HomeKnowledge HubStandards & Frameworks › ISO/IEC 27001:2022

International standard · Standards & Frameworks

ISO/IEC 27001:2022 — the certifiable information security management system standard

ISO/IEC JTC 1/SC 27Edition 3, published 25 October 2022Amendment 1:2024

ISO/IEC 27001 specifies what an information security management system (ISMS) must contain — context, leadership, risk assessment and treatment, controls, monitoring and improvement — and is the standard organisations certify against. For privacy work it is the security foundation most processor contracts, supplier questionnaires and UK GDPR Article 32 conversations end up referring to.

Published by
ISO and IEC, through Joint Technical Committee 1, Subcommittee 27 (Information security, cybersecurity and privacy protection).
Type
Management system standard; certifiable.
Versions and language
Edition 3, published 25 October 2022 (19 pages), English and French. Amendment 1:2024 (“Climate action changes”) is issued free of charge. The 2013 edition and its two corrigenda are withdrawn.
Jurisdiction
International.
Primary audience
CISOs, security and compliance leads, DPOs, internal and external auditors.
Topic tags
information security · ISMS · risk management · certification · UK GDPR Art. 32
Availability
Paid (CHF 155 from ISO at the time of verification); a read-only preview is available on the ISO Online Browsing Platform.

Why it matters

Two things about the 2022 edition are worth knowing before it is cited. First, the structure: the 2022 text follows the harmonised ISO management-system structure, and its Annex A controls were reorganised and renumbered in line with ISO/IEC 27002:2022 — so a control reference written against the 2013 edition will not map one-to-one, and a statement of applicability or a supplier questionnaire that still quotes 2013 control numbers needs the correspondence table before it is carried forward. Second, the amendment: ISO lists Amendment 1:2024 as “climate action changes”; it does not alter the controls.

The UK position. UK GDPR Article 32 does not require ISO/IEC 27001, and certification is not treated by the ICO as proof of compliance. It is, however, the reference most UK processor agreements and supplier due-diligence questionnaires reach for when they ask about “appropriate technical and organisational measures”, which makes the edition and scope of a certificate a practical thing to check rather than a formality. The privacy-specific companion is ISO/IEC 27701:2025, which since its 2025 edition can stand alone as a management system standard but is still written to sit alongside an ISMS.

For UK organisations that held BS 10012, note that BSI’s product record now shows that standard as withdrawn; we are confirming the position with BSI before changing its entry on this list.

A curated reference entry maintained by VulaPri. We summarise and link to the original; we do not reproduce or host it. Listed since 16 June 2026 · last verified 15 September 2026 — facts verified against iso.org. Suggest a correction.