Resources · Article
ISO 27001:2022 clauses that lead to certification
It is clauses 4 through 10, not Annex A, that determine whether you get ISO 27001 certified. The seven certifiable clauses in plain language, for the audit.
By Sentrix · Published 2026-07-15
In short
ISO/IEC 27001:2022 has two main parts. Clauses 4 to 10 set out the mandatory requirements: they describe the information security management system (ISMS) your organization has to build and keep running. Annex A is a catalogue of 93 security controls the ISMS selects based on its risks. Certification is earned by demonstrating compliance with the clauses; that is the heart of the audit. This article walks through each of the seven certifiable clauses, in plain language, with what the auditor is actually looking for.
Clauses or Annex A? The distinction that changes everything
In plain language: you do not get certified "against Annex A." You get certified against clauses 4 through 10. Annex A is a toolbox the ISMS draws from to address its own risks.
| Clauses 4 to 10 | Annex A |
|---|---|
| Mandatory, auditable requirements | Catalogue of reference controls (93 controls) |
| Describe the ISMS: how you manage security | Describe controls: what to put in place |
| Written with "shall", not negotiable | Selected through the Statement of Applicability (SoA) |
| The heart of the certification audit | Justified (included or excluded) based on risk |
Clauses 0 to 3 (introduction, scope, normative references, terms and definitions) are part of the standard but contain no auditable requirements. The certifiable requirements start at clause 4.
The thread that ties it together: the PDCA cycle
The seven clauses are not an arbitrary list: they follow the Plan-Do-Check-Act (PDCA) continual-improvement logic shared by every ISO management-system standard. Understanding this cycle helps you see how the clauses connect, rather than memorizing them one by one.
- Plan (clauses 4 to 6). Understand your context, secure leadership commitment, and set objectives and risk treatment.
- Do (clauses 7 and 8). Provide resources and competence, then run the system day to day.
- Check (clause 9). Measure, audit internally, and review with leadership.
- Act (clause 10). Correct gaps and improve continually.
The complete clause map
Every clause and sub-clause below links to its own page in the ISO 27001:2022 clause guide. Use this list as a standing table of contents for the whole standard.
- Clause 4 · Context of the organization: 4.1 understanding the organization and its context · 4.2 needs and expectations of interested parties · 4.3 scope of the ISMS · 4.4 information security management system
- Clause 5 · Leadership: 5.1 leadership and commitment · 5.2 policy · 5.3 roles, responsibilities and authorities
- Clause 6 · Planning: 6.1 actions to address risks and opportunities (6.1.1 general, 6.1.2 risk assessment, 6.1.3 risk treatment) · 6.2 security objectives · 6.3 planning of changes
- Clause 7 · Support: 7.1 resources · 7.2 competence · 7.3 awareness · 7.4 communication · 7.5 documented information (7.5.1 general, 7.5.2 creating and updating, 7.5.3 control)
- Clause 8 · Operation: 8.1 operational planning and control · 8.2 risk assessment · 8.3 risk treatment
- Clause 9 · Performance evaluation: 9.1 monitoring, measurement, analysis and evaluation · 9.2 internal audit (9.2.1 general, 9.2.2 audit programme) · 9.3 management review (9.3.1 general, 9.3.2 inputs, 9.3.3 results)
- Clause 10 · Improvement: 10.1 continual improvement · 10.2 nonconformity and corrective action
The 7 certifiable clauses, in plain language
Clause 4 · Context of the organization
Before building anything, you have to understand who you are, what surrounds you, and what your interested parties expect. This clause asks you to identify internal and external issues relevant to your information security, map the parties whose expectations matter (clients, regulators, shareholders), and use that understanding to draw the boundaries of your ISMS: which systems, sites, and services it actually covers. Read the full breakdown of clause 4.
Clause 5 · Leadership
An ISMS that top management does not actively own is a documentation exercise, not a management system. This clause requires visible leadership commitment, a published information security policy, and clearly assigned roles and responsibilities, so accountability for security does not sit with a single person by default. Read the full breakdown of clause 5.
Clause 6 · Planning
This is where risk assessment and treatment happen: identifying risks to your information assets, evaluating them, and deciding how to address them. It also covers setting measurable security objectives and producing the Statement of Applicability (SoA), the document justifying which of the 93 Annex A controls you include or exclude, and why. Read the full breakdown of clause 6.
Clause 7 · Support
The ISMS needs resources to run: people with the right competence, staff who are aware of their security responsibilities, a communication plan for security matters, and, crucially for the audit, properly controlled documented information (policies, procedures, records) that is current, approved, and accessible to the people who need it. Read the full breakdown of clause 7.
Clause 8 · Operation
This is where planning turns into practice: executing the risk treatment plan, controlling operational changes so they do not introduce new gaps, and re-running risk assessments at planned intervals or when significant changes occur. It is the clause auditors use to check that the ISMS is actually operating, not just documented. Read the full breakdown of clause 8.
Clause 9 · Performance evaluation
You have to prove the ISMS works, not just claim it does. This clause requires ongoing monitoring and measurement of security performance, a formal internal audit program covering the whole ISMS on a planned cycle, and a documented management review where leadership examines results and decides what needs to change. Internal audit findings here are usually the single best predictor of how the certification audit will go. Read the full breakdown of clause 9.
Clause 10 · Improvement
When something does not conform, a control fails, an audit finds a gap, an incident exposes a weakness, this clause requires you to react, correct it, and address the root cause so it does not recur. Combined with clause 9, this is what makes the ISMS a living system rather than a one-time project: nonconformities get logged, treated, and closed, and the cycle starts again. Read the full breakdown of clause 10.
The mandatory documents the clauses require
Certain clauses explicitly require documented information. An auditor will systematically ask for these. The main ones:
- The ISMS scope (clause 4.3)
- The information security policy (clause 5.2)
- The risk assessment and treatment process (clause 6.1)
- The Statement of Applicability, SoA (clause 6.1.3)
- The information security objectives (clause 6.2)
- Evidence of competence (clause 7.2)
- Documented information necessary for operation (clause 8.1)
- The results of risk assessment and treatment (clauses 8.2, 8.3)
- Evidence of monitoring and measurement (clause 9.1)
- The internal audit program and results (clause 9.2)
- The results of management reviews (clause 9.3)
- Nonconformities and corrective actions (clause 10.2)
How to use this guide
- You are new to the standard. Read the clauses in order: they tell a story, from context (4) to improvement (10).
- You are preparing for the audit. Focus on clause 9 (internal audit, management review) and the mandatory documents list above.
- You came from Annex A. Remember that controls are worthless without the ISMS these clauses describe.
From requirements to certification
Understanding the clauses is the starting point; building a compliant ISMS and proving it at audit is the real work. The ISO 27001 compliance service supports you from structuring the ISMS through to the certificate, and the ISO 27001 framework page summarizes what the standard requires.
Sources
Frequently asked questions
- What are the mandatory clauses of ISO 27001?
- Clauses 4 through 10 contain the mandatory, auditable requirements: context of the organization, leadership, planning, support, operation, performance evaluation and improvement. Clauses 0 to 3 (introduction, scope, normative references, terms and definitions) are part of the standard but contain no auditable requirements. Certification is therefore assessed against the seven clauses 4 to 10.
- What is the difference between the clauses and Annex A?
- Clauses 4 to 10 describe the information security management system (ISMS) and are mandatory: they say how the organization manages security. Annex A is a catalogue of 93 security controls from which you choose the ones that address your risks, through the Statement of Applicability; every inclusion or exclusion must be justified. Certification covers the clauses, not Annex A.
- Can a clause be excluded?
- No. Unlike Annex A controls, which can be excluded with justification in the Statement of Applicability, the requirements of clauses 4 through 10 are all mandatory and apply to every organization seeking certification, whatever its size, sector or scope. You cannot remove a clause from your certification scope.
- What is the PDCA cycle in ISO 27001?
- PDCA (Plan, Do, Check, Act) is the continual-improvement logic shared by every ISO management-system standard and it structures the clauses: plan (clauses 4 to 6, context, leadership, planning), do (clauses 7 and 8, support and operation), check (clause 9, performance evaluation) and act (clause 10, improvement). Understanding this cycle helps you see how the clauses connect.
Related pages
Resources · Article
CPCSC explained for Canadian defence suppliers
Level 1 of the Canadian Program for Cyber Security Certification has been available since April 1, 2026. What Levels 1, 2 and 3 require, and where to start.
Resources · Article
Law 25: the five gaps that persist
Most Law 25 obligations have been in force since September 2023. Five gaps still come up in personal information protection programs; here is how to close them.
Let's talk about your compliance program.
Last updated: 2026-09-17
