Back to blog
Comparisons

ISO 27001 vs ISO 27002: which one do you certify against?

One is a certifiable standard, the other is guidance you cannot certify against. How they relate, why 27002 is where the practical detail lives, and which one your customer actually means.
GRC Copilot Team
ISO 27001 vs ISO 27002: which one do you certify against?

You certify against ISO 27001. You cannot certify against ISO 27002 - it is guidance. That single fact resolves most of the confusion, but the relationship between them is worth understanding, because 27002 is where the practical implementation detail actually lives.

The relationship in one paragraph

ISO 27001 specifies the requirements for an information security management system, and includes Annex A - a list of 93 controls stated in a single line each. ISO 27002 takes those same 93 controls and expands each one into implementation guidance: purpose, how it works, what to consider, and other information. Same controls, different depth, different purpose.

Side by side

  • Nature. 27001 is a requirements standard using "shall" language. 27002 is a code of practice using "should" language.
  • Certifiable. 27001 yes, by an accredited body. 27002 no - there is no such certificate, and any vendor claiming one has misunderstood.
  • What it contains. 27001: management-system clauses 4 to 10 plus Annex A control titles. 27002: detailed guidance for each control.
  • Length. 27001 is comparatively short. 27002 is several times longer, because guidance takes space.
  • Who uses it. 27001 is used by management, auditors and certification bodies. 27002 is used by whoever has to actually implement a control and wants to know what "good" looks like.
The practical workflow: read 27001 to know what is required, read 27002 to know how to do it, and record your decisions in the Statement of Applicability - which is a 27001 artefact.

Turn Annex A into an assessed control set

GRC Copilot assesses you against ISO 27001 control by control, links each to real evidence, and keeps your Statement of Applicability current as things change.

The 2022 restructure

The current versions reorganised the controls from the older fourteen-clause structure into four themes - organisational, people, physical and technological - and consolidated the count to 93, introducing a number of controls reflecting modern practice such as threat intelligence, cloud service security, and secure coding.

Controls also carry attributes - for example control type, security property, and operational capability - which make it easier to filter and report on them. If you are working from an older transition, that attribute model is one of the more useful additions.

What this means practically

  • Annex A alone is often too terse to implement from. "Information security policies shall be defined" tells you the requirement, not what belongs in them. That is what 27002 supplies.
  • You are audited against 27001, including your own Statement of Applicability - not against how closely you followed 27002 guidance.
  • Deviating from 27002 is legitimate where your risk assessment justifies a different approach. It is guidance, not requirement.
  • Buying 27002 is usually worth it if you are implementing rather than merely governing. Teams that skip it tend to re-derive the same guidance more slowly.

Where the rest of the family fits

  • ISO 27005 - guidance on information security risk management.
  • ISO 27017 and 27018 - cloud security and cloud privacy guidance.
  • ISO 27701 - the privacy extension, which is certifiable but only alongside 27001.
  • ISO 27004 - monitoring, measurement, analysis and evaluation.

Only 27001 and 27701 lead to certificates. The rest are guidance you draw on as needed.

Frequently asked questions

Can we be "ISO 27002 certified"?

No. If a supplier claims this, they either mean ISO 27001 or they have misunderstood the standards - which is itself worth probing.

Do we need to buy both?

You need 27001 to certify. Most implementation teams find 27002 worth the cost because it turns one-line control titles into actionable guidance.

Do we have to follow 27002 exactly?

No. It is guidance. Your risk assessment justifies your implementation, and the Statement of Applicability records it.

What actually changed in 2022?

Controls were restructured into four themes and consolidated to 93, with new controls covering modern practice and a new attribute model for filtering and reporting.

Key takeaways

  • 27001 is certifiable requirements; 27002 is non-certifiable guidance.
  • Same 93 controls - 27002 just explains how to implement them.
  • You are audited against 27001 and your own Statement of Applicability.
  • Deviating from 27002 is fine when your risk assessment supports it.
#iso27001 #iso27002 #comparison #annex-a #certification