Edition 2026.09 · Desk research from public vendor pages, last reviewed 29 September 2026

Lesson 1 of 10 · Track A · · Updated

What an ISMS is and what ISO 27001 certifies

Short answer

An information security management system (ISMS) is the set of policies, processes, roles and records an organisation uses to manage information security risk and improve over time. ISO/IEC 27001:2022 sets the requirements for one, and certification means an external auditor has checked that yours meets them.

G-01

Where does ISO 27001 come from?

ISO/IEC 27001 is published jointly by ISO and the IEC and maintained by the committee ISO/IEC JTC 1/SC 27. The current version is ISO/IEC 27001:2022, Edition 3, published in October 2022; iso.org lists it at 19 pages with one amendment, and sells it for CHF 155. ISO describes it as the world's best-known standard for information security management systems. The full title is worth reading once, because it tells you the scope: Information security, cybersecurity and privacy protection, Information security management systems, Requirements.

G-02

What does 'management system' mean in practice?

A management system is a loop, not a document set. You decide what the ISMS covers, work out which risks matter, choose controls to treat them, run those controls, check that they work, and fix what does not. The standard's requirements sit in clauses 4 to 10, which follow that loop from context and leadership through planning, support and operation to performance evaluation and improvement. The controls themselves are listed in Annex A, and you record which ones apply to you, and why, in a Statement of Applicability. A company can own excellent security tools and still fail an ISO 27001 audit if it cannot show the loop running: risk assessments that are current, reviews that happened, and actions that were closed.

G-03

What does a certificate actually say?

An ISO 27001 certificate says that a certification body audited your ISMS against the standard and found that it conforms, for a stated scope. The scope matters. A certificate that covers one product and one office says nothing about the rest of the business, and customers who read certificates carefully will ask. The certificate does not say your company cannot be breached, and it does not certify a product. It certifies that you manage information security in a disciplined, reviewable way.

G-04

What can a compliance platform do for an ISMS?

Platforms help most with the repetitive parts: collecting evidence from cloud accounts and HR systems, tracking controls, reminding owners, drafting policies and preparing the auditor's view. On our clause map, every vendor we cover describes evidence collection and some form of monitoring, which are clause 8 and clause 9 work. None describes setting the ISMS scope, which is clause 4 work and stays with you. The larger differences are in who does the work. Scytale describes a dedicated compliance expert who runs readiness with weekly meetings. Vanta and Drata describe partner networks. Sprinto describes support channels on its entry plan. Scrut describes AI agents for policy, risk and internal audit tasks.

G-05

What should you decide before choosing a tool?

Three things. First, a draft scope: which products, locations and teams the certificate should cover, because every later decision depends on it. Second, who owns the ISMS internally, because a platform cannot attend management review for you. Third, which other frameworks are coming, such as SOC 2 or the Essential Eight, because that decides how much cross-mapping is worth to you. With those three answers, the rankings and the cost estimator on this site become much easier to read.