Framework · ISO 27001:2022
ISO 27001:2022: from ISMS to certification in one program
The international standard for information security management systems: clauses 4 to 10, 93 Annex A controls, and a two-stage certification audit.
ISO 27001:2022 is the international reference standard for information security management systems (ISMS), published by ISO and IEC. It applies to any organization, in any sector or region, that wants to demonstrate to regulators, clients and partners that information security is managed systematically and continuously improved. The 2022 revision introduced 11 new controls and reorganized Annex A into four themes: organizational, people, physical and technological controls.
Key facts
- 2022: current revision of the standard, with 11 new Annex A controls.
- 93: Annex A controls, grouped into four themes (A.5 organizational, A.6 people, A.7 physical, A.8 technological).
- Clauses 4 to 10: the management system requirements, from context to improvement.
- Two stages: Stage 1 and Stage 2 certification audit by an accredited body, then annual surveillance audits.
What ISO 27001:2022 requires
ISO 27001 requires a documented management system, a formal risk assessment, application of Annex A controls, and an internal audit program. The certification process requires organizations to define the scope of their ISMS, conduct a risk assessment, select applicable controls, produce a Statement of Applicability, implement and operate the controls, and undergo an accredited external audit. The certification body performs a two-stage audit (Stage 1 and Stage 2) and annual surveillance audits.
- Clauses 4–6: context, leadership, planning; ISMS policy and risk assessment
- Clause 7: support; documented competence, awareness, and communication
- Clause 8: operation; risk treatment plans and operational controls
- Clause 9: performance evaluation; internal audits, management review
- Clause 10: improvement; nonconformities, corrective actions
- Annex A: 93 baseline controls in four themes, each included or excluded in the Statement of Applicability
What Sentrix provides for ISO 27001
ISO 27001:2022 gap assessment
Connect your integrations and Sentrix identifies which Annex A controls are satisfied, which have partial gaps, and which need new evidence. The gap report ranks the remaining work by criticality and estimated effort, and feeds directly into a remediation plan with owners and due dates.
Statement of Applicability (SoA)
Sentrix generates and maintains your Statement of Applicability from your risk assessment and gap analysis data. As evidence arrives, the SoA updates; your certification body gets a document that reflects your real posture, not a six-month-old snapshot.
ISMS scope and risk register
Guided templates for the scope statement, aligned with Clause 4, capture the organizational context, interested parties and assets covered. The risk register supports asset-based and scenario-based methodologies, calculates residual risk after controls are applied and flags risks that exceed the organization's defined risk appetite.
Nonconformity management
Track Stage 1, Stage 2, and surveillance audit nonconformities with deadlines, owners, and evidence attachments. Close findings before they affect your certification status.
Evidence collection and audit readiness
Sentrix connects to the cloud infrastructure, identity providers, and SaaS applications you already operate and pulls configuration evidence on a schedule. Policy documents, penetration test reports, training records, and access review logs are stored against the controls they satisfy, with timestamps and version history.
Certification body workspace
Give your certification body direct read-only access to evidence organized by Annex A control, reducing fieldwork time and review cycles.
Crosswalks
- SOC 2: substantial overlap between the Trust Services Criteria and Annex A; existing SOC 2 evidence is mapped to ISO 27001.
- NIST CSF 2.0: Annex A controls are mapped to the six CSF functions.
- ISO 42001: same Annex SL structure; ISMS clauses 4 to 10 serve as the base of the AI management system.
- TISAX: the VDA ISA questionnaire aligns substantially with ISO 27001.
- TGV: the TGV security domain overlaps with ISO 27001.
- NIS2: ISO 27001 evidence is mapped to the ten Article 21 measures.
- Law 25 and PIPEDA: many Annex A controls address the same data protection outcomes those laws require.
Further reading
The Sentrix ISO 27001:2022 clause guide describes each clause with the evidence the auditor will ask for and the common pitfalls; the ISO 27001 certification support service covers certification preparation. Article: ISO 27001:2022 clauses: the requirements that lead to certification.
See how many ISO 27001:2022 controls you already satisfy.
Frequently asked questions
- What is a Statement of Applicability, and does Sentrix generate it?
- The Statement of Applicability (SoA) records which Annex A controls apply to your organization, which are excluded, and why. It is one of the first documents an ISO 27001 auditor requests. Sentrix generates and maintains it from your live risk assessment and gap analysis data, so your certification body always sees a current document instead of a stale snapshot maintained separately.
- Can our ISO 27001 evidence be reused for SOC 2 or NIST CSF?
- Yes. The Annex A controls overlap substantially with the SOC 2 Trust Services Criteria and the NIST CSF functions. Sentrix maps existing evidence across all active frameworks in your program, so you can add ISO 27001 to a SOC 2 program, or the reverse, without restarting evidence collection from zero. The crosswalk shows the delta that still needs documenting.
- Can our certification body access Sentrix directly?
- Yes. You can give your certification body direct read-only access to evidence organized by Annex A control. The auditor navigates the evidence, each item linked to the control it satisfies and the integration that collected it, which reduces fieldwork time and review cycles compared with emailing documents back and forth.
Related pages
Framework · SOC 2
SOC 2 is a continuous program, not a one-time audit
AICPA attestation framework across five Trust Services Criteria categories, reported as Type I or Type II. Continuous evidence, drift alerts, auditor access.
Framework · NIST CSF 2.0
NIST CSF 2.0: the risk framework your board understands
The NIST Cybersecurity Framework, version 2.0 of 2024: six outcome-based functions, including the new Govern function, that layer on top of your standards.
Framework · ISO 42001
ISO 42001: the first AI management system standard
ISO/IEC 42001:2023: requirements for an AI management system for any organization that develops, provides or uses AI, on the Annex SL structure of ISO 27001.
Framework · TISAX
TISAX: VDA ISA controls, ENX assessment, shared label
The automotive industry's information security standard: VDA ISA questionnaire, three assessment levels, ENX-accredited providers, label valid three years.
Framework · TGV
TGV: four domains, one BCH certification dossier
The BCH/MSSS Trousse globale de vérification for technological products and services in Québec's health and social services network: four evaluation domains.
Framework · NIS2
NIS2: ten measures, management liability, 24-hour warning
The EU network and information security directive: ten minimum measures under Article 21, management body accountability and 24-hour incident early warning.
Let's talk about your compliance program.
Last updated: 2026-09-17
