On this page
- Choose the correct published document
- Requirements for a system, not a list of products
- Compare the work behind an ISMS quotation
- Example: a service company using a cloud platform
- Choose complementary documents for distinct objectives
- Edition and assessment questions
- Primary sources and edition check
- Explore more standards buying guides
Genorma’s verified European record is EN ISO/IEC 27001:2023, adopting ISO/IEC 27001:2022, with the published A1:2024 amendment. Do not confuse the European adoption year with a separate ISO technical revision. European adoption and history; Amendment record.
Choose the correct published document
EN ISO/IEC 27001:2023 — Information security management systems
The link is the exact European base product. Check how you will access A1:2024; the separately linked Genorma amendment page is a published supporting record, not a verified sale offer here.
Confirm the final price, taxes, available language, delivery format and permitted users at the merchant checkout. No fixed price is quoted here.
Requirements for a system, not a list of products
The scope addresses establishment and continuing improvement of an ISMS, including assessment and treatment of information-security risks for the organisation. ISO describes information security as reaching people, processes and technology, including information in different forms. Published requirements scope; ISO explanation.
For a useful brief, name the service the organisation delivers and follow the information supporting it. Describe where it is received, used, stored and shared. A scope defined only by the name of an IT platform can miss the people and outsourced services that keep the customer-facing activity working.
Compare the work behind an ISMS quotation
| Proposed purchase | What the buyer should clarify |
|---|---|
| Security product | Which functions are supplied and who configures and maintains them? |
| Technical test | What systems, methods, dates and limitations does the test cover? |
| ISMS implementation | Which information activities, responsibilities and records are included? |
| Training | Which roles need decision-specific guidance rather than general awareness? |
| Certification assessment | What organisational scope and exact edition will the assessment address? |
Ask providers how findings become owned actions. A report identifying weaknesses and a maintained system for deciding and following up work have different boundaries. The quotation should state what information you must provide, who will approve decisions and what happens when a supplier or service changes after the engagement ends.
Example: a service company using a cloud platform
Imagine a consultancy whose customer work is stored in a cloud platform. A bidder offers to configure the platform and describes the result as an “ISO 27001 solution”. Another bidder proposes a wider programme involving access decisions, supplier arrangements and staff processes. Before comparing prices, the company could trace a customer project from receipt to completion and eventual deletion.
Who creates access? Who approves a subcontractor’s involvement? What happens when an employee leaves or the customer requests a change? Which information is retained outside the main platform? Those questions reveal whether the proposed work reaches the service boundary or only one tool. This is an original procurement scenario, not a security architecture or an assessment of the platform.
Choose complementary documents for distinct objectives
For privacy management, examine EN ISO/IEC 27701 and check its current edition: the published 2025 privacy standard is an independent management-system standard, rather than assuming every edition has the older extension role. ISO privacy-standard explanation.
For continuing operations through disruption, see EN ISO 22301. For a specific cloud-security guidance purchase, see ISO/IEC 27017. Plan these around the organisation’s needs; this is a comparison of purchasing objectives, not a list that automatically applies to every ISMS.
Edition and assessment questions
Is ISO 27001 the full designation?
ISO identifies the official international designation as ISO/IEC 27001. For the European order, preserve the full EN ISO/IEC reference and year shown on the chosen product. Publisher’s designation explanation.
Does a certificate guarantee that no incident can occur?
Ask what organisational scope and assessment basis a certificate describes. Do not use its existence as a substitute for checking the technical service, contract commitments or evidence needed for your particular purchase.
Should I buy controls guidance instead of the requirements?
Use the requirements publication when you need the basis for the management system. A guidance publication or tool can support implementation, but verify its role and edition before treating it as equivalent to that basis.
Primary sources and edition check
- Genorma: European 2023 adoption, scope and ISO relationship
- Genorma: published A1:2024 amendment
- ISO: published ISO/IEC 27001:2022 and ISMS explanation
Publication and purchase records checked on 7 October 2026. The examples and procurement questions are original guidance. Detailed implementation requires the applicable licensed text and decisions for the actual project.
Explore more standards buying guides
Browse standards by reference and subject to compare related document choices.
Editorial information
How this page is maintained
No documented technical review of this version is recorded. Sources and an update date are not a conformity assessment.
Scope: Information security management-system requirements; distinguishes ISMS work from technical tests, security products and privacy or continuity objectives.
View registered primary sources
Keep this guide useful
Your reading list and topic feeds
Saves stay on this browser. Feeds cover guidance on this website, not every change to a standard.