Compliance & frameworks

What is ISO 27001?

A plain-English guide to ISO 27001, the international standard for managing information security. What it is, how certification works and how it maps to NIS2 and GDPR in Sweden.

Key takeaways
  • ISO 27001 is the international standard for an information security management system (ISMS), published by ISO and the IEC. The current edition is ISO/IEC 27001:2022.
  • It is risk-based. You assess the risks to your information, choose controls to treat them and keep improving the system.
  • Annex A lists 93 reference controls across four themes (Organizational 37, People 8, Physical 14 and Technological 34). You apply only those your risk assessment justifies.
  • The Statement of Applicability records which controls apply and why, and it is the first thing an auditor reads.
  • You certify against clauses 4 to 10 and your applicable Annex A controls. ISO 27002 is the controls guidance you build from, and you do not certify against it.
  • A certificate is valid three years, with annual surveillance audits and a recertification audit in year three (ISO/IEC 17021-1).
  • Use a certification body accredited by a recognised body such as Swedac, or the certificate carries little weight.
  • The ISO Survey 2024 counted 96,709 valid ISO 27001 certificates worldwide. Since 31 October 2025 every valid certificate is to the 2022 version.
  • ISO 27001 is voluntary but demonstrates many NIS2 Article 21 measures and supports GDPR. ISO/IEC 27701:2025 is the standalone privacy standard.
  • Certification reduces and structures risk. It does not guarantee you will not be breached.

ISO 27001 Defined in Plain Terms

ISO 27001 is the international standard for an information security management system or ISMS. Published jointly by ISO and the IEC, it sets out how an organisation should assess the risks to its information, choose controls to treat them and keep improving the system over time. The current edition is ISO/IEC 27001:2022.

For most organisations the push to certify comes from outside. Customers ask for it in security questionnaires, public tenders name it as a requirement and regulators expect evidence that security is actively managed. A certificate is a short way to show that an independently audited system stands behind your security claims.

How ISO 27001 Works

ISO 27001 is built around a management system. The idea is that security is an ongoing process you plan, run, check and improve so ISO 27001 asks you to build a repeatable system for it. Clauses 4 to 10 of the standard hold the mandatory requirements for that system.

The clauses run from understanding your context and setting leadership responsibilities through planning and providing resources, to running, measuring and improving the system. Leadership matters most here. Clause 5 requires top management to own the system so ISO 27001 has to be driven from board level and cannot be delegated wholesale to IT.

The engine of the system is risk. You assess the risks to your information, decide how to treat each one and then choose controls to match. Most controls come from Annex A of the standard, a reference set of 93 safeguards.

You do not apply all 93. You apply the controls your risk assessment justifies and record the rest as excluded in the Statement of Applicability with a reason for each decision. That document is what an auditor reads first.

Once the system runs, it does not stop. The standard requires internal audits, a management review and continual improvement so the ISMS keeps pace with new risks and changes in the business. That ongoing cycle is what keeps a certificate meaningful over its three-year life.

The Annex A Controls in Four Themes

Annex A groups its 93 controls into four themes sorted by who or what puts each control into practice. The 2022 revision cut the count from 114 and reorganised the old 14 domains into these four which makes it easier to give each control an owner.

  • Organizational (37 controls): Policies, roles, supplier and cloud security, threat intelligence, incident management and business continuity.
  • People (8 controls): Screening, terms of employment, security awareness training and the handover when someone joins, moves role or leaves.
  • Physical (14 controls): Secure areas, equipment, clear-desk practice and protection against physical and environmental threats.
  • Technological (34 controls): Access control, cryptography, secure configuration, monitoring, backup and secure development.

These are a reference set, not a mandate. You pick what your risks call for and justify the rest. The 2022 revision also added 11 new controls that reflect how work has changed among them threat intelligence, information security for cloud services and ICT readiness for business continuity.

The ISO 27000 Family Explained

ISO 27001 sits in a wider family of standards each with a different job. Knowing which is which saves confusion because people often name the wrong one. You certify against ISO 27001 alone. The others support it.

  • ISO/IEC 27000: The overview and vocabulary. It defines the terms used across the family and is free to download from ISO.
  • ISO/IEC 27001: The requirements for the management system. The only standard in the family you are certified against.
  • ISO/IEC 27002: Implementation guidance for the Annex A controls with a page of detail on each. You use it to build controls but you do not certify against it.
  • ISO/IEC 27005: Guidance on managing information security risk which supports the risk work at the heart of ISO 27001.
  • ISO/IEC 27017 and 27018: Extra controls for cloud services and for protecting personal data in public clouds.
  • ISO/IEC 27701: The privacy information management standard. Its 2025 edition became a standalone certifiable standard that maps closely to GDPR. Earlier versions were an extension to ISO 27001.

For a Swedish organisation the two that matter most alongside 27001 are usually 27002 for building the controls and 27701 for privacy.

Real-World Cases

ISO 27001 is easier to grasp through the failures it exists to reduce. Two recent Swedish incidents show the kind of risk its controls address and the honest limit of what any standard can promise.

The Miljödata Supply-Chain Attack

In August 2025 a ransomware attack hit Miljödata, a supplier of HR and sick-leave software used by roughly 80 percent of Sweden’s municipalities. By the supplier’s own estimate the disruption reached around 200 of Sweden’s 290 municipalities and regions. Attackers demanded a ransom of 1.5 bitcoin and data on about 1.5 million people was later published on the dark web.

The damage spread through one shared supplier. That is exactly what Annex A’s supplier and supply-chain controls exist to manage including the duty to assess supplier risk and set security expectations in contracts.

Certification of Miljödata would not have prevented the attack. What the standard changes is the customer’s side. It forces you to ask how much of your operation depends on a single vendor and what happens when that vendor goes dark.

The Tietoevry Ransomware Outage

In January 2024 the Akira ransomware group hit one of Tietoevry’s datacentres in Sweden. The attack took down services for many Swedish customers including the Primula payroll system used by most Swedish universities and more than 30 government authorities along with retail and a regional health-record system. Tietoevry warned that recovery could take days or weeks.

Two ISO 27001 lessons stand out. Akira commonly breaks in through remote-access appliances at organisations without multi-factor authentication, per CISA, which is why access control and strong authentication are core technological controls. And when systems do go down, tested backups and a continuity plan decide whether an outage is an inconvenience or a crisis.

Neither case argues that certification prevents attacks. Both show that a structured, risk-based system changes how badly an attack lands.

ISO 27001 and Swedish Regulation

ISO 27001 is voluntary. No Swedish or EU law requires the certificate itself. What the law increasingly requires is that you manage information security to a demonstrable standard and this is where certification earns its place because it is independent evidence that you do.

Under NIS2, brought into Swedish law as Cybersäkerhetslagen (SFS 2025:1506) in force since 15 January 2026, in-scope organisations must take specific security measures. Article 21 covers risk management, incident handling, business continuity, supply-chain security and staff awareness all of which an ISO 27001 ISMS is built to deliver. Article 20 makes the management body accountable and a certificate gives boards evidence they can point to.

NIS2 also adds duties ISO 27001 does not cover on its own such as strict incident-reporting timelines so certification takes you a long way towards compliance without finishing the job.

For personal data, ISO 27001 supports the security-of-processing duty under GDPR Article 32. The privacy-specific standard is ISO/IEC 27701 whose 2025 edition is a standalone certifiable standard that maps to GDPR requirements. Many organisations run the two together, one for security and one for privacy.

Financial entities have a further regime in DORA which sets ICT risk-management rules that overlap with much of ISO 27001. Whichever rules apply to you, a certified ISMS is a practical way to show an auditor that the measures behind your policies are real. For how these obligations apply to a Swedish organisation, see our ISO 27001 compliance overview.

How ISO 27001 Certification Works

Certification is a defined process, run by an external certification body. Before it starts, most organisations do a gap analysis against the standard, build the missing parts of the ISMS, then run at least one internal audit and a management review so there is evidence the system actually operates.

The audit itself has two stages. Stage 1 is a documentation and readiness review where the auditor checks your scope, policies, risk assessment and Statement of Applicability. Stage 2 is the main audit, where the auditor samples evidence, interviews staff and confirms the controls you selected are working. A clean Stage 1 does not certify you. Only a passed Stage 2 does.

A certificate is then valid for three years. The certification body runs a lighter surveillance audit in each of the first two years, then a fuller recertification audit in the third year that starts the cycle again. Miss the audits and the certificate lapses.

One detail decides whether a certificate means anything. The certification body should itself be accredited by a recognised national accreditation body which in Sweden is Swedac. This whole audit structure is set by ISO/IEC 17021-1, the standard certification bodies work to. An unaccredited certificate can look identical and carry far less weight.

Adoption is wide and growing. The ISO Survey 2024 counted 96,709 valid ISO/IEC 27001 certificates worldwide, up from 48,671 the year before, though the 2024 figures also draw on a broader data source. Since the 2013 version’s transition window closed on 31 October 2025, every valid certificate is now to the 2022 revision.

How to Get Started with ISO 27001

You do not need to solve everything at once. ISO 27001 is designed to be scoped so a first project can be tightly bounded and grown later. A sensible order of first steps looks like this.

  • Define the scope: Decide which parts of the business, systems and locations the ISMS will cover and keep it realistic.
  • Get leadership behind it: The standard needs top management to own the system, set direction and provide resources.
  • Run a gap analysis: Compare what you do today against the standard’s requirements to see the real distance to certification.
  • Assess your risks: Identify the risks to your information, then decide how to treat each one.
  • Select controls and write the Statement of Applicability: Choose the Annex A controls your risks call for and record what you include and exclude.
  • Operate, then audit yourself: Run the system, then complete an internal audit and a management review before inviting an external auditor.
  • Choose an accredited certification body: Check it is accredited by Swedac or another recognised body before you book Stage 1.

If the internal skills or time are not there, many organisations bring in outside help such as a CISO advisory service to run the gap analysis and risk assessment.

Done well, ISO 27001 leaves you with more than a certificate. You get a clear picture of your risks, a set of controls that match them and a routine for keeping both current as the business and its threats change.

Myths & Facts

Myth

ISO 27001 is an IT project.

A certificate means you cannot be breached.

You must implement all 93 Annex A controls.

ISO 27001 is only for large enterprises.

Once you are certified, the work is done.

ISO 27001 and ISO 27002 are the same thing.

Fact

It is a management-system standard owned by leadership. Clause 5 requires top management involvement and the controls span people, physical and organisational measures, not only technology.

Certification shows you manage security risk to a recognised standard. It lowers the likelihood and impact of incidents but does not guarantee prevention, and certified organisations have still been breached.

You apply the controls your risk assessment justifies and record the rest as excluded in the Statement of Applicability, with a reason. Annex A is a reference set.

The standard scales to the organisation. A small company certifies by scoping the ISMS tightly, and many small firms hold the certificate.

A certificate lasts three years with annual surveillance audits, and the standard requires continual improvement. Maintaining it is ongoing work, not a one-off.

ISO 27001 holds the certifiable requirements. ISO 27002 is implementation guidance for the controls, and you do not certify against it.

Test Yourself

Four real-world scenarios, then six knowledge questions. See how prepared you would be under pressure.

Scenario Simulation

  1. An auditor asks to see your Statement of Applicability and notices you have excluded several Annex A controls.

    What is the right response?

    • Quickly implement the excluded controls before the audit continues
    • Show the documented justification for each exclusion
    • Remove the exclusions from the document
  2. A new supplier will handle some of your customer data and wants access to your systems.

    What does an ISO 27001 approach require?

    • Grant access quickly to avoid delaying the project
    • Assess the supplier's risk and set security requirements in the contract
    • Rely on the supplier's own assurances that they are secure
  3. Your organisation was certified 18 months ago and has heard nothing from the certification body.

    What should be happening?

    • Nothing until the certificate expires in three years
    • A surveillance audit each year to confirm the ISMS still works
    • A full recertification audit every six months
  4. Leadership tells the IT team to make the company ISO 27001 compliant and considers the job delegated.

    What is the problem with this?

    • Nothing, information security is an IT responsibility
    • The standard requires top management to own the system
    • IT should hire an external auditor to run the project

Knowledge Test

  1. What does an ISO 27001 certificate certify?

    • A single security product
    • An information security management system
    • A one-time penetration test
    • A specific software version

    ISO 27001 certifies a management system for information security, not a product or a single test.

  2. How many controls are in Annex A of ISO 27001:2022?

    • 114
    • 27
    • 93
    • 10

    The 2022 revision lists 93 controls in four themes, down from 114 in the 2013 edition.

  3. Which document records which controls apply and why?

    • The risk register
    • The Statement of Applicability
    • The audit report
    • The security policy

    The Statement of Applicability lists which Annex A controls apply and justifies any exclusions.

  4. How long is an ISO 27001 certificate valid before recertification?

    • One year
    • Three years
    • Five years
    • It never expires

    A certificate is valid for three years, with annual surveillance audits in between.

  5. Which standard gives implementation guidance for the controls?

    • ISO 27000
    • ISO 27002
    • ISO 27701
    • ISO 27005

    ISO 27002 provides detailed guidance on implementing the controls, while you certify against ISO 27001.

  6. Is ISO 27001 certification legally required under NIS2?

    • Yes, it is mandatory
    • No, but it demonstrates many required measures
    • Only for banks
    • Only in Sweden

    Certification is voluntary, but it evidences many of the security measures NIS2 requires.

Take It with You

Share the Summary PDF with Your Team

A short distilled brief in PDF: key findings, red flags and action steps.

Download summary PDF

Why Training Matters

People are a core part of the standard. Annex A includes a specific control for information security awareness, education and training, and the People theme covers what staff must know and do. An ISMS depends on the everyday habits of the people inside it.

That is why regular, role-based security awareness training sits at the core of both ISO 27001 and NIS2, whose Article 21 names staff awareness among its required measures. Security awareness training keeps that human control current as threats change.

Frequently Asked Questions

What is ISO 27001?

ISO 27001 is the international standard for an information security management system, or ISMS, published jointly by ISO and the IEC. It sets out how an organisation should assess information risks, choose controls to treat them and keep improving the system. The current edition is ISO/IEC 27001:2022.

What is the difference between ISO 27001 and ISO 27002?

ISO 27001 holds the certifiable requirements for the management system, while ISO 27002 is guidance on how to implement the security controls. You are audited and certified against ISO 27001, using ISO 27002 as the manual for building each control. You do not certify against ISO 27002.

How does ISO 27001 certification work?

An accredited certification body audits your ISMS in two stages. Stage 1 reviews your documentation and readiness, and Stage 2 checks that the controls you selected are working. A passed Stage 2 earns a certificate valid for three years, kept alive by annual surveillance audits and a recertification audit in year three.

How many controls are in ISO 27001?

ISO/IEC 27001:2022 lists 93 controls in Annex A, grouped into four themes (Organizational 37, People 8, Physical 14 and Technological 34). The 2013 version had 114 controls across 14 domains. Annex A is a reference set, so you apply only the controls your risk assessment justifies.

Is ISO 27001 mandatory in Sweden?

No, ISO 27001 certification is voluntary and no Swedish or EU law requires the certificate itself. Laws such as NIS2, brought into Sweden as Cybersäkerhetslagen, do require in-scope organisations to manage security to a demonstrable standard. Certification is a widely accepted way to prove you meet that duty.

What is the current version of ISO 27001?

The current version is ISO/IEC 27001:2022, published on 25 October 2022. It replaced the 2013 edition, and the transition window for older certificates closed on 31 October 2025. Since then every valid ISO 27001 certificate is to the 2022 revision, which restructured Annex A into 93 controls under four themes.

What is the difference between ISO 27001 and ISO 27701?

ISO 27001 manages information security, while ISO/IEC 27701 manages privacy, or the handling of personal data. The 2025 edition of ISO 27701 became a standalone certifiable standard that maps to GDPR, where earlier versions were an extension to ISO 27001. Many organisations certify to both, one for security and one for privacy.

Does ISO 27001 help with NIS2 and GDPR?

Yes. An ISO 27001 ISMS delivers many of the security measures NIS2 Article 21 requires, such as risk management, incident handling and staff awareness, and gives boards evidence for their Article 20 accountability. For GDPR, it supports the security-of-processing duty, and ISO/IEC 27701 adds privacy-specific controls on top.

You Understand the Risk.
Now See Where You Stand.

Book a 30-minute briefing with one of our analysts, or run the free breach check first to find out what attackers already know about your organisation.

Book a 30-Min Briefing
No sales pitch, just a straight assessment

How eBuilder Security Can Help

Awareness is the first layer. These are the services that turn it into measurable protection.