatable risk methodology
  • A risk register with owners
  • A treatment plan that links to Annex A controls
7–8

Clauses 7 and 8: resources, competence and running the controls

Support covers people, awareness, communication and documented information. Operation is where planned controls actually run and risks are re-assessed as things change.

What it looks like in practice

  • Training and awareness records
  • Controlled documents and version history
  • Evidence that treatments were carried out
9–10

Clauses 9 and 10: audit, review and continual improvement

You measure the ISMS, run internal audits and hold management reviews. When something fails, you record a nonconformity and fix the cause.

What it looks like in practice

  • An internal audit programme
  • Minutes from management reviews
  • Corrective actions that close out
A.5–A.6

Annex A organizational (37) and people (8) controls

Policies, roles, asset management, supplier relationships, incident management, business continuity, screening, awareness and remote working all sit here.

What it looks like in practice

  • Supplier security reviews
  • An incident response process that has been exercised
  • Background checks and onboarding or offboarding steps
A.7–A.8

Annex A physical (14) and technological (34) controls

Technological controls include access control, cryptography, secure development, logging, vulnerability management and security testing. Physical controls cover premises, equipment and secure disposal.

What it looks like in practice

  • Management of technical vulnerabilities (A.8.8)
  • Security testing in development and acceptance (A.8.29)
  • Logging, monitoring and secure configuration
Where testing fits

How penetration testing supports ISO 27001

ISO 27001 does not prescribe a penetration test every year, but several Annex A controls expect you to identify and manage technical weaknesses and to test security before release. Human-led testing gives assessors objective proof for those controls.

A.8.8

Management of technical vulnerabilities

Obtain information about vulnerabilities, assess exposure and act. Test findings with severity and fix status document the full cycle.

A.8.29

Security testing in development and acceptance

Define and implement testing processes for new or changed systems. A scoped application test supports this directly.

A.8.9

Configuration management

Hardware, software and network configurations must be established and reviewed. Testing shows where defaults or drift remain.

A.5.36

Compliance with policies and standards

Management reviews whether information security is implemented as planned. Independent test results feed that review.

Avoid these

Common ISO 27001 mistakes, and how to avoid them

!

Copying a template ISMS

Assessors look for fit. Policies that do not describe how your team really works fail Stage 2 quickly.

!

Over-scoping the first certificate

Starting with the product and teams customers care about is faster, and you can widen scope later.

!

Writing the SoA last

The Statement of Applicability should come out of the risk assessment, not be filled in at the end to look complete.

!

Skipping the internal audit

Assessors expect to see at least one full internal audit and a management review before certification.

FAQ

ISO 27001 questions, answered

Is ISO 27001 the same as SOC 2?

No. ISO 27001 certifies an ISMS against an international standard and results in a certificate. SOC 2 is an auditor’s attestation report on controls. Many companies pursue both.

How many controls does ISO 27001:2022 have?

Annex A lists 93 controls in four themes. You are not required to implement all of them, but you must justify every exclusion in the Statement of Applicability.

Does ISO 27001 require penetration testing?

The standard does not use that wording, but controls on managing technical vulnerabilities and security testing mean most organisations pursuing ISO 27001 run regular penetration tests.

How long is an ISO 27001 certificate valid?

Three years. In between, the certification body carries out annual surveillance audits, and you recertify at the end of the cycle.

Can we pursue ISO 27001 without a consultant?

Yes, many teams do, but the risk assessment and Statement of Applicability reward experience. Summit can run the gap analysis, testing and retest so your evidence is ready for the assessor.

Ready to get ISO 27001 sorted?

Tell us your scope, your deadline and who is asking. You get a fixed-scope quote in 15 minutes and a named lead from day one.

Get a Quote in 15 mins →