ISO 27001 in plain language: what it is and what it asks of a software supplier
6 min read Last checked on
ISO 27001 is the international standard for information security, in its current version since October 2022. It consists of requirements for a management system in clauses 4 to 10 and an annex, Annex A, with 93 controls in four themes. Certificates against the 2013 version have not been valid since 31 October 2025.
ISO 27001 is the international standard for managing information security, and its current version was published in October 2022. The standard has two parts: requirements for a management system in clauses 4 to 10, and an annex of 93 controls, Annex A. An organisation can choose to be certified against it by an accredited certification body.
What an information security management system is and how its parts connect is covered in the article on the ISMS. This article is about the standard itself, and about what it concretely asks of an IT or software supplier.
Why a software supplier runs into it
A SaaS company, a hosting provider or a supplier of healthcare software processes its customers' information. Those customers want to know that this is done with care, and a certificate is an answer they recognise. That is why ISO 27001 keeps coming up in tenders, supplier questionnaires and contracts with healthcare and public sector organisations.
The standard does not prescribe technology. It asks you to know your risks, choose deliberately what you do about them and be able to show that it works. Two companies with the same certificate can therefore have quite different controls.
The 2022 version and the transition
| What | Date or fact |
|---|---|
| Publication of ISO/IEC 27001:2022 | 25 October 2022 |
| Dutch edition | NEN-EN-ISO/IEC 27001:2023 |
| Last initial and recertification audits against the 2013 version | up to and including 30 April 2024 |
| End of the transition period | 31 October 2025 |
| Climate change amendment | Amendment 1:2024 |
After 31 October 2025, all certificates against the 2013 version expired or were withdrawn. Anyone holding or seeking a certificate today works with the 2022 version. The 2024 amendment asks you, when looking at context and interested parties (clauses 4.1 and 4.2), to consider whether climate change is a relevant issue for your organisation. For most software companies that is a short, reasoned note.
Clauses 4 to 10 from a software company's point of view
All clauses are mandatory. The table shows, in our own words, what an auditor usually expects to see at a software supplier.
| Clause | What you record | Example at a SaaS supplier |
|---|---|---|
| 4 Context | Scope, interested parties and their requirements | The scope is the platform, the development pipeline and the support team; interested parties are customers, the hosting provider and regulators. |
| 5 Leadership | Policy, roles, management commitment | The CTO owns the ISMS; the board approves the policy and sees the risks. |
| 6 Planning | Risk assessment, risk treatment, objectives, planned changes | Risks around customer data in the production database, with a treatment plan and a Statement of Applicability. |
| 7 Support | Competence, awareness, communication, document control | Onboarding with security training for new developers, version control on policy documents. |
| 8 Operation | Carrying out the plans and reassessing risks when things change | A new sub-processor or a move to another cloud region triggers a fresh risk assessment. |
| 9 Performance evaluation | Measuring, internal audit, management review | An annual internal audit by someone who does not do the work themselves, and a management review that ends in decisions. |
| 10 Improvement | Resolving nonconformities, improving continually | An incident or audit finding gets a root cause analysis and a correction you can point to. |
One of the additions in the 2022 version is clause 6.3: changes to the ISMS are planned rather than made ad hoc. For a growing company adding a second product or a new office to the scope, that is a familiar moment.
Annex A: 93 controls in four themes
Annex A is a list of controls to choose from. The guidance for each control sits in a separate standard, ISO/IEC 27002, which cannot be certified against. The numbering follows four themes:
| Theme | Numbers | Count | Examples for a software company |
|---|---|---|---|
| Organisational | 5.1 to 5.37 | 37 | Policies, suppliers and cloud services, incident management, continuity, legal requirements |
| People | 6.1 to 6.8 | 8 | Screening, confidentiality, training, remote working, reporting events |
| Physical | 7.1 to 7.14 | 14 | Office access, clear desk, equipment off the premises, secure disposal |
| Technological | 8.1 to 8.34 | 34 | Access rights, logging, vulnerability management, backups, secure development, separate environments |
The previous version had 114 controls. Many were merged, and 11 new ones were added. Several of those affect software suppliers directly: information security for the use of cloud services (5.23), configuration management (8.9), monitoring (8.16) and secure coding (8.28).
Two misunderstandings are common. Annex A is not a checklist to work through from top to bottom: you select controls because your risk assessment calls for them. And exclusions are allowed, provided you justify them. A fully cloud-based company with no server room of its own, for instance, excludes part of the physical controls or places them with its hosting provider. Those choices are recorded in the Statement of Applicability.
What the standard asks in practice
For a software company of 10 to 100 people, it usually comes down to four things.
- A sharp scope. The whole company, or only the product customers buy. A smaller scope is quicker to get in order, but customers read on the certificate what it covers.
- Risks in business language. Not "loss of integrity", but "a developer accidentally pushes to production" or "the hosting provider is down for a day".
- Evidence that grows with the work. Pull request reviews, access reviews, backup tests and incident logs are evidence you already produce, as long as you record it.
- An annual cycle. Internal audit, management review and improvement, every year, because the certification body comes back every year too.
From standard to certificate
Certification runs through a two-stage audit by a certification body, followed by annual checks. How that works, what it costs and how to prepare are covered in the articles on certification, cost and the checklist.
Whatever form your ISMS takes, the standard assesses what the organisation does, not which tool it uses. Trustbird records each control once in business language and links it to the clauses and Annex A numbers, with an audit trail an auditor can read for themselves.
Frequently asked questions
What is ISO 27001?
ISO/IEC 27001 is the international standard that sets out what an information security management system must meet. An organisation can have a certification body assess it against the standard.
Which version of ISO 27001 applies now?
The 2022 version, published in the Netherlands as NEN-EN-ISO/IEC 27001:2023, with a small 2024 amendment on climate change. Certificates against the 2013 version expired or were withdrawn after 31 October 2025.
How many controls are in Annex A?
93, grouped into four themes: organisational (37), people (8), physical (14) and technological (34). The 2013 version had 114.
Do I have to implement all 93 controls?
No. You select controls based on your risk assessment and record in the Statement of Applicability which ones you apply and why you exclude others. Clauses 4 to 10, however, are all mandatory.
Is ISO 27001 certification mandatory?
No, certification is voluntary. In practice customers often ask for it, for example in tenders or in contracts with healthcare and public sector organisations.
Read next
ISO 27001
Internal audit and management review without the theatre
Read more
Management system and policy
What an ISMS is, and why a spreadsheet stops at the second standard
Read more
ISO 27001
ISO 27001 certification: steps, timeline and who does what
Read more
ISO 27001
ISO 27001 checklist for IT and software companies
Read more
ISO 27001
ISO 27001 controls: the 93 Annex A controls, grouped the way an IT company experiences them
Read more
ISO 27001
What ISO 27001 certification costs in the Netherlands
Read more
ISO 27001
Statement of Applicability: what goes in it and how to keep it current
Read more
Sources
- ISO, ISO/IEC 27001:2022 Information security management systems
- ISO, ISO/IEC 27002:2022 Information security controls
- NEN, frequently asked questions about ISO/IEC 27001 (Dutch)
- NEN, NEN-EN-ISO/IEC 27001:2023/A1:2024 (climate amendment)
- IAF MD 26, transition requirements for ISO/IEC 27001:2022
- Dutch Accreditation Council (RvA), transition to ISO/IEC 27001:2022
Trustbird is being built with two certified design partners, and we are looking for more companies to join them at co-founder pricing.
Become a design partner