Compliance & Regulations/Cross-jurisdictional/ISO 27001
ISO / Cross-jurisdiction · Global

ISO/IEC 27001:2022

The global Information Security Management System standard, updated in 2022 with 93 Annex A controls in four themes.

Regulator
ISO / IEC — accredited certification bodies
Jurisdiction
Global
Status
Active — 2022 revision with transition deadline October 2025 from 2013.
In force since
Active
Regulator's source
Who it applies to

Any organisation operating an ISMS and seeking accredited certification.

Audit / certification status

Safeguard maintains an ISO/IEC 27001:2022 certification covering its production environment.

What it requires

What ISO 27001 actually requires.

These are the obligations a regulated entity owes — the things an assessor or supervisor will ask about.

01

An ISMS with leadership, planning, support, operation, performance evaluation, improvement clauses.

02

Risk assessment and risk treatment plan.

03

Statement of Applicability covering 93 Annex A controls in 4 themes (organisational, people, physical, technological).

04

Internal audit and management review.

How Safeguard maps to it

Pre-mapped controls. Continuous evidence.

Each requirement above is bound to live telemetry — not screenshots. The mapping below is what your auditor or regulator sees.

ISMS structure mapped to clauses 4–10.

93 Annex A control evidence with continuous attestation.

Statement of Applicability auto-generated and version-controlled.

Crosswalks to SOC 2, NIST CSF, PCI-DSS, and HIPAA to reuse evidence.

Evidence we produce

Artifacts your auditor accepts.

Each evidence artifact is signed and timestamped. Auditors can verify integrity without trusting Safeguard.

ISMS scope statement.

Statement of Applicability (SoA).

Risk treatment plan.

Internal audit reports.

Annex A control evidence bundle.

Ready for ISO 27001?

Bring the framework. We'll walk the controls with you — section by section, evidence packet by evidence packet, with the regulators you actually have to answer to.

Safeguard | Software Supply Chain Security Platform | Zero CVE + Self-Healing