ISO/IEC 27001:2022 · International certification · ISMS
FRAMEWORKISO 27001 certifies an information security management system the processes by which you run security against 93 Annex A controls. An accredited body audits it in two stages, then surveils it annually.
Median time to Stage 2: 90 days
UKAS & ANAB-accredited bodies supported

Your Statement of Applicability lists all 93 Annex A controls and records, for each one, whether it applies and why. Excluding a control is allowed justifying the exclusion is mandatory. The certification body audits the SoA before it audits anything else.
Last reviewed
Annex A controls
93Reorganized in the 2022 revision into four themes down from 114 controls across 14 domains in 2013.
ISMS clauses
7· 4–10The mandatory management-system requirements. This is what actually gets certified.
Certification cycle
3yearsStage 1 + Stage 2, then annual surveillance audits, full recertification at year three.
Authority
ISO/IECCertified by an accredited body (UKAS, ANAB). A certification not an attestation.
Shared with SOC 2
~70%Most Annex A controls map to SOC 2 Common Criteria. Do one, you've nearly done the other.
The 2022 revision collapsed 14 domains into four readable themes. You justify each control's inclusion (or exclusion) in your Statement of Applicability. Uproot generates that document from your real environment and rewrites it the moment the environment changes.
Organizational
Policies, roles, threat intel, suppliers, and incident management the biggest theme, and where most of the ISMS lives.
People
Screening, terms of employment, awareness training, and offboarding.
Physical
Secure areas, equipment, and utilities largely inherited from your cloud provider's audited data centers.
Technological
Access control, cryptography, logging, secure development, network security where an engineering org actually lives.
A real path from a Series-B customer who already ran SOC 2 with Uproot. Net-new ISMS programs take a little longer at Stage 1.
Week 0
Scope the ISMS
Define boundaries, context, and interested parties. Uproot drafts the scope statement from your org and asset inventory.
Week 1–2
Generate the SoA
All 93 Annex A controls assessed against your stack. Inclusions justified, exclusions documented. Day-one coverage: 70–80%.
Week 3–6
Risk treatment
Risk register, treatment plan, and gap remediation issued as tickets to owners. Mandatory clauses 4–10 stood up.
Week 7–9
Stage 1 audit
Certification body reviews your ISMS documentation through the read-only portal. Findings closed before Stage 2.
Week 12–13
Stage 2 audit
The body tests that controls operate. Evidence is continuous, so there's nothing to scramble for.
Year 1–3
Certified + surveillance
Certificate issued. Annual surveillance audits read from the same live evidence. Recert at year three is a formality.
A Statement of Applicability in a spreadsheet, accurate the day it’s signed and drifting ever after
A binder of policies nobody operates, assembled for the auditor and shelved until next year
A £30k consultant who leaves, taking the only understanding of your ISMS with them
Surveillance audits that re-trigger the panic every single year
An SoA generated from your environment and rewritten automatically when it changes
Controls that operate in production, with evidence pulled from the systems that enforce them
The ISMS lives in one place your whole team can read no single point of failure
Surveillance audits are a portal invite, not a fire drill
A partial map of the evidence behind the Technological theme pulled from the systems that enforce each control, hashed and timestamped.
Access & auth
Okta · MFA + SSO
312
AWS · IAM least-priv
14 roles
GitHub · SSO enforced
org
1Password · secrets vault
live
Crypto & data
AWS · KMS at rest
all
ACM · TLS in transit
1.2+
S3 · public-access block
on
RDS · encryption
enabled
Logging & monitor
Datadog · monitors
218
CloudTrail · audit log
multi-rgn
GuardDuty · threat det
on
PagerDuty · on-call
12w
Secure dev
GitHub · branch protect
main
Snyk · dependency scan
live
CircleCI · pipeline
signed
Terraform · IaC review
enforced
Only an accredited certification body can issue an ISO 27001 certificate. Uproot is body-agnostic and gives yours a read-only portal scoped to your ISMS UKAS, ANAB, or any IAF-recognized accreditation.
Auro Security
CPA FIRM
Atom Audit
CPA FIRM
Cert Pro
CPA FIRM
Johanson Group
CPA FIRM
Prescient Security
CPA FIRM
Tempo audits
CPA FIRM
A-lign
CPA FIRM
MJD Advisors
CPA FIRM
Attinkom
CPA FIRM
Darata
CPA FIRM
Glocert
CPA FIRM
+ 23 more
on request
8 articles
ISO 27001 certification process, Annex A controls, ISMS scope and ISO 42001 for AI management.
The standard, its structure, and the 93 Annex A controls.
Stage 1, Stage 2, and what the certification body looks for.
Risk software, and the AI management standard built on the same ISMS.
No, but they overlap heavily roughly 70% of controls. SOC 2 is a US attestation report; ISO 27001 is an international certification of your management system. Uproot maps both to the same evidence, so the second one is mostly already done.
The SoA lists all 93 Annex A controls and justifies whether each is included or excluded, with rationale. It’s the spine of your certification. Uproot generates it from your real environment and keeps it current automatically.
Stage 1 is a documentation and readiness review does the ISMS exist and make sense. Stage 2 tests that the controls actually operate. With continuous evidence, Stage 2 stops being a scramble.
No. You apply the controls relevant to your risks and justify any exclusions in the SoA. Most cloud-native companies exclude a handful of physical controls inherited from their provider’s audited data centers.
Three years, with annual surveillance audits in between. Full recertification happens at year three. Because Uproot’s evidence is continuous, surveillance audits are low-drama.
ISO/IEC 27001:2022 is current; the 2013 version is being retired. Uproot ships the 2022 Annex A (93 controls, four themes) and handles the transition mapping if you’re migrating an older ISMS.
Connect your stack, generate the Statement of Applicability, and watch readiness climb in real time. Invite your certification body when Stage 2 is a formality.