Sentrix

Framework · ISO 27001:2022

ISO 27001:2022: from ISMS to certification in one program

The international standard for information security management systems: clauses 4 to 10, 93 Annex A controls, and a two-stage certification audit.

ISO 27001:2022 is the international reference standard for information security management systems (ISMS), published by ISO and IEC. It applies to any organization, in any sector or region, that wants to demonstrate to regulators, clients and partners that information security is managed systematically and continuously improved. The 2022 revision introduced 11 new controls and reorganized Annex A into four themes: organizational, people, physical and technological controls.

Key facts

  • 2022: current revision of the standard, with 11 new Annex A controls.
  • 93: Annex A controls, grouped into four themes (A.5 organizational, A.6 people, A.7 physical, A.8 technological).
  • Clauses 4 to 10: the management system requirements, from context to improvement.
  • Two stages: Stage 1 and Stage 2 certification audit by an accredited body, then annual surveillance audits.

What ISO 27001:2022 requires

ISO 27001 requires a documented management system, a formal risk assessment, application of Annex A controls, and an internal audit program. The certification process requires organizations to define the scope of their ISMS, conduct a risk assessment, select applicable controls, produce a Statement of Applicability, implement and operate the controls, and undergo an accredited external audit. The certification body performs a two-stage audit (Stage 1 and Stage 2) and annual surveillance audits.

  1. Clauses 4–6: context, leadership, planning; ISMS policy and risk assessment
  2. Clause 7: support; documented competence, awareness, and communication
  3. Clause 8: operation; risk treatment plans and operational controls
  4. Clause 9: performance evaluation; internal audits, management review
  5. Clause 10: improvement; nonconformities, corrective actions
  6. Annex A: 93 baseline controls in four themes, each included or excluded in the Statement of Applicability

What Sentrix provides for ISO 27001

ISO 27001:2022 gap assessment

Connect your integrations and Sentrix identifies which Annex A controls are satisfied, which have partial gaps, and which need new evidence. The gap report ranks the remaining work by criticality and estimated effort, and feeds directly into a remediation plan with owners and due dates.

Statement of Applicability (SoA)

Sentrix generates and maintains your Statement of Applicability from your risk assessment and gap analysis data. As evidence arrives, the SoA updates; your certification body gets a document that reflects your real posture, not a six-month-old snapshot.

ISMS scope and risk register

Guided templates for the scope statement, aligned with Clause 4, capture the organizational context, interested parties and assets covered. The risk register supports asset-based and scenario-based methodologies, calculates residual risk after controls are applied and flags risks that exceed the organization's defined risk appetite.

Nonconformity management

Track Stage 1, Stage 2, and surveillance audit nonconformities with deadlines, owners, and evidence attachments. Close findings before they affect your certification status.

Evidence collection and audit readiness

Sentrix connects to the cloud infrastructure, identity providers, and SaaS applications you already operate and pulls configuration evidence on a schedule. Policy documents, penetration test reports, training records, and access review logs are stored against the controls they satisfy, with timestamps and version history.

Certification body workspace

Give your certification body direct read-only access to evidence organized by Annex A control, reducing fieldwork time and review cycles.

Crosswalks

  • SOC 2: substantial overlap between the Trust Services Criteria and Annex A; existing SOC 2 evidence is mapped to ISO 27001.
  • NIST CSF 2.0: Annex A controls are mapped to the six CSF functions.
  • ISO 42001: same Annex SL structure; ISMS clauses 4 to 10 serve as the base of the AI management system.
  • TISAX: the VDA ISA questionnaire aligns substantially with ISO 27001.
  • TGV: the TGV security domain overlaps with ISO 27001.
  • NIS2: ISO 27001 evidence is mapped to the ten Article 21 measures.
  • Law 25 and PIPEDA: many Annex A controls address the same data protection outcomes those laws require.

Further reading

The Sentrix ISO 27001:2022 clause guide describes each clause with the evidence the auditor will ask for and the common pitfalls; the ISO 27001 certification support service covers certification preparation. Article: ISO 27001:2022 clauses: the requirements that lead to certification.

See how many ISO 27001:2022 controls you already satisfy.

Contact us

Frequently asked questions

What is a Statement of Applicability, and does Sentrix generate it?
The Statement of Applicability (SoA) records which Annex A controls apply to your organization, which are excluded, and why. It is one of the first documents an ISO 27001 auditor requests. Sentrix generates and maintains it from your live risk assessment and gap analysis data, so your certification body always sees a current document instead of a stale snapshot maintained separately.
Can our ISO 27001 evidence be reused for SOC 2 or NIST CSF?
Yes. The Annex A controls overlap substantially with the SOC 2 Trust Services Criteria and the NIST CSF functions. Sentrix maps existing evidence across all active frameworks in your program, so you can add ISO 27001 to a SOC 2 program, or the reverse, without restarting evidence collection from zero. The crosswalk shows the delta that still needs documenting.
Can our certification body access Sentrix directly?
Yes. You can give your certification body direct read-only access to evidence organized by Annex A control. The auditor navigates the evidence, each item linked to the control it satisfies and the integration that collected it, which reduces fieldwork time and review cycles compared with emailing documents back and forth.

Let's talk about your compliance program.

Last updated: 2026-09-17