
ISO 27001 vs ISO 27002: Key Differences, Requirements and Benefits
ISO 27001 and ISO 27002 are companion standards. They share the same 93 security controls, and they do very different jobs. ISO 27001 sets the auditable requirements for an information security management system (ISMS), and it is the standard you certify against. ISO 27002 explains how to implement each control in depth, and it has nothing to certify.
There is no ISO 27002 certificate. Certification bodies audit and certify against ISO 27001 only. ISO 27002 contains guidance, not requirements, so “ISO 27002 certified” is always a misstatement.
This guide compares the two 2022 editions side by side. It shows where each standard fits in an ISO 27001 certification project and how to use them together. If you are weighing ISO 27001 certification for your business, the comparison below will save you time and avoid costly mistakes.
ISO 27001 is the requirements standard for an information security management system, and it is the one you certify against. ISO 27002 is the companion guidance standard with implementation advice for the same 93 controls, and it carries no certificate. You certify to ISO 27001. You consult ISO 27002.
The names invite confusion. The numbers are consecutive, the subject is identical, and the same ISO/IEC committee maintains both. Yet the division of labor is clean. ISO/IEC 27001:2022 is titled “Information security management systems — Requirements.” Its Clauses 4 to 10 set out what a certifiable ISMS must do, written as auditable “shall” statements. Annex A then lists 93 reference controls in one line each.
ISO/IEC 27002:2022 takes those same 93 controls and expands each one into a purpose statement, implementation guidance, and supporting information. One standard is the exam. The other is the textbook.
Key Takeaways
- ISO 27001 sets the auditable requirements for an ISMS. That means mandatory Clauses 4 to 10 plus the 93-control Annex A reference set. It is the only one of the pair you can certify to.
- ISO 27002 provides per-control implementation guidance: a purpose, detailed advice, and five attributes for each control. It has no requirements and no certificate.
- Both 2022 editions share the same 93 controls in four themes: Organizational (37), People (8), Physical (14), and Technological (34). The previous editions listed 114 controls.
- The working sequence is simple. Run the risk assessment, select controls, record decisions in the Statement of Applicability, then implement using ISO 27002 guidance.
- “ISO 27002 certified” does not exist. Auditors audit against ISO 27001, but they expect implementations that match good practice, which is what ISO 27002 describes.
What Is the Difference Between ISO 27001 and ISO 27002?
ISO 27001 tells you what an information security management system must do. ISO 27002 tells you how to implement the security controls that ISO 27001 references. Everything else about the relationship follows from that split.
Most teams meet the two standards in that order. A customer, partner, or regulator asks for ISO 27001 certification. The people doing the work then discover ISO 27002 the first time a one-line Annex A control raises more questions than it answers.
ISO/IEC 27001:2022: The Requirements Standard
ISO 27001 is a specification. Its clauses are written so an auditor can test your ISMS against them.
- Full title: “Information security management systems — Requirements.”
- Mandatory clauses: Clauses 4 to 10 cover context, leadership, planning, support, operation, performance evaluation, and improvement. None of them can be excluded from your scope.
- Annex A: It lists 93 controls as a reference set. You select against it and justify every inclusion and exclusion in the Statement of Applicability.
- Certifiable: An accredited certification body audits the ISMS in a Stage 1 and Stage 2 audit, then issues the certificate. Surveillance audits maintain it across a three-year cycle.
ISO/IEC 27002:2022: The Guidance Standard
ISO 27002 is a reference. It exists to help the people who build and run the controls.
- Full title: “Information security, cybersecurity and privacy protection — Information security controls.” The 2022 edition retired the older “Code of practice” name.
- Depth: It expands each of the same 93 controls into a purpose statement, implementation guidance, and other information. Annex A deliberately leaves this detail out.
- Attributes: Every control carries five tags: control type, information security properties, cybersecurity concepts, operational capabilities, and security domains. Teams use them to filter and map the catalogue.
- Not certifiable: It contains guidance, not requirements. There are no “shall” statements, nothing to audit against, and no certificate.
Here is a useful mental model. ISO 27001 is short and formal because every sentence has to be auditable. ISO 27002 is long and practical because none of it has to be. That is the design, not a flaw.
The split is also old. Both standards descend from the British standard BS 7799. Part 1, a code of practice, became ISO/IEC 17799 in 2000 and was renumbered ISO/IEC 27002 in 2007. Part 2, the certifiable specification, became ISO/IEC 27001 in 2005. The two have been revised in step ever since. They were built as a pair, never as competitors or substitutes.
ISO 27001 vs ISO 27002 at a Glance
Five dimensions answer almost every question that buyers, implementers, and auditors ask about the pair. The same rows come up again and again in procurement questionnaires and audit planning.
Dimension | ISO/IEC 27001:2022 | ISO/IEC 27002:2022 |
Purpose | Defines the requirements a certifiable ISMS must meet. It is the standard your organization is audited against. | Gives detailed implementation guidance for information security controls. It is the reference you build from. |
Structure | Mandatory Clauses 4 to 10 plus Annex A, with 93 reference controls stated in one line each. | The same 93 controls in four themes, each expanded with a purpose, guidance, other information, and five attributes. |
Certifiable? | Yes. Accredited certification bodies audit against it and issue ISO 27001 certificates. | No. It contains no requirements, so there is nothing to certify against. |
Primary audience | Leadership and the ISMS owner, plus the auditors, customers, and regulators who ask for the certificate. | Implementers such as security engineers, IT operations, and control owners deciding what “good” looks like. |
How it is used | Builds the management system: scope, risk process, Statement of Applicability, internal audit, and management review. | Consulted control by control during implementation. Auditors also read it as a benchmark of good practice. |
The certifiable row matters most in practice. Suppose a customer questionnaire asks about “ISO 27002 compliance.” The real answer is an ISO 27001 certificate whose Statement of Applicability shows which of the 93 controls are in scope. A certificate against ISO 27002 alone cannot exist.
The audience row is the other one to act on. Give ISO 27001 to whoever owns the management system. It defines the records leadership will be asked to produce: the scope statement, risk methodology, Statement of Applicability, internal audit programme, and management review minutes. Give ISO 27002 to the people who own the controls. It reads like an engineering reference because that is what it is.
Read contracts closely, too. A promise to “implement controls aligned with ISO 27002” is a design benchmark. A promise to “maintain ISO 27001 certification” is an auditable obligation with an annual external check attached.
Same 93 Controls, Different Depth
The dependency runs from ISO 27002 to ISO 27001. Annex A is derived from the ISO 27002 control catalogue, not the other way around. That is why the 2022 refresh arrived in two steps.
ISO 27002:2022 came first, in February 2022. It restructured the catalogue from 114 controls in 14 clauses into 93 controls in four themes. ISO 27001:2022 followed in October 2022 with an Annex A aligned to the new set.
Overlapping controls were merged, and eleven were new. Threat intelligence, cloud services security, data masking, and secure coding are among them. The numbering now runs identically in both documents, from 5.1 through 8.34. Every row of your Statement of Applicability therefore maps one to one with a chapter of implementation guidance.
The four themes break down as follows:
- Organizational controls (5.1 to 5.37): 37 controls covering policies, roles, supplier relationships, and incident management.
- People controls (6.1 to 6.8): 8 controls covering screening, awareness, and remote working.
- Physical controls (7.1 to 7.14): 14 controls covering secure areas, equipment, and media.
- Technological controls (8.1 to 8.34): 34 controls covering access, cryptography, logging, and secure development.
The difference between the documents is altitude, not content. Annex A states control 8.24, use of cryptography, in a single sentence. ISO 27002 expands the same control into guidance on cryptographic policy and key management. Multiply that by 93 and you have the practical relationship. Annex A is the checklist you justify decisions against. ISO 27002 is the reference you open to implement each line.
The five attributes are ISO 27002’s quiet upgrade. Each control is tagged across five dimensions:
- Control type: preventive, detective, or corrective.
- Information security properties: confidentiality, integrity, and availability.
- Cybersecurity concepts: identify, protect, detect, respond, and recover.
- Operational capabilities: the practical function the control supports.
- Security domains: the broad area of security it belongs to.
The standard also lets organizations add attributes of their own. Mature teams use the tags to slice the catalogue. Filter by detective controls to review monitoring coverage. Use the cybersecurity concepts to cross-map the control set against other frameworks. Annex A carries none of this metadata, which is one more reason the two documents are read together rather than interchangeably.
How to Use ISO 27001 and ISO 27002 Together
A certification project uses both standards in a fixed sequence. The order matters more than most teams expect. Controls should be chosen because a risk assessment demanded them.
Some organizations start by implementing the ISO 27002 catalogue front to back. They end up with unused controls and a Statement of Applicability written backwards to justify them. Avoid that route.
- Run the risk assessment. ISO 27001 Clause 6.1.2 requires a documented process to identify, analyse, and evaluate information security risks. This process drives every control decision that follows.
- Select controls to treat the risks. Under Clause 6.1.3 you determine the controls your risk treatment needs, from any source. You then compare them against Annex A to confirm nothing necessary was overlooked.
- Record decisions in the Statement of Applicability. The SoA covers all 93 Annex A controls, with a justification for each inclusion and exclusion.
- Implement using ISO 27002. For each selected control, the matching ISO 27002 entry is the natural starting point for your policy, procedure, or technical configuration.
- Certify against ISO 27001. An accredited certification body audits the ISMS, including the clauses, risk process, SoA, and control operation. It then issues the certificate. ISO 27002 never appears on it.
The certification audit tests both halves of that sequence. Stage 1 is mostly a documentation review of the scope, risk methodology, Statement of Applicability, and mandatory records. Stage 2 checks whether the ISMS and the selected controls actually operate. Auditors look at evidence, records, interviews, and observation.
ISO 27002 is never the audit criterion at either stage. Still, a control built from its guidance walks into Stage 2 with far less to prove.
How Auditors Treat ISO 27002
This is where the most common confusion resolves. Certification auditors audit against ISO 27001. It is the only standard on the audit plan. But when they examine how a control operates, they expect an implementation consistent with recognized good practice. ISO 27002 is the most direct written expression of that practice.
An organization that ignores ISO 27002 is not non-compliant by definition. It has simply chosen to argue that its controls are suitably designed from scratch, instead of building on the answer key.
The same logic protects you as a buyer. A supplier that claims “ISO 27002 alignment” without an ISO 27001 certificate is describing an uncertified implementation. It may be a good one, but no independent auditor has examined it.
The Wider ISO 27000 Family
The numbering keeps confusing people beyond 27002, so here is a one-line map of the family:
- ISO/IEC 27000 defines the shared vocabulary.
- ISO/IEC 27005 gives guidance on information security risk management.
- ISO/IEC 27701 extends the ISMS into privacy information management.
All of them orbit ISO 27001, the requirements standard at the centre of the family.
Where QCert360 Fits In
For organizations heading toward ISO 27001 certification, this pairing is the whole project in miniature. ISO 27001 supplies the management-system spine and the audit. ISO 27002 supplies the depth behind each control.
QCert360 is an ISO certification consulting firm based in Bengaluru, serving clients across 175+ countries. Our ISO 27001 consultants support both halves of the split:
- Scoping and risk assessment
- Statement of Applicability drafting
- ISO 27002-aligned control implementation
- Internal audit and management review preparation
- Coordination of the certification audit with accredited certification bodies
The certificate itself always comes from the certification body. An advisor who offers to “issue” one is selling something else.
Every business has a different scope, risk profile, and timeline, so we price each engagement on request. Share your requirements and we will send a custom quote for your ISO 27001 certification. Talk to a QCert360 ISO 27001 consultant today.
ISO 27001 vs ISO 27002: Frequently Asked Questions
What is the difference between ISO 27001 and ISO 27002?
ISO 27001 is the requirements standard. It specifies what a certifiable information security management system must do, through mandatory Clauses 4 to 10 and the 93-control Annex A reference set. Accredited certification bodies audit against it. ISO 27002 is the companion guidance standard. It expands the same 93 controls into implementation advice, with no requirements and no certificate. In short, ISO 27001 defines the destination, and ISO 27002 describes a well-trodden way to get there.
Can you get certified to ISO 27002?
No. ISO 27002 contains guidance rather than requirements. There are no “shall” statements to audit against, so no certification scheme exists for it. Certification is available only against ISO 27001. A vendor claiming to be “ISO 27002 certified” is either describing an ISO 27001 certificate loosely or misrepresenting its status. Ask for the ISO 27001 certificate, the accredited certification body that issued it, and the scope statement.
Do I need to buy both standards?
If you are certifying, you need ISO 27001. It is the specification your ISMS will be audited against, and a paraphrase is no substitute. ISO 27002 is technically optional but strongly recommended. Annex A gives you each control in one line, while ISO 27002 turns that line into guidance your control owners can act on. Most implementation teams keep both open. Both are sold by ISO and by national standards bodies.
Are the controls in ISO 27001 and ISO 27002 the same?
Yes. Annex A of ISO 27001:2022 is derived from ISO 27002:2022. The controls, the four themes, and the numbering from 5.1 to 8.34 are the same. The difference is depth. Annex A states each control in a sentence as a reference list for the Statement of Applicability. ISO 27002 adds a purpose statement, implementation guidance, other information, and five classification attributes.
What changed in the 2022 editions?
ISO 27002:2022 arrived in February 2022. It changed its title, cut 114 controls in 14 clauses down to 93 controls in four themes, and added new controls such as threat intelligence, cloud services security, data masking, and secure coding. It also introduced the five-attribute tagging system. ISO 27001:2022 followed in October 2022 and aligned Annex A to the new catalogue, with modest clause-level edits. The transition window for certificates issued against the 2013 edition closed on 31 October 2025.
Where do the 93 controls come from?
They come from ISO 27002. The ISO/IEC committee that maintains the 27000 family develops and revises the control catalogue there. ISO 27001 then reproduces it in summary form as Annex A. That is why ISO 27002 was revised first in 2022 and ISO 27001 followed months later. Neither standard requires you to implement all 93 controls. You select controls based on your risk assessment and justify any exclusions in the Statement of Applicability.
How long does ISO 27001 certification take?
Timelines depend on scope, size, and existing security maturity. A smaller organization with solid controls moves faster than a multi-site business starting from scratch. The main stages are scoping, risk assessment, control implementation, internal audit, and the two-stage certification audit. A QCert360 consultant can give you a realistic timeline once we understand your scope.
Do small businesses need ISO 27001 certification?
No law requires it in most cases, but customers and partners increasingly ask for it. Enterprise buyers often make an ISO 27001 certificate a condition of doing business, especially for software, outsourcing, and data-handling services. For small businesses, certification can open doors to larger contracts and shorten security due diligence.
Our Services
ISO Standards
- ISO 9001 Certification
- ISO 14001 Certification
- ISO 45001 Certification
- ISO 22000 Certification
- ISO 17025 Certification
- ISO 27001 Certification
- ISO 13485 Certification
- ISO 20000-1 Certification
- ISO 41001 Certification
- ISO 22716 Certification
- ISO 50001 Certification
- ISO 22301 Certification
- ISO 29993 Certification
Product Certifications
Other international standards
- FSSC 22000 Certification
- HIPAA
- HACCP Certification
- SA 8000 Certification
- GMP Certification
- GDPR
- GDP Certification
- GLP Certification
- Certificate of Conformity
QCert360 provides a wide range of services including ISO certification, audit support, compliance consulting, and training. They specialize in helping businesses achieve global standards and certifications like ISO 9001, ISO 27001, ISO 14001, and many others. Their team ensures a seamless experience from consultation to certification, supporting clients at every stage.
The time it takes to achieve certification can vary depending on the complexity of the standard and the readiness of your organization. On average, it takes about 3 to 6 months. QCert360 works closely with clients to streamline the process, ensuring that all requirements are met efficiently and within a reasonable timeline.
QCert360 is a trusted partner with years of experience in helping businesses obtain international certifications. Their expert consultants provide tailored solutions, ensuring your organization not only meets but exceeds industry standards. With a customer-centric approach, they focus on offering end-to-end support to simplify the certification journey.
QCert360 serves a wide range of industries including manufacturing, healthcare, information technology, education, and services, among others. They customize their certification solutions to meet the unique requirements of each industry, ensuring relevance and compliance with global standards.
Yes, QCert360 provides ongoing support even after certification. They offer services like surveillance audits, recertification guidance, and consultancy to help maintain and improve your certification status. Their team ensures that your organization stays compliant and up-to-date with any changes in certification standards.
Getting started with QCert360 is simple. You can contact them via their website to request a consultation. Their team will assess your needs, discuss the best certification options for your business, and outline the steps involved. From there, they’ll guide you through the entire process, ensuring you’re prepared for certification.
QCert360 stands out due to its customer-focused approach, industry expertise, and comprehensive service offerings. Their team doesn’t just help you obtain certification but works to ensure your organization thrives in compliance with international standards. They also offer personalized consultation, making the process smoother and more efficient, ensuring long-term success for your business.
The cost of certification varies depending on factors such as the type of certification, the size and complexity of your organization, and the specific industry requirements. QCert360 offers competitive pricing and provides tailored quotes based on your unique needs. They ensure transparency and work with you to find the most cost-effective solution for your certification goals.
Yes, QCert360 offers internal audit services to help assess and improve your organization’s processes. Their expert auditors conduct thorough reviews of your systems and operations to ensure they meet required standards. They also provide actionable recommendations to help enhance efficiency and compliance, making sure you’re fully prepared for external audits.
If your organization doesn’t pass an audit or certification assessment, QCert360 works with you to understand the reasons for non-compliance and provides support to rectify the issues. They offer guidance on corrective actions and help you prepare for a re-assessment. Their goal is to ensure your organization meets the necessary standards for certification, and they will be by your side to make the process as smooth as possible.