Sentrix

ISO 27001 guide

ISO 27001:2022 clauses guide

Clauses 4 to 10 are the certifiable requirements of ISO/IEC 27001:2022, the ISMS itself. What each clause asks for, in plain language, and what auditors check.

By Sentrix · Published 2026-07-16

Clauses or Annex A? The distinction that changes everything

In plain language: you do not get certified “against Annex A.” You get certified against clauses 4 through 10. Annex A is a toolbox the ISMS draws from to address its own risks.

Clauses 4 to 10Annex A
Mandatory, auditable requirementsCatalogue of reference measures (93 controls)
Describe the ISMS: how you manage securityDescribe controls: what to put in place
Written with “shall” — not negotiableSelected through the Statement of Applicability (SoA)
The heart of the certification auditJustified (included/excluded) based on risk

Clauses 0 to 3 (introduction, references, terms and definitions) are part of the standard but contain no auditable requirements. The certifiable requirements start at clause 4.

The thread that ties it together: the PDCA cycle

The seven clauses are not an arbitrary list — they follow the Plan-Do-Check-Act (PDCA) continuous improvement logic shared by every ISO management-system standard. Understanding this cycle helps you see how the clauses connect, rather than memorizing them one by one.

  • Plan — clauses 4 to 6: understand your context, secure leadership commitment, and set objectives and risk treatment.
  • Do — clauses 7 and 8: provide resources and competence, then run the system day to day.
  • Check — clause 9: measure, audit internally, and review with leadership.
  • Act — clause 10: correct gaps and improve continuously.

The 7 certifiable clauses, in plain language

Every clause links to its own page, and from there to each of its sub-clauses. Use this guide as a standing table of contents for the whole standard.

Clause 4 · Context of the organization

Before building anything, you have to understand who you are, what surrounds you, and what your interested parties expect. This clause asks you to identify internal and external issues relevant to your information security, map the parties whose expectations matter (clients, regulators, shareholders), and use that understanding to draw the boundaries of your ISMS — which systems, sites, and services it actually covers.

Clause 5 · Leadership

An ISMS that top management does not actively own is a documentation exercise, not a management system. This clause requires visible leadership commitment, a published information security policy, and clearly assigned roles and responsibilities — so accountability for security does not sit with a single person by default.

Clause 6 · Planning

This is where risk assessment and treatment happen: identifying risks to your information assets, evaluating them, and deciding how to address them. It also covers setting measurable security objectives and producing the Statement of Applicability (SoA) — the document justifying which of the 93 Annex A controls you include or exclude, and why.

Clause 7 · Support

The ISMS needs resources to run: people with the right competence, staff who are aware of their security responsibilities, a communication plan for security matters, and — crucially for the audit — properly controlled documented information (policies, procedures, records) that is current, approved, and accessible to the people who need it.

Clause 8 · Operation

This is where planning turns into practice: executing the risk treatment plan, controlling operational changes so they do not introduce new gaps, and re-running risk assessments at planned intervals or when significant changes occur. It is the clause auditors use to check that the ISMS is actually operating, not just documented.

Clause 9 · Performance evaluation

You have to prove the ISMS works, not just claim it does. This clause requires ongoing monitoring and measurement of security performance, a formal internal audit program covering the whole ISMS on a planned cycle, and a documented management review where leadership examines results and decides what needs to change. Internal audit findings here are usually the single best predictor of how the certification audit will go.

Clause 10 · Improvement

When something does not conform — a control fails, an audit finds a gap, an incident exposes a weakness — this clause requires you to react, correct it, and address the root cause so it does not recur. Combined with clause 9, this is what makes the ISMS a living system rather than a one-time project: nonconformities get logged, treated, and closed, and the cycle starts again.

The mandatory documents the clauses require

Certain clauses explicitly require documented information. An auditor will systematically ask for these. The main ones:

How to use this guide

  • You are new to the standard: read the clauses in order — they tell a story, from context (4) to improvement (10).
  • You are preparing for the audit: focus on clause 9 (internal audit, management review) and the mandatory documents list above.
  • You came from Annex A: remember that controls are worthless without the ISMS these clauses describe.

Going further

The ISO 27001 framework page presents the standard, certification and the 93 Annex A controls. For support on the road to certification, see the ISO 27001 compliance service or contact us.

Sources

Frequently asked questions

What are the mandatory clauses of ISO 27001?
Clauses 4 through 10 contain the mandatory, auditable requirements: context, leadership, planning, support, operation, performance evaluation and improvement. Clauses 0 to 3 (introduction, references, terms and definitions) are part of the standard but are not auditable. Certification is therefore assessed against the seven clauses 4 to 10, and against those alone.
What is the difference between the clauses and Annex A?
Clauses 4 to 10 describe the management system (the ISMS) and are mandatory: they say how you manage security. Annex A is a catalogue of 93 security measures from which you choose the ones that address your risks, through the Statement of Applicability. Certification covers the clauses, not Annex A.
Can a clause be excluded?
No. Unlike Annex A controls, which can be excluded with a risk-based justification, the requirements of clauses 4 through 10 are all mandatory and written with shall. You cannot remove a clause from your scope: every one of them is checked during the certification audit.
What is the PDCA cycle in ISO 27001?
PDCA (Plan, Do, Check, Act) is the continuous-improvement logic that structures the standard, shared by every ISO management-system standard: plan (clauses 4 to 6), do (clauses 7 and 8), check (clause 9) and act (clause 10). Understanding this cycle helps you see how the clauses connect, rather than memorizing them one by one.

Let's talk about your compliance program.

Last updated: 2026-09-17