ISO 27001 Requirements: Clauses, Controls & Documents
To meet the ISO 27001 requirements, an organization must build an information security management system (ISMS) that satisfies mandatory clauses 4 to 10 of ISO/IEC 27001:2022 and implement the applicable Annex A controls, all supported by a defined set of documented information. These requirements are what an external auditor checks before a company can be certified. This guide breaks down each mandatory clause, the four Annex A control themes, and the specific documents your ISMS must produce and maintain.
ISO/IEC 27001:2022 is the current version of the standard. It replaced the 2013 edition, and the transition period ended on 31 October 2025 — so 2022 is now the only valid version to certify against. If you want a general introduction first, read our overview of the ISO 27001 standard. This page focuses on the concrete, auditable requirements you need to satisfy.
How the ISO 27001 Requirements Are Structured
The standard is split into two parts that work together:
- The main clauses (4–10): the mandatory management-system requirements. Every organization seeking certification must meet all of these. They cannot be excluded.
- Annex A: a reference set of 93 information security controls. You do not have to implement every control, but you must consider all of them and justify what you include or exclude in a Statement of Applicability (SoA).
Together these define what a certifiable ISMS looks like. Below we walk through each part.
Mandatory Clauses 4–10 Explained
Clauses 4 through 10 hold the requirements you must comply with. Clauses 1 to 3 (scope, references, and terms) are informative context and contain no requirements.
Clause 4 — Context of the Organization
You must determine the internal and external issues relevant to your ISMS, identify interested parties (customers, regulators, employees) and their requirements, and define the scope of the ISMS. The scope is a required document that states exactly which parts of the business, locations, assets, and technologies the ISMS covers. A well-drafted scope prevents disputes later in the audit: it tells the certification body precisely what will and will not be assessed, and it stops the ISMS from sprawling beyond what your organization can realistically manage.
Clause 5 — Leadership
Top management must demonstrate commitment to the ISMS. This clause requires a documented information security policy, clearly assigned roles and responsibilities, and evidence that leadership is actively supporting and resourcing the system rather than delegating it entirely.
Clause 6 — Planning
This is one of the most heavily assessed clauses, because it forces you to prove that your controls are driven by real risk rather than guesswork. It requires you to:
- Conduct an information security risk assessment using a defined, repeatable methodology so results are consistent each time you run it.
- Carry out information security risk treatment, selecting controls to address the risks you identify and deciding whether to treat, tolerate, transfer, or terminate each risk.
- Produce a Statement of Applicability (SoA) listing the Annex A controls, whether each is applied, and the justification.
- Create a risk treatment plan and set measurable information security objectives.
Clause 6 also introduces the requirement to plan for changes to the ISMS in a controlled way, so that updates to your systems or business do not silently undermine your security posture.
Clause 7 — Support
Clause 7 covers the resources that keep the ISMS running: competence, awareness, communication, and documented information. You must retain competence records showing that staff with security responsibilities are qualified, and control how documents and records are created, approved, and updated.
Clause 8 — Operation
Here you put the plans from Clause 6 into practice. You operate the processes needed to meet your requirements, perform risk assessments at planned intervals or when significant change occurs, and implement your risk treatment plan. You must keep records demonstrating that these processes were carried out as intended.
Clause 9 — Performance Evaluation
You must monitor, measure, analyze, and evaluate the ISMS. This clause specifically requires:
- Monitoring and measurement results that show whether controls and objectives are effective.
- An internal audit program and documented internal audit results.
- Management review conducted by top management, with recorded outputs and decisions.
For a deeper look at how these evaluations are conducted, see our guide to the ISO 27001 audit.
Clause 10 — Improvement
The ISMS must continually improve. When something goes wrong, you must record the nonconformity, take corrective action, and document what you did to prevent recurrence. This closes the Plan-Do-Check-Act loop that runs through the whole standard.
Annex A Controls (2022)
Annex A of ISO/IEC 27001:2022 contains 93 controls organized into four themes:
- Organizational controls — 37 controls. Policies, roles, supplier relationships, threat intelligence, incident management, and information transfer.
- People controls — 8 controls. Screening, terms of employment, awareness and training, disciplinary process, and responsibilities after termination.
- Physical controls — 14 controls. Secure areas, equipment protection, physical entry, clear desk and clear screen, and secure disposal.
- Technological controls — 34 controls. Access control, cryptography, secure development, malware protection, logging and monitoring, and network security.
You review every control against your risk assessment and document your decisions in the Statement of Applicability. Controls that address your risks are implemented; controls you exclude must have a stated reason. The 2022 restructure reorganized the controls into these four themes and added new controls covering areas such as threat intelligence, information security for cloud services, and secure coding — reflecting how the threat landscape has changed since the previous edition.
It is worth stressing what Annex A is not: it is not a checklist you tick off in isolation. Each control only earns its place in your ISMS because a risk justified it. This is why the risk assessment in Clause 6 and the Annex A controls are so tightly linked — the assessment tells you which controls you need, and the SoA records that reasoning for the auditor.
ISO 27001 Documentation Requirements
A common question is which documents are mandatory. Auditors expect to see the following documented information as evidence that your ISMS meets the requirements:
- ISMS scope (Clause 4).
- Information security policy (Clause 5).
- Information security risk assessment process and its results (Clause 6).
- Information security risk treatment process (Clause 6).
- Statement of Applicability (Clause 6).
- Risk treatment plan (Clauses 6 and 8).
- Information security objectives (Clause 6).
- Competence records (Clause 7).
- Monitoring and measurement results (Clause 9).
- Internal audit program and audit results (Clause 9).
- Management review results (Clause 9).
- Nonconformity and corrective action records (Clause 10).
Beyond these, you keep whatever additional records your own processes and selected Annex A controls generate — for example access logs, training records, or supplier agreements. Think of this list as your core ISO 27001 documentation checklist.
A Simple ISO 27001 Requirements Checklist
Use this as a high-level starting point when preparing your ISMS:
- Define and document the ISMS scope.
- Secure leadership commitment and publish an information security policy.
- Choose a risk assessment methodology and complete a risk assessment.
- Produce a risk treatment plan and Statement of Applicability.
- Implement the applicable Annex A controls.
- Set measurable security objectives and assign competent people.
- Run internal audits and a management review.
- Record nonconformities and corrective actions.
- Undergo the certification audit with an accredited body.
Common Challenges in Meeting the Requirements
Organizations most often struggle with the same handful of requirements:
- Scope that is too broad or too vague. An unclear scope makes the whole ISMS harder to run and expands the audit unnecessarily.
- A risk assessment that does not connect to controls. Auditors look for a clear line from each identified risk to the control that treats it. Missing that traceability is a frequent nonconformity.
- Documentation that exists but is not maintained. A policy written once and never reviewed does not satisfy the intent of the standard. Records must reflect current practice.
- Weak evidence for Clause 9. Internal audits and management reviews are mandatory, yet many organizations under-document them. Keep dated records of what was reviewed and what was decided.
- Treating certification as a one-time project. Clause 10 requires continual improvement, and surveillance audits check that the ISMS keeps evolving.
Addressing these early makes the certification audit far smoother and reduces the risk of findings that delay your certificate.
How the Requirements Lead to Certification
Meeting these requirements is what makes an organization ready for a certification audit. Note that ISO 27001 is certified to organizations, not to individuals — professionals earn qualifications through training, but the certificate belongs to the company. To understand the assessment stages, review our ISO 27001 certification process and the broader ISO audit procedure. Organizations ready to move forward can explore ISO 27001 certification in the USA.
How IAS Supports Your ISO 27001 Journey
Integrated Assessment Services (IAS) provides ISO 27001 certification within its applicable UQAS accreditation scope. Where a JAS-ANZ-accredited certification route is applicable, IAS supports certification through its group company Empowering Assurance Systems (EAS). For ISO 27001 lead auditor training, IAS markets applicable CQI and IRCA Certified courses in association with EAS; EAS evaluates candidate eligibility, conducts the training and assessment, and manages the applicable course certification. For ISO 27001 internal auditor training, the course and certificate should be described according to the specific programme being offered. Contact us to confirm the applicable route.


