ISO 27001 certification requires you to implement a set of information security controls drawn from Annex A of the standard, but the exact controls you need depend entirely on your organisation’s risk assessment. There is no fixed list that every organisation must apply in full. Instead, ISO 27001 gives you a structured process for selecting the controls that are relevant to your specific risks, context, and scope. The sections below walk through how that selection works, what auditors look for, and how these controls connect to other frameworks your organisation may already be working with. If you have questions along the way, feel free to get in touch with us, and we are happy to help you think it through.

Which controls does ISO 27001 actually require you to implement?

ISO 27001 does not prescribe a fixed list of mandatory controls. Instead, it requires you to conduct a risk assessment, identify your information security risks, and then select controls from Annex A that address those risks. The controls you implement are documented in a Statement of Applicability, which records which controls apply, which do not, and why.

This means two organisations in the same industry can have quite different control sets and both still achieve certification. What the standard does mandate is that your control selection is justified, documented, and traceable back to your risk assessment results. The process itself is what certification auditors evaluate, not a checklist of specific controls ticked off in isolation.

That said, certain controls are so broadly applicable that almost every certified organisation ends up implementing them. Access control policies, incident management procedures, asset management, and supplier security assessments appear consistently across certified organisations because the underlying risks they address are nearly universal.

What is Annex A and how does it relate to internal controls?

Annex A is the reference control set embedded in ISO 27001. It lists 93 controls across four categories: organisational controls, people controls, physical controls, and technological controls. These controls serve as a menu of recognised security measures that organisations use to treat identified risks. Annex A does not require you to implement all 93 controls, only those relevant to your risk profile.

The relationship between Annex A and your internal controls is one of alignment rather than direct equivalence. Your internal controls are the actual policies, procedures, and technical measures you put in place inside your organisation. Annex A provides the reference framework that ensures your internal controls are comprehensive and that you have not overlooked a recognised category of risk.

When your auditor reviews your Statement of Applicability, they are checking that you have considered every Annex A control, made a deliberate decision about each one, and that your justifications are coherent. Controls you exclude must be justified just as carefully as the ones you include. This is where many organisations run into difficulty during certification, particularly when exclusions have not been properly documented or reasoned.

How do you decide which ISO 27001 controls apply to your organisation?

You decide which controls apply by working through a structured risk assessment process. Start by defining your scope, identifying your information assets, and assessing the threats and vulnerabilities relevant to each asset. For each identified risk, you then select one or more Annex A controls that reduce that risk to an acceptable level. The output is your risk treatment plan and your Statement of Applicability.

In practice, this process involves several concrete steps:

  • Define the scope of your information security management system, including which assets, processes, and locations are covered
  • Identify information assets and classify them by sensitivity and criticality
  • Assess risks by considering the likelihood and potential impact of threats to each asset
  • Select Annex A controls that address the identified risks, and document your reasoning
  • Record all decisions, including exclusions, in your Statement of Applicability

The quality of your risk assessment directly determines the quality of your control selection. A superficial risk assessment leads to a control set that either over-engineers low-priority areas or leaves genuine gaps unaddressed. Auditors are trained to probe this relationship, so the logic connecting your risks to your chosen controls needs to be clear and defensible.

Continuous governance plays a significant role here. Your risk landscape does not stay static after you achieve certification. New systems, new suppliers, new regulations, and organisational changes all create new risks. Organisations that treat ISO 27001 as a living system rather than a one-time project maintain a control set that actually reflects their current risk exposure, rather than the situation they faced when they first applied for certification.

What controls do auditors most commonly flag during ISO 27001 certification?

Auditors most commonly flag gaps in access control management, supplier security, incident response documentation, and management review processes. These areas consistently appear in certification findings because they require ongoing operational discipline rather than a single implementation effort. A policy can be written in a day; demonstrating that it is consistently followed over time is significantly harder.

The specific areas that generate the most findings include:

  • Access control: Poorly maintained user access rights, lack of regular access reviews, and inadequate offboarding procedures are among the most frequent issues
  • Supplier management: Many organisations underestimate the depth of documentation required for third-party security assessments and contractual security requirements
  • Incident management: Having an incident response plan is not enough; auditors want evidence that it has been tested and that staff know how to use it
  • Internal audit and management review: These are mandatory processes under ISO 27001, and auditors look for evidence of genuine engagement rather than box-ticking
  • Asset inventory: Incomplete or outdated asset registers are a persistent problem, particularly in organisations with cloud infrastructure or rapid growth

What connects most of these findings is governance drift: the gap that opens up between a well-designed control environment and the reality of how an organisation actually operates as time passes. This is precisely why governance needs to be a permanent, operational capability rather than something that is refreshed only when the next certification audit approaches.

Can you exclude Annex A controls from your ISO 27001 scope?

Yes, you can exclude Annex A controls from your ISO 27001 scope, but only if you can justify the exclusion based on your risk assessment. A control can be excluded if it is not applicable to your organisation’s context, for example, if you have no physical offices and therefore certain physical security controls are not relevant, or if the risk the control addresses does not exist in your environment.

What you cannot do is exclude a control simply because it is inconvenient or costly to implement. If your risk assessment identifies a risk that a particular Annex A control addresses, excluding that control requires you to demonstrate either that you have treated the risk through an alternative measure or that you have accepted the residual risk with appropriate justification.

Auditors scrutinise exclusions carefully. A Statement of Applicability with a large number of excluded controls will prompt detailed questioning about whether the scope of the ISMS has been defined too narrowly, or whether risks have been underestimated. The exclusion process is legitimate and often appropriate, but it must be rigorous and honest.

How do ISO 27001 controls connect to GDPR, NIS2, and other frameworks?

ISO 27001 controls overlap significantly with the technical and organisational measures required by GDPR, NIS2, DORA, and the EU AI Act. The frameworks share common ground in areas such as access control, incident response, risk management, and supplier security. Implementing ISO 27001 controls properly creates a strong foundation that satisfies many of the security requirements embedded in these regulatory regimes.

The relationship is not one of perfect equivalence, however. Each framework has its own scope, legal obligations, and specific requirements that go beyond what ISO 27001 covers. GDPR, for example, adds data subject rights, lawful basis requirements, and data protection impact assessments that have no direct counterpart in ISO 27001. NIS2 introduces sector-specific obligations and incident reporting timelines that require their own governance processes.

The practical implication is that organisations subject to multiple frameworks benefit enormously from an integrated governance approach. Rather than maintaining separate control sets for each framework, a unified system maps controls to multiple requirements simultaneously, reduces duplication, and makes it far easier to demonstrate compliance across the board. This is the kind of cross-domain integration that turns governance into a genuine organisational capability rather than a series of disconnected compliance exercises.

For organisations operating in the EU, particularly scale-ups and mid-market companies navigating ISO 27001 alongside NIS2, GDPR, or AI-related regulation, the overlap between frameworks is an opportunity as much as a challenge. A well-structured control environment built around ISO 27001 can serve as the backbone for meeting multiple regulatory obligations at once. You can learn more about how we approach this kind of integrated governance on our services page, or get in touch to plan a conversation about where your organisation stands today.

Frequently Asked Questions

How long does it typically take to implement ISO 27001 controls and achieve certification?

The timeline varies depending on your organisation's size, complexity, and how mature your existing security practices are. For most small to mid-sized organisations starting from scratch, a realistic timeframe is 6 to 12 months from initial scoping to certification audit. Organisations that already have documented security policies and some governance infrastructure in place can sometimes move faster, but rushing the risk assessment phase tends to create problems that surface during the audit.

What is a Statement of Applicability and how detailed does it need to be?

A Statement of Applicability (SoA) is a formal document that lists all 93 Annex A controls, states whether each one is applicable to your organisation, and provides justification for both inclusions and exclusions. It needs to be detailed enough that an auditor can clearly trace each decision back to your risk assessment results. Vague justifications such as 'not relevant' without explanation are a common reason auditors push back, so each exclusion should reference the specific context or risk rationale that supports it.

Do we need to hire an external consultant to implement ISO 27001 controls, or can we do it in-house?

It is entirely possible to implement ISO 27001 in-house if you have staff with sufficient information security knowledge and the capacity to dedicate meaningful time to the project. That said, many organisations benefit from external support, particularly during the risk assessment and SoA development stages, where gaps in methodology can undermine the entire certification effort. A middle-ground approach — using external expertise for the framework design and audit preparation while building internal ownership of day-to-day controls — tends to produce the most sustainable results.

What happens if a gap is identified during the certification audit — does it mean we fail?

Not necessarily. Auditors distinguish between major nonconformities, which must be resolved before certification can be granted, and minor nonconformities or observations, which are recorded but do not automatically block certification. A major nonconformity typically means a required process is absent or a significant control gap exists. Minor findings are common and manageable. The key is to engage with findings constructively, provide a credible corrective action plan, and demonstrate that your governance process is capable of identifying and addressing gaps over time.

How often do ISO 27001 controls need to be reviewed and updated after initial certification?

ISO 27001 requires you to conduct regular internal audits and management reviews, and to reassess your risks whenever significant changes occur — such as adopting new technology, onboarding major suppliers, expanding into new markets, or experiencing a security incident. In practice, a formal annual review cycle is the minimum, but high-growth or rapidly changing organisations should treat control reviews as a continuous process rather than a calendar event. Surveillance audits conducted by your certification body in the years between full recertification cycles will also check that your controls remain current and effective.

Can a small or early-stage company realistically achieve ISO 27001 certification, or is it only practical for larger organisations?

ISO 27001 is genuinely scalable and well-suited to smaller organisations, particularly those in sectors where customers or enterprise partners require demonstrated security credentials. The scope of your ISMS can be defined narrowly to match your actual footprint, which keeps the control set proportionate. Many early-stage companies pursue certification specifically because it accelerates enterprise sales cycles and removes a common procurement barrier. The investment is real, but for organisations handling sensitive data or operating in regulated industries, the commercial and risk management benefits typically justify it.

What is the most common mistake organisations make when selecting controls for the first time?

The most common mistake is treating the control selection process as a documentation exercise rather than a genuine risk-driven analysis. This usually means copying a standard control set from a template without properly mapping controls to the organisation's specific risks, assets, and context. The result is either a bloated control environment full of measures that do not address real risks, or a superficial one that misses genuine exposures. Auditors are experienced at spotting control sets that are disconnected from the underlying risk assessment, and this disconnect is one of the most frequent reasons certification programmes stall or fail.

Related Articles

Share