Skip to content

Independent standards discovery and compliance platform

How we work
European standard guide European standard guide

EN ISO/IEC 27001

EN ISO/IEC 27001

Choose EN ISO/IEC 27001 when the project needs requirements for an information security management system. The first procurement decision is which information, services and organisational activities the system will cover. A security-tool licence, a penetration test and an ISMS implementation engagement can all be useful, but they are different purchases.
Editorial guide Content updated 7 October 2026
On this page
  1. Choose the correct published document
  2. Requirements for a system, not a list of products
  3. Compare the work behind an ISMS quotation
  4. Example: a service company using a cloud platform
  5. Choose complementary documents for distinct objectives
  6. Edition and assessment questions
  7. Primary sources and edition check
  8. Explore more standards buying guides

Genorma’s verified European record is EN ISO/IEC 27001:2023, adopting ISO/IEC 27001:2022, with the published A1:2024 amendment. Do not confuse the European adoption year with a separate ISO technical revision. European adoption and history; Amendment record.

Choose the correct published document

Requirements for a system, not a list of products

The scope addresses establishment and continuing improvement of an ISMS, including assessment and treatment of information-security risks for the organisation. ISO describes information security as reaching people, processes and technology, including information in different forms. Published requirements scope; ISO explanation.

For a useful brief, name the service the organisation delivers and follow the information supporting it. Describe where it is received, used, stored and shared. A scope defined only by the name of an IT platform can miss the people and outsourced services that keep the customer-facing activity working.

Compare the work behind an ISMS quotation

An original information-security buying comparison
Proposed purchaseWhat the buyer should clarify
Security productWhich functions are supplied and who configures and maintains them?
Technical testWhat systems, methods, dates and limitations does the test cover?
ISMS implementationWhich information activities, responsibilities and records are included?
TrainingWhich roles need decision-specific guidance rather than general awareness?
Certification assessmentWhat organisational scope and exact edition will the assessment address?

Ask providers how findings become owned actions. A report identifying weaknesses and a maintained system for deciding and following up work have different boundaries. The quotation should state what information you must provide, who will approve decisions and what happens when a supplier or service changes after the engagement ends.

Example: a service company using a cloud platform

Imagine a consultancy whose customer work is stored in a cloud platform. A bidder offers to configure the platform and describes the result as an “ISO 27001 solution”. Another bidder proposes a wider programme involving access decisions, supplier arrangements and staff processes. Before comparing prices, the company could trace a customer project from receipt to completion and eventual deletion.

Who creates access? Who approves a subcontractor’s involvement? What happens when an employee leaves or the customer requests a change? Which information is retained outside the main platform? Those questions reveal whether the proposed work reaches the service boundary or only one tool. This is an original procurement scenario, not a security architecture or an assessment of the platform.

Choose complementary documents for distinct objectives

For privacy management, examine EN ISO/IEC 27701 and check its current edition: the published 2025 privacy standard is an independent management-system standard, rather than assuming every edition has the older extension role. ISO privacy-standard explanation.

For continuing operations through disruption, see EN ISO 22301. For a specific cloud-security guidance purchase, see ISO/IEC 27017. Plan these around the organisation’s needs; this is a comparison of purchasing objectives, not a list that automatically applies to every ISMS.

Edition and assessment questions

Is ISO 27001 the full designation?

ISO identifies the official international designation as ISO/IEC 27001. For the European order, preserve the full EN ISO/IEC reference and year shown on the chosen product. Publisher’s designation explanation.

Does a certificate guarantee that no incident can occur?

Ask what organisational scope and assessment basis a certificate describes. Do not use its existence as a substitute for checking the technical service, contract commitments or evidence needed for your particular purchase.

Should I buy controls guidance instead of the requirements?

Use the requirements publication when you need the basis for the management system. A guidance publication or tool can support implementation, but verify its role and edition before treating it as equivalent to that basis.

Primary sources and edition check

Publication and purchase records checked on 7 October 2026. The examples and procurement questions are original guidance. Detailed implementation requires the applicable licensed text and decisions for the actual project.

Explore more standards buying guides

Browse standards by reference and subject to compare related document choices.

From reading to action

Need help interpreting, implementing or testing against this standard?

Describe the product, organisation, target market and decision you need to make. We will direct you to the most relevant guide or specialist route available on the platform.

Describe your project