To get ISO 27001 certified, you need to meet a set of mandatory requirements defined in the standard’s clauses 4 through 10, plus select and implement relevant security controls from Annex A. The exact number of controls you implement depends on your organisation’s specific risk profile; there is no single fixed list that applies to every company. The sections below break down each part of the standard so you know exactly what to prepare for.
How many requirements does ISO 27001 actually have?
ISO 27001 contains 10 main clauses, of which clauses 4 to 10 are mandatory for certification. In addition, Annex A lists 93 controls across four themes that organisations must evaluate, though not all of them need to be implemented. The total number of controls you actually apply will vary based on your risk assessment results.
The 93 Annex A controls are grouped into four categories: organisational controls, people controls, physical controls, and technological controls. These cover everything from access management and cryptography to supplier relationships and incident response. Importantly, the standard does not require you to implement all 93; it requires you to justify which ones apply to your situation and document why you excluded any that do not.
What are the mandatory clauses of ISO 27001?
The mandatory clauses of ISO 27001 are clauses 4 through 10. Every organisation seeking certification must fully address all seven of these clauses, regardless of size or industry. Clauses 1 to 3 provide scope, references, and definitions and are not audited as requirements.
Here is what each mandatory clause covers:
- Clause 4 – Context of the organisation: Understand your internal and external environment, identify interested parties, and define the scope of your Information Security Management System (ISMS).
- Clause 5 – Leadership: Top management must demonstrate commitment, assign roles, and establish an information security policy.
- Clause 6 – Planning: Conduct a risk assessment, define risk treatment options, and set measurable security objectives.
- Clause 7 – Support: Provide the necessary resources, competence, awareness, and documented information to run the ISMS.
- Clause 8 – Operation: Implement and control the processes defined in your planning phase, including the risk treatment plan.
- Clause 9 – Performance evaluation: Monitor, measure, audit, and review the ISMS regularly.
- Clause 10 – Improvement: Address nonconformities, take corrective actions, and continually improve the system.
What is the Statement of Applicability in ISO 27001?
The Statement of Applicability (SoA) is a mandatory document that lists all 93 Annex A controls, states whether each one is applicable to your organisation, and explains the justification for including or excluding it. The SoA is one of the most important documents an auditor will review during your certification audit.
Think of the SoA as the bridge between your risk assessment and your actual security controls. For each control you include, you should reference the reason, whether it addresses a specific risk, meets a legal obligation, or reflects a business requirement. For each control you exclude, you need to clearly justify why it does not apply. A well-prepared SoA demonstrates that your ISMS is thoughtful and tailored, not just a generic checklist. For digital companies, controls around remote access, cloud security, and data encryption are typically marked as applicable, while some physical controls may be excluded if you operate without a traditional office environment.
Which ISO 27001 controls are required versus optional?
No Annex A control is automatically required, but no control can be excluded without documented justification. The controls you must implement are those that your risk assessment identifies as necessary to reduce risk to an acceptable level. In practice, most organisations implement the majority of controls, particularly those covering access control, incident management, and asset management.
Some controls are almost universally applicable. These include:
- Access control policies and user access management
- Information classification and handling
- Cryptography and key management
- Logging and monitoring
- Supplier security and third-party management
- Business continuity and backup procedures
- Incident response and reporting
Controls that are more commonly excluded, and only for well-justified reasons, tend to relate to physical security measures that simply do not apply to fully remote or cloud-based operations. If your team works entirely online and you have no physical server rooms, certain physical access controls may not be relevant. The key is always to document your reasoning clearly.
How does a risk assessment determine your ISO 27001 requirements?
The risk assessment is the foundation of your entire ISMS. It identifies the information assets you need to protect, the threats and vulnerabilities that affect them, and the likelihood and impact of potential security incidents. The results of this assessment directly determine which Annex A controls you need to implement.
The process works in a structured sequence. First, you identify your assets: data, systems, people, and processes. Then you assess what could go wrong with each asset and how serious the consequences would be. Based on this, you calculate a risk level and decide whether to treat, tolerate, transfer, or terminate each risk. For every risk you decide to treat, you select one or more controls from Annex A (or justify a custom control) and document this in your risk treatment plan.
For digital companies, this often surfaces risks around data breaches, unauthorised access, phishing, and third-party software vulnerabilities. The risk assessment is not a one-time exercise; you need to repeat it at planned intervals and whenever significant changes occur in your environment. This ongoing process is what keeps your ISO 27001 certification meaningful rather than just a badge on a shelf.
What documentation is required to pass an ISO 27001 audit?
ISO 27001 requires a specific set of documented information to pass a certification audit. These documents prove that your ISMS is designed correctly, implemented in practice, and maintained over time. Missing or incomplete documentation is one of the most common reasons audits result in nonconformities.
The core documents you must have in place include:
- ISMS scope document: Defines the boundaries of your information security system.
- Information security policy: A top-level statement of your organisation’s commitment to security.
- Risk assessment methodology and results: Documents how you identified and evaluated risks.
- Risk treatment plan: Shows how you plan to address each identified risk.
- Statement of Applicability: Lists all 93 controls with inclusion/exclusion justifications.
- Security objectives: Measurable targets that support your security policy.
- Evidence of competence and training: Records showing staff are qualified and aware of their responsibilities.
- Internal audit results: Documentation of your internal audit programme and findings.
- Management review records: Evidence that leadership regularly reviews the ISMS’s performance.
- Records of nonconformities and corrective actions: Show how you handle and resolve issues.
Beyond these mandatory documents, you will also need operational records, such as access logs, incident reports, and supplier agreements, that demonstrate your controls are actually working in day-to-day operations. Auditors look for evidence of real implementation, not just polished policy documents.
How DICIS AG helps you meet ISO 27001 requirements
Getting ISO 27001 certified involves a lot of moving parts: risk assessments, documentation, control selection, and audit preparation. We built our platform specifically to make this manageable for small digital companies that do not have a dedicated compliance team or months to spare.
Here is what working with us looks like in practice:
- AI-assisted documentation: Our platform guides you through building your ISMS documentation, including the SoA, risk assessment, and security policy, without needing to start from scratch or hire an external consultant.
- Online audits: We conduct the entire certification audit digitally, which means no travel, no scheduling headaches, and no disruption to your daily operations.
- Fast turnaround: The preparation process that traditionally takes months can be completed in days using our structured approach.
- Tailored to small teams: Our process is designed for companies with up to 50 people; the requirements are applied proportionally to your actual situation, not copied from enterprise frameworks.
If you are ready to get your information security management certified without the usual complexity, explore our ISO 27001 certification process and see how quickly you can get started.

