ISO 27001:2022 is the latest revision. Organizations certified under the 2013 version must transition by October 2025.
Who needs ISO 27001?
Global businesses
Organizations operating internationally, especially in European and APAC markets where ISO 27001 is the standard security expectation.
Enterprise vendors
Companies whose customers require formal certification as part of procurement or vendor assessment.
ISO 27001:2022 Annex A themes
The 2022 revision restructured 93 controls into 4 themes:| Theme | Controls | Examples |
|---|---|---|
| Organizational | 37 | Security policies, roles, asset management, supplier relations |
| People | 8 | Screening, awareness training, disciplinary processes |
| Physical | 14 | Physical entry controls, equipment security, clear desk policy |
| Technological | 34 | Access rights, authentication, encryption, logging, monitoring |
Certification process
Conduct risk assessment
Identify information security risks and define treatment plans using DSALTA’s risk register.
Implement controls
DSALTA maps all 93 Annex A controls. Implement policies, configure technical controls, and collect evidence.
How DSALTA helps
- Pre-built ISMS policies — AI-generated policies covering all Annex A requirements
- Risk register — likelihood × impact scoring with treatment plans (Mitigate, Accept, Transfer, Avoid)
- 93 Annex A controls mapped to evidence requirements
- Statement of Applicability — auto-generated based on your control selections
- Cross-framework mapping — ~70% overlap with SOC 2, significant overlap with GDPR and NIS 2
Frequently asked questions
How long does certification take?
How long does certification take?
Typically 3–6 months for implementation plus the two-stage audit. DSALTA’s pre-built controls and policies accelerate this significantly.
What changed in the 2022 version?
What changed in the 2022 version?
Restructured from 14 domains to 4 themes, added 11 new controls (threat intelligence, cloud security, data masking, etc.), and updated existing controls.
Do I need to certify, or just be compliant?
Do I need to certify, or just be compliant?
You can implement ISO 27001 without certification, but many customers specifically require the formal certificate from an accredited body.
How does it overlap with SOC 2?
How does it overlap with SOC 2?
Approximately 60–70% of controls overlap. DSALTA maps these automatically, so completing one framework accelerates the other.
.png?fit=max&auto=format&n=tsMQJyneJ1xquFUo&q=85&s=4d401cc03b547d99b6f75a6bd170c334)