ISO/IEC 27001:2022 specifies the requirements for an information security management system: the policies, risk assessments, controls and reviews an organisation uses to protect information.1 A certificate means an accredited body has audited that system and found it conforms.
What a certificate does and does not tell you
| Topic | It tells you | It does not tell you |
|---|---|---|
| Scope | The system covers the activities named on the certificate. | That every part of the business is in scope. Read the scope statement. |
| Risk | Risks to information are identified and treated by a defined method. | That every risk has been removed. |
| Continuity | The system is re-audited, so the certificate can be withdrawn. | That the next audit will pass. |
The current edition
Questions to ask any certified provider
- What is the certificate's scope, word for word?
- Which certification body issued it, and is that body accredited?
- When was the last surveillance audit, and were there major findings?
- Does the scope include the storage facility, transport and retrieval?
Sources
2 sources verified, last checked 4 October 2026- 1
- 2