What Is ISO/IEC 27001 — Briefly and Clearly
If your company handles customer data, access credentials, or source code, and a partner in the EU or US asks you to "show a certificate," they almost certainly mean ISO 27001, formally ISO/IEC 27001. It's the international standard for an information security management system (ISMS), one that defines how a company identifies risks to its data, chooses appropriate controls, and proves on paper that the system actually works rather than just existing for show.
The standard is published jointly by two organizations, ISO (International Organization for Standardization) and IEC (International Electrotechnical Commission), which is why the full name always carries the slash: ISO/IEC 27001. The current edition is ISO/IEC 27001:2022, which replaced the 2013 version. The standard doesn't tell you which specific tools to buy or what your password policy should look like. It tells you something different: identify your risks, choose adequate controls, keep evidence that those controls work, and keep improving the system. That's the key difference from purely technical standards like PCI DSS: ISO/IEC 27001 is about management, not a fixed checklist of firewall settings.
The first version came out in 2005, based on the British BS 7799-2. The second arrived in 2013, and the current one in 2022. Each revision cuts bureaucracy and brings the standard closer to real-world risk: the 2013 edition dropped an overly rigid link to specific technologies, and the 2022 edition restructured the controls around today's threats, including cloud services, threat intelligence, and supply-chain attacks. In 2026, when attacks through vendors and contractors have become routine rather than the exception, that logic translates directly into business risk.
Certification tells the outside world something specific: an independent, accredited body reviewed your ISMS and confirmed it meets the standard's requirements. For B2B contracts in IT, finance, or defense manufacturing, that's no longer a competitive edge, it's table stakes. Without the certificate, you simply don't get into the tender or the due-diligence process. Ekontrol prepares companies for exactly that outcome; see the ISO/IEC 27001 certification page for details.
ISO/IEC 27001 in Brief
The standard sets requirements for an information security management system (ISMS). The current edition is ISO/IEC 27001:2022, which fully replaced the 2013 version as of October 2025. Ukraine has a national counterpart, DSTU ISO/IEC 27001:2023. The certificate is issued for 3 years with a mandatory annual surveillance audit. The standard doesn't dictate specific technical tools: it requires risk assessment, selection of adequate controls from the 93 Annex A controls, and documented evidence that the system works in practice rather than existing only on paper.
How an ISMS Works: The Information Security Management Cycle
An ISMS (information security management system) isn't a binder of policies or antivirus software running on a server. It's a management cycle that ISO/IEC 27001 builds around Plan-Do-Check-Act logic: you plan controls based on risk, implement them, check their effectiveness through internal audits and metrics, and correct what didn't work. The cycle repeats every year; it isn't a one-off exercise before an audit.
The core of the system is risk assessment. A company builds a register of information assets (databases, servers, source code, customer personal data), identifies threats to each one (leakage, loss of access, compromise), evaluates likelihood and impact, and decides: accept the risk, reduce it with a control, transfer it through insurance or outsourcing, or avoid it. The output is the Statement of Applicability (SoA): a document that tells the auditor which of the 93 Annex A controls apply, which don't, and why.
This is where a common mistake creeps in. An ISMS built entirely around the IT department fails audits regularly. The standard requires leadership involvement (clause 5), people management (the People controls), and physical security of the office. In other words, it's an organizational system, not a security department's side project. If top management doesn't take part in at least one management review a year, the auditor will flag a nonconformity even if every technical control is perfectly configured.
Who Needs ISO/IEC 27001 Certification in Ukraine
Formally, ISO/IEC 27001 is voluntary. In practice, for six categories of Ukrainian business it has long since become a contractual requirement.
- IT and SaaS companies outsourcing for clients in the EU and US. A European client handing over personal data or source code will ask for proof of security as early as the security-questionnaire stage; a certificate closes that question with one document instead of a month of correspondence.
- Fintech and e-commerce. Payment data, KYC records, transaction history: these are all high-value-loss assets, and sooner or later a regulator or payment scheme will ask for proof of control.
- BPO and shared service centers, which process customer data at scale with no direct contact with the end user. Trust here rests entirely on process, and the certificate substitutes for personal reputation.
- Defense manufacturers in NATO supply chains. ISO/IEC 27001 layers on top of an existing ISO 9001 or AQAP 2110: design documentation for a drone or an EW system needs the same level of access control as a bank's financial data, just with different consequences if it leaks.
- Government and municipal organizations, where data protection is a legal requirement, not a client preference.
- Companies preparing for a tender or an investment round, where due diligence includes a cyber-risk review. Holding the certificate removes that item from an investor's or a public buyer's list of concerns.
Annex A: Standard Structure and the 93 Security Controls
ISO/IEC 27001:2022 itself is a compact document built on the shared Annex SL structure common to every management-system standard (ISO 9001, ISO 14001, and others). Ten clauses run from the organization's context (clause 4) and leadership (5) through risk planning (6), support (7), operation (8), performance evaluation (9), and improvement (10). Clauses 1-3 are introductory: scope, normative references, terms and definitions.
The largest practical part isn't the main text at all, it's Annex A: a list of 93 controls grouped into four themes. The 2022 edition cut them down from 114 (in the 2013 version) by merging overlapping items, not by weakening requirements. Quite the opposite: it added 11 new controls for modern threats, including threat intelligence, cloud service security, data masking, data leakage prevention (DLP), physical security monitoring, and secure coding.
A company isn't required to implement all 93 controls. It selects the applicable ones based on its risk assessment and records the choice, including the justification for any exclusions, in the Statement of Applicability. An auditor checks the logic behind that selection, not a mechanical checklist count.
| Annex A theme | Number of controls | Examples |
|---|---|---|
| Organizational (A.5) | 37 | Security policies, supplier relationships, incident management |
| People (A.6) | 8 | Screening at hire, training, disciplinary process |
| Physical (A.7) | 14 | Perimeter control, equipment protection, clear desk |
| Technological (A.8) | 34 | Access control, cryptography, malware protection, DLP |
For a typical IT company with 30-80 employees, a realistic scope of applicable controls is 65-80 out of 93. Some physical controls, industrial perimeter requirements, for instance, get excluded as irrelevant for a rented co-working space running on cloud infrastructure. That's fine, as long as the exclusion is justified in the SoA rather than simply ignored.
ISO/IEC 27001:2022 vs. the 2013 Edition: What Changed
If your company still holds a certificate against the 2013 edition, that's no longer possible: the transition period ended on 31 October 2025. The International Accreditation Forum (IAF) set that as the final date, certification bodies stopped issuing new certificates against the old edition back on 30 April 2024, and any 2013 certificate not migrated to the 2022 edition became invalid as of 1 November 2025. In 2026, any valid ISO/IEC 27001 certificate is automatically the 2022 edition.
Here's what actually changed. The most visible shift is the Annex A structure: the 14 domains (A.5-A.18) of the 2013 edition became 4 themes. That's not cosmetic. The old domains often duplicated each other (a separate "security policy" domain and a separate "organization of security" domain), and the new structure maps more logically onto real processes. Second, 11 new controls address threats that barely existed in their current form back in 2013: cloud service security, physical security monitoring, data leakage prevention, web filtering. Third, updated requirements for organizational context and interested parties (clause 4) reflect more closely how real businesses manage supply-chain risk.
For a company starting from scratch, the version difference doesn't matter much: you implement 2022 from day one. But if you already hold a valid certificate, check the date of your last surveillance audit. If the certification body hasn't confirmed the move to the new edition yet, it's time to act.
DSTU, NIS2, and CERT-UA: The Ukrainian Cybersecurity Context
Ukraine has an official national counterpart to the standard: DSTU ISO/IEC 27001:2023, "Information security, cybersecurity and privacy protection. Information security management systems. Requirements," adopted by the state enterprise UkrNDNC through identical adoption (IDT), meaning no technical deviation from the original ISO/IEC 27001:2022. It replaced the earlier DSTU ISO/IEC 27001:2015, withdrawn by order on 17 August 2023. This is the direct answer to anyone searching for "ISO 27001 in Ukrainian": an official translation exists, and for public tenders or procurements where the buyer specifically requires the DSTU reference rather than the international certificate, it's the same document under a Ukrainian number.
The second layer of context is national law. Ukraine's Law "On the Basic Principles of Cybersecurity" (No. 2163-VIII, 2017), substantially strengthened by Law No. 4336-IX of 27 March 2025, requires operators of critical information infrastructure, including energy, transport, banking, and state registries, to adopt a unified protection-level classification and undergo cyber-defense audits. CERT-UA, the state incident-response team operating under the State Service of Special Communications and Information Protection, receives incident reports from these entities and tracks attack statistics. A working ISMS built on ISO/IEC 27001 already covers the practical side of these requirements: an asset register, an incident-response procedure, and documented evidence of controls are all part of the standard.
The third layer is European. Ukraine isn't an EU member, so the NIS2 Directive (2022/2555) doesn't apply to Ukrainian companies directly. But for businesses serving EU clients, or preparing for the country's eventual EU accession, the trend is unmistakable: European counterparts increasingly expect Ukrainian suppliers to demonstrate NIS2-equivalent practices, and an ISO/IEC 27001 certificate is the simplest way to prove that without a separate legal review on every contract.
DSTU and the International Certificate Aren't Two Separate Projects
DSTU ISO/IEC 27001:2023 and the international ISO/IEC 27001:2022 are the same standard under two different numbers, national and international. Certification bodies operating in Ukraine (Bureau Veritas, TÜV, SGS, and others) issue a certificate recognized both internationally and in Ukrainian tenders that reference the DSTU. There's no need to certify separately against each number.
Related Standards: ISO 27002, ISO 27701, ISO 22301, and SOC 2
ISO/IEC 27001 rarely stands alone. In Ekontrol's practice, it's almost always surrounded by neighboring documents, and the confusion between them is one of the most common questions on a first call.
ISO/IEC 27002 isn't a separate certifiable standard, it's a reference guide that spells out in detail how to implement each Annex A control. If ISO/IEC 27001 says "implement access control," 27002 describes what that looks like in practice: a role-based model, periodic access reviews, logging. Companies get certified against 27001 and use 27002 as a working handbook.
ISO 27701 covers privacy management, a Privacy Information Management System (PIMS), and addresses GDPR-style requirements: how a company processes personal data, a broader question than breach protection alone. Until October 2025 it existed only as an extension to ISO/IEC 27001, with no way to certify against it separately. The ISO/IEC 27701:2025 edition, published on October 14, 2025, changed that: it's now a standalone standard with its own certificate, 78 controls in three tables, and a direct mapping to GDPR articles. For companies handling personal data of EU customers, it's a natural companion to 27001, and since the 2025 edition, also a possible starting point without it.
ISO 22301 is the business continuity standard (BCMS): what to do once an incident has already happened and you need to restore operations within a defined time. ISO/IEC 27001 focuses on prevention, ISO 22301 on recovery after a disruption. Together they close the full loop, from prevention to disaster recovery.
SOC 2 is the American counterpart, more often requested by North American clients. The difference is fundamental: SOC 2 is an auditor's report on compliance with selected Trust Services Criteria as of a specific date, while ISO/IEC 27001 is a certificate for a management system valid for 3 years with annual surveillance. European clients tend to ask for ISO/IEC 27001, American ones for SOC 2 Type II. Companies serving both markets usually end up implementing both.
| Standard | What it covers | When you need it |
|---|---|---|
| ISO/IEC 27001 | Information security management system (ISMS) | Baseline certificate for B2B deals and tenders |
| ISO/IEC 27002 | Detailed implementation guidance for controls | Working reference, not separately certified |
| ISO 27701 | Privacy management (PIMS), GDPR context; standalone since the 2025 edition | Processing personal data of EU customers |
| ISO 22301 | Business continuity (BCMS) | Recovery after incidents, critical services |
| SOC 2 | Trust Services Criteria (auditor's report) | North American clients |
Check Your ISO/IEC 27001 Readiness
A free preliminary gap assessment against Annex A requirements from a Bureau Veritas partner in Ukraine.
Learn about ISO/IEC 27001 certificationHow Much ISO 27001 Certification Costs and How Long It Takes
There's no fixed price, and anyone who quotes a number without a diagnostic is either guessing or selling something else. The budget breaks down into three independent blocks, and each depends on your specific situation.
The first block is preparation: gap analysis, policy development, control implementation, team training. The main factor here is your starting point: a company that already has ISO 9001 or at least formalized IT processes moves through preparation faster and cheaper than a team starting from zero. The second factor is size and complexity: 15 people in one office running on cloud infrastructure is one scope of work; 200 people with an in-house data center and multiple sites is a completely different one.
The second block is the certification body's audit. Its cost is tied to the number of auditor person-days, set by the IAF MD 5 formula, which factors in headcount, number of sites, and system complexity. For a small SaaS team, that's typically 3-5 person-days for Stage 1 and Stage 2 combined; for a mid-sized business with several locations, considerably more.
The third block is maintaining the system: an annual surveillance audit (shorter than the main one), internal audits, updated risk assessments, training for new hires. This isn't a one-time investment, it's an ongoing cost line for as long as the certificate stays valid.
On timing: a company with existing processes and a dedicated project owner typically reaches Stage 2 certification in 4-6 months. Starting from zero, with no dedicated owner, a realistic timeline is 8-12 months. Once Stage 2 succeeds, the certificate is issued for 3 years, with a mandatory annual surveillance audit and full recertification in year four.
| Factor | How it affects cost and timeline |
|---|---|
| Existing ISO 9001 or another management system | Cuts preparation by 30-40%: part of the documentation and process work is already done |
| Number of employees and sites | Directly sets the auditor's person-days under the IAF MD 5 formula |
| Cloud vs. in-house infrastructure | Cloud simplifies some technological controls but adds supplier-related requirements |
| A dedicated project owner | Roughly halves implementation time compared to a part-time effort |
| Choice of certification body | Affects audit cost and how the certificate is recognized by international partners |
Implementation Roadmap: 6 Steps to ISMS Certification
The path from "we need ISO/IEC 27001" to an actual certificate breaks down into six steps. Each has its own timeline, and its own most common failure point.
Step 1. Readiness Diagnostic for ISO/IEC 27001 and Defining the Scope
Before implementing anything, you need to define the ISMS boundaries: which departments, products, locations, and data centers fall within the certification scope. Too broad a scope stretches the project out over months; too narrow doesn't reassure clients asking for a certificate that covers the specific data their product handles. A gap analysis of current controls runs in parallel. Duration: 1-3 weeks, the cheapest step, and the one that sets the budget for everything that follows.
Step 2. Risk Assessment and the Statement of Applicability
The team builds an asset register, assesses threats and likelihood, selects applicable controls from Annex A, and documents the choice in the Statement of Applicability. This is analytical work, not paperwork: if the risk assessment is done as a box-ticking exercise, the whole system built on top of it will be too. Duration: 2-4 weeks, depending on the number of assets.
Step 3. Policy Development and Control Implementation
Based on the SoA, the team writes the mandatory documents (security policy, incident-management procedure, continuity plan) and implements technical and organizational controls: access management, backups, staff training, supplier agreements. This is the longest step in the project, 2-4 months, because it involves real process change rather than paperwork alone.
Step 4. Internal Audit and the First Management Review
An internal team (or an outside auditor) checks the system against every applicable control before the certification body does. Any nonconformities found get closed before Stage 1. Leadership holds a formal management review, with minutes, not a hallway conversation. Duration: 2-3 weeks.
Step 5. Stage 1 and Stage 2 Certification Body Audits
Stage 1 checks documentation and readiness (1-2 days); Stage 2 is a full review of implementation in practice: staff interviews, record checks, control testing (1-5 days depending on company size). Between Stage 1 and Stage 2, 4-8 weeks usually pass while findings get closed.
Step 6. Certification and Annual Surveillance
After a successful Stage 2, the body issues a certificate valid for 3 years. From there, an annual surveillance audit (shorter than the main one) confirms the system hasn't gone dormant right after the certificate arrived. Year three brings full recertification. Companies that treat surveillance as a formality are the ones most likely to lose their certificate at exactly this stage.
Common Mistakes When Implementing ISO/IEC 27001
Across implementation projects, both in Ekontrol's own practice and in the cases we walk through with clients, the same mistakes repeat with remarkable consistency.
First: treating ISO/IEC 27001 as an IT project. The standard requires leadership involvement, HR (the People controls), and the admin team (physical office security). If the IT director builds the system alone, without a mandate from top management, the auditor will spot the gap between the documents and actual governance as early as Stage 1.
Second: writing policies for the audit instead of for real processes. The classic trap is a beautifully worded procedure nobody actually follows. ISO/IEC 27001 auditors work through interviews and sampled record checks: a mismatch between what's written and what staff actually do is the single most common finding on real audits.
Third: underestimating the risk assessment. Companies rush straight to controls, skipping a genuine analysis of assets and threats. The result is controls that don't address the real risks, and a Statement of Applicability that falls apart under an auditor's questions.
Fourth: leaving staff training until the last week. People are the most common source of incidents: phishing, weak passwords, accidental disclosure. A one-off briefing right before the audit doesn't build a habit; you need an ongoing awareness program.
Fifth: choosing a certification body on price alone. Not every certificate is recognized equally by international partners, so check accreditation with the national accreditation body (NAAU in Ukraine) and membership in the IAF MLA.
Important: A Certificate Doesn't Mean Zero Incidents
An ISO/IEC 27001 certificate confirms that a risk-management system works, not that incidents will never happen. Companies that treat certification as a finish line, rather than an annual maintenance cycle, are the ones most likely to lose the certificate at a surveillance audit or to face an incident that exposes the gap between documentation and practice.
What to Read Next on ISO 27001 and Information Security
This guide is a map of the topic. Every section compressed into a few paragraphs here has its own full article in the Ekontrol blog, with the practical detail to match:
- what an ISMS is and how it works, covering the PDCA cycle, the Statement of Applicability, and the system's first year;
- how to write an information security policy, the document structure under clause 5.2 of the standard, with an example;
- personal data protection under ISO 27701, covering Law No. 2297-VI, GDPR, and standalone PIMS certification under the 2025 edition;
- SOC 2 vs. ISO 27001 for an IT company, what EU and US clients actually request, and when you need both;
- a map of international information security standards, the ISO 2700x family: which numbers are certifiable and which remain guidance;
- information security threats for business, phishing, ransomware, wartime attacks, and how to close those risks systematically rather than piecemeal;
- cyber incident response and the role of CERT-UA, what to do in the first hours of an attack, who to notify, and what the standard requires;
- the risk-based cyber protection model for critical infrastructure, what Resolution No. 1470 changes for operators;
- the news brief on the shift to a risk-based model, a short summary of what applies to critical infrastructure operators from November 20, 2025.
Each article stands on its own: there's no need to read them all in order, pick the one that matches your next step.
How Ekontrol Prepares Companies for ISO/IEC 27001 Certification
Ekontrol supports ISO 27001 implementation (formally ISO/IEC 27001) as part of its information security practice, alongside ISO/IEC 27002, ISO 27701, and ISO 22301 for companies that need a broader system. The team has worked as a Bureau Veritas partner in Ukraine since 2014, and the same approach, staged, with a realistic budget at every step, applies equally to IT companies and to defense manufacturers that need ISO/IEC 27001 on top of an existing ISO 9001 or AQAP 2110.
A project starts with a diagnostic: within a few days, the team identifies the gap between the current state and Annex A requirements, and gives a realistic budget and timeline estimate, no sugarcoating. Implementation follows: policy development, building the risk-assessment process, training internal auditors, preparing the Statement of Applicability. The last stage before certification is audit support during Stage 1 and Stage 2, so the client isn't left alone with the auditor.
After certification, most clients move to annual support: surveillance audits don't catch the system off guard, and risk assessments get updated on schedule rather than in the final week before the auditor arrives. If your company serves clients in the EU or US, handles sensitive data, or is preparing for a tender that requires proof of data protection, the ISO/IEC 27001 certification page has the service details and a form for a first consultation.

Need a certification consultation?
Free Consultation
On This Page
- What Is ISO/IEC 27001 — Briefly and Clearly
- How an ISMS Works: The Information Security Management Cycle
- Who Needs ISO/IEC 27001 Certification in Ukraine
- Annex A: Standard Structure and the 93 Security Controls
- ISO/IEC 27001:2022 vs. the 2013 Edition: What Changed
- DSTU, NIS2, and CERT-UA: The Ukrainian Cybersecurity Context
- Related Standards: ISO 27002, ISO 27701, ISO 22301, and SOC 2
- How Much ISO 27001 Certification Costs and How Long It Takes
- Implementation Roadmap: 6 Steps to ISMS Certification
- Common Mistakes When Implementing ISO/IEC 27001
- What to Read Next on ISO 27001 and Information Security
- How Ekontrol Prepares Companies for ISO/IEC 27001 Certification
- FAQ — Frequently Asked Questions About ISO 27001
What Is ISO/IEC 27001 — Briefly and Clearly
If your company handles customer data, access credentials, or source code, and a partner in the EU or US asks you to "show a certificate," they almost certainly mean ISO 27001, formally ISO/IEC 27001. It's the international standard for an information security management system (ISMS), one that defines how a company identifies risks to its data, chooses appropriate controls, and proves on paper that the system actually works rather than just existing for show.
The standard is published jointly by two organizations, ISO (International Organization for Standardization) and IEC (International Electrotechnical Commission), which is why the full name always carries the slash: ISO/IEC 27001. The current edition is ISO/IEC 27001:2022, which replaced the 2013 version. The standard doesn't tell you which specific tools to buy or what your password policy should look like. It tells you something different: identify your risks, choose adequate controls, keep evidence that those controls work, and keep improving the system. That's the key difference from purely technical standards like PCI DSS: ISO/IEC 27001 is about management, not a fixed checklist of firewall settings.
The first version came out in 2005, based on the British BS 7799-2. The second arrived in 2013, and the current one in 2022. Each revision cuts bureaucracy and brings the standard closer to real-world risk: the 2013 edition dropped an overly rigid link to specific technologies, and the 2022 edition restructured the controls around today's threats, including cloud services, threat intelligence, and supply-chain attacks. In 2026, when attacks through vendors and contractors have become routine rather than the exception, that logic translates directly into business risk.
Certification tells the outside world something specific: an independent, accredited body reviewed your ISMS and confirmed it meets the standard's requirements. For B2B contracts in IT, finance, or defense manufacturing, that's no longer a competitive edge, it's table stakes. Without the certificate, you simply don't get into the tender or the due-diligence process. Ekontrol prepares companies for exactly that outcome; see the ISO/IEC 27001 certification page for details.
ISO/IEC 27001 in Brief
The standard sets requirements for an information security management system (ISMS). The current edition is ISO/IEC 27001:2022, which fully replaced the 2013 version as of October 2025. Ukraine has a national counterpart, DSTU ISO/IEC 27001:2023. The certificate is issued for 3 years with a mandatory annual surveillance audit. The standard doesn't dictate specific technical tools: it requires risk assessment, selection of adequate controls from the 93 Annex A controls, and documented evidence that the system works in practice rather than existing only on paper.
How an ISMS Works: The Information Security Management Cycle
An ISMS (information security management system) isn't a binder of policies or antivirus software running on a server. It's a management cycle that ISO/IEC 27001 builds around Plan-Do-Check-Act logic: you plan controls based on risk, implement them, check their effectiveness through internal audits and metrics, and correct what didn't work. The cycle repeats every year; it isn't a one-off exercise before an audit.
The core of the system is risk assessment. A company builds a register of information assets (databases, servers, source code, customer personal data), identifies threats to each one (leakage, loss of access, compromise), evaluates likelihood and impact, and decides: accept the risk, reduce it with a control, transfer it through insurance or outsourcing, or avoid it. The output is the Statement of Applicability (SoA): a document that tells the auditor which of the 93 Annex A controls apply, which don't, and why.
This is where a common mistake creeps in. An ISMS built entirely around the IT department fails audits regularly. The standard requires leadership involvement (clause 5), people management (the People controls), and physical security of the office. In other words, it's an organizational system, not a security department's side project. If top management doesn't take part in at least one management review a year, the auditor will flag a nonconformity even if every technical control is perfectly configured.
Who Needs ISO/IEC 27001 Certification in Ukraine
Formally, ISO/IEC 27001 is voluntary. In practice, for six categories of Ukrainian business it has long since become a contractual requirement.
- IT and SaaS companies outsourcing for clients in the EU and US. A European client handing over personal data or source code will ask for proof of security as early as the security-questionnaire stage; a certificate closes that question with one document instead of a month of correspondence.
- Fintech and e-commerce. Payment data, KYC records, transaction history: these are all high-value-loss assets, and sooner or later a regulator or payment scheme will ask for proof of control.
- BPO and shared service centers, which process customer data at scale with no direct contact with the end user. Trust here rests entirely on process, and the certificate substitutes for personal reputation.
- Defense manufacturers in NATO supply chains. ISO/IEC 27001 layers on top of an existing ISO 9001 or AQAP 2110: design documentation for a drone or an EW system needs the same level of access control as a bank's financial data, just with different consequences if it leaks.
- Government and municipal organizations, where data protection is a legal requirement, not a client preference.
- Companies preparing for a tender or an investment round, where due diligence includes a cyber-risk review. Holding the certificate removes that item from an investor's or a public buyer's list of concerns.
Annex A: Standard Structure and the 93 Security Controls
ISO/IEC 27001:2022 itself is a compact document built on the shared Annex SL structure common to every management-system standard (ISO 9001, ISO 14001, and others). Ten clauses run from the organization's context (clause 4) and leadership (5) through risk planning (6), support (7), operation (8), performance evaluation (9), and improvement (10). Clauses 1-3 are introductory: scope, normative references, terms and definitions.
The largest practical part isn't the main text at all, it's Annex A: a list of 93 controls grouped into four themes. The 2022 edition cut them down from 114 (in the 2013 version) by merging overlapping items, not by weakening requirements. Quite the opposite: it added 11 new controls for modern threats, including threat intelligence, cloud service security, data masking, data leakage prevention (DLP), physical security monitoring, and secure coding.
A company isn't required to implement all 93 controls. It selects the applicable ones based on its risk assessment and records the choice, including the justification for any exclusions, in the Statement of Applicability. An auditor checks the logic behind that selection, not a mechanical checklist count.
| Annex A theme | Number of controls | Examples |
|---|---|---|
| Organizational (A.5) | 37 | Security policies, supplier relationships, incident management |
| People (A.6) | 8 | Screening at hire, training, disciplinary process |
| Physical (A.7) | 14 | Perimeter control, equipment protection, clear desk |
| Technological (A.8) | 34 | Access control, cryptography, malware protection, DLP |
For a typical IT company with 30-80 employees, a realistic scope of applicable controls is 65-80 out of 93. Some physical controls, industrial perimeter requirements, for instance, get excluded as irrelevant for a rented co-working space running on cloud infrastructure. That's fine, as long as the exclusion is justified in the SoA rather than simply ignored.
ISO/IEC 27001:2022 vs. the 2013 Edition: What Changed
If your company still holds a certificate against the 2013 edition, that's no longer possible: the transition period ended on 31 October 2025. The International Accreditation Forum (IAF) set that as the final date, certification bodies stopped issuing new certificates against the old edition back on 30 April 2024, and any 2013 certificate not migrated to the 2022 edition became invalid as of 1 November 2025. In 2026, any valid ISO/IEC 27001 certificate is automatically the 2022 edition.
Here's what actually changed. The most visible shift is the Annex A structure: the 14 domains (A.5-A.18) of the 2013 edition became 4 themes. That's not cosmetic. The old domains often duplicated each other (a separate "security policy" domain and a separate "organization of security" domain), and the new structure maps more logically onto real processes. Second, 11 new controls address threats that barely existed in their current form back in 2013: cloud service security, physical security monitoring, data leakage prevention, web filtering. Third, updated requirements for organizational context and interested parties (clause 4) reflect more closely how real businesses manage supply-chain risk.
For a company starting from scratch, the version difference doesn't matter much: you implement 2022 from day one. But if you already hold a valid certificate, check the date of your last surveillance audit. If the certification body hasn't confirmed the move to the new edition yet, it's time to act.
DSTU, NIS2, and CERT-UA: The Ukrainian Cybersecurity Context
Ukraine has an official national counterpart to the standard: DSTU ISO/IEC 27001:2023, "Information security, cybersecurity and privacy protection. Information security management systems. Requirements," adopted by the state enterprise UkrNDNC through identical adoption (IDT), meaning no technical deviation from the original ISO/IEC 27001:2022. It replaced the earlier DSTU ISO/IEC 27001:2015, withdrawn by order on 17 August 2023. This is the direct answer to anyone searching for "ISO 27001 in Ukrainian": an official translation exists, and for public tenders or procurements where the buyer specifically requires the DSTU reference rather than the international certificate, it's the same document under a Ukrainian number.
The second layer of context is national law. Ukraine's Law "On the Basic Principles of Cybersecurity" (No. 2163-VIII, 2017), substantially strengthened by Law No. 4336-IX of 27 March 2025, requires operators of critical information infrastructure, including energy, transport, banking, and state registries, to adopt a unified protection-level classification and undergo cyber-defense audits. CERT-UA, the state incident-response team operating under the State Service of Special Communications and Information Protection, receives incident reports from these entities and tracks attack statistics. A working ISMS built on ISO/IEC 27001 already covers the practical side of these requirements: an asset register, an incident-response procedure, and documented evidence of controls are all part of the standard.
The third layer is European. Ukraine isn't an EU member, so the NIS2 Directive (2022/2555) doesn't apply to Ukrainian companies directly. But for businesses serving EU clients, or preparing for the country's eventual EU accession, the trend is unmistakable: European counterparts increasingly expect Ukrainian suppliers to demonstrate NIS2-equivalent practices, and an ISO/IEC 27001 certificate is the simplest way to prove that without a separate legal review on every contract.
DSTU and the International Certificate Aren't Two Separate Projects
DSTU ISO/IEC 27001:2023 and the international ISO/IEC 27001:2022 are the same standard under two different numbers, national and international. Certification bodies operating in Ukraine (Bureau Veritas, TÜV, SGS, and others) issue a certificate recognized both internationally and in Ukrainian tenders that reference the DSTU. There's no need to certify separately against each number.
Related Standards: ISO 27002, ISO 27701, ISO 22301, and SOC 2
ISO/IEC 27001 rarely stands alone. In Ekontrol's practice, it's almost always surrounded by neighboring documents, and the confusion between them is one of the most common questions on a first call.
ISO/IEC 27002 isn't a separate certifiable standard, it's a reference guide that spells out in detail how to implement each Annex A control. If ISO/IEC 27001 says "implement access control," 27002 describes what that looks like in practice: a role-based model, periodic access reviews, logging. Companies get certified against 27001 and use 27002 as a working handbook.
ISO 27701 covers privacy management, a Privacy Information Management System (PIMS), and addresses GDPR-style requirements: how a company processes personal data, a broader question than breach protection alone. Until October 2025 it existed only as an extension to ISO/IEC 27001, with no way to certify against it separately. The ISO/IEC 27701:2025 edition, published on October 14, 2025, changed that: it's now a standalone standard with its own certificate, 78 controls in three tables, and a direct mapping to GDPR articles. For companies handling personal data of EU customers, it's a natural companion to 27001, and since the 2025 edition, also a possible starting point without it.
ISO 22301 is the business continuity standard (BCMS): what to do once an incident has already happened and you need to restore operations within a defined time. ISO/IEC 27001 focuses on prevention, ISO 22301 on recovery after a disruption. Together they close the full loop, from prevention to disaster recovery.
SOC 2 is the American counterpart, more often requested by North American clients. The difference is fundamental: SOC 2 is an auditor's report on compliance with selected Trust Services Criteria as of a specific date, while ISO/IEC 27001 is a certificate for a management system valid for 3 years with annual surveillance. European clients tend to ask for ISO/IEC 27001, American ones for SOC 2 Type II. Companies serving both markets usually end up implementing both.
| Standard | What it covers | When you need it |
|---|---|---|
| ISO/IEC 27001 | Information security management system (ISMS) | Baseline certificate for B2B deals and tenders |
| ISO/IEC 27002 | Detailed implementation guidance for controls | Working reference, not separately certified |
| ISO 27701 | Privacy management (PIMS), GDPR context; standalone since the 2025 edition | Processing personal data of EU customers |
| ISO 22301 | Business continuity (BCMS) | Recovery after incidents, critical services |
| SOC 2 | Trust Services Criteria (auditor's report) | North American clients |
Check Your ISO/IEC 27001 Readiness
A free preliminary gap assessment against Annex A requirements from a Bureau Veritas partner in Ukraine.
Learn about ISO/IEC 27001 certificationHow Much ISO 27001 Certification Costs and How Long It Takes
There's no fixed price, and anyone who quotes a number without a diagnostic is either guessing or selling something else. The budget breaks down into three independent blocks, and each depends on your specific situation.
The first block is preparation: gap analysis, policy development, control implementation, team training. The main factor here is your starting point: a company that already has ISO 9001 or at least formalized IT processes moves through preparation faster and cheaper than a team starting from zero. The second factor is size and complexity: 15 people in one office running on cloud infrastructure is one scope of work; 200 people with an in-house data center and multiple sites is a completely different one.
The second block is the certification body's audit. Its cost is tied to the number of auditor person-days, set by the IAF MD 5 formula, which factors in headcount, number of sites, and system complexity. For a small SaaS team, that's typically 3-5 person-days for Stage 1 and Stage 2 combined; for a mid-sized business with several locations, considerably more.
The third block is maintaining the system: an annual surveillance audit (shorter than the main one), internal audits, updated risk assessments, training for new hires. This isn't a one-time investment, it's an ongoing cost line for as long as the certificate stays valid.
On timing: a company with existing processes and a dedicated project owner typically reaches Stage 2 certification in 4-6 months. Starting from zero, with no dedicated owner, a realistic timeline is 8-12 months. Once Stage 2 succeeds, the certificate is issued for 3 years, with a mandatory annual surveillance audit and full recertification in year four.
| Factor | How it affects cost and timeline |
|---|---|
| Existing ISO 9001 or another management system | Cuts preparation by 30-40%: part of the documentation and process work is already done |
| Number of employees and sites | Directly sets the auditor's person-days under the IAF MD 5 formula |
| Cloud vs. in-house infrastructure | Cloud simplifies some technological controls but adds supplier-related requirements |
| A dedicated project owner | Roughly halves implementation time compared to a part-time effort |
| Choice of certification body | Affects audit cost and how the certificate is recognized by international partners |
Implementation Roadmap: 6 Steps to ISMS Certification
The path from "we need ISO/IEC 27001" to an actual certificate breaks down into six steps. Each has its own timeline, and its own most common failure point.
Step 1. Readiness Diagnostic for ISO/IEC 27001 and Defining the Scope
Before implementing anything, you need to define the ISMS boundaries: which departments, products, locations, and data centers fall within the certification scope. Too broad a scope stretches the project out over months; too narrow doesn't reassure clients asking for a certificate that covers the specific data their product handles. A gap analysis of current controls runs in parallel. Duration: 1-3 weeks, the cheapest step, and the one that sets the budget for everything that follows.
Step 2. Risk Assessment and the Statement of Applicability
The team builds an asset register, assesses threats and likelihood, selects applicable controls from Annex A, and documents the choice in the Statement of Applicability. This is analytical work, not paperwork: if the risk assessment is done as a box-ticking exercise, the whole system built on top of it will be too. Duration: 2-4 weeks, depending on the number of assets.
Step 3. Policy Development and Control Implementation
Based on the SoA, the team writes the mandatory documents (security policy, incident-management procedure, continuity plan) and implements technical and organizational controls: access management, backups, staff training, supplier agreements. This is the longest step in the project, 2-4 months, because it involves real process change rather than paperwork alone.
Step 4. Internal Audit and the First Management Review
An internal team (or an outside auditor) checks the system against every applicable control before the certification body does. Any nonconformities found get closed before Stage 1. Leadership holds a formal management review, with minutes, not a hallway conversation. Duration: 2-3 weeks.
Step 5. Stage 1 and Stage 2 Certification Body Audits
Stage 1 checks documentation and readiness (1-2 days); Stage 2 is a full review of implementation in practice: staff interviews, record checks, control testing (1-5 days depending on company size). Between Stage 1 and Stage 2, 4-8 weeks usually pass while findings get closed.
Step 6. Certification and Annual Surveillance
After a successful Stage 2, the body issues a certificate valid for 3 years. From there, an annual surveillance audit (shorter than the main one) confirms the system hasn't gone dormant right after the certificate arrived. Year three brings full recertification. Companies that treat surveillance as a formality are the ones most likely to lose their certificate at exactly this stage.
Common Mistakes When Implementing ISO/IEC 27001
Across implementation projects, both in Ekontrol's own practice and in the cases we walk through with clients, the same mistakes repeat with remarkable consistency.
First: treating ISO/IEC 27001 as an IT project. The standard requires leadership involvement, HR (the People controls), and the admin team (physical office security). If the IT director builds the system alone, without a mandate from top management, the auditor will spot the gap between the documents and actual governance as early as Stage 1.
Second: writing policies for the audit instead of for real processes. The classic trap is a beautifully worded procedure nobody actually follows. ISO/IEC 27001 auditors work through interviews and sampled record checks: a mismatch between what's written and what staff actually do is the single most common finding on real audits.
Third: underestimating the risk assessment. Companies rush straight to controls, skipping a genuine analysis of assets and threats. The result is controls that don't address the real risks, and a Statement of Applicability that falls apart under an auditor's questions.
Fourth: leaving staff training until the last week. People are the most common source of incidents: phishing, weak passwords, accidental disclosure. A one-off briefing right before the audit doesn't build a habit; you need an ongoing awareness program.
Fifth: choosing a certification body on price alone. Not every certificate is recognized equally by international partners, so check accreditation with the national accreditation body (NAAU in Ukraine) and membership in the IAF MLA.
Important: A Certificate Doesn't Mean Zero Incidents
An ISO/IEC 27001 certificate confirms that a risk-management system works, not that incidents will never happen. Companies that treat certification as a finish line, rather than an annual maintenance cycle, are the ones most likely to lose the certificate at a surveillance audit or to face an incident that exposes the gap between documentation and practice.
What to Read Next on ISO 27001 and Information Security
This guide is a map of the topic. Every section compressed into a few paragraphs here has its own full article in the Ekontrol blog, with the practical detail to match:
- what an ISMS is and how it works, covering the PDCA cycle, the Statement of Applicability, and the system's first year;
- how to write an information security policy, the document structure under clause 5.2 of the standard, with an example;
- personal data protection under ISO 27701, covering Law No. 2297-VI, GDPR, and standalone PIMS certification under the 2025 edition;
- SOC 2 vs. ISO 27001 for an IT company, what EU and US clients actually request, and when you need both;
- a map of international information security standards, the ISO 2700x family: which numbers are certifiable and which remain guidance;
- information security threats for business, phishing, ransomware, wartime attacks, and how to close those risks systematically rather than piecemeal;
- cyber incident response and the role of CERT-UA, what to do in the first hours of an attack, who to notify, and what the standard requires;
- the risk-based cyber protection model for critical infrastructure, what Resolution No. 1470 changes for operators;
- the news brief on the shift to a risk-based model, a short summary of what applies to critical infrastructure operators from November 20, 2025.
Each article stands on its own: there's no need to read them all in order, pick the one that matches your next step.
How Ekontrol Prepares Companies for ISO/IEC 27001 Certification
Ekontrol supports ISO 27001 implementation (formally ISO/IEC 27001) as part of its information security practice, alongside ISO/IEC 27002, ISO 27701, and ISO 22301 for companies that need a broader system. The team has worked as a Bureau Veritas partner in Ukraine since 2014, and the same approach, staged, with a realistic budget at every step, applies equally to IT companies and to defense manufacturers that need ISO/IEC 27001 on top of an existing ISO 9001 or AQAP 2110.
A project starts with a diagnostic: within a few days, the team identifies the gap between the current state and Annex A requirements, and gives a realistic budget and timeline estimate, no sugarcoating. Implementation follows: policy development, building the risk-assessment process, training internal auditors, preparing the Statement of Applicability. The last stage before certification is audit support during Stage 1 and Stage 2, so the client isn't left alone with the auditor.
After certification, most clients move to annual support: surveillance audits don't catch the system off guard, and risk assessments get updated on schedule rather than in the final week before the auditor arrives. If your company serves clients in the EU or US, handles sensitive data, or is preparing for a tender that requires proof of data protection, the ISO/IEC 27001 certification page has the service details and a form for a first consultation.


