ISO 27001:2022 Certification — ISMS Implementation & Audit
ISO 27001 is the internationally recognised standard for an Information Security Management System (ISMS) — a systematic approach to managing information security risk through policy, process, and control. The 2022 edition reorganised Annex A into 93 controls across four themes (organisational, people, physical, technological), aligned to ISO/IEC 27002:2022. The transition window for organisations still certified to the 2013 edition closed in October 2025, so any live ISO 27001 certificate now has to be against the 2022 text.
Mutex Systems runs ISO 27001:2022 implementations from gap analysis through certification audit, led by qualified Lead Implementers and Lead Auditors — typical timeline six to nine months, depending on the existing control baseline and ISMS scope.
- Category
- Compliance Framework
- Jurisdiction
- International
- Issuing Body
- International Organization for Standardization (ISO) / IEC
- Current Version
- ISO/IEC 27001:2022 — organisations still certified to the 2013 edition were required to transition by October 2025
- Who It's For
- Any organisation that wants independently verified evidence of information security governance — commonly a condition of enterprise procurement, cyber insurance, or regulator expectations, and a frequent requirement in UK and EU public-sector tenders.
Core Domains
A Practical Compliance Path
- 01
Gap Analysis
Assess current controls against the 93 Annex A controls and the 2022 clause structure to scope the ISMS and quantify the remediation effort.
- 02
Risk Assessment & Treatment
Build the risk register, define risk appetite, and produce the Statement of Applicability justifying each control's inclusion or exclusion.
- 03
ISMS Documentation & Rollout
Implement policies, procedures, and technical controls, with the internal audit programme running alongside to catch gaps before the external audit.
- 04
Certification Audit
Stage 1 (documentation review) and Stage 2 (implementation audit) with the certification body, followed by annual surveillance audits and 3-year recertification.
Led by Qualified Lead Implementers
ISO 27001:2022 implementations are led by qualified Lead Implementers, covering gap analysis, risk treatment, and the full ISMS documentation set through to certification body liaison.
- Gap analysis, risk treatment, and ISMS documentation set built together, not as separate disconnected deliverables
- Internal audit programme and management review support ahead of the external certification audit
- Typical timeline six to nine months from gap analysis to initial certification audit
The Statement of Applicability, Kept Live Instead of Rebuilt
grComply, Mutex Systems' own GRC automation platform, loads the ISO 27001:2022 Annex A control set as a versioned framework and maps it against the other frameworks you hold, so one piece of evidence uploaded once satisfies ISO 27001 and any overlapping SOC 2 or NIST CSF requirement automatically.
- Cross-framework control mapping means evidence for an access-control policy or encryption standard is uploaded once and auto-linked everywhere it applies, not re-collected per audit
- Live completion-percentage rollup per Annex A theme replaces the manual Statement of Applicability spreadsheet, visible to the whole ISMS team in real time
- A structured raise / respond / review / close observation workflow with countersign matches how certification body auditors actually track non-conformities during Stage 2 and surveillance audits
- The Claude-powered AI assistant drafts ISMS policy language and explains control gaps in plain terms, cutting the documentation load during implementation
grComply is Mutex Systems' own multi-tenant GRC automation platform — the framework library, hybrid scanning, risk and audit workflow, and AI-assisted compliance behind every point above are live in production today.
See How grComply WorksCommon Questions About ISO 27001
What changed between ISO 27001:2013 and ISO 27001:2022?
The 2022 edition reorganised Annex A from 114 controls across 14 categories down to 93 controls across four themes — organisational, people, physical, and technological — aligned to the updated ISO/IEC 27002:2022 control guidance. Eleven new controls were added, covering areas such as threat intelligence, cloud security, and data masking. Organisations certified under the 2013 edition were required to transition to the 2022 edition by October 2025; any live ISO 27001 certificate today should be against the 2022 text.
How long does ISO 27001 certification typically take?
A typical programme runs six to nine months from initial gap analysis to the Stage 2 certification audit, depending on the existing control baseline, the size of the ISMS scope, and how quickly documentation and evidence can be produced. Certification is followed by annual surveillance audits and full recertification every three years.
What is the difference between ISO 27001 and ISO 27002?
ISO 27001 is the certifiable management-system standard — it specifies the requirements an organisation must meet to be audited and certified. ISO 27002 is a companion standard providing detailed implementation guidance for the Annex A controls referenced in ISO 27001; it is not itself certifiable.
Do we need ISO 27001 if we already have SOC 2?
They serve overlapping but distinct purposes. SOC 2 is an AICPA attestation report most commonly requested by US and SaaS buyers, typically covering a defined period of operating effectiveness. ISO 27001 is an internationally recognised, formally certified management system more commonly expected in UK, EU, and public-sector procurement. Many organisations selling internationally end up holding both, and a well-built control set can be mapped to satisfy evidence requirements for each with less duplicated work.
Can Mutex Systems support an ISO 27001:2022 implementation end to end?
Yes. Mutex Systems runs ISO 27001:2022 implementations from initial gap analysis through ISMS documentation, internal audit, and certification body liaison, led by qualified Lead Implementers and Lead Auditors.
Ready to Start Your ISO 27001 Programme?
Send us your current posture and timeline. Within two working days you will receive a written response and a proposed scoping call.