Client support
Home Services The facility Clients Knowledge About Contact Storage calculator Request a proposal
Explainer

What ISO/IEC 27001:2022 actually certifies

It is not a quality badge and it is not a product rating. It certifies that a management system for information security exists, works and is independently audited.

ISO/IEC 27001:2022 specifies the requirements for an information security management system: the policies, risk assessments, controls and reviews an organisation uses to protect information.1 A certificate means an accredited body has audited that system and found it conforms.

What a certificate does and does not tell you

TopicIt tells youIt does not tell you
ScopeThe system covers the activities named on the certificate.That every part of the business is in scope. Read the scope statement.
RiskRisks to information are identified and treated by a defined method.That every risk has been removed.
ContinuityThe system is re-audited, so the certificate can be withdrawn.That the next audit will pass.

The current edition

20221,2
edition of ISO/IEC 27001, amended in 2024 to add climate action considerations

Questions to ask any certified provider

  • What is the certificate's scope, word for word?
  • Which certification body issued it, and is that body accredited?
  • When was the last surveillance audit, and were there major findings?
  • Does the scope include the storage facility, transport and retrieval?

Sources

2 sources verified, last checked 4 October 2026
  1. 1
  2. 2
    ISO/IEC 27001:2022/Amd 1:2024 Climate action changes
    International Organization for Standardization, February 2024

Talk to us about your own records