
ISO/IEC 27001 is the requirements standard: it sets out what an information security management system (ISMS) must do, and it is the standard a certification body audits you against. ISO/IEC 27002 is guidance: it describes 93 information security controls and how to implement them, and ISO states plainly that it cannot be certified to. You use them together, with 27001 deciding which controls you need and how you manage them, and 27002 explaining each control in detail.
Our cybersecurity consulting engagements assess your controls against the framework you are measured by, rank the gaps and write the policies, which is the groundwork any ISO project starts with; the certification audit itself stays with an independent certification body. For how ISO compares with the NIST frameworks and the CIS Controls, see our NIST, ISO 27001 and CIS Controls comparison.
What is the difference between ISO 27001 and ISO 27002?
ISO/IEC 27001 is written as requirements. Its clauses 4 to 10 cover the context and scope of the ISMS, leadership, risk assessment and treatment, resources and documented information, operation, monitoring, internal audit, management review and improvement, and the IEC listing for ISO/IEC 27001:2022 notes that excluding any of those clauses is not acceptable if you claim conformity. Its Annex A is a normative reference list of information security controls, which the 2022 edition aligned with ISO/IEC 27002:2022.
ISO/IEC 27002 is written as guidance. Its scope describes a reference set of generic information security controls with implementation guidance, for use inside an ISMS based on 27001, for implementing controls from recognized good practice, or for writing your own guidelines. Each control comes with its purpose and guidance, plus attributes, such as operational capabilities and security domains, for filtering the list.
| ISO/IEC 27001:2022 | ISO/IEC 27002:2022 | |
|---|---|---|
| Kind of document | Requirements for an ISMS | Guidance on information security controls |
| Current edition | Third edition, published October 25, 2022 | Third edition, published February 15, 2022 |
| Length | 19 pages | 152 pages |
| Core content | Clauses 4 to 10, plus Annex A, a reference list of controls | 93 controls in four themes, each with its purpose and guidance |
| Can you be certified to it? | Yes, by a certification body | No |
| Who uses it day to day | Leadership and the person who owns the ISMS | The people who design, build or test the controls |
| What you must do | Meet every requirement in clauses 4 to 10 to claim conformity | Apply the controls your risk assessment calls for |
| List price on the IEC webstore, October 2026 | CHF 155 | CHF 227 |
How do ISO 27001 and ISO 27002 work together?
27001 decides; 27002 explains. Under 27001 you define the scope of the ISMS, assess information security risks and decide how to treat them. ISO/IEC 27002 describes the same step from the other side: determining controls depends on the organization's decisions after a risk assessment with a clearly defined scope, controls can come from any source, and not every control in the document applies to every organization.
In practice, the control numbers you meet in an ISO 27001 project, such as 5.15 Access control, 8.8 Management of technical vulnerabilities or 8.13 Information backup, are the ones 27002 describes. A team implementing access control works from the 27002 guidance for 5.15, while 27001 asks whether your risk treatment calls for the control and whether you can show it working.
What are the 93 controls in ISO 27002:2022?
The 2022 edition groups its 93 controls into four themes:
- Organizational controls, 5.1 to 5.37: 37 controls, from security policies and roles to supplier relationships, cloud services, incident management and legal requirements.
- People controls, 6.1 to 6.8: 8 controls, including screening and security awareness, education and training.
- Physical controls, 7.1 to 7.14: 14 controls, from physical security perimeters to the secure disposal or reuse of equipment.
- Technological controls, 8.1 to 8.34: 34 controls, including user endpoint devices, protection against malware, vulnerability management, backup, logging, monitoring and secure coding.
The 2022 revision changed the structure, not just the wording. ISO merged some controls, deleted others and introduced several new ones, and Annex B of 27002 maps every 2022 control to the 2013 edition. That table helps if your policies or contracts still cite the old control numbers.
Can you get certified to ISO 27002?
No. ISO's page for ISO/IEC 27002 says it provides best practice recommendations and cannot be certified to, and that organizations get certified to ISO/IEC 27001, which references the 27002 guidance. If a vendor offers you an ISO 27002 certificate, ask exactly what it attests.
Certification to 27001 is not done by ISO either. ISO's certification page says it does not perform certification or issue certificates; external certification bodies do. Accreditation of the certification body is not compulsory, but it gives independent confirmation of the body's competence, and ISO points buyers to the IAF CertSearch database to check a certificate issued by an accredited body.
Which fits a small team: ISO 27001 certification or ISO 27002 as a guide?
Decide by who is asking and what they will accept:
- A customer or tender requires a certificate: you need an ISMS that meets 27001, audited by a certification body. 27002 is the reference your team uses to build the controls.
- Nobody requires a certificate: you can use 27002 on its own as a catalog of good practice, applying the controls your risks justify, without the management-system overhead.
- A US customer asks for a SOC 2 report instead: that is a different product, an examination by a CPA firm. Our post on ISO 27001 vs SOC 2 compares the two.
Be honest about the ISMS work before you commit. 27001 requires internal audits, management reviews and corrective action, so someone in the business has to own the system all year, not just in the month before the audit. The ISO/IEC 27001 page on ISO's site lists a practical guide to the standard written for small and medium-sized enterprises for exactly that reason.
What drives the cost and effort of ISO 27001 compared with 27002?
Buying the standards is the smallest line: as of October 2026 the IEC webstore lists ISO/IEC 27001:2022 at CHF 155 and ISO/IEC 27002:2022 at CHF 227. Using 27002 as a guide costs only the time to implement the controls you choose. Certification adds several lines, and we publish no prices for any of them:
- Scope. Which parts of the business, which sites and which systems the ISMS covers. A narrow scope tied to the service your customers buy keeps every other line smaller.
- Risk assessment and treatment. The work of identifying risks, choosing controls and recording the decisions.
- Control gaps. Technical fixes such as MFA, device management, logging and tested backups, plus the written policies.
- Running the ISMS. Internal audits, management reviews, corrective actions and the records that show they happened.
- The certification body's fee, which it quotes from your scope.
Budget for staff time as well. A management system needs regular meetings, decisions and records, and those hours come from people who already have day jobs.
How does NetSys help with ISO 27001 and ISO 27002 work?
We do the assessment and the engineering, not the certification. Our cybersecurity consulting engagements review identity, email, devices, backups, the network and key vendors against the framework you are measured by, rank the findings by likelihood and business impact, and turn them into a roadmap with an owner and a date for every item. We write or revise the policies the findings call for and rehearse incident response with leadership in a tabletop exercise.
For managed clients we also run many of the technical controls 27002 describes, including access control, malware protection, vulnerability management, backup and monitoring, and we map the controls we run to the framework you choose. The certification audit is performed by an independent certification body that you engage directly. Consulting is quoted as a fixed-scope project after a scoping call, and managed services run month to month.
Book a call with a NetSys engineer to talk through who is asking for ISO 27001, the scope that would satisfy them and where your current controls stand.
Frequently asked questions
What is the difference between ISO 27001 and ISO 27002?
ISO/IEC 27001 sets the requirements for an information security management system and is the standard you certify against. ISO/IEC 27002 is guidance that explains 93 information security controls and how to implement them; it cannot be certified to. 27001 decides which controls you need, and 27002 explains how to build them.
Is ISO 27002 required for ISO 27001 certification?
You certify against 27001 alone. ISO describes 27002 as the detailed best practice and controls that can be applied within the ISMS, so it is worth buying as the working reference while you implement the controls your risk assessment selects.
Which fits a small team?
If a customer or tender requires a certificate, 27001 with 27002 as the guide. If nobody requires one, 27002 alone is a practical catalog of controls to adopt by risk, without running a full management system.
What affects the cost, implementation and support?
Scope, the control gaps you find, the staff time to run internal audits and management reviews, and the certification body's fee. The standards themselves are a minor cost. Support continues after the certificate, because the ISMS has to keep operating.
How many controls are in ISO 27002:2022?
93, in four themes: 37 organizational, 8 people, 14 physical and 34 technological. Each control has a purpose, guidance and attributes for sorting the list.
What changed in the 2022 editions?
ISO/IEC 27002:2022 reorganized the controls into four themes with attributes, merging some, deleting some and adding several new ones, with Annex B mapping them to the 2013 edition. ISO/IEC 27001:2022 aligned its text with the harmonized structure for management system standards and with ISO/IEC 27002:2022.
Discuss cybersecurity consulting for your business.
Tell us about your current systems, the result you need and your timeline. We will discuss the work, responsibilities and pricing before you decide on an engagement.


