Sentrix

Resources · Article

ISO 27001:2022 clauses that lead to certification

It is clauses 4 through 10, not Annex A, that determine whether you get ISO 27001 certified. The seven certifiable clauses in plain language, for the audit.

By Sentrix · Published 2026-07-15

In short

ISO/IEC 27001:2022 has two main parts. Clauses 4 to 10 set out the mandatory requirements: they describe the information security management system (ISMS) your organization has to build and keep running. Annex A is a catalogue of 93 security controls the ISMS selects based on its risks. Certification is earned by demonstrating compliance with the clauses; that is the heart of the audit. This article walks through each of the seven certifiable clauses, in plain language, with what the auditor is actually looking for.

Clauses or Annex A? The distinction that changes everything

In plain language: you do not get certified "against Annex A." You get certified against clauses 4 through 10. Annex A is a toolbox the ISMS draws from to address its own risks.

Clauses 4 to 10Annex A
Mandatory, auditable requirementsCatalogue of reference controls (93 controls)
Describe the ISMS: how you manage securityDescribe controls: what to put in place
Written with "shall", not negotiableSelected through the Statement of Applicability (SoA)
The heart of the certification auditJustified (included or excluded) based on risk

Clauses 0 to 3 (introduction, scope, normative references, terms and definitions) are part of the standard but contain no auditable requirements. The certifiable requirements start at clause 4.

The thread that ties it together: the PDCA cycle

The seven clauses are not an arbitrary list: they follow the Plan-Do-Check-Act (PDCA) continual-improvement logic shared by every ISO management-system standard. Understanding this cycle helps you see how the clauses connect, rather than memorizing them one by one.

  • Plan (clauses 4 to 6). Understand your context, secure leadership commitment, and set objectives and risk treatment.
  • Do (clauses 7 and 8). Provide resources and competence, then run the system day to day.
  • Check (clause 9). Measure, audit internally, and review with leadership.
  • Act (clause 10). Correct gaps and improve continually.

The complete clause map

Every clause and sub-clause below links to its own page in the ISO 27001:2022 clause guide. Use this list as a standing table of contents for the whole standard.

The 7 certifiable clauses, in plain language

Clause 4 · Context of the organization

Before building anything, you have to understand who you are, what surrounds you, and what your interested parties expect. This clause asks you to identify internal and external issues relevant to your information security, map the parties whose expectations matter (clients, regulators, shareholders), and use that understanding to draw the boundaries of your ISMS: which systems, sites, and services it actually covers. Read the full breakdown of clause 4.

Clause 5 · Leadership

An ISMS that top management does not actively own is a documentation exercise, not a management system. This clause requires visible leadership commitment, a published information security policy, and clearly assigned roles and responsibilities, so accountability for security does not sit with a single person by default. Read the full breakdown of clause 5.

Clause 6 · Planning

This is where risk assessment and treatment happen: identifying risks to your information assets, evaluating them, and deciding how to address them. It also covers setting measurable security objectives and producing the Statement of Applicability (SoA), the document justifying which of the 93 Annex A controls you include or exclude, and why. Read the full breakdown of clause 6.

Clause 7 · Support

The ISMS needs resources to run: people with the right competence, staff who are aware of their security responsibilities, a communication plan for security matters, and, crucially for the audit, properly controlled documented information (policies, procedures, records) that is current, approved, and accessible to the people who need it. Read the full breakdown of clause 7.

Clause 8 · Operation

This is where planning turns into practice: executing the risk treatment plan, controlling operational changes so they do not introduce new gaps, and re-running risk assessments at planned intervals or when significant changes occur. It is the clause auditors use to check that the ISMS is actually operating, not just documented. Read the full breakdown of clause 8.

Clause 9 · Performance evaluation

You have to prove the ISMS works, not just claim it does. This clause requires ongoing monitoring and measurement of security performance, a formal internal audit program covering the whole ISMS on a planned cycle, and a documented management review where leadership examines results and decides what needs to change. Internal audit findings here are usually the single best predictor of how the certification audit will go. Read the full breakdown of clause 9.

Clause 10 · Improvement

When something does not conform, a control fails, an audit finds a gap, an incident exposes a weakness, this clause requires you to react, correct it, and address the root cause so it does not recur. Combined with clause 9, this is what makes the ISMS a living system rather than a one-time project: nonconformities get logged, treated, and closed, and the cycle starts again. Read the full breakdown of clause 10.

The mandatory documents the clauses require

Certain clauses explicitly require documented information. An auditor will systematically ask for these. The main ones:

  • The ISMS scope (clause 4.3)
  • The information security policy (clause 5.2)
  • The risk assessment and treatment process (clause 6.1)
  • The Statement of Applicability, SoA (clause 6.1.3)
  • The information security objectives (clause 6.2)
  • Evidence of competence (clause 7.2)
  • Documented information necessary for operation (clause 8.1)
  • The results of risk assessment and treatment (clauses 8.2, 8.3)
  • Evidence of monitoring and measurement (clause 9.1)
  • The internal audit program and results (clause 9.2)
  • The results of management reviews (clause 9.3)
  • Nonconformities and corrective actions (clause 10.2)

How to use this guide

  • You are new to the standard. Read the clauses in order: they tell a story, from context (4) to improvement (10).
  • You are preparing for the audit. Focus on clause 9 (internal audit, management review) and the mandatory documents list above.
  • You came from Annex A. Remember that controls are worthless without the ISMS these clauses describe.

From requirements to certification

Understanding the clauses is the starting point; building a compliant ISMS and proving it at audit is the real work. The ISO 27001 compliance service supports you from structuring the ISMS through to the certificate, and the ISO 27001 framework page summarizes what the standard requires.

Sources

Frequently asked questions

What are the mandatory clauses of ISO 27001?
Clauses 4 through 10 contain the mandatory, auditable requirements: context of the organization, leadership, planning, support, operation, performance evaluation and improvement. Clauses 0 to 3 (introduction, scope, normative references, terms and definitions) are part of the standard but contain no auditable requirements. Certification is therefore assessed against the seven clauses 4 to 10.
What is the difference between the clauses and Annex A?
Clauses 4 to 10 describe the information security management system (ISMS) and are mandatory: they say how the organization manages security. Annex A is a catalogue of 93 security controls from which you choose the ones that address your risks, through the Statement of Applicability; every inclusion or exclusion must be justified. Certification covers the clauses, not Annex A.
Can a clause be excluded?
No. Unlike Annex A controls, which can be excluded with justification in the Statement of Applicability, the requirements of clauses 4 through 10 are all mandatory and apply to every organization seeking certification, whatever its size, sector or scope. You cannot remove a clause from your certification scope.
What is the PDCA cycle in ISO 27001?
PDCA (Plan, Do, Check, Act) is the continual-improvement logic shared by every ISO management-system standard and it structures the clauses: plan (clauses 4 to 6, context, leadership, planning), do (clauses 7 and 8, support and operation), check (clause 9, performance evaluation) and act (clause 10, improvement). Understanding this cycle helps you see how the clauses connect.

Let's talk about your compliance program.

Last updated: 2026-09-17