iso27001partnersUK certification, costed Get a cost estimate

ISO 27001 vs ISO 27002: the standard you certify to, and the guidance behind it

Written from the standards themselves · Editor-reviewed · Checked against the current editions on 20 September 2026
By the iso27001partners.co.uk editorial team · Published 20 September 2026 · Last reviewed 20 September 2026 · 8 min read
4 primary sources cited on this page. How we check what is on this site
The one-line answer 27001 is certified. 27002 is guidance.

A certificate may mention ISO/IEC 27002 only as a source of controls, and must say it is “not a certification thereof” — ISO/IEC 27006:2015/Amd 1:2020, 8.2.1.

The two standards are sold side by side, numbered one apart, and share the same 93 controls, so they are easy to confuse. They do different jobs. One tells you what an information security management system must do; the other tells you how each control might be implemented. Only one of them can appear on your certificate as the thing you are certified to.

ISO 27001 and ISO 27002, side by side

ISO/IEC 27001:2022 and ISO/IEC 27002:2022 compared
ISO/IEC 27001ISO/IEC 27002
What it isRequirements for an information security management system“This document provides a reference set of generic information security controls including implementation guidance.”
Can you be certified to it?Yes — by an accredited certification bodyNo — it can only be named on a certificate as a control set source
Language“shall” — requirementsGuidance on implementing controls
Normative referencesISO/IEC 27000“There are no normative references in this document.”
ControlsAnnex A lists 93, one line each93 controls in the same four themes, with implementation guidance
StructureClauses 4–10 (the management system) plus Annex AClauses 5–8, one per theme; Annex A “Using attributes”, Annex B the correspondence with the 2013 edition
Current editionISO/IEC 27001:2022ISO/IEC 27002:2022 (third edition)
Who needs to read itAnyone implementing or being audited against the ISMSWhoever designs and operates the controls

What ISO 27002 says it is for

“This document provides a reference set of generic information security controls including implementation guidance.” It is designed to be used by organisations:

ISO/IEC 27002:2022, clause 1 (verbatim)
This document is designed to be used by organisations
awithin the context of an information security management system (ISMS) based on ISO/IEC 27001
bfor implementing information security controls based on internationally recognized best practices
cfor developing organization-specific information security management guidelines

And its introduction puts the relationship plainly: “It is to be used as a reference for determining and implementing controls for information security risk treatment in an information security management system (ISMS) based on ISO/IEC 27001.”

Guidance, not requirements

ISO/IEC 27002 has no normative references and sets no requirements you are audited against. It even says of itself: “Not all of the controls and guidance in this document can be applicable to all organizations.” What decides which controls apply to you is the risk process in ISO 27001, not 27002.

Why only ISO 27001 can be certified

Certification bodies certify management systems, and ISO/IEC 27001 is the management system standard. The ISMS certification rules deal with other standards named on a certificate directly:

“The certification documents may reference national and international standards as source(s) of control set for controls that are determined as necessary in the organization’s Statement of Applicability … The reference on the certification documents shall be clearly stated as being only a control set source for controls applied in the Statement of Applicability and not a certification thereof.”

ISO/IEC 27006:2015/Amd 1:2020, 8.2.1, quoted verbatim

So a supplier that says it is “ISO 27002 certified” is describing something the certification rules do not allow. What it may hold is an ISO 27001 certificate that lists 27002 as the source of its controls. Ask to see the certificate.

How ISO 27001 points to the controls

ISO 27001 never requires you to follow ISO 27002. Clause 6.1.3 requires you to determine the controls your risk treatment needs, and then compare them with Annex A. Its notes set the boundaries:

  • “Organizations can design controls as required, or identify them from any source.”
  • “Annex A contains a list of possible information security controls. Users of this document are directed to Annex A to ensure that no necessary information security controls are overlooked.”
  • “The information security controls listed in Annex A are not exhaustive and additional information security controls can be included if needed.”

ISO 27002 makes the same point from the other side: “The organization can design controls as required or identify them from any source.” The result of that comparison goes into your Statement of Applicability.

The four themes

ISO/IEC 27002:2022 arranges its controls into four themes, one clause each. We counted them from its contents list; the total matches ISO 27001's Annex A exactly.

ISO/IEC 27002:2022 themes and control counts
ThemeControls27002 clauseAnnex A
Organisational37Clause 5A.5
People8Clause 6A.6
Physical14Clause 7A.7
Technological34Clause 8A.8

For the controls themselves, theme by theme, see the Annex A controls.

What a control is

“A control is defined as a measure that modifies or maintains risk.” And an example the standard gives that is worth remembering: “An information security policy, for example, can only maintain risk, whereas compliance with the information security policy can modify risk.”

Where requirements come from

ISO/IEC 27002 names three main sources of information security requirements:

ISO/IEC 27002:2022, 0.2 (verbatim extract)
Source
athe assessment of risks to the organization, taking into account the organization’s overall business strategy and objectives
bthe legal, statutory, regulatory and contractual requirements that an organization and its interested parties (trading partners, service providers, etc.) have to comply with and their socio-cultural environment
cthe set of principles, objectives and business requirements for all the steps of the life cycle of information that an organization has developed to support its operations

What changed in the 2022 editions

“This third edition cancels and replaces the second edition (ISO/IEC 27002:2013), which has been technically revised.” Its foreword lists the main changes:

  • the title has been modified
  • the structure of the document has been changed, presenting the controls using a simple taxonomy and associated attributes
  • some controls have been merged, some deleted and several new controls have been introduced. The complete correspondence can be found in Annex B.

ISO/IEC 27001:2022 followed, with Annex A going from 114 controls to 93. Certificates against the 2013 edition ceased to be valid on 31 October 2025.

The sector extensions

“There are sector-specific standards that have additional controls which aim at addressing specific areas (e.g. ISO/IEC 27017 for cloud services, ISO/IEC 27701 for privacy, ISO/IEC 27019 for energy, ISO/IEC 27011 for telecommunications organizations and ISO 27799 for health).” These add controls for a sector; they do not replace ISO 27001 as the standard you are certified to.

We do not audit, certify or consult, and are paid the same fixed fee per enquiry whichever certification body or consultancy you use. Both standards are sold by ISO; the quotations above are from their official previews.

Where this fits

Common questions

What is the difference between ISO 27001 and ISO 27002?

ISO/IEC 27001 sets the requirements for an information security management system and is the standard organisations are certified against. ISO/IEC 27002 is guidance: in its own words it “provides a reference set of generic information security controls including implementation guidance.” The 93 controls listed in 27001's Annex A are the ones 27002 explains in detail.

Can you get ISO 27002 certified?

No. Certification is to ISO/IEC 27001. The rules certification bodies follow allow a certificate to name another standard only as a control set source, and require that it be “clearly stated as being only a control set source for controls applied in the Statement of Applicability and not a certification thereof”.

Do I need ISO 27002 to get ISO 27001?

You need to meet ISO 27001, not to buy 27002. But 27001's Annex A gives each control in a single line, and 27002 is where the guidance on implementing it sits. ISO 27001 itself notes that “Organizations can design controls as required, or identify them from any source.”

Are the controls in ISO 27002 the same as Annex A?

They are the same set: 93 controls in both, grouped into the same four themes with the same counts. ISO 27001 lists them in Annex A for the comparison clause 6.1.3 requires; ISO 27002 adds implementation guidance for each.

What changed in ISO 27002:2022?

Its foreword lists three main changes: the title was modified; the structure now presents the controls using a simple taxonomy and associated attributes; and some controls were merged, some deleted and several new ones introduced, with the full correspondence in its Annex B.

Do we have to implement every control in ISO 27002?

No. 27002 says so itself: “Not all of the controls and guidance in this document can be applicable to all organizations.” Which controls you apply is decided by your risk assessment and recorded, with reasons, in your Statement of Applicability.

What are ISO 27017 and ISO 27701?

Sector-specific extensions. ISO/IEC 27002 describes them as standards “that have additional controls which aim at addressing specific areas”, naming ISO/IEC 27017 for cloud services and ISO/IEC 27701 for privacy among others.

Sources cited on this page

  1. ISO/IEC 27002:2022, official preview (contents, foreword, introduction, clauses 1–3), read first-hand
  2. ISO/IEC 27001:2022, official preview (clauses 1 to 6.3 and contents), read first-hand
  3. ISO/IEC 27006:2015/Amd 1:2020, Requirements for bodies providing audit and certification of information security management systems — Amendment 1
  4. ISO/IEC 27002:2022, Information security controls

Every figure above was read from the source it is attributed to on 20 September 2026. Figures that are our own arithmetic rather than a published rule are labelled as estimates wherever they appear. How we check this.

Working out which controls apply?

Say how far the risk assessment and Statement of Applicability have got.

Step 1 of 6
What has made this a live question?

Almost nobody certifies for its own sake. Whatever is pushing this usually also sets the deadline, so it is worth saying first.

When do you need the certificate in your hand?

Stage 1 and Stage 2 are separate visits with a gap between them, so the certificate always lands some weeks after the last audit day. A date inside three months is a different piece of work from a date inside a year.

How many people would be inside the scope?

Not your whole payroll — everyone doing work under your control inside the certified scope, contractors included. This is the number the audit-day table in ISO/IEC 27006-1 runs on, so it decides the audit fee before anything else does.

What exists already?

There is no wrong answer here and nothing to be embarrassed about. Most enquiries are at the first option.

How do you want the work done?

The three routes cost very different amounts and suit very different teams. If you have not decided, say so — that is a useful answer too.

Where should the consultancy reach you?

This is the only step that asks you to type anything.

By clicking “Send my enquiry” I agree that iso27001partners.co.uk may pass the details above to up to three ISO 27001 consultancies that advertise for my sector, so that they can contact me at the business details I have given. Consent is not a condition of anything — every page, table and calculator on this site works without it. You can withdraw consent at any time by replying to any message you receive, or by writing to contact@iso27001partners.co.uk. We are not a certification body, not an accreditation body and not a consultancy; the disclaimer linked in the footer sets out the whole arrangement.

  • Your details go to consultancies only, and to no more than three
  • Free to you — consultancies pay us a fixed fee per enquiry, set in advance
  • No obligation, and no certification body is involved at this stage

Your enquiry is ready to send

Here is what happens after you submit:

  1. Your answers go to ISO 27001 consultancies that advertise for your sector.
  2. No more than three of them may contact you, using the details you gave.
  3. You decide who, if anyone, you speak to. You are committed to nothing.

We are not a certification body and cannot issue, arrange or influence a certificate. Only a UKAS-accredited certification body can do that, and you appoint it yourself.

Free enquiryFive clicks · no obligation Start now