July 30, 2026

ISO 27001 vs ISO 27002

ISO 27001 sets the requirements for an information security management system and is the standard you certify against; ISO 27002 is the companion guidance for implementing its Annex A controls.

By
Full name
Share this post
https://www.hicomply.com/hub/iso-27001-vs-iso-27002
A woman smiles while using a tablet, surrounded by digital notifications and a data chart.

The short answer: ISO 27001 is the standard you certify against — it sets out the requirements for an information security management system (ISMS). ISO 27002 is its companion guidance: a detailed manual explaining how to implement the security controls that ISO 27001 lists in Annex A. You cannot be certified to ISO 27002, but almost every organisation pursuing ISO 27001 certification uses it.

The two standards are so closely related that they are often confused — and choosing the wrong reference point can cost your team weeks. This guide explains what each standard does, how the 2022 revisions changed them, and how to use them together on the way to certification.

{{snapshot}}

ISO 27001 vs ISO 27002 at a glance

  • ISO 27001 defines the requirements for an ISMS and is the standard your organisation is audited and certified against.
  • ISO 27002 provides implementation guidance for the 93 Annex A controls — it is a reference document, not certifiable.
  • Both were revised in 2022, reorganising the controls into four themes: organisational, people, physical and technological.
  • Think of it as the exam versus the textbook: 27001 tells you what must be in place, 27002 shows you how to build it.

{{/snapshot}}

What is ISO 27001?

ISO 27001 is the international standard for information security management. It specifies the requirements for establishing, implementing, maintaining and continually improving an information security management system — the policies, processes and controls that protect the confidentiality, integrity and availability of your information.

The standard is built around clauses 4–10, which cover the management system itself: understanding your organisation and its context, leadership, planning, support, operation, performance evaluation and improvement. Annex A then lists 93 security controls, which organisations select and justify through a risk assessment and a Statement of Applicability.

Crucially, ISO 27001 is certifiable. An accredited external auditor assesses your ISMS, and successful certification signals to customers, partners and regulators that your security practices meet the international benchmark. Learn more about how to get ISO 27001 certified.

What is ISO 27002?

ISO 27002 — formally "Information security, cybersecurity and privacy protection — Information security controls" — is the companion code of practice to ISO 27001. Where Annex A of ISO 27001 lists each control in a single line, ISO 27002 dedicates pages to it: the control's purpose, how to implement it, and the attributes that help you classify it.

ISO 27002 exists to answer the practical questions Annex A raises. What does "information classification" actually involve? What should a secure development policy contain? The guidance turns a checklist into an implementation plan.

Because it is guidance rather than a requirements standard, there is no ISO 27002 certificate. Its role is to make your ISO 27001 implementation faster, more consistent and easier to defend in an audit.

{{snapshot}}

What changed in the 2022 revisions

  • The controls were restructured from 14 domains and 114 controls into 93 controls across four themes.
  • The four themes: 37 organisational, 8 people, 14 physical and 34 technological controls.
  • 11 new controls were introduced, including threat intelligence, cloud services security, data leakage prevention, secure coding and web filtering.
  • ISO 27002:2022 also added attributes — tags for control type, CIA properties, cybersecurity concepts, operational capabilities and security domains.

{{/snapshot}}

ISO 27001 vs ISO 27002: the key differences

AspectISO 27001ISO 27002
PurposeSets the requirements for building and running an ISMSProvides detailed guidance for implementing the Annex A security controls
CertificationCertifiable — assessed by an accredited external auditorNot certifiable — a reference document only
StructureManagement system clauses 4–10 plus Annex A listing 93 controlsOne chapter per control: purpose, implementation guidance and attributes
Risk assessmentRequired — controls are selected based on your risks and documented in the Statement of ApplicabilityNot covered — assumes control selection has already happened
How you use itThe benchmark your auditor certifies you againstThe manual your team works from while implementing controls

How the two standards work together

In practice, the two standards are used side by side throughout an ISO 27001 project:

  • Scoping and risk assessment. You define your ISMS scope and assess risks under ISO 27001's requirements.
  • Control selection. You choose the applicable Annex A controls and record the rationale in your Statement of Applicability.
  • Implementation. For each selected control, ISO 27002 tells you what good looks like — policy content, technical measures and operational practices.
  • Audit. Your certification audit is conducted against ISO 27001. Auditors frequently reference ISO 27002 guidance when judging whether a control is properly implemented.

A common mistake is treating ISO 27002 as a compliance checklist and implementing all 93 controls indiscriminately. ISO 27001 explicitly requires risk-based selection — implementing everything wastes budget on controls your risk profile doesn't justify.

{{snapshot}}

Hicomply's take

In our experience, teams move fastest when they treat ISO 27002 as a reference library rather than a to-do list: run the risk assessment first, select controls deliberately, then pull up the 27002 guidance only for the controls that made the cut. A compliance platform makes this practical — each control in your Statement of Applicability links to its implementation evidence, so the auditor sees the full chain. Explore how on a platform tour.

{{/snapshot}}

Which one does your business need?

If your goal is certification — because customers, investors or regulators expect proof of information security — you need ISO 27001. ISO 27002 is not an alternative; it is the supporting guidance that makes implementation quicker and audit conversations easier.

If you simply want to strengthen security practices without pursuing certification yet, ISO 27002 on its own is a well-structured control catalogue to borrow from. Many organisations start there, then formalise into a full ISMS when the first enterprise deal or SOC 2 or ISO 27001 requirement lands.

FAQ: ISO 27001 vs ISO 27002

Can you get certified to ISO 27002?
No. ISO 27002 is a code of practice, not a requirements standard. Certification is only available against ISO 27001.

Do I need to buy both standards?
Most organisations pursuing certification do. ISO 27001 defines what your ISMS must achieve; ISO 27002's implementation guidance saves significant time when you build the controls.

Did ISO 27002 replace Annex A?
No — they mirror each other. The 93 controls in ISO 27001's Annex A are the same controls ISO 27002 explains in detail. The 2022 revisions aligned both documents around the four-theme structure.

Is ISO 27002 mandatory for ISO 27001 certification?
No. Auditors certify against ISO 27001 only. But because ISO 27002 represents recognised good practice, following its guidance is the most defensible way to implement your selected controls.

Get audit-ready faster with Hicomply

Hicomply maps your risk assessment, Statement of Applicability and control evidence in one platform, so the ISO 27001 requirements and the ISO 27002 guidance behind them stay connected from day one. Say Hi to certification without the spreadsheet safari — start with our free compliance tools or book a demo to see how much of the process you can automate.

Risk Management
Compliance Reporting
Policy Management
Incident Management
Audits and Assessments

Ready to Take Control of Your Privacy Compliance?

See how Hicomply can accelerate your path to CAF compliance in a 15-minute demo.

Risk Management

Identify, assess, and mitigate security risks with an integrated risk register.Hicomply’s automated risk management software maps controls across ISO 27001, SOC 2, and NIST frameworks — helping teams track risk treatment plans, assign ownership, and monitor real-time compliance status. Build a resilient ISMS that reduces audit findings and demonstrates continuous improvement.

Compliance Reporting

Generate instant, audit-ready compliance reports across multiple frameworks — from ISO 27001 and SOC 2 to GDPR, DORA, and NHS DSPT.Automated evidence collection and built-in dashboards provide a single source of truth for your compliance posture, saving weeks of manual work during audits.

Policy Management

Centralise, version, and publish all your information security policies in one place.Hicomply automates approvals, reminders, and distribution, ensuring your ISMS documentation stays current and aligned with frameworks like ISO 42001 and NIST CSF.Say goodbye to outdated PDFs — manage policies dynamically and maintain full traceability.

Incident Management

Capture, investigate, and resolve security incidents with structured workflows and automated evidence trails.Hicomply integrates with ticketing tools like Jira, Zendesk, and Azure DevOps to streamline incident response and link findings to risk and control updates — a key step for SOC 2 Type II readiness.

Audits and Assessments

Simplify internal and external audit preparation with built-in audit templates and automated task assignments.
Hicomply’s audit management platform aligns with ISO 27001, ISO 9001, and ISO 14001, giving teams a clear overview of control effectiveness, audit evidence, and corrective actions — all from one dashboard.

Getting Started
Computer Software
IT and Services
Professional Services
Growth