The short answer
ISO/IEC 27001 is the standard you certify against. ISO/IEC 27002 explains how to build the controls that ISO 27001 names.
Designing controls based on ISO 27002 is not recommended, since it offers too many implementation options across organizations.
Sources: ISO/IEC 27001:2022 · ISO/IEC 27002:2022 · IAF MD 26
How the two standards fit together
ISO 27001 is an ISMS standard with a control list bolted on at the back. ISO 27002 is the expansion pack for that list.
ISO 27001 holds two things. Clauses 4 to 10 are the ISMS rules you must meet. Annex A names 93 controls in about a line each. ISO 27002 takes those same 93 controls and explains each one across some 150 pages.
ISO/IEC 27001:2022
The requirements standard. This is what you certify against.
ISO/IEC 27002:2022
The guidance document. Nobody audits you against it.
Read it from the left. Clauses 4 to 10 are the machine. Annex A is a list of 93 parts the machine may or may not need, depending on what your risk assessment says. ISO 27002 is the manual that explains each part.
The mistake this distinction exists to prevent
Teams open ISO 27002 and work through all 93 controls from the top. That inverts the standard. ISO 27001 wants you to pick controls from a risk assessment. Your Statement of Applicability then has to justify each one, in or out, against it.
Building the controls first and writing the risk assessment to match is a common audit finding. It is also expensive, because you will have built controls you never needed.
What ISO 27001 holds
ISO and the IEC publish it together. The current version is ISO/IEC 27001:2022, and it replaced the 2013 edition.
It splits in two. Clauses 4 to 10 are the ISMS rules. Every one is auditable and you cannot drop any of them. Annex A is a list of 93 controls you pick from, based on risk.
| Clause | Title | What it asks for |
|---|---|---|
| 4 | Context | Name your internal and external issues, your interested parties and what they want, then set the ISMS scope |
| 5 | Leadership | Management commitment you can show, a security policy, and named roles |
| 6 | Planning | Risk assessment and treatment, the Statement of Applicability, and security objectives you can measure |
| 7 | Support | Resources, competence, awareness, communication, and document control |
| 8 | Operation | Run the risk assessment and treatment you planned |
| 9 | Performance evaluation | Monitoring, measurement, internal audit, and management review |
| 10 | Improvement | Handle nonconformities, take corrective action, keep improving |
What ISO 27002 holds
The full title is Information security, cybersecurity and privacy protection. Information security controls. ISO published edition 3 on 15 February 2022.
For each of the 93 controls you get four things. A control statement. The purpose. Several paragraphs of guidance. Notes on when the control applies.
The 2022 version also added five attributes to each control, so you can filter the same set five ways. Control type (preventive, detective, corrective). Security properties (confidentiality, integrity, availability). Cybersecurity concepts (identify, protect, detect, respond, recover). Operational capabilities. Security domains.
Those attributes earn their keep when you map Annex A onto another framework you already run, such as the NIST Cybersecurity Framework.
What ISO 27002 does not hold is a single requirement. No clause structure. No management system. Nothing an auditor can test. That is the whole reason you cannot certify against it.
What changed in 2022
ISO published 27002:2022 in February 2022. ISO 27001:2022 followed in October. The transition window for firms certified against the 2013 edition closed on 31 October 2025.
“Your existing ISO/IEC 27001:2013 certification becomes invalid, potentially leading to loss of business, along with trust, compliance and contractual issues, and fines.”
SGSOn missing the 31 October 2025 transition deadline
So watch what lands on your desk. A gap assessment, a template, or a proposal that talks about 114 controls and 14 domains is out of date. Check the date on all of it.
| 2013 edition | 2022 edition | |
|---|---|---|
| Controls | 114 | 93 |
| Structure | 14 domains (A.5 to A.18) | 4 themes (A.5 to A.8) |
| Themes | None | Organizational 37, People 8, Physical 14, Technological 34 |
| New controls | None | 11 added |
| Attributes | None | 5 per control |
The arithmetic behind 114 to 93
The drop is consolidation, not deletion. ISO merged 57 controls into 24. It split one into two. It left 35 alone with new numbers. Then it added 11 that did not exist before. Nothing got deleted.
The 11 new ones are what to review first, because they mark what changed between 2013 and 2022.
Threat intelligence
5.7
Cloud services
5.23
ICT readiness for continuity
5.30
Physical security monitoring
7.4
Configuration management
8.9
Information deletion
8.10
Data masking
8.11
Data leakage prevention
8.12
Monitoring activities
8.16
Web filtering
8.23
Secure coding
8.28
One later change is easy to miss. Amendment 1:2024 added climate change to Clauses 4.1 and 4.2 in February 2024. Your context record has to show you considered it. Your answer can be no.
Where the rest of the ISO 27000 family fits
ISO 27001 and 27002 are the two most-cited members of a family of more than forty standards. Most of the confusion about which one you need comes from not knowing what the neighbours do. Only two of them lead to a certificate.
| Standard | What it is for | Certifiable |
|---|---|---|
| ISO/IEC 27000 | Overview and vocabulary for the whole family. Defines the terms the others use. ISO publishes it free. | No |
| ISO/IEC 27001 | ISMS rules. The one you certify against. | Yes |
| ISO/IEC 27002 | How to build the Annex A controls. | No |
| ISO/IEC 27003 | How to build the ISMS itself, the Clauses 4 to 10 side. Often the standard people want when they ask about 27002. | No |
| ISO/IEC 27004 | Monitoring, measurement, and evaluation. How to build the metrics Clause 9 asks for. | No |
| ISO/IEC 27005 | How to manage information security risk. The method behind Clause 6. | No |
| ISO/IEC 27017 | Cloud control guidance, extending Annex A for cloud providers and their customers. | No |
| ISO/IEC 27018 | Protecting personal data in public clouds. | No |
| ISO/IEC 27701 | Privacy Information Management System. Extends ISO 27001 to cover privacy duties such as GDPR and Law 25. | Yes, as an extension |
If you are comparing 27001, 27002 and 27003
Hold it this way. 27001 is the requirement. 27003 tells you how to build the ISMS. 27002 tells you how to build the controls. 27003 is the one most teams have never heard of, and the one most of them need.
How to use both standards together
This is where the theory stops being useful. Below is the order we run for clients, and what goes wrong at each step. The order is not optional. Most expensive projects go wrong because two of these got swapped.
Define the ISMS scope
Write down what the ISMS covers. Which legal entities, which products, which sites, which systems, which people. Clause 4.3 wants this in writing, and your certificate will state it word for word.
What goes wrong: scope creep in both directions. Scope too narrow and the certificate is worthless to the customer who asked for it. A certificate covering only corporate IT reassures nobody buying your SaaS platform. Scope too wide and you are rolling out controls across subsidiaries that have nothing to do with the product. Decide by asking who will read the certificate and what they need it to say.
Run the risk assessment
Find the risks to confidentiality, integrity and availability inside your scope. Give each one an owner. Score them the same way each time. ISO 27005 gives you a method if you do not have one. The output is a risk register you can defend.
What goes wrong: risk assessments written backwards. A team picks the controls it wants, often the ones its current tooling already provides, then writes risks that justify them. Auditors spot this fast, because the register holds no risk that would force anything inconvenient. The test of a real risk assessment is whether it ever gave you an answer you did not want.
Select controls and build the SoA
Now open Annex A, and not before. For each of the 93 controls, record whether it applies, why, and where it stands. That is your Statement of Applicability, and the audit will scrutinise it more than any other document.
What goes wrong: the SoA contradicts the risk register. A control gets excluded as “not applicable” while the register holds a risk that control would treat. Each exclusion has to trace back to the risk work. This is also where ISO 27002 earns its price, because the one-line Annex A description tells you too little to decide.
Design and build the controls
Here you work from ISO 27002 instead of ISO 27001. Read the purpose and the guidance for each control you selected, then build something in proportion to the risk you found. Not the most thorough version the guidance describes.
What goes wrong: over-engineering. ISO 27002 describes good practice for firms of any size. A fifteen-person company that builds out the full guidance for each control will spend a year on an ISMS heavier than its product. The standard asks for controls that suit your risk. “Proportionate” is a position you can defend in an audit. “We did everything the guidance said” is an expensive one.
Internal audit and management review
Clause 9 wants you to audit your own ISMS and hold a management review on the record before anyone external shows up. Both have to have happened, with evidence, or the certification body cannot start.
What goes wrong: the person who built the ISMS audits it, finds nothing, and writes a one-page report. An internal audit that raises zero nonconformities is itself a finding. Make it independent and let it find things. That is what makes Stage 2 uneventful.
The certification audit
An accredited body runs Stage 1, a document review that confirms the ISMS exists and is ready. Then Stage 2 tests whether it runs the way you wrote it down. Certificates last three years, with a surveillance audit each year.
What goes wrong: booking Stage 2 before the ISMS has run long enough to produce evidence. Auditors sample records over a period. A control you switched on three weeks earlier has almost nothing to sample. “We have the policy” is not the same as “we followed the policy”. Most teams need two to three months of operating history.
The one-sentence version
ISO 27001 tells you to pick controls based on risk. ISO 27002 tells you how to build the ones you picked. Anyone who opens 27002 before finishing the risk assessment has already added months to the project.
Doing this in Canada
The two standards read the same everywhere. Who signs your certificate does not.
Use an accredited body
In Canada, the Standards Council of Canada accredits the bodies that issue ISO 27001 certificates. A body has to meet ISO/IEC 17021-1 first. The SCC signs the IAF Multilateral Recognition Arrangement, which is what makes a Canadian certificate count abroad.
“Certification to ISO/IEC 27001 by SCC-accredited certification bodies is widely accepted internationally.”
Standards Council of CanadaInformation Security Management Systems accreditation program
Check the accreditation before you sign anything. An unaccredited certificate costs less and buys you nothing, because the buyer who asked for it will check the register.
Canadian data residency compliance
Your scope and risk work have to name the law you live under. PIPEDA at the federal level. PHIPA for Ontario health data. Quebec Law 25. PIPA in Alberta and B.C. Financial services add OSFI B-13 and B-10, which push third-party and technology risk into the register.
ISO 27002 helps here in a specific way. Use the guidance on the supplier and transfer controls. It tells you where data can sit and what a vendor has to show you. Buyers in health, government, and finance ask that question before they ask for the certificate.
Nank.ai runs SOC 2 and ISO 27001 in Toronto, Ontario, and across Canada, and holds client data in the client’s own country.
Running SOC 2 alongside
Plenty of Canadian teams need both. SOC 2 answers North American buyers. ISO 27001 travels further. The controls overlap by a wide margin, so ISO 27002 doubles as the build guide for controls that satisfy both frameworks.
Is that your path? Start with what SOC 2 is and SOC 2 Type 1 vs Type 2. Build the risk register once for both.
What it costs and how long it takes
Cost splits into two buckets, and most published figures blur them.
Certification body fees are the predictable half. Scope, headcount and site count drive them, and they cover Stage 1, Stage 2 and the surveillance audits across the three-year cycle. Bodies quote these per audit day. Ask for the three-year figure, not the Stage 2 quote.
Implementation effort is the larger and far more variable half. Gap assessment. Writing the ISMS documents. Building or buying whatever controls your risk work demands. Training. The internal audit. Plus the staff time all of it eats.
Four things drive your number more than anything else:
- Where you start. A team with access reviews, logging and vendor management already running is doing documentation. A team starting from nothing is doing engineering.
- How big the scope is. Each extra legal entity, site and product multiplies audit days and evidence collection.
- Whether you absorb the work or outsource it. Internal staff time is real cost, and it is the line most often left out of comparisons.
- Tooling. Evidence collection runs by itself, or someone does it by hand every quarter, forever.
On timeline, a focused first certification runs three to six months from kick-off to Stage 2 for a small scope with reasonable starting maturity. Longer where the risk assessment turns up real engineering work.
Frequently asked questions
What is the difference between ISO 27001 and ISO 27002?
ISO 27001 states the requirements for an information security management system, and it is what you get certified against. ISO 27002 gives implementation guidance for the 93 controls that ISO 27001 names in Annex A. One is auditable. The other is a reference manual.
Can you get certified against ISO 27002?
No. ISO 27002 holds advice rather than rules, so a certification body has nothing to test you against. Anyone claiming to be “ISO 27002 certified” has misread the standards or is describing something that does not exist. The certificate is always against ISO 27001.
Do you need to buy both documents?
You need ISO 27001, because it is what the audit tests. ISO 27002 is optional but hard to work without. Annex A gives each control about a line, which seldom tells you whether it applies or how to build it. Most teams buy both. ISO 27000, which defines the vocabulary, is free.
Which comes first, ISO 27001 or ISO 27002?
ISO 27001, every time. It sets the scope, the risk work and the control picks that decide which parts of ISO 27002 you ever read. Starting with 27002 means building controls before you know whether your risk assessment needs them.
What is the difference between ISO 27002 and ISO 27003?
ISO 27002 covers the Annex A controls. ISO 27003 covers building the ISMS itself, the Clauses 4 to 10 side. Stuck on scope, risk method or management review rather than on single controls? ISO 27003 is the document you want.
Does ISO 27002 still help if we follow another framework?
Yes, and the 2022 attributes make it easier. Each control carries cybersecurity-concept attributes lined up with identify, protect, detect, respond and recover, which maps onto the NIST Cybersecurity Framework. Teams running SOC 2 alongside ISO 27001 use ISO 27002 as the build reference for controls that satisfy both.
Is ISO 27002 mandatory for ISO 27001 certification?
No. Nothing in ISO 27001 requires you to own or follow ISO 27002. Annex A is normative. The guidance behind it is not. In practice most teams use it, because deciding applicability from a one-line control name is guesswork.
Key takeaways
- ISO 27001 holds requirements and leads to a certificate. ISO 27002 holds guidance and leads to nothing an auditor can test.
- Annex A names 93 controls in about a line each. ISO 27002 explains the same 93 across some 150 pages.
- The 114 to 93 drop is consolidation. ISO merged 57 controls into 24 and added 11 new ones. It deleted none.
- Certificates against the 2013 edition stopped being valid on 31 October 2025. Check the date on any template or proposal that mentions 114 controls.
- Run the risk assessment before you open Annex A. Reversing that order is the most expensive mistake in the project.
- ISO 27003 covers the management system. It is the standard most teams need and have never heard of.
- In Canada, use an SCC-accredited body so buyers outside the country accept the certificate.
Related reading
References
- ISO/IEC 27001:2022, Information security, cybersecurity and privacy protection. Information security management systems. Requirements. ISO, October 2022.
- ISO/IEC 27002:2022, Information security controls. ISO, edition 3, 15 February 2022.
- ISO/IEC 27000:2018, Overview and vocabulary. ISO, free of charge.
- IAF MD 26, transition requirements for ISO/IEC 27001:2022. Transition period ended 31 October 2025.
- Standards Council of Canada, Information Security Management Systems accreditation program.
Getting this done
The distinction is simple. Running the programme it describes is what takes months. Talk to us about SOC 2 and ISO 27001 in Toronto and across Canada, with your data held in your own country.
Hunter Zhu Founder of Nank.ai, a Toronto firm that takes Canadian companies to ISO 27001, SOC 2, and ISO 42001. Connect on LinkedIn