ISO Management System Certification

ISO/IEC 27001:2022 - Information Security Management Systems

ISO/IEC 27001:2022 establishes requirements for an Information Security Management System (ISMS) to manage information risks systematically, protecting confidentiality, integrity, and availability.

Standard ISO/IEC 27001:2022
Certified worldwide 96,709
Certificate validity 3 years
Surveillance Annual

Overview

What ISO/IEC 27001:2022 is — and why it matters

ISO/IEC 27001:2022 establishes requirements for an Information Security Management System (ISMS) to manage information risks systematically, protecting confidentiality, integrity, and availability.

It uses a risk-based approach, with Annex A providing 93 controls across 4 themes: organizational, people, physical, technological.

The Standard

What the standard requires

Built on the common ISO “Annex SL” structure, the requirements map to these clauses:

Clause 4

Context – Internal/external issues, interested parties.

Clause 5

Leadership – Policy, roles.

Clause 6

Planning – Risks/opportunities, objectives.

Clause 7

Support – Resources, competence, communication.

Clause 8

Operation – Risk treatment, controls implementation.

Clause 9

Performance – Monitoring, audits, reviews.

Clause 10

Improvement – Nonconformity, continual improvement.

Annex A

Controls selection via Statement of Applicability (SoA).

Getting Ready

What you’ll need to get certified

  • Information asset inventory and risk register; SoA justifying control selection/exclusions; evidence of control effectiveness (e.g., access logs, encryption policies).
  • Incident management procedures with response times; supplier security agreements; awareness training metrics.
  • Internal audits covering ISMS scope; management reviews with risk updates; simulated breach exercises.

The Audit

How ACS-GP certifies your management system

Our audits follow ISO/IEC 17021-1 (requirements for certification bodies) and ISO 19011 (guidelines for auditing management systems).

  1. Compliant with ISO/IEC 17021-1 for ISMS certification and ISO 19011 for cybersecurity audit methods, emphasizing confidentiality.

  2. Process: Stage 1 SoA/risk review; Stage 2 control testing via penetration simulations if applicable; surveillance on threat landscapes.

  3. Auditors certified in CISA/CISM; findings per ISO 19011, with remote options for global teams.

Value Addition Auditing. We assess both efficiency and effectiveness — so your management system becomes a genuine business asset, not just a certificate on the wall — while upholding impartiality, competence and evidence-based findings.

The Payoff

The benefits of certification

What the standard delivers

  • Reduces breach risks by 30-50%, minimizing financial losses (average breach cost $4.45M).
  • Provides regulatory assurance (e.g., GDPR, HIPAA), building trust with clients and partners.
  • Fosters a security-aware culture, improving incident response times by 40%.
  • Enables competitive differentiation in digital markets, with certified firms winning 20% more contracts.

Why certify with ACS-GP

  • IASCB-backed for universal acceptance, including cloud providers.
  • Bundled with ISO 20000 for IT security synergy.
  • ACSGP cyber threat intelligence briefings quarterly.
  • Gap analysis tools tailored to Annex A updates.

Questions

ISO/IEC 27001:2022 certification — FAQs

Who should get ISO/IEC 27001:2022 certified?
Any organisation that wants independent proof its management system meets the standard — to win and reassure customers, satisfy regulators, reduce risk and improve day-to-day performance. It suits businesses of any size, in any sector.
How long does certification take?
It depends on how ready your management system is. Once your documented system is implemented and running, we complete a two-stage initial audit (readiness review, then the certification audit). We’ll give you a clear timeline after understanding your scope and sites.
How long is the certificate valid?
The certificate is valid for three years. Each year we carry out a surveillance audit to confirm your system stays effective, and in year three a recertification audit renews the cycle.
How much does ISO/IEC 27001:2022 certification cost?
Audit time — and therefore cost — depends on your organisation’s size, the number of sites, and the complexity and risk of your processes. Request a quote and we’ll prepare a clear, no-obligation proposal.

Ready to certify to ISO/IEC 27001:2022?

Talk to ACS-GP about certifying your organisation — or explore the other standards we certify against.