Skip to content

ISO 27001 in plain language: what it is and what it asks of a software supplier

6 min read Last checked on

ISO 27001 is the international standard for information security, in its current version since October 2022. It consists of requirements for a management system in clauses 4 to 10 and an annex, Annex A, with 93 controls in four themes. Certificates against the 2013 version have not been valid since 31 October 2025.

ISO 27001 is the international standard for managing information security, and its current version was published in October 2022. The standard has two parts: requirements for a management system in clauses 4 to 10, and an annex of 93 controls, Annex A. An organisation can choose to be certified against it by an accredited certification body.

What an information security management system is and how its parts connect is covered in the article on the ISMS. This article is about the standard itself, and about what it concretely asks of an IT or software supplier.

Why a software supplier runs into it

A SaaS company, a hosting provider or a supplier of healthcare software processes its customers' information. Those customers want to know that this is done with care, and a certificate is an answer they recognise. That is why ISO 27001 keeps coming up in tenders, supplier questionnaires and contracts with healthcare and public sector organisations.

The standard does not prescribe technology. It asks you to know your risks, choose deliberately what you do about them and be able to show that it works. Two companies with the same certificate can therefore have quite different controls.

The 2022 version and the transition

What Date or fact
Publication of ISO/IEC 27001:2022 25 October 2022
Dutch edition NEN-EN-ISO/IEC 27001:2023
Last initial and recertification audits against the 2013 version up to and including 30 April 2024
End of the transition period 31 October 2025
Climate change amendment Amendment 1:2024

After 31 October 2025, all certificates against the 2013 version expired or were withdrawn. Anyone holding or seeking a certificate today works with the 2022 version. The 2024 amendment asks you, when looking at context and interested parties (clauses 4.1 and 4.2), to consider whether climate change is a relevant issue for your organisation. For most software companies that is a short, reasoned note.

Clauses 4 to 10 from a software company's point of view

All clauses are mandatory. The table shows, in our own words, what an auditor usually expects to see at a software supplier.

Clause What you record Example at a SaaS supplier
4 Context Scope, interested parties and their requirements The scope is the platform, the development pipeline and the support team; interested parties are customers, the hosting provider and regulators.
5 Leadership Policy, roles, management commitment The CTO owns the ISMS; the board approves the policy and sees the risks.
6 Planning Risk assessment, risk treatment, objectives, planned changes Risks around customer data in the production database, with a treatment plan and a Statement of Applicability.
7 Support Competence, awareness, communication, document control Onboarding with security training for new developers, version control on policy documents.
8 Operation Carrying out the plans and reassessing risks when things change A new sub-processor or a move to another cloud region triggers a fresh risk assessment.
9 Performance evaluation Measuring, internal audit, management review An annual internal audit by someone who does not do the work themselves, and a management review that ends in decisions.
10 Improvement Resolving nonconformities, improving continually An incident or audit finding gets a root cause analysis and a correction you can point to.

One of the additions in the 2022 version is clause 6.3: changes to the ISMS are planned rather than made ad hoc. For a growing company adding a second product or a new office to the scope, that is a familiar moment.

Annex A: 93 controls in four themes

Annex A is a list of controls to choose from. The guidance for each control sits in a separate standard, ISO/IEC 27002, which cannot be certified against. The numbering follows four themes:

Theme Numbers Count Examples for a software company
Organisational 5.1 to 5.37 37 Policies, suppliers and cloud services, incident management, continuity, legal requirements
People 6.1 to 6.8 8 Screening, confidentiality, training, remote working, reporting events
Physical 7.1 to 7.14 14 Office access, clear desk, equipment off the premises, secure disposal
Technological 8.1 to 8.34 34 Access rights, logging, vulnerability management, backups, secure development, separate environments

The previous version had 114 controls. Many were merged, and 11 new ones were added. Several of those affect software suppliers directly: information security for the use of cloud services (5.23), configuration management (8.9), monitoring (8.16) and secure coding (8.28).

Two misunderstandings are common. Annex A is not a checklist to work through from top to bottom: you select controls because your risk assessment calls for them. And exclusions are allowed, provided you justify them. A fully cloud-based company with no server room of its own, for instance, excludes part of the physical controls or places them with its hosting provider. Those choices are recorded in the Statement of Applicability.

What the standard asks in practice

For a software company of 10 to 100 people, it usually comes down to four things.

  1. A sharp scope. The whole company, or only the product customers buy. A smaller scope is quicker to get in order, but customers read on the certificate what it covers.
  2. Risks in business language. Not "loss of integrity", but "a developer accidentally pushes to production" or "the hosting provider is down for a day".
  3. Evidence that grows with the work. Pull request reviews, access reviews, backup tests and incident logs are evidence you already produce, as long as you record it.
  4. An annual cycle. Internal audit, management review and improvement, every year, because the certification body comes back every year too.

From standard to certificate

Certification runs through a two-stage audit by a certification body, followed by annual checks. How that works, what it costs and how to prepare are covered in the articles on certification, cost and the checklist.

Whatever form your ISMS takes, the standard assesses what the organisation does, not which tool it uses. Trustbird records each control once in business language and links it to the clauses and Annex A numbers, with an audit trail an auditor can read for themselves.

Frequently asked questions

What is ISO 27001?

ISO/IEC 27001 is the international standard that sets out what an information security management system must meet. An organisation can have a certification body assess it against the standard.

Which version of ISO 27001 applies now?

The 2022 version, published in the Netherlands as NEN-EN-ISO/IEC 27001:2023, with a small 2024 amendment on climate change. Certificates against the 2013 version expired or were withdrawn after 31 October 2025.

How many controls are in Annex A?

93, grouped into four themes: organisational (37), people (8), physical (14) and technological (34). The 2013 version had 114.

Do I have to implement all 93 controls?

No. You select controls based on your risk assessment and record in the Statement of Applicability which ones you apply and why you exclude others. Clauses 4 to 10, however, are all mandatory.

Is ISO 27001 certification mandatory?

No, certification is voluntary. In practice customers often ask for it, for example in tenders or in contracts with healthcare and public sector organisations.

Read next

Sources

  1. ISO, ISO/IEC 27001:2022 Information security management systems
  2. ISO, ISO/IEC 27002:2022 Information security controls
  3. NEN, frequently asked questions about ISO/IEC 27001 (Dutch)
  4. NEN, NEN-EN-ISO/IEC 27001:2023/A1:2024 (climate amendment)
  5. IAF MD 26, transition requirements for ISO/IEC 27001:2022
  6. Dutch Accreditation Council (RvA), transition to ISO/IEC 27001:2022

Trustbird is being built with two certified design partners, and we are looking for more companies to join them at co-founder pricing.

Become a design partner