What Is an ISMS? ISO 27001 Information Security Management System Explained
August 6, 2026 · by Pentevo
What Is an ISMS?
An ISMS (Information Security Management System) is a documented set of policies, processes, roles and controls that an organisation uses to manage information security risk deliberately rather than reactively. It is defined by ISO/IEC 27001, and it is the thing you certify against — not the individual security tools you buy. An ISMS covers people, processes and technology, and its defining feature is that it runs on a repeating cycle: assess risk → treat it → check it worked → improve.
The single most common misunderstanding is this: an ISMS is not software, and it is not a firewall. You cannot buy one. Vendors sell "ISMS tools" that help you document and track it, but the management system itself is your organisation's own set of decisions, evidence and routines.
Who actually needs an ISMS
Most organisations build one because something external forces the question.
| Driver | What it demands | Is ISO 27001 mandatory? |
|---|---|---|
| Customer or tender requirement | An ISO 27001 certificate before they sign | No, but you lose the deal |
| NIS2 (essential / important entities) | Risk-management measures under Art. 21 | No — but an ISMS is the accepted way to evidence it |
| TISAX (automotive supply chain) | VDA ISA assessment | No, but heavily ISO 27001-derived |
| DORA (financial entities) | ICT risk management framework | No, but the same building blocks |
| Public sector / KRITIS in Germany | BSI IT-Grundschutz or ISO 27001 | Often effectively yes |
| Insurance / due diligence | Demonstrable security governance | No |
Important distinction: none of these laws say "you must be ISO 27001 certified." They say you must manage risk and be able to prove it. An ISMS is simply the most recognised way to produce that proof.
The standard: ISO/IEC 27001:2022
The current version is ISO/IEC 27001:2022, plus Amendment 1:2024, which added climate-change considerations to clauses 4.1 and 4.2.
If you hold an older certificate: the transition period from ISO 27001:2013 ended on 31 October 2025. Certificates issued against the 2013 version are no longer valid. If a supplier presents one dated to the old standard, it has expired.
The standard has two parts, and people routinely confuse them:
- Clauses 4–10 — the management system requirements. These are mandatory. You cannot exclude any of them.
- Annex A — a catalogue of 93 controls. These are not all mandatory. You select them based on your risk assessment, and justify what you leave out.
Clauses 4–10: what the standard actually requires
This is the part auditors test. Everything here is compulsory.
Clause 4 — Context of the organisation
Determine internal and external issues relevant to your ISMS (4.1), identify interested parties and their requirements (4.2), define the scope (4.3), and establish the ISMS itself (4.4).
Scope is the decision that shapes everything downstream. Define it too broadly and implementation becomes unmanageable; too narrowly and customers won't accept the certificate. Scope by legal entity, site, service or product line — and write down what is excluded and why.
Clause 5 — Leadership
Top management must demonstrate commitment (5.1), publish an information security policy (5.2), and assign roles, responsibilities and authorities (5.3).
"Demonstrate" is literal. Auditors look for meeting minutes, approved budgets and signed policies — not a stated intention.
Clause 6 — Planning
- 6.1.2 Risk assessment — a defined, repeatable process with risk criteria set in advance
- 6.1.3 Risk treatment — choose treatment options, select controls, compare against Annex A, and produce the Statement of Applicability
- 6.2 Objectives — measurable security objectives with plans to reach them
- 6.3 Planning of changes — added in 2022; changes to the ISMS must be planned, not improvised
Clause 7 — Support
Resources (7.1), competence (7.2), awareness (7.3), communication (7.4) and documented information (7.5). Clause 7.5 is where document control lives: versioning, approval, availability and protection.
Clause 8 — Operation
Operational planning and control (8.1), plus performing the risk assessment (8.2) and implementing the risk treatment plan (8.3) at planned intervals. 8.1 also requires you to control externally provided processes — the supply-chain hook.
Clause 9 — Performance evaluation
- 9.1 Monitoring, measurement, analysis and evaluation — decide what you measure and when, before you measure it
- 9.2 Internal audit — an audit programme covering the whole ISMS, conducted by someone independent of the area audited
- 9.3 Management review — at planned intervals, against a defined input list
Clause 10 — Improvement
Continual improvement (10.1) and nonconformity and corrective action (10.2). Note the 2022 revision reversed the order of these two subclauses compared with 2013.
Annex A: the 93 controls
The 2022 revision restructured the old 114 controls across 14 domains into 93 controls in 4 themes:
| Theme | Controls | What it covers |
|---|---|---|
| A.5 Organizational | 37 | Policies, roles, supplier relationships, incident management, legal and contractual requirements |
| A.6 People | 8 | Screening, terms of employment, awareness, disciplinary process, remote working |
| A.7 Physical | 14 | Perimeters, entry, equipment, clear desk, secure disposal |
| A.8 Technological | 34 | Access control, cryptography, logging, network security, secure development |
Each control also carries five attributes for filtering — control type, information security properties (confidentiality / integrity / availability), cybersecurity concepts (Identify, Protect, Detect, Respond, Recover), operational capabilities, and security domains.
The 11 controls that were new in 2022
If you are transitioning from the 2013 version, these are the gaps you will find:
| Control | Name |
|---|---|
| A.5.7 | Threat intelligence |
| A.5.23 | Information security for use of cloud services |
| A.5.30 | ICT readiness for business continuity |
| A.7.4 | Physical security monitoring |
| A.8.9 | Configuration management |
| A.8.10 | Information deletion |
| A.8.11 | Data masking |
| A.8.12 | Data leakage prevention |
| A.8.16 | Monitoring activities |
| A.8.23 | Web filtering |
| A.8.28 | Secure coding |
In practice A.8.28 Secure coding and A.5.7 Threat intelligence are where most organisations have the thinnest evidence.
The Statement of Applicability
Required by clause 6.1.3 d), the SoA is the document auditors reach for first. It must:
- List all 93 Annex A controls
- State whether each is applicable
- Give the justification for inclusion
- Give the justification for exclusion where a control is not applied
- State whether the control is implemented
The most common finding on a first audit is an SoA that excludes controls with a justification amounting to "not relevant to us" and nothing more. Exclusions must trace back to your risk assessment. If the risk assessment does not support the exclusion, it is a nonconformity.
How an ISMS is actually built
A realistic sequence for a first certification. Timelines assume an organisation of roughly 50–250 people with no prior management system.
| # | Step | Output | Typical effort |
|---|---|---|---|
| 1 | Define scope and context | Scope statement, interested-parties register | 1–2 weeks |
| 2 | Secure leadership commitment | Signed policy, assigned roles, budget | 1–2 weeks |
| 3 | Build the asset / information inventory | Asset register with owners | 2–4 weeks |
| 4 | Define risk methodology and criteria | Risk assessment procedure | 1–2 weeks |
| 5 | Run the risk assessment | Risk register | 3–6 weeks |
| 6 | Risk treatment + control selection | Risk treatment plan, SoA | 2–4 weeks |
| 7 | Implement controls and write procedures | Policies, procedures, technical changes | 3–6 months |
| 8 | Operate and collect evidence | Logs, records, training records | min. 3 months |
| 9 | Internal audit + management review | Audit report, review minutes | 3–4 weeks |
| 10 | Stage 1 and Stage 2 certification audit | Certificate | 4–8 weeks |
Total: typically 9–15 months for a first certification. The step people underestimate is #8 — you need a period of operating evidence. An auditor cannot certify a management system that has not yet run a cycle.
Certification structure
- Stage 1 — documentation review, readiness check
- Stage 2 — implementation audit, evidence sampling
- Surveillance audits — years 1 and 2
- Recertification — year 3
ISMS and NIS2 Article 21
This is the question most German organisations arrive with in 2026: does ISO 27001 make us NIS2 compliant?
No — but it covers most of it. NIS2 Art. 21(2) lists ten measure areas. Here is how they map:
| NIS2 Art. 21(2) measure | Primary ISO 27001 coverage |
|---|---|
| (a) Risk analysis and information system security policies | Clauses 6.1.2, 6.1.3; A.5.1 |
| (b) Incident handling | A.5.24–A.5.28 |
| (c) Business continuity, backup, disaster recovery, crisis management | A.5.29, A.5.30, A.8.13 |
| (d) Supply chain security | A.5.19–A.5.22 |
| (e) Security in acquisition, development and maintenance; vulnerability handling and disclosure | A.8.8, A.8.25–A.8.31 |
| (f) Assessing effectiveness of risk-management measures | Clauses 9.1, 9.2, 9.3 |
| (g) Cyber hygiene and security training | A.6.3, A.8.7 |
| (h) Cryptography and encryption | A.8.24 |
| (i) HR security, access control, asset management | A.6.1–A.6.6, A.5.9–A.5.11, A.8.1–A.8.5 |
| (j) MFA, secured voice/video/text, emergency communications | A.8.5, A.5.14 |
What ISO 27001 does not give you:
- Registration with the BSI. A legal duty under the German NIS2UmsuCG, independent of any certificate.
- The Art. 23 reporting cascade — 24-hour early warning, 72-hour notification, final report within one month. ISO 27001 requires incident management; it does not impose these deadlines or this recipient.
- Management liability and training under Art. 20. Members of management bodies must approve the measures, oversee implementation, and undergo training. They can be held personally liable.
- Scope alignment. A certificate scoped to one product line does not cover the entity that NIS2 captures.
Treat ISO 27001 as roughly 70–80% of the technical and organisational work, with the registration, reporting and governance duties as separate obligations. (That proportion is a practitioner rule of thumb, not an official figure — your gap depends entirely on your scope.)
ISMS frameworks compared
| ISO 27001 | BSI IT-Grundschutz | TISAX | |
|---|---|---|---|
| Origin | International (ISO/IEC) | Germany (BSI) | Germany (VDA / ENX) |
| Approach | Risk-based, you choose controls | Baseline modules, prescriptive | VDA ISA catalogue |
| Best for | International customers, broad recognition | German public sector, KRITIS | Automotive supply chain |
| Effort | Moderate | High — very detailed | Moderate |
| Result | Certificate | Certificate (ISO 27001 on the basis of IT-Grundschutz) | Label, shared via ENX portal |
| NIS2 evidence | Strong | Strong, explicitly BSI-aligned | Partial |
If you sell into German automotive, you will likely need TISAX regardless. If you sell internationally, ISO 27001 travels furthest.
What auditors actually find
The recurring nonconformities, in rough order of frequency:
- Risk assessment done once, never repeated. Clause 8.2 requires it at planned intervals and when significant changes occur.
- SoA exclusions with no justification traceable to risk.
- Internal audit not independent — the person who built the ISMS auditing their own work.
- Management review missing required inputs, or held informally with no minutes.
- No evidence of operation. Policies exist; records showing they were followed do not.
- Supplier controls documented but not applied — A.5.19–A.5.22 written up, no actual supplier assessments on file.
- Corrective actions closed without root cause analysis, so the same finding recurs.
- Scope drift — the certificate scope no longer matches what the business actually does.
The pattern: documentation is rarely the problem. Evidence of operation is.
Common mistakes when starting
- Buying a tool first. Tools help you run an ISMS; they do not decide your scope, risk criteria or control selection. Those decisions come first.
- Copying someone else's risk register. An auditor will ask how you arrived at it. "We used a template" is a finding.
- Scoping to the whole company by default. Start with the scope your customers actually ask about.
- Treating Annex A as a checklist to fully implement. It is a menu you select from, driven by risk. Implementing all 93 controls regardless of risk shows you did not do a real risk assessment.
- Leaving management out until the audit. Clause 5 failures are the hardest to remediate late, because they require evidence over time.
FAQ
Is an ISMS the same as ISO 27001? No. The ISMS is your management system. ISO 27001 is the standard that specifies what an ISMS must contain and against which you can be certified.
How many controls does ISO 27001:2022 have? 93, grouped into four themes: organizational (37), people (8), physical (14), technological (34). The 2013 version had 114 across 14 domains.
Do I have to implement all 93 controls? No. You select controls based on your risk assessment and document your reasoning — including exclusions — in the Statement of Applicability.
How long does ISO 27001 certification take? Typically 9–15 months for a first certification, including a minimum operating period of about three months before the Stage 2 audit.
Does ISO 27001 make me NIS2 compliant? It covers most of the Art. 21 risk-management measures, but not BSI registration, the Art. 23 reporting cascade, or the Art. 20 management liability and training duties.
Is ISO 27001:2013 still valid? No. The transition period ended on 31 October 2025.
Can a small company get certified? Yes. Scope and risk drive effort, not headcount. Certified organisations of under 20 people are common — the management system is simply smaller.
What is the Statement of Applicability? A mandatory document listing all 93 Annex A controls with, for each, whether it applies, the justification, and its implementation status.
Next step
If you are working out whether NIS2 applies to you before deciding how far to take an ISMS, start with scope:
→ NIS2 Scope Checker — are you in scope?
Related reading:
Frequently asked questions
Is an ISMS the same as ISO 27001?
No. The ISMS is your management system. ISO 27001 is the standard that specifies what an ISMS must contain and against which you can be certified.
How many controls does ISO 27001:2022 have?
93, grouped into four themes: organizational (37), people (8), physical (14), technological (34). The 2013 version had 114 across 14 domains.
Do I have to implement all 93 controls?
No. You select controls based on your risk assessment and document your reasoning — including exclusions — in the Statement of Applicability.
How long does ISO 27001 certification take?
Typically 9–15 months for a first certification, including a minimum operating period of about three months before the Stage 2 audit.
Does ISO 27001 make me NIS2 compliant?
It covers most of the Art. 21 risk-management measures, but not BSI registration, the Art. 23 reporting cascade, or the Art. 20 management liability and training duties.
Is ISO 27001:2013 still valid?
No. The transition period ended on 31 October 2025.
Can a small company get certified?
Yes. Scope and risk drive effort, not headcount. Certified organisations of under 20 people are common — the management system is simply smaller.
What is the Statement of Applicability?
A mandatory document listing all 93 Annex A controls with, for each, whether it applies, the justification, and its implementation status.
Related reading
EU Cyber Resilience Act (CRA) Explained: Who It Affects and What It Requires
The CRA applies to all products with digital elements sold in the EU. Essential requirements, SBOM mandate, 24-hour vulnerability reporting, and the December 2027 deadline.
complianceNIS2 Explained: Who Is Affected, What You Must Do, and by When
NIS2 in practice — Annex I and II sectors, size thresholds, essential vs important entities, the ten Article 21 measures, the 24/72-hour reporting cascade, and management liability.
complianceSBOM Explained: Software Bill of Materials, Formats, and Why the CRA Requires One
What an SBOM is, what belongs in one, CycloneDX vs SPDX, how to generate and maintain one, and exactly what the EU Cyber Resilience Act mandates.
complianceKRITIS Explained: Germany's Critical Infrastructure Security Requirements
A practitioner's guide to KRITIS — the legal basis, which sectors and thresholds apply, what §8a BSIG demands, how the KRITIS-Dachgesetz adds physical resilience, and what BSI inspectors look for.
Practice this hands-on
Pentevo Academy turns these concepts into guided lessons, videos and quizzes — free.
Start learning free