# ISO/IEC 27001:2022, Information Security Guide 2026

> ISO 27001 guide 2026: 93 Annex A controls, ISMS build, Stage 1 / Stage 2, costs, mapping to DSG, GDPR and NIS2. Practitioner guide by SIDD.

- Source: https://www.sidd.swiss/en/insights/iso-27001-guide-2026/
- Language: en
- Published: 2026-05-24
- Last updated: 2026-06-18
- Author: Dr. Dominic Staiger
- Publisher: SIDD Institute for Data Protection and Data Security, a brand of Priverion GmbH, Zugerstrasse 32, 6340 Baar (ZG), Switzerland

## What is ISO/IEC 27001:2022?

ISO/IEC 27001:2022 is the international standard for Information Security Management Systems (ISMS). It was published on 25 October 2022 by the International Organization for Standardization (ISO) jointly with the International Electrotechnical Commission (IEC) as a revision of the 2013 edition. The standard sets binding requirements for the establishment, operation, monitoring and continual improvement of an ISMS.

The standard follows the Harmonised High-Level Structure (HLS / Annex SL) for ISO management systems and is therefore structurally aligned with ISO 9001 (quality), ISO 14001 (environment) and ISO 22301 (business continuity). The normative main chapters 4 to 10 (context, leadership, planning, support, operation, performance evaluation, improvement) form the management system in the narrower sense. Annex A contains the reference catalogue of security controls.

Compared to the 2013 predecessor, the 2022 revision reduces the Annex A controls from 114 to 93 and reorganises them into four themes: Organizational (37), People (8), Physical (14), Technological (34). Eleven controls were newly introduced, including Threat Intelligence (A.5.7), Information Security for Cloud Services (A.5.23), ICT Readiness for Business Continuity (A.5.30), Data Masking (A.8.11) and Secure Coding (A.8.28). The transition period for organisations holding certificates under ISO/IEC 27001:2013 expired on 31 October 2025.

ISO/IEC 27001 is the only standard in the 27000 family against which an accredited third-party certification is possible. The standard is YMYL-relevant for any company processing customer data, trade secrets or regulated data, and is, in many procurement processes, particularly in the public sector and for financial service providers, effectively a prerequisite.

## ISO 27001 vs ISO 27002, what is the difference?

ISO/IEC 27001 and ISO/IEC 27002 are two sister standards of the same family but serve different functions. ISO 27001 is the certifiable requirements standard for the management system. ISO 27002 is the non-certifiable guidance for implementing the security controls. The two documents are used together but are legally and audit-wise clearly separated.

**Function.** ISO 27001 contains the binding requirements ("shall") against which an auditor assesses the management system. ISO 27002 contains recommendations ("should") and detailed implementation guidance for each Annex A control, including examples, risk indications and attributes for filtering and reporting.

**Structure.** ISO 27001 comprises the normative chapters 4 to 10 and the normative Annex A with 93 controls. ISO 27002:2022 (published in February 2022) is the detailed companion standard for precisely these 93 controls and introduces four attributes: Control type (preventive, detective, corrective), Information security properties (confidentiality, integrity, availability), Cybersecurity concepts (NIST CSF: identify, protect, detect, respond, recover) and Operational capabilities.

**Certification.** Only ISO 27001 is certifiable. An organisation is certified to ISO/IEC 27001:2022, not to ISO 27002. ISO 27002 is referenced in the audit as an interpretative basis but is not itself the subject of the assessment.

**Practice.** We recommend that every organisation procure both documents in parallel. ISO 27001 structures the management system; ISO 27002 provides the operational implementation depth per control. Further standards in the family, ISO 27005 (risk management), ISO 27017 (cloud), ISO 27018 (personal data in public clouds), ISO 27701 (Privacy Information Management), supplement it depending on the scope of application.

## What is an ISMS (Information Security Management System)?

An Information Security Management System (ISMS) is the systematic framework with which an organisation manages the confidentiality, integrity and availability of its information on a risk-based basis. It comprises policies, processes, roles, resources and controls as well as their continual monitoring and improvement following the Plan-Do-Check-Act cycle (PDCA).

**Demarcation.** An ISMS is not an IT security tool and not a purely technical measure. It is a management system within the meaning of the ISO high-level structure and therefore located at the leadership and organisational level. Technical measures such as firewalls, endpoint detection or encryption are components, but not the essence, of an ISMS.

**Scope.** The scope of application is defined by the organisation itself pursuant to chapter 4.3 of the standard and documented in the Statement of Applicability. It may cover a single business field, a site, a data centre or the entire organisation. The scope is stated in the certificate and is decisive for the effort of certification.

**Core processes.** An ISMS under ISO 27001:2022 requires, as a minimum: context and stakeholder analysis (chapter 4), leadership and policy (chapter 5), risk assessment and treatment (chapter 6), resources, competence, awareness, communication, documented information (chapter 7), operational planning and control (chapter 8), monitoring, measurement, internal audit, management review (chapter 9) as well as improvement and corrective action in the event of nonconformities (chapter 10).

**Effect.** An effective ISMS connects security work with business objectives. It demonstrably reduces risk, creates auditability towards customers and supervisory authorities and enables the clean implementation of statutory requirements such as Art. 8 DSG (data security) or Art. 32 GDPR (security of processing).

## ISO 27001 Annex A: the 93 controls in four themes

Annex A of ISO/IEC 27001:2022 contains 93 security controls organised in four themes. The controls form the reference catalogue against which every organisation aligns its risk treatment. The thematic grouping replaces the 14 domains of the 2013 edition and simplifies mapping to other frameworks such as NIST CSF, CIS Controls and BSI Grundschutz.

**A.5 Organizational controls (37 controls).** The organisational controls form the backbone of the ISMS. They include, among others, information security policies (A.5.1), roles and responsibilities (A.5.2), segregation of duties (A.5.3), Threat Intelligence (A.5.7, new), information security in supplier relationships (A.5.19 et seq.), information security for cloud services (A.5.23, new), incident management (A.5.24 et seq.), ICT Readiness for Business Continuity (A.5.30, new) as well as compliance with legal and contractual requirements (A.5.31 et seq.).

**A.6 People controls (8 controls).** The people controls address the human factor. They range from screening (A.6.1) through terms and conditions of employment (A.6.2), awareness and training (A.6.3), disciplinary process (A.6.4), responsibilities on termination (A.6.5), confidentiality agreements (A.6.6), remote work (A.6.7) to reporting of information security events (A.6.8).

**A.7 Physical controls (14 controls).** The physical controls protect buildings, rooms and hardware. They include security perimeters (A.7.1), physical entry controls (A.7.2), protection against physical and environmental threats (A.7.5), workplace and screen protection (Clear Desk / Clear Screen, A.7.7), secure disposal or reuse of equipment (A.7.14) as well as the security of cabling and supporting utilities.

**A.8 Technological controls (34 controls).** The technological controls form the classic cyber security core: identity and access management (A.8.2 et seq.), privileged access (A.8.2), cryptographic measures (A.8.24), vulnerability management (A.8.8), configuration management (A.8.9), Data Masking (A.8.11, new), Data Leakage Prevention (A.8.12, new), backup (A.8.13), monitoring (A.8.15 f.), Web Filtering (A.8.23, new), Secure Coding (A.8.28, new) as well as separation of development, test and production environments (A.8.31).

The selection, justification and implementation depth of each control must be documented in the Statement of Applicability. A blanket "all 93 implemented" assertion is audit-critical and rarely justifiable in practice.

## Statement of Applicability (SoA), nature and purpose

The Statement of Applicability (SoA) is the central ISMS document that records, for each of the 93 Annex A controls, whether the control is applicable, how it is implemented and, in the case of non-applicability, why it has been excluded. The obligation arises from chapter 6.1.3 lit. d of the standard and cannot be delegated.

**Mandatory content.** The SoA contains, per control: status (applicable / not applicable), justification of selection (typically the risk treatment plan, a legal or contractual requirement, best practice), justification of exclusion (where not applicable) and reference to the implementing document or process. A mere tabular listing without justification is audit-critical and regularly leads to major nonconformities.

**Function.** The SoA is the link between the risk assessment, the risk treatment plan and the operational implementation. It is the first document a certification auditor requests and provides the map for the sample audit in Stage 2.

**Exclusions.** A full exclusion of a control must be justified by the risk profile or the scope. Example: a pure SaaS organisation without its own development can exclude A.8.28 (Secure Coding), provided it develops no software of its own. An SME without cloud usage can exclude A.5.23, which is rarely the case in today's practice. Blanket exclusions on cost grounds are not permitted.

**Versioning.** The SoA is documented information within the meaning of chapter 7.5 of the standard and is subject to strict versioning. Every change to scope, risks or controls triggers an update. We recommend a complete SoA review at least once a year and before each surveillance audit.

## Risk assessment and risk treatment

Risk assessment and risk treatment form, under chapters 6.1.2 and 6.1.3 of the standard, the methodological heart of the ISMS. They define which risks the organisation deems unacceptable and which measures it employs to reduce them. Without a documented, repeatable methodology certification is not possible.

**Methodology.** The standard prescribes no specific method but requires consistency, repeatability and comparability of the results. In Swiss practice, ISO/IEC 27005 (qualitative or semi-quantitative assessment based on likelihood and impact), the BSI Grundschutz model and ENISA-based procedures predominate. For financial institutions, FINMA Circular 2023/1 (Operational Risks and Resilience) often supplements them.

**Steps.** An ISO-conformant risk assessment comprises: identification of assets (information assets) and their protection goals, identification of threats and vulnerabilities, assessment of likelihood and impact, determination of the risk level, comparison with defined risk acceptance criteria as well as prioritisation of the risks.

**Risk treatment (chapter 6.1.3).** For each unacceptable risk a treatment option must be chosen: mitigation through controls from Annex A or supplementary measures, transfer (insurance, outsourcing), avoidance (discontinuation of the process) or conscious acceptance by top management. The selected controls must be documented in the risk treatment plan (RTP) and reconciled with the SoA.

**Residual risk acceptance.** Acceptance of residual risk must be effected and documented formally by the responsible top management. An implicit acceptance "because no measure was taken" is regularly challenged by auditors.

**Frequency.** Risk assessment and treatment must be repeated at planned intervals and on significant changes. A proven approach in practice is an annual full cycle with intra-year updates on new projects, suppliers or threat situations.

## Which mandatory documents does ISO 27001:2022 require?

ISO/IEC 27001:2022 requires a defined set of documented information that must be verifiable in the audit. The standard consistently uses the term "documented information", replacing the older terms "documents" and "records". The obligation is governed by the formulation "shall maintain documented information" in the relevant chapters.

**Core mandatory documents.**

- **Scope of the ISMS** (chapter 4.3).
- **Information security policy** (chapter 5.2), adopted by top management.
- **Information security objectives** and plans for achieving them (chapter 6.2).
- **Risk assessment and risk treatment methodology** (chapters 6.1.2 and 6.1.3).
- **Risk assessment report** containing the identified risks (chapter 8.2).
- **Risk treatment plan** (chapters 6.1.3 and 8.3).
- **Statement of Applicability (SoA)** (chapter 6.1.3 lit. d).
- **Evidence of competence** of the persons assigned with information security (chapter 7.2).
- **Operational planning and control evidence** (chapter 8.1).
- **Results of monitoring and measurement** (chapter 9.1).
- **Internal audit programme and audit reports** (chapter 9.2).
- **Management review minutes** (chapter 9.3).
- **Evidence of nonconformities and corrective actions** (chapter 10.2).

**Annex A additionally yields** policies and procedures, the extent of which depends on the SoA: topic-specific policies on access management, cryptography, backup, supplier relationships, incident management, business continuity, secure development, cloud and awareness. The standard does not require that each topic-specific policy be a separate document, bundling is permitted provided findability and currency are ensured.

**Format.** The standard is media-neutral. Word, wiki, GRC tool or markdown solutions are permitted provided versioning, approval, distribution and protection against unauthorised modification are ensured. We recommend a lean documentation architecture for SMEs with a maximum of three levels: policy, topic-specific policy, work instruction.

## Internal audit and management review

Internal audit and management review are two mandatory evaluation mechanisms of the ISMS under chapters 9.2 and 9.3 of the standard. They must be kept separate, pursue different purposes and are examined in the certification audit as independent evidentiary duties.

**Internal audit (chapter 9.2).** The organisation must conduct internal audits at planned intervals to verify that the ISMS conforms to the requirements of the standard and the organisation's own requirements and is effectively implemented and maintained. Requirements: a documented audit programme with frequency, methods, responsibilities and reporting; selection of auditors who ensure objectivity and impartiality (auditors must not audit their own area of work); reporting to top management; retention of the audit results as documented information.

**Frequency.** The standard prescribes no fixed frequency. A proven approach is a three-year rollout of all controls with a focused annual audit covering at least all normative chapters and one third of the Annex A controls. Before each surveillance audit we recommend a dedicated internal audit as preparation.

**External internal audit.** For SMEs without dedicated internal audit resources, assigning the work to an external auditor is permissible and common in practice. Important: the external auditor must not be identical with the consultant who built the ISMS (separation of consultancy / audit) and must not be identical with the certification body.

**Management review (chapter 9.3).** Top management must review the ISMS at planned intervals. The standard lists the mandatory inputs (status of previous actions, changes in external and internal issues, feedback from interested parties, fulfilment of information security objectives, nonconformities and corrective actions, monitoring results, audit results, risk assessment results, status of the risk treatment plan, opportunities for improvement) and mandatory outputs (decisions on improvements, resource needs, adjustments to the ISMS).

**Frequency.** At least once per year, often half-yearly. The meeting must be minuted, with agenda, participants and resolutions. The minutes are an audit-critical mandatory document.

## The certification process (Stage 1 + Stage 2 + surveillance audits)

ISO 27001 certification is performed by an accredited certification body in a two-stage initial audit (Stage 1 and Stage 2), followed by annual surveillance audits and a recertification audit after three years. The process is standardised in ISO/IEC 17021-1 and is binding for all accredited bodies.

**Preparation phase.** Before the initial audit, the ISMS should be operationally lived for at least three months, with a documented risk assessment, lived processes, at least one internal audit and at least one management review. Certification without this minimum operating period is typically refused by accredited bodies.

**Stage 1 (readiness audit).** The certification body reviews the documentation: scope, policy, risk assessment, SoA, internal audit programme, management review. Stage 1 is usually conducted remotely and identifies gaps before Stage 2. Severe documentation deficiencies lead to a postponement of Stage 2.

**Stage 2 (certification audit).** On-site (or hybrid), the effectiveness of implementation is examined through sampling across all relevant sites and business areas. Examined: policy and objectives, risk management, implementation of the controls under the SoA, awareness of employees, effectiveness of incident and change processes. Findings are documented as Major Nonconformity (NC) or Minor NC. Major NCs must be remediated before the certificate is granted; Minor NCs within an agreed deadline.

**Certificate.** Upon successful audit, the certification body issues the certificate with three years of validity, issued for the defined scope of application.

**Surveillance audits.** In the first and second year following certification, surveillance audits are conducted with reduced scope. Focus: changes in the ISMS, effectiveness of corrective actions, sampling in areas not examined in the initial audit.

**Recertification.** Before the three years expire, a complete recertification audit covering the entire scope is conducted.

**Accredited certification body.** Decisive is the body's accreditation under ISO/IEC 17021-1 by a nationally recognised accreditation authority (in Switzerland: SAS; in Austria: Akkreditierung Austria; in Germany: DAkkS). SIDD works for certification with CIS Cert (Quality Austria Group), an ISO/IEC 17021-accredited body with DACH experience and a Swiss client base.

## ISO 27001 and DSG / GDPR, overlap with data protection

ISO 27001 and data protection law (DSG, GDPR) pursue different but complementary protective goals. ISO 27001 protects information generically by confidentiality, integrity and availability. Data protection law protects personal data and the personality of data subjects. The overlap is substantial, but identity does not exist.

**Art. 8 DSG.** The Swiss Data Protection Act obliges controllers and processors under Art. 8 DSG in conjunction with Art. 1 et seq. DSV to take technical and organisational measures that ensure data security appropriate to the risk (confidentiality, integrity, availability, traceability). An ISO 27001 certification covers these requirements organisationally to a large extent but does not replace the data protection-specific duties such as the records of processing activities (Art. 12 DSG), the information duty (Art. 19 DSG) or the data protection impact assessment (Art. 22 DSG).

**Art. 32 GDPR.** On the EU side, Art. 32 GDPR requires appropriate TOMs taking into account the state of the art, cost of implementation and risk. ISO 27001 is accepted in supervisory practice as a recognised evidence but is not exhaustive, on pseudonymisation, data minimisation and data subject rights the GDPR contains independent requirements.

**ISO 27701.** Those wishing to map the data protection requirements integrated within the ISMS can certify under ISO/IEC 27701 (Privacy Information Management). ISO 27701 is an extension of ISO 27001 and supplements the ISMS with data protection-specific controls for controllers (PII controller) and processors (PII processor).

**FINMA and sector-specific law.** For Swiss financial service providers, FINMA Circulars (in particular 2023/1 Operational Risks and Resilience) refer to recognised standards. ISO 27001 is recognised but is not the sole basis; sector-specific requirements (outsourcing, data residency, notification duties) remain independent. Comparable considerations apply for regulated sectors such as therapeutic products (Therapeutic Products Act), critical infrastructure and electricity.

**Practical recommendation.** Building data protection and ISO 27001 jointly is more efficient than two parallel projects. We dovetail the records of processing activities, TOM documentation, incident response and supplier management via a shared control repository.

## ISO 27001 and NIS2, overlap and divergence

The EU Directive (EU) 2022/2555 (NIS2, Network and Information Security Directive 2) entered into force on 16 January 2023, with Member State transposition required by 17 October 2024. NIS2 obliges essential and important entities in 18 sectors to risk-based cybersecurity management, notification duties and supply-chain security. ISO 27001 is a recognised implementation framework but does not fully cover all NIS2 duties.

**Overlap.** NIS2 Art. 21 requires ten minimum measures (risk analysis and security concepts, incident handling, business continuity, supply-chain security, security in acquisition, effectiveness testing, cyber hygiene and training, cryptography, personnel security and access control, multi-factor authentication). These largely correspond with Annex A, in particular with A.5.7 (Threat Intelligence), A.5.19 et seq. (Supplier Relationships), A.5.24 et seq. (Incident Management), A.5.30 (ICT Readiness for Business Continuity), A.6.3 (Awareness), A.8.5 (Secure Authentication) and A.8.24 (Cryptography).

**Divergence.** NIS2 contains duties that ISO 27001 does not directly map: strict notification deadlines (early warning within 24 hours, incident notification within 72 hours, final report within one month under Art. 23 NIS2), personal liability of management (Art. 20 NIS2), training duty for management as well as registration duties with the national cybersecurity authority.

**Switzerland.** NIS2 does not apply directly to Switzerland. Swiss companies are, however, frequently affected indirectly: as suppliers to EU entities via Art. 21(2)(d) NIS2 (supply chain) or as Swiss subsidiaries of an EU group. For critical infrastructure in Switzerland, the Information Security Act (ISG) additionally applies, with a notification duty to the BACS (Federal Office for Cybersecurity) effective from 1 April 2025.

**DORA.** For financial service providers, the EU Regulation 2022/2554 (DORA, Digital Operational Resilience Act) applies as of 17 January 2025. DORA prevails over NIS2 in the financial sector and requires independently ICT risk management, incident reporting, threat-led penetration testing and ICT third-party risk management. ISO 27001 supports implementation but does not replace the DORA regime.

## Cost and duration of an ISO 27001 certification

The costs and project duration of an ISO 27001 certification depend strongly on the scope, the number of employees, the maturity of the existing security organisation and the number of sites. Reliable flat-rate figures do not exist; the following ranges serve as orientation for DACH conditions.

**Project duration.** For an SME with 20 to 100 employees and a single site we typically anticipate six to nine months between project start and the Stage 1 audit, plus two to three months until the certificate is granted. Mid-sized organisations with multiple sites or a cloud stack anticipate nine to fifteen months. Group-wide roll-outs take several years.

**Consulting costs.** External consulting (risk assessment, SoA build, policies, internal audit, preparation for Stage 1 / Stage 2) typically lies, depending on scope, for an SME in the range of CHF 40,000 to CHF 120,000. The main cost drivers are scope, number of sites, maturity of the starting situation and tooling selection.

**Certification costs.** The audit costs of the accredited certification body are calculated under IAF MD 5 in audit days, depending on the number of employees and the risk of the activity. For an SME with 50 employees the initial audit (Stage 1 + Stage 2) typically takes three to six audit days. Annual surveillance audits cover approximately one third of the initial audit effort. Daily rates of certification bodies are, depending on the provider, in the mid four-digit Swiss franc range.

**Internal costs.** Frequently underestimated. Personnel costs for the ISMS team, awareness training, tooling, documentation build-up and internal audits can exceed the consulting budget. We recommend planning for at least 0.3 to 0.7 full-time equivalents for ISMS operation on a permanent basis.

**Maintenance costs.** After certification, annual costs are incurred for surveillance audits, ISMS maintenance, internal audit and, where applicable, tool licences. Realistic range for an SME: CHF 25,000 to CHF 50,000 per year, depending on scope.

**Readiness-only.** For organisations that first wish to build a standard-conformant ISMS without a certificate (for example because customer requirements only call for "ISO 27001-aligned"), the effort is reduced by the audit costs and part of the documentation rigour, the operational substance, however, remains the same.

## Common pitfalls in building an ISMS

ISMS projects rarely fail on technical hurdles, frequently on organisational and methodological errors. The following pitfalls are the ones we see most frequently in practice.

**Too broad a scope.** Those who set the scope across the entire organisation without creating the prerequisites for it fail on effort and heterogeneity. We recommend a sharply delineated scope for initial certification (one business area, one site, one product) and a roll-out in follow-on projects.

**Risk assessment as a mandatory exercise.** A risk assessment that is drawn up once and never updated is audit-critical. It must be conducted as a continual process with defined triggers (new suppliers, new systems, incidents, threat intelligence).

**SoA as a mere table.** An SoA without justification of selection and reference to implementing documents will be challenged in the audit. Each control needs status, justification, reference.

**Lacking tone from the top.** Where executive management does not actively live the information security policy, the awareness programme fails. The management review must be led by a member of executive management and not delegated.

**Consultant = internal auditor.** Those who use the external consultant simultaneously as the internal auditor breach the independence requirement of chapter 9.2. Consultancy and audit must be separated in terms of persons.

**Neglect of supplier management.** A.5.19 to A.5.23 (supplier relationships and cloud services) are a focal point in the audit. A mere list of suppliers without risk assessment, contractual duties and periodic review will be challenged.

**Awareness training as a one-off.** Onboarding e-learning does not suffice. Required is a continual, role-specific awareness regime with effectiveness measurement (A.6.3).

**Incident management only on paper.** An incident playbook without a tabletop exercise and without recording of the exercise is assessed in the audit as not effective. At least one documented exercise per year.

**Forgotten vulnerability management duty (A.8.8).** Patch cycles without documented risk assessment of the vulnerabilities and without escalation paths for critical CVEs are a frequent audit finding.

**Underestimation of the transition period.** Organisations holding certificates under ISO/IEC 27001:2013 had to migrate to the 2022 edition by 31 October 2025. Those who missed the deadline lost their certificate and must seek a new certification.

## ISO 27001 compliance checklist for SMEs (10 steps)

The following checklist summarises the steps with which a Swiss small and medium-sized enterprise (SME) builds an ISO/IEC 27001:2022-conformant security organisation. It does not replace individual advice but serves as a structuring aid.

1. **Define the scope (chapter 4.3).** Choose a clearly delineated scope: site, business area, product. Analyse stakeholders and internal / external issues.
2. **Secure top management commitment (chapter 5).** Have the information security policy adopted by executive management, assign responsibilities, provide resources.
3. **Establish risk assessment (chapter 6.1.2).** Choose a methodology (ISO 27005-based), identify assets, assess threats and vulnerabilities, define risk acceptance criteria.
4. **Prepare the Statement of Applicability (chapter 6.1.3 lit. d).** Document all 93 Annex A controls per status (applicable / not applicable), justification and reference.
5. **Implement the risk treatment plan.** Mitigate, transfer, avoid or accept. Have residual risks formally accepted by top management.
6. **Build topic-specific policies and procedures.** As a minimum: access management, cryptography, backup, incident management, supplier management, awareness, business continuity, secure development (where applicable).
7. **Establish awareness and training (A.6.3).** Mandatory onboarding module, annual refresher, role-specific deepening, effectiveness measurement.
8. **Conduct the internal audit (chapter 9.2).** At least one complete internal audit of all normative chapters and one third of the Annex A controls before Stage 1. Auditor independent from the area audited.
9. **Conduct the management review (chapter 9.3).** With defined inputs and documented resolutions. Retain the minutes as a mandatory document.
10. **Select an accredited certification body and plan Stage 1 / Stage 2.** Choose a certification body with sector experience and acceptable regional presence. SIDD works for this purpose with CIS Cert (Quality Austria Group).

## How SIDD supports you towards ISO 27001

SIDD is the data protection and InfoSec brand of Priverion GmbH (Baar/ZG), founded in 2017. We accompany you from scope definition through risk assessment, SoA build, topic-specific policies, awareness and internal audit to audit readiness for Stage 1 and Stage 2. For the accredited certification we work with [CIS Cert (Quality Austria Group)](https://www.cis-cert.com/), an ISO/IEC 17021-accredited certification body with DACH experience. We combine the [ISMS mandate](https://www.sidd.swiss/en/services/iso-27001-isms/) with targeted [penetration testing](https://www.sidd.swiss/en/services/penetration-test/) (Annex A.8.8, A.8.25, A.8.29) and the dovetailing with your [Swiss Data Protection Adviser mandate](https://www.sidd.swiss/en/services/data-protection-advisor-switzerland/) under Art. 10 DSG. Consultancy and audit we keep strictly separated.

## Frequently asked questions

### When did ISO/IEC 27001:2022 enter into force?

The revision was published by ISO and IEC on 25 October 2022. Accredited certification bodies have since offered audits to the new edition. The transition period for organisations holding certificates under ISO/IEC 27001:2013 expired on 31 October 2025; from that date only certificates to the 2022 edition are valid.

### How many Annex A controls does ISO 27001:2022 contain?

93 controls in four themes: Organizational (37), People (8), Physical (14), Technological (34). The 2013 edition contained 114 controls in 14 domains. Eleven controls were newly introduced, including Threat Intelligence (A.5.7), Cloud Services (A.5.23), ICT Readiness for Business Continuity (A.5.30), Data Masking (A.8.11) and Secure Coding (A.8.28).

### Do I have to implement all 93 controls?

No. The risk assessment is decisive. In the Statement of Applicability it is documented per control whether it is applicable and how it is implemented. Non-applicable controls must be excluded with a comprehensible justification. Blanket exclusions on cost grounds are not permitted and lead to audit findings.

### How long is the certificate valid?

Three years. During this period, two annual surveillance audits with reduced scope take place. Before the three years expire, a recertification audit covering the entire scope is required to renew the certificate for a further three years.

### What does an ISO 27001 certification cost for an SME?

It depends on the scope. For an SME with 50 employees and a single site, external consulting costs typically lie between CHF 40,000 and CHF 120,000, and the certification costs of the accredited body lie at three to six audit days for Stage 1 and Stage 2. To these are added internal personnel, training and tooling costs.

### Does ISO 27001 replace DSG compliance?

No. ISO 27001 covers the TOM duties under Art. 8 DSG to a large extent but does not replace the data protection-specific duties such as the records of processing activities (Art. 12 DSG), the information duty (Art. 19 DSG), the data protection impact assessment (Art. 22 DSG) or the notification duty (Art. 24 DSG). Both regimes should be considered in an integrated manner.

### Do I need an external consultant or can I build the ISMS in-house?

Both are possible. SMEs without a dedicated information security team generally benefit from external support, because methodology, SoA logic and audit resilience are experience-driven. Important: the consultant must not simultaneously perform the internal audit or the certification audit. Consultancy and audit must be separated in terms of persons.

### How does ISO 27001 differ from SOC 2?

SOC 2 is a US attestation procedure by the AICPA, not a certification within the ISO meaning. SOC 2 evaluates the effectiveness of controls over a period (Type II) against the five Trust Services Criteria. ISO 27001 certifies a management system against an international standard. In the DACH region and in European B2B procurement, ISO 27001 enjoys significantly higher acceptance.

## Cited legislation and sources

- ISO/IEC 27001:2022
- ISO/IEC 27002:2022
- ISO/IEC 27005:2022
- ISO/IEC 27017:2015
- ISO/IEC 27018:2019
- ISO/IEC 27701:2019
- ISO/IEC 17021-1:2015
- IAF MD 5:2019
- ISO 9001:2015
- ISO 14001:2015
- ISO 22301:2019
- NIST Cybersecurity Framework
- CIS Controls
- BSI IT-Grundschutz
- Art. 8 DSG
- Art. 12 DSG
- Art. 19 DSG
- Art. 22 DSG
- Art. 24 DSG
- Art. 10 DSG
- Art. 1 DSV
- Art. 32 GDPR
- Directive (EU) 2022/2555 (NIS2)
- Art. 20 NIS2
- Art. 21 NIS2
- Art. 23 NIS2
- Regulation (EU) 2022/2554 (DORA)
- FINMA Circular 2023/1
- Information Security Act (ISG)

---

This document is the Markdown rendition of the page linked above. Please cite the HTML URL.
