ISO 27001 vs ISO 27002
ISO 27001 sets the requirements for an information security management system and is the standard you certify against; ISO 27002 is the companion guidance for implementing its Annex A controls.

The short answer: ISO 27001 is the standard you certify against — it sets out the requirements for an information security management system (ISMS). ISO 27002 is its companion guidance: a detailed manual explaining how to implement the security controls that ISO 27001 lists in Annex A. You cannot be certified to ISO 27002, but almost every organisation pursuing ISO 27001 certification uses it.
The two standards are so closely related that they are often confused — and choosing the wrong reference point can cost your team weeks. This guide explains what each standard does, how the 2022 revisions changed them, and how to use them together on the way to certification.
{{snapshot}}
ISO 27001 vs ISO 27002 at a glance
- ISO 27001 defines the requirements for an ISMS and is the standard your organisation is audited and certified against.
- ISO 27002 provides implementation guidance for the 93 Annex A controls — it is a reference document, not certifiable.
- Both were revised in 2022, reorganising the controls into four themes: organisational, people, physical and technological.
- Think of it as the exam versus the textbook: 27001 tells you what must be in place, 27002 shows you how to build it.
{{/snapshot}}
What is ISO 27001?
ISO 27001 is the international standard for information security management. It specifies the requirements for establishing, implementing, maintaining and continually improving an information security management system — the policies, processes and controls that protect the confidentiality, integrity and availability of your information.
The standard is built around clauses 4–10, which cover the management system itself: understanding your organisation and its context, leadership, planning, support, operation, performance evaluation and improvement. Annex A then lists 93 security controls, which organisations select and justify through a risk assessment and a Statement of Applicability.
Crucially, ISO 27001 is certifiable. An accredited external auditor assesses your ISMS, and successful certification signals to customers, partners and regulators that your security practices meet the international benchmark. Learn more about how to get ISO 27001 certified.
What is ISO 27002?
ISO 27002 — formally "Information security, cybersecurity and privacy protection — Information security controls" — is the companion code of practice to ISO 27001. Where Annex A of ISO 27001 lists each control in a single line, ISO 27002 dedicates pages to it: the control's purpose, how to implement it, and the attributes that help you classify it.
ISO 27002 exists to answer the practical questions Annex A raises. What does "information classification" actually involve? What should a secure development policy contain? The guidance turns a checklist into an implementation plan.
Because it is guidance rather than a requirements standard, there is no ISO 27002 certificate. Its role is to make your ISO 27001 implementation faster, more consistent and easier to defend in an audit.
{{snapshot}}
What changed in the 2022 revisions
- The controls were restructured from 14 domains and 114 controls into 93 controls across four themes.
- The four themes: 37 organisational, 8 people, 14 physical and 34 technological controls.
- 11 new controls were introduced, including threat intelligence, cloud services security, data leakage prevention, secure coding and web filtering.
- ISO 27002:2022 also added attributes — tags for control type, CIA properties, cybersecurity concepts, operational capabilities and security domains.
{{/snapshot}}
ISO 27001 vs ISO 27002: the key differences
| Aspect | ISO 27001 | ISO 27002 |
|---|---|---|
| Purpose | Sets the requirements for building and running an ISMS | Provides detailed guidance for implementing the Annex A security controls |
| Certification | Certifiable — assessed by an accredited external auditor | Not certifiable — a reference document only |
| Structure | Management system clauses 4–10 plus Annex A listing 93 controls | One chapter per control: purpose, implementation guidance and attributes |
| Risk assessment | Required — controls are selected based on your risks and documented in the Statement of Applicability | Not covered — assumes control selection has already happened |
| How you use it | The benchmark your auditor certifies you against | The manual your team works from while implementing controls |
How the two standards work together
In practice, the two standards are used side by side throughout an ISO 27001 project:
- Scoping and risk assessment. You define your ISMS scope and assess risks under ISO 27001's requirements.
- Control selection. You choose the applicable Annex A controls and record the rationale in your Statement of Applicability.
- Implementation. For each selected control, ISO 27002 tells you what good looks like — policy content, technical measures and operational practices.
- Audit. Your certification audit is conducted against ISO 27001. Auditors frequently reference ISO 27002 guidance when judging whether a control is properly implemented.
A common mistake is treating ISO 27002 as a compliance checklist and implementing all 93 controls indiscriminately. ISO 27001 explicitly requires risk-based selection — implementing everything wastes budget on controls your risk profile doesn't justify.
{{snapshot}}
Hicomply's take
In our experience, teams move fastest when they treat ISO 27002 as a reference library rather than a to-do list: run the risk assessment first, select controls deliberately, then pull up the 27002 guidance only for the controls that made the cut. A compliance platform makes this practical — each control in your Statement of Applicability links to its implementation evidence, so the auditor sees the full chain. Explore how on a platform tour.
{{/snapshot}}
Which one does your business need?
If your goal is certification — because customers, investors or regulators expect proof of information security — you need ISO 27001. ISO 27002 is not an alternative; it is the supporting guidance that makes implementation quicker and audit conversations easier.
If you simply want to strengthen security practices without pursuing certification yet, ISO 27002 on its own is a well-structured control catalogue to borrow from. Many organisations start there, then formalise into a full ISMS when the first enterprise deal or SOC 2 or ISO 27001 requirement lands.
FAQ: ISO 27001 vs ISO 27002
Can you get certified to ISO 27002?
No. ISO 27002 is a code of practice, not a requirements standard. Certification is only available against ISO 27001.
Do I need to buy both standards?
Most organisations pursuing certification do. ISO 27001 defines what your ISMS must achieve; ISO 27002's implementation guidance saves significant time when you build the controls.
Did ISO 27002 replace Annex A?
No — they mirror each other. The 93 controls in ISO 27001's Annex A are the same controls ISO 27002 explains in detail. The 2022 revisions aligned both documents around the four-theme structure.
Is ISO 27002 mandatory for ISO 27001 certification?
No. Auditors certify against ISO 27001 only. But because ISO 27002 represents recognised good practice, following its guidance is the most defensible way to implement your selected controls.
Get audit-ready faster with Hicomply
Hicomply maps your risk assessment, Statement of Applicability and control evidence in one platform, so the ISO 27001 requirements and the ISO 27002 guidance behind them stay connected from day one. Say Hi to certification without the spreadsheet safari — start with our free compliance tools or book a demo to see how much of the process you can automate.
Ready to Take Control of Your Privacy Compliance?
See how Hicomply can accelerate your path to CAF compliance in a 15-minute demo.


.avif)




















