ISO 27001, The Complete Guide for 2026

6 min readLast updated By Oliver Stutz

Introduction

In 2026, ISO/IEC 27001 is no longer the voluntary crown on a mature security programme, in many tenders it is a hard barrier to entry. Swiss vendors in SaaS, MedTech, finance and critical infrastructure are routinely asked for the certificate before functionality is even on the table. At the same time, the 2022 revision has visibly modernised the standard: 93 controls instead of 114, four new themes (threat intelligence, cloud security, ICT readiness for business continuity, information deletion) and a new Annex A structure across four domains.

This guide condenses what we have learned from more than 200 ISO projects. It covers:

  • History and the logic of the 27000 family
  • The 2022 revision and the transition deadline of 31 October 2025
  • The mandatory clauses 4 to 10
  • The 93 Annex A controls in four theme blocks
  • The certification path with Stage 1, Stage 2 and surveillance audits
  • Integration with DSG, GDPR, NIS2 and DORA

Throughout we refer to the Swiss accreditation landscape (SAS-accredited certification bodies) and we name the effort ranges that SMEs and mid-market firms should realistically plan for.

History and logic of the standard family

ISO/IEC 27001 originates from the British standard BS 7799, which in 1995 first documented standardised security practice and became an ISO standard in 2005. Since then it has been the global reference for Information Security Management Systems (ISMS). The family now spans more than 50 related standards, including ISO/IEC 27002 (control guidance), ISO/IEC 27005 (risk management), ISO/IEC 27017 (cloud security), ISO/IEC 27018 (PII in the cloud), ISO/IEC 27701 (privacy information management) and ISO/IEC 27036 (supplier security).

The core idea is not a static catalogue of measures but a learning management process. At the centre sits the Plan-Do-Check-Act cycle:

  1. Plan: context, risks, objectives, Statement of Applicability
  2. Do: implement controls, training, supplier management
  3. Check: monitoring, internal audit, management review
  4. Act: corrective actions, continual improvement

That logic is what distinguishes an ISMS from a one-off security initiative. Certification bodies primarily test the functioning of this cycle, not the sheer existence of individual measures. Anyone who turns up at Stage 2 with a fully populated SoA but no operating audit cycle will routinely fail.

The 2022 revision in detail

The ISO/IEC 27001:2022 revision was published in October 2022 and supersedes the 2013 version. The main body (clauses 4–10) was lightly adjusted; the real depth of change sits in Annex A. Instead of 114 controls in 14 domains there are now 93 controls in four theme blocks:

  • A.5 Organisational controls (37)
  • A.6 People controls (8)
  • A.7 Physical controls (14)
  • A.8 Technological controls (34)

Eleven controls are new, among them A.5.7 Threat Intelligence, A.5.23 Information Security for Use of Cloud Services, A.5.30 ICT Readiness for Business Continuity, A.7.4 Physical Security Monitoring, A.8.9 Configuration Management, A.8.10 Information Deletion, A.8.11 Data Masking, A.8.12 Data Leakage Prevention, A.8.16 Monitoring Activities, A.8.23 Web Filtering and A.8.28 Secure Coding. Five new control attributes (control type, information security properties, cybersecurity concepts, operational capabilities, security domains) make filtering and mapping (for example to NIST CSF) much easier.

The transition window ended on 31 October 2025. Since January 2026 all certificates are issued exclusively under the 2022 version. Anyone still holding a 2013 certificate should migrate at the next surveillance audit at the latest.

Mandatory clauses 4 to 10

While Annex A dominates the marketing, auditors decide on pass or fail primarily on clauses 4 to 10. They are not optional and cannot be excluded via the SoA.

  • Clause 4, Context of the organisation: interested parties, internal and external issues, scope definition.
  • Clause 5, Leadership: visible top-management commitment, information security policy, roles and responsibilities.
  • Clause 6, Planning: risk assessment, risk treatment, SoA, security objectives.
  • Clause 7, Support: resources, competence, awareness, communication, documented information.
  • Clause 8, Operation: operational implementation of risk treatment, change control.
  • Clause 9, Performance evaluation: monitoring, internal audit, management review.
  • Clause 10, Improvement: corrective actions and continual improvement.

Audit findings most often hit clause 6 (unclear risk method), 9.2 (no formal internal audit) and 10.2 (corrections without root-cause analysis). Where these are clean, isolated Annex A gaps can usually be downgraded from minor non-conformities to mere observations.

Annex A, 93 controls in four theme blocks

Annex A is not a mandatory checklist but a reference catalogue from which deviation is allowed and justified via the Statement of Applicability (SoA). It is most useful when steered along the four theme blocks:

A.5 Organisational controls (37): policies, roles, supplier security, incident management, business continuity, threat intelligence (A.5.7), cloud security (A.5.23). The largest block, and for most SMEs the one with the heaviest documentation lift.

A.6 People controls (8): background screening, confidentiality agreements, awareness, disciplinary process, remote working. Content rarely fails here, what fails is the proof of actually delivered training.

A.7 Physical controls (14): access control, secure areas, protection against environmental threats, clear desk, physical asset management, physical security monitoring (A.7.4). SMEs running cloud-only setups will argue much of this via provider certificates.

A.8 Technological controls (34): identity and access, cryptography, logging, monitoring (A.8.16), vulnerability management, secure coding (A.8.28), backup, network security, web filtering, data masking, information deletion (A.8.10). For most organisations this is the largest implementation and investment block, especially when endpoint detection, SIEM and IAM are not yet in place.

The certification path

Initial certification in the Swiss SME context typically takes 9 to 14 months from project kick-off to issued certificate. The path breaks into four phases:

  1. Initiation and GAP analysis (months 1–2): scope definition, stakeholder mapping, maturity assessment against all 93 controls and clauses 4–10.
  2. Build-up (months 3–8): select the risk method, identify risks, write the SoA, draft policies and procedures, implement controls, start the awareness programme.
  3. Maturity phase (months 7–10): internal audit by an independent person, management review, corrective actions, evidence of at least one complete PDCA cycle.
  4. Certification audit (months 11–14): Stage 1 as documentation and maturity check, Stage 2 as on-site or hybrid operational implementation test.

After Stage 2 the certificate is issued for three years; surveillance audits take place in years 1 and 2, recertification in year 3. Choose an SAS-accredited certification body (for example SQS, SGS, KPMG Cert, BSI, DNV, TÜV SÜD) where the certificate must be broadly accepted across Switzerland and the EU.

Integration with DSG, GDPR, NIS2 and DORA

The ROI of an ISMS rises sharply when it is run as a central compliance backbone rather than an isolated security silo. The most important interfaces:

DSG (Switzerland): Art. 8 DSG requires appropriate technical and organisational measures. The implementing ordinance DSV concretises this in Art. 1–6 with topics such as access control, data integrity and logging. A certified ISMS meets these requirements without separate documentation.

GDPR: supervisory authorities routinely accept ISO 27001 as evidence for Art. 32 GDPR. For the additional PIMS view (privacy by design, data subject rights), ISO/IEC 27701 extends the ISMS and can be audited by the same auditor in one engagement.

NIS2 directive (EU 2022/2555): the ten minimum measures in Art. 21(2), risk analysis, incident handling, business continuity, supply-chain security, vulnerability disclosure, cryptography, personnel security, access control, multi-factor authentication, encryption, map almost one-to-one to Annex A.5/A.6/A.7/A.8.

DORA (EU 2022/2554): for financial firms, ISO 27001 is not sufficient on its own but is an excellent foundation. ICT risk management (Art. 5–14), incident reporting (Art. 17–23) and ICT third-party risk (Art. 28–30) extend the ISMS with sector-specific duties and are run efficiently inside an Integrated Management System.

How SIDD supports you

SIDD takes companies pragmatically through the full ISO 27001 lifecycle. Our ISMS and ISO 27001 service covers GAP analysis, risk methodology, SoA, policy library, training, internal audit and accompaniment through the certification audit. We work with fixed implementation packages (SME up to 100 FTE, mid-market up to 500 FTE, group) and transparent day rates.

When you also need a permanent CISO function, we step in as external CISO or information security officer, with or without a certification target. For continuous technical assurance we combine the ISMS with penetration tests and vulnerability scans; staff enablement runs through our IT security workshops for SMEs. Arrange an initial baseline call via our contact form or request an offer with a fixed price and effort plan.

Need help putting this into practice? SIDD operates the matching service.
See service →

ISO 27001, The Complete Guide for 2026

INSIGHT

InfoSec
24 May 2026
Oliver Stutz
ISO/IEC 27001 at a glance: the standards family, the 2022 revision, clauses 4 to 10, Annex A, the certification path and links to FADP, GDPR, NIS2, DORA.

Subscribe to our newsletter for free here

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.