What is ISO/IEC 27001:2022?
The international standard for information security management systems. It is voluntary and certifiable: an accredited body audits your ISMS and issues a certificate with a three-year cycle.
Nobody by law. It is adopted because customers, insurers and tenders ask for it — which in practice makes it as binding as regulation for organisations selling into enterprise or public-sector buyers.
Down from 114 in the 2013 edition, regrouped into four themes.
Organizational, People, Physical, Technological.
Annex A is a reference set you select from; the management system is what is certified.
Dates that matter
- October 2022The current edition, ISO/IEC 27001:2022, replacing the 2013 version.
- 31 October 2025End of the transition period for certificates issued against the 2013 edition.
What people get wrong
Annex A is not the standard
The certifiable requirements are Clauses 4 to 10 — context, leadership, planning, support, operation, performance evaluation and improvement. Annex A is a catalogue of controls you select from on the basis of your own risk assessment, and the Statement of Applicability records what you selected and why.
The 2022 edition reorganised rather than rewrote
Eleven controls are new, fifty-seven were merged and the rest were renamed or regrouped. If your documentation still references 2013 control numbers, that is a mapping exercise rather than a new programme.
Certification is an audit, not a questionnaire
A Stage 1 documentation review is followed by a Stage 2 audit of the system in operation, then annual surveillance. Nothing produced by a self-assessment tool substitutes for that.
What Vivid Risk does with ISO/IEC 27001:2022
Annex A control references on every scored control, each printing the standard's own control title.
Checked against the standard's own control statements, from a licensed copy of ISO/IEC 27002:2022. None of ISO's text is reproduced here, and we do not certify anyone.
Questions
Does Vivid Risk certify me to ISO 27001?
No, and no software can. Certification comes from an accredited certification body after an audit. What you get here is a self-assessed view of where you stand, with Annex A references on every scored control.
How were the control references checked?
Against the control statement, purpose and guidance that ISO/IEC 27002:2022 gives for each one, from a licensed copy — the same standard of check the regulations got against their own published texts. Six references were corrected by that reading. Until September 2026 they had been checked against the Annex A titles alone, which is a real check and a weaker one, and were labelled as such until the text was in hand.
One assessment, every framework
The same answers produce your citations across every framework we cover at once, rather than one questionnaire per regulation.