# ISO/IEC 27001

> ISO/IEC 27001 is the internationally recognised standard for an information security management system (ISMS); it is voluntary, but is frequently required by large customers, in tenders and in due-diligence reviews. The current version, ISO/IEC 27001:2022, requires a risk-based management system under chapters 4 to 10 and a justified selection from 93 controls in Annex A. A certificate from an accredited certification body is valid for three years and is confirmed through annual surveillance audits.

- Type: Standard, Market-driven
- Scope: Switzerland, EU, Germany
- As of: 24 September 2026
- Page: https://sacosi.ch/en/norms/iso27001
- Regulatory Check: https://sacosi.ch/en/regulation#normencheck

## When does ISO 27001 apply to you?

- Role towards customers: Supplier (only together with industry or activity) (Likely applies): Large customers and corporate groups increasingly require their suppliers to demonstrate a certified ISMS before entering into a contractual relationship.
- Activity: Public-sector clients (Recommend individual review): Public-sector tenders in many cases require an ISO 27001 certificate or an equivalent ISMS as an eligibility criterion.
- Industry: Aviation (Likely applies): The European Part-IS regulations expressly allow aviation organisations an information security management system based on ISO/IEC 27001; anyone choosing this route needs the standard as a foundation.
- Activity: Special category personal data, AI provider (own AI products) (Recommend individual review): Anyone processing special category data or providing AI systems is frequently asked by customers and investors about a documented information security management system.
- Markets: EU, Germany (only together with industry or activity) (Recommend individual review): In the EU area, an ISO 27001 certificate is a common standard piece of evidence in due-diligence reviews for funding rounds and company sales.

## Exceptions

- No statutory obligation to be certified; an ISMS can also be operated in line with the standard's principles without external certification.
- Micro-enterprises without a contractual requirement from a customer generally have no trigger.

## Obligations

- Build an ISMS meeting the requirements of chapters 4 to 10 (context of the organisation, leadership, planning, support, operation, performance evaluation, improvement)
- Carry out risk assessment and treatment, including a justified selection of which of the 93 controls in Annex A are applied or excluded (Statement of Applicability)
- Conduct internal audits and management review at defined intervals
- Continually improve the ISMS

## Evidence

- Certificate from an accredited certification body following a Stage 1 audit (document review) and Stage 2 audit (implementation review)
- Annual surveillance audits
- Recertification every three years
- Statement of Applicability as an internal evidence document

## Penalties

No fine, since voluntary; in practice: without a valid certificate, exclusion from tenders, loss of large customers, or deductions in due-diligence valuations for investments or company sales are a risk.

## Frequently asked questions

**Does a start-up need to be certified to ISO 27001?**
Not legally. But corporate customers, tenders and investors often ask about it. It makes sense to build your processes early on so that a later certification is a small step, not a rebuild.

**What does an ISO 27001 certificate show, and what doesn't it show?**
It shows that a company operates a functioning, audited information security management system and has made a justified selection of the measures in Annex A. It does not guarantee one hundred percent protection against incidents, but it evidences a structured, repeatedly reviewed approach to risk.

**How long is an ISO 27001 certificate valid?**
Three years, with annual surveillance audits by the certification body; recertification is then required.

**What changes with the 2022 version compared with 2013?**
Annex A was reorganised: instead of 114 controls in 14 categories, there are now 93 controls in four themes (organisational, people, physical, technological).

## Open points of the research

- iso.org responded to direct retrieval in this session with HTTP 403 (bot block); the iso.org URL is kept only as a source reference (source type accordingly 'secondary', since no standard text was read). The facts on Annex A (93 controls, four themes: 37 organisational, 8 people, 14 physical, 34 technological) and on the certification process come from secondary sources (GRC Solutions, ANSI blog search result), not from the ISO original text.
- That Part-IS expressly allows an ISMS 'based on ISO/IEC 27001' is evidenced via the FOCA (BAZL) page, but only as a secondary summary (search result), not as a verbatim reading of the regulation's text.
- Specific thresholds (e.g. number of employees) from which customers require a certificate were not researched and are deliberately not listed as a trigger.

## Sources

- [ISO/IEC 27001:2022 — Information security management systems](https://www.iso.org/standard/27001), ISO, retrieved 24 September 2026
- [ISO/IEC 27001:2022 – Information Security Systems](https://blog.ansi.org/anab/iso-iec-27001-2022-information-security-systems/), ANSI National Accreditation Board (Suchergebnis), retrieved 24 September 2026
- [ISO/IEC 27001:2022 – The Information Security Management Standard](https://grcsolutions.io/guide-to-iso-iec-27001-2022/), GRC Solutions, retrieved 24 September 2026
- [BAZL: EU-Verordnungen zur Informationssicherheit (Part-IS)](https://www.bazl.admin.ch/de/eu-verordnungen-zur-informationssicherheit-part-is), Bundesamt für Zivilluftfahrt (BAZL), retrieved 24 September 2026

---
A professional assessment based on publicly available sources, not legal advice. Whether a given rule applies in your specific case depends on circumstances that are not fully captured here.
Source: SACOSI, Situational Awareness Consulting by Ivo Schönberner (https://sacosi.ch).
