ISO 27001:2022 and how the standard is structured
ISO 27001:2022 is the latest edition of the international standard for information security management systems (ISMS). The move from the 2013 version brought a substantial reorganisation of the security controls — their number fell from 114 to 93, and the structure was simplified by grouping them into four main themes: organisational controls, people controls, physical controls and technological controls. This change does not mean the requirements were weakened — on the contrary, they became more targeted and more practical for contemporary cyber threats.
The transition period is over — where things stand in 2026
This is the first thing that needs saying plainly today, because half the guidance available online still describes the move to the 2022 edition as something yet to happen.
The transition period from ISO/IEC 27001:2013 ended on 31 October 2025. IAF MD 26 allowed no grace period: certificates based on the 2013 edition expired or were withdrawn. From 1 May 2024 onwards, all initial and recertification audits had to be conducted exclusively against the 2022 edition.
The practical consequence: if an organisation did not complete the transition in time, there is no "extension" and no shortened route. There is new certification from scratch — with a full two-stage audit.
The second change concerns certification bodies. From 31 March 2026, all ISMS certifications must be conducted in accordance with ISO/IEC 27006-1:2024, which replaced the 2015 edition. Among other things, the methodology for calculating audit time changed (the concept of "effective number of personnel"), as did the rules on remote audits. If you are comparing certification offers today against a quotation from two years ago, the figures may not line up — and that is not a price rise, it is a different basis of calculation.
In Poland the standard exists as PN-EN ISO/IEC 27001:2023-08 (also available in Polish), and the climate amendment as PN-EN ISO/IEC 27001:2023-08/A1:2025-02.
The climate amendment — one sentence that is easy to forget
On 23 February 2024 ISO published Amendment 1:2024, "Climate action changes" — an amendment covering 36 management system standards, ISO/IEC 27001 among them. The whole text fits on a single page and comes down to two additions:
- clause 4.1 gains a requirement: the organisation shall determine whether climate change is a relevant issue for its context;
- clause 4.2 gains a note that interested parties may have requirements related to climate change.
In a joint communiqué, ISO and IAF stressed that the intention is not to turn the ISMS audit into a climate audit. The requirement is nonetheless auditable: the auditor will ask for a documented outcome of the analysis, not for a climate policy. The answer "climate change is not relevant to us in the context of information security" is entirely acceptable — provided the conclusion was actually reached somewhere and written down.
In practice the most common shortcoming is not a wrong answer but the absence of any trace that the question was ever asked.
The implementation process
Implementing ISO 27001:2022 in a typical mid-sized company takes six to twelve months, depending on the starting state of information security and on the commitment of senior management. The first stage of implementation — the gap analysis — involves examining in detail the organisation's current state of information security and comparing it with the requirements of the standard. That assessment should cover every aspect of the ISMS, from policies and procedures through the technology infrastructure to the competence of staff. Clause 4.1 of ISO 27001:2022 expressly requires the organisation to determine the scope and boundaries of the ISMS, and clause 4.4 requires it to assess the state of existing controls systematically.
The number of controls fell from 114 to 93.
The second key element is carrying out an information security risk assessment. Standardising this process matters particularly — clause 6.2 of ISO 27001:2022 requires the organisation to conduct a risk assessment covering the identification of threats, the estimation of vulnerabilities, and the determination of the impact and likelihood of each risk materialising. That assessment must be documented and recorded, and its results form the basis for selecting the appropriate controls. In Poland many companies use the OCTAVE methodology (Operationally Critical Threat, Asset, and Vulnerability Evaluation) or a method developed in-house, but it always rests on identifying information assets, assessing their business value and analysing the threats they face.
Statement of Applicability
The Statement of Applicability (SoA) — the document setting out which of the 93 controls in Annex A of the standard are relevant to a given organisation — is the foundation of an ISO 27001:2022 implementation. For every control the organisation must decide whether it is "applicable" or "not applicable". Where a control is applicable, clause 5.1 of the standard requires that decision to be documented together with its justification. This document will be central during the certification audit, since auditors from DNV, TÜV or BSI will be checking whether the organisation has correctly identified the controls that apply to it.
Annex A is a checklist, not a shop full of controls
The most common methodological mistake during implementation looks like this: the team opens Annex A, works through the 93 controls, ticks "we apply this / we do not", and builds the Statement of Applicability on that basis. The order is the reverse of what was intended.
The standard requires controls to follow from the risk treatment process (clause 6.1.3). Annex A comes into play only afterwards — as a verification list to compare against your own set of controls, to check that nothing significant has been missed. The 2026 edition of ISO/IEC 27000 states this role explicitly, correcting an interpretation that is widespread in market practice.
The difference shows up in the audit. Under the risk-first approach the auditor asks about a risk and hears which control addresses it. Under the Annex A-first approach the question "why this particular control?" is met with silence, because the answer is "because it was on the list".
The Statement of Applicability must contain four elements: the list of necessary controls, the justification for their inclusion, information on whether they have been implemented, and the justification for excluding controls from Annex A. That exclusion justification is not a formality — it is the sentence the auditor will read most carefully.
It is also worth remembering two structural changes in the 2022 edition that are easy to overlook when updating documentation: clause 6.3 Planning of changes was added, and in Clause 10 the order was reversed — continual improvement now sits in 10.1, and nonconformity and corrective action in 10.2.
Implementing the controls
Implementing the controls themselves is a lengthy process. The organisational controls, listed under theme A5 (A5.1 to A5.23), cover among other things the development of information security policies, access management procedures (aligned with the least privilege principle), and the organisation of change management. Clause 7.1 of ISO 27001:2022 requires management commitment and the implementation of procedures controlling access to information. The people controls (A6.1 to A6.8) cover security awareness training, procedures for people leaving the organisation, and the management of employee competence — under clause 7.2, the organisation must ensure that staff with access to information assets are properly trained and aware of their responsibilities.
The physical controls (A7.1 to A7.14) cover access control to rooms where information assets are held and protection against theft and destruction. For companies with server rooms or data centres these requirements are particularly relevant — clause 8.1 of the standard requires physical access controls across the organisation's premises. The technological controls (A8.1 to A8.28) form the largest group and cover encryption of data at rest and data in transit, cryptographic key management, endpoint security, and network security monitoring.
ISMS documentation
ISMS documentation must be comprehensive. Beyond the SoA, the organisation must produce or update a range of documents: the information security policy, access management procedures, change management procedures, incident management procedures, the business continuity plan, and internal audit procedures. Clause 8.2 of ISO 27001:2022 requires the organisation to ensure that information relating to the ISMS is retained and protected in line with requirements on records retention and data management.
Internal audits
Internal audits are critical to a successful implementation. Clause 9.2 of the standard requires the organisation to conduct internal audits at least once a year, or more often, to check that the ISMS conforms to the requirements of the standard and is being implemented effectively. Internal audits should be carried out by staff independent of the area being audited, to ensure objectivity. In Poland, many companies employ auditors holding an ISO 27001 Internal Auditor certificate issued by a recognised certification body.
If you do not yet have a baseline, start with an IT security audit — its report is a natural input to the gap analysis.
Management review and certification
The management review — described in clause 9.3 — is the final stage before certification. The organisation's leadership must review the ISMS to satisfy itself that it remains suitable, adequate and effective. That review should take account of internal audit results, the risk assessment, information security events and input from stakeholders.
Certification for a mid-sized company costs PLN 15,000 to PLN 30,000.
ISO 27001:2022 certification is carried out by accredited certification bodies such as DNV (Det Norske Veritas), TÜV (Technischer Überwachungs-Verein) and BSI (British Standards Institution). The certification process has two stages: the stage 1 audit, in which the auditors assess the organisation's readiness, and the stage 2 certification audit, in which they verify the actual implementation of all 93 controls and conformity with the requirements of the standard. Typical certification costs for a mid-sized company are PLN 15,000 to PLN 30,000, depending on the complexity of the organisation and the scope of the ISMS. Once the certificate has been obtained, annual surveillance audits are required; the certificate is valid for three years, after which recertification is needed.
The mistakes most often made during implementation include insufficient management commitment, implementing controls without a prior risk assessment, and treating the ISMS as an IT project rather than a strategic initiative spanning the whole organisation. Successful implementation of ISO 27001:2022 requires a change of mindset across the organisation — information security is not the IT department's job alone but the responsibility of every employee, from the board to operational staff. For that reason, implementing ISO 27001 in an organisation is best run as a project covering the full cycle — from gap analysis, through documentation and training, to preparation for the certification audit.
In local government units, ISO 27001 is best read alongside the KRI requirements — the two regimes overlap to a large extent.
ISO 27001 versus the KSC Act, NIS-2 and DORA — where the regulations actually point to the standard
The question clients ask most often is: "does NIS-2 require ISO 27001 certification?". The answer is no. But that does not make the standard irrelevant here — it helps to separate three levels.
Level one: no certification requirement. Neither the NIS-2 Directive nor the Polish KSC Act names ISO/IEC 27001 as a requirement. Poland's Ministry of Digital Affairs states this directly when describing the requirements for cybersecurity documentation: the elements of that documentation derive from standards such as PN-EN ISO/IEC 27001 and PN-EN ISO 22301, but they do not require certification of conformity with those standards. The requirement concerns implementing a system, not holding a piece of paper.
Level two: the standard as a ready-made map of the requirements. In June 2025 ENISA published technical implementation guidance on Implementing Regulation (EU) 2024/2690, in which every regulatory requirement is mapped to specific requirements of ISO/IEC 27001:2022 and 27002:2022 (as well as NIST CSF 2.0 and other standards). ENISA notes that mapping does not mean equivalence — but an organisation with a working ISMS gains from it a ready-made evidence trail rather than a blank page.
Level three: the standard in Polish implementing legislation. Here the references are direct. The KRI Regulation (§19(3)) treats the requirements as satisfied where the ISMS is based on PN-ISO/IEC 27001, the controls on PN-ISO/IEC 27002 and risk management on PN-ISO/IEC 27005. The Regulation of the Minister of Digital Affairs of 12 October 2018 lists the ISMS lead auditor certificate under PN-EN ISO/IEC 27001 among the qualifications entitling a person to carry out a KSC audit.
With DORA the mechanism is similar: Delegated Regulation (EU) 2024/1774 repeatedly refers to "leading practices and standards" without naming ISO. Conformity runs through the European standardisation system rather than through a reference to a specific standard.
A timetable worth setting against your implementation plan. Entities covered by the amended KSC Act from 3 April 2026 have until 3 October 2026 to be entered in the register, until 3 April 2027 to implement a security management system, and — for essential entities — until 3 April 2028 to complete their first audit. Implementing ISO 27001 typically takes anywhere from several months to well over a year, so these dates are a real constraint on the schedule rather than a distant prospect.
What it costs and how long it takes
An honest answer starts with a caveat: there are no official, publicly available statistics on the cost of ISO 27001 certification in Poland. Accreditation bodies do not publish price lists, and every figure circulating online comes from commercial material, with differences of several dozen times between them. The main reason for the divergence is mundane: three quite different items get mixed together.
The certification audit is the certification body's cost — counted in audit days, calculated under the ISO/IEC 27006-1:2024 methodology, and dependent on the number of employees within scope, the number of locations and system complexity.
Implementation is the cost of bringing the organisation to a state in which an audit makes sense — gap analysis, risk assessment, policies and procedures, deployment of controls, training, internal audit. This is usually the largest and most variable item, because it depends on the starting point.
Maintenance is the annual cost: surveillance audits, management reviews, documentation updates, further internal audits.
On timing the framework is more predictable. The certificate is issued for a maximum of 3 years, with surveillance audits every 12 months and full recertification after three years. The certification audit itself has two stages: Stage 1 is a review of documentation and readiness, Stage 2 an assessment of actual implementation. A few weeks are usually left between the stages to close out the Stage 1 findings.
If anyone quotes an implementation price without first establishing the scope, the state of the documentation and the number of locations, they are quoting for something other than what you need.
The most common implementation mistakes
Public statistics on nonconformities from ISO 27001 certification audits do not exist — no certification or accreditation body publishes them. The list below reflects observations from audits carried out by our team, not statistical data.
The risk assessment as a one-off file. A spreadsheet completed before the certification audit and not opened again until recertification. The standard requires a process, not a document — and you recognise a process by the fact that something comes out of it.
A Statement of Applicability out of step with reality. A control declared as implemented for which no operational evidence exists. This is the fastest route to a major nonconformity, because it undermines the credibility of the entire documentation set.
An ISMS scope set for the audit rather than for the organisation. Cutting the difficult areas out of scope produces a certificate that fails to answer the questions clients and regulators are asking — and they were usually the reason for certifying in the first place.
An internal audit performed by the person who implemented the system. Formally there is an audit. In substance it is a self-assessment.
A management review as minutes with no content. The standard requires specific inputs and decisions as outputs. Minutes recording that "the system is functioning correctly" contain neither.
No record of the climate analysis. Since 2024 the easiest nonconformity to avoid, and still one of the more frequently encountered — as described above.


