Any Questions?

Feel free to reach out if you would like to find out how Athereon GRC can support you with current governance, risk and compliance issues.

26.8.2026
8 minutes

ISO 27001 Requirements at a Glance: What Companies Really Need to Fulfill

ISO 27001 is the internationally authoritative standard for information security management systems (ISMS). Its requirements can be divided into two levels: the mandatory standard clauses 4 through 10 and the security controls from Annex A. Together, they define what an organization must establish, document, and demonstrate in order to operate a certifiable ISMS.

The currently applicable version is ISO/IEC27001:2022, adopted in Germany as DIN ISO/IEC 27001:2024-01. The three-year transition period for the 2013 predecessor version ended on October 31, 2025. Since then, only the 2022 version has been eligible for certification; certificates issued under the previous version have lost their accreditation status. For organizations that have not yet completed the transition, ISO 27001 certification based on the requirements of the current standard is no longer something that can be postponed—it is a prerequisite for holding a valid certificate.

The Two Levels of ISO 27001 Requirements

The standard deliberately distinguishes between the management system and the specific protective measures. The main body in chapters 4 through 10 describes generically and non-prescriptively how an ISMS is to be established, operated, and improved. It does not specify which technical measures must be implemented, but rather requires a functioning governance process.

Annex A provides the prescriptive counterpart: a reference list of 93 measures (controls) from which each organization makes a risk-based selection. This selection is documented in the Statement ofApplicability (SoA). Important to understand: The 93 controls are not a rigid requirements catalog that must be checked off in its entirety. What matters is a comprehensible justification of which controls are applicable and how their effectiveness is demonstrated.

Chapters 4 Through 10 in Detail

The main body follows the harmonized structure that is also used by ISO 9001 and ISO 14001. This makes it easier to integrate the standard into existing management systems. At the same time, the seven chapters reflect the PDCA cycle: plan (chapters 4 through 6), do (7 and 8), check (9), and act (10).

Chapter 4: context of the organization

The first step is to define the scope. The organization identifies internal and external issues relevant to information security, along with the expectations of interested parties such as customers, regulators, or suppliers. Only once the scope has been clearly delineated can an ISMS be built in a meaningful way.

Chapter 5: leadership

Top management bears responsibility. It adopts the information security policy, provides resources, and assigns roles and authorities. Information security without visible commitment from management is regularly flagged in audits. For regulated industries, this point is particularly relevant because NIS2 establishes personal accountability at the management level.

Chapter 6: planning

This is the heart of the ISO 27001 requirements and, in practice, the most common source of errors. Chapter 6 requires a documented information security risk assessment: The organization identifies risks to the confidentiality, integrity, and availability of its information assets, evaluates their likelihood and impact, and defines acceptance criteria. The standard does not prescribe a specific method. Common approaches include an asset-based method, which starts from information assets, and a scenario-based method, which reasons from potential threats. The critical point is that the chosen method is applied consistently and produces repeatable results. Each risk is also assigned a risk owner, who is responsible for its treatment and formally accepts residual risks.

Risk treatment builds on this foundation: For each relevant risk, the organization decides whether to reduce, accept, transfer, or avoid it. The measures derived from this are matched against Annex A and recorded in the Statement of Applicability. This must indicate, for each of the 93 controls, whether it is applicable, on what grounds, and whether it has been implemented. Exclusions are permitted but must be justified in acomprehensible manner. Chapter 6 additionally requires measurable information security objectives. In audits, most findings arise because risk assessment and documentation remain incomplete or the link between a risk and the chosen control is not traceable.

Chapter 7: support

An ISMS requires resources, competence, awareness, and regulated communication. This chapter also requires proper control of documented information: Policies, procedures, and evidence must be current, versioned, and retrievable. In practice, many deviations occur here as well, because documentation drifts apart over time.

Chapter 8: operation

The planned processes are implemented and controlled. Risk assessment and risk treatment are not a one-time exercise but are repeated at planned intervals and whenever significant changes occur. In addition, the standard requires control of outsourced processes, which includes supplier and cloud relationships.

Chapter 9: performance evaluation

The organization monitors, measures, and evaluates the effectiveness of its ISMS. This includes internal audits following a rolling plan, as well as management reviews conducted at least annually, in which leadership reviews results and decides on adjustments.

Chapter 10: improvement

Nonconformities are recorded, corrected, and investigated for their root causes. The standard thereby establishes a continuous improvement process that prevents information security from stagnating after initial implementation.

AnnexA: an overview of the 93 controls

With the 2022 revision, Annex A was restructured. The previous 114 controls in 14 categories were consolidated into 93 controls across four thematic areas. Eleven new controls were added, addressing developments that were missing in the previous version, such as threat intelligence (A.5.7), information security for cloud services (A.5.23), data masking (A.8.14), and secure software development.

The four categories are structured as follows:

  • A.5 Organizational controls (37): policies, roles, supplier relationships, incident handling, and overarching governance.
  • A.6 People controls (8): background screening, training and awareness, arrangements for role changes or departures.
  • A.7 Physical controls (14): access control, protection of premises and equipment, physical monitoring.
  • A.8 Technological controls (34): access management, cryptography, logging, protection against malware, and secure development.

Since November 2024, Amendment Amd 1:2024 has added climate-related aspects that must be considered as part of the context and risk assessment. In terms of content, the German version DIN EN ISO/IEC 27001:2024-01 remains identical to the international ISO/IEC 27001:2022.

Requirementsfor the certification process

The actual certification is carried out by an accredited body in two stages: a document review (stage 1) and an in-depth audit of the implementation (stage 2). Afterward, annual surveillance audits confirm that the ISMS is being operated effectively; recertification is due after three years. ISO 27002 serves as a guideline for the concrete implementation of the Annex A measures, but is not itself certifiable.

A GAP analysis has proven effective for preparation. It compares the current state with the standard's requirements, uncovers gaps in processes and evidence, and provides the basis for a prioritized implementation plan. Especially for smaller organizations, it is worthwhile to work through the measures not according to the numbering in Annex A, but by risk priority and quickly achievable security gains.

For companies, this means: A certificate does not result from a one-time effort, but from a continuously maintained system. The ISO 27001 requirements for evidence and documentation accompany the entire lifecycle of the ISMS and thus extend beyond the audit date.

Classification: ISO 27001, NIS2, and DORA

Demand for the standard has risen significantly of late—and there is a regulatory reason for this. In Germany, the NIS2 Implementation Act entered into force on December 6, 2025, without any transition period, expanding the number of regulated entities within the country from around 4,500 to approximately 29,500. The obligation to register with the BSI ended on March 6, 2026; those who missed the deadline are in default but remain obligated to register. Since then, the BSI has been in the operational review and supervisory phase. NIS2 is thus no longer a preview but applicable law in most European countries—with the risk of fines and personalliability for management.

An ISMS based on ISO 27001 covers a large portion of these obligations, particularly risk management as well as technical and organizational measures. However, complete overlap does not exist. Open issues remain regarding the statutory reporting obligations (early warning within 24 hours, full report within 72 hours, final report within one month), registration with the BSI, the training requirement for management, and the extended documentation on supply chain security. Organizations that are also subject to DORA in the financial sector—applicable since January 17, 2025—should consider both frameworks together to avoid duplicate work. For companies, this means: An existing ISMS provides a solid foundation but does not replace the additional legal obligations.

Implementing the ISO 27001 requirements withAthereon GRC

As a leading European GRC platform with a 100% made in Germany commitment, Athereon GRC maps the requirements of ISO 27001 into clear, auditable processes. The ISMS module guides you from context and scope definition through risk assessment to the Statement of Applicability, without evidence getting lost in scattered files. Complementary modules such as ERM, BCM, DSM, and SRM integrate information security into an overarching governance system.

The framework-agnostic approach makes it possible to address ISO 27001 alongside adjacent regulations such as NIS2, DORA, or TISAX®, rather than managing each topic separately. You are supported by the AI agent LAiKA. You can draw on a wide variety of agents depending on your needs: The Infrastructure Mapper, for example, captures your system landscape, the Compliance Assistant maps controls to the standard's chapters and controls, and the Questionnaire Assistant speeds up responses to audit and supplier questionnaires. The guiding principle is "Nothing without your OK": LAiKA prepares and suggests; the decision remains with you.

Our overview of ISO 27001 shows how to build a certifiable ISMS step by step.

Conclusion

The ISO 27001 requirements aim at a continuously operated management system that understands risks, justifies controls, and demonstrates their effectiveness. Chapters 4 through 10 provide the governance framework, while Annex A offers the risk-based toolbox. Companies that bring both together and maintain them with a suitable platform see compliance as an opportunity: as robust evidence that builds trust with customers, partners, and regulators.

Would you like to learn more?

Book a noncommittal demo appointment with our team to analyze your individual use case with us.