ISO 27001
ISO 27001 information security management
ISO 27001 is the standard for an information security management system (ISMS). ComplyTrain gives you the framework to build, run and evidence your ISMS - the certificate stays yours to earn.
Standards · Cybersecurity
ISO/IEC 27001 and its family, the NIST and CIS frameworks, IEC 62443, SOC 2 and TISAX, and the EU laws that bind you directly: NIS2, DORA, the Cyber Resilience Act and GDPR. Explained in plain words, in one catalogue, with every entry linked to its source.
Overview
A security requirement arrives as a standard, a framework or a law. Knowing which one you are looking at tells you who checks it and what evidence they want.
ISO/IEC 27001 is the management system a customer asks for. An accredited body audits it and issues the certificate; 27002, 27005, 27017, 27018 and 27701 are read on top of it.
NIST CSF 2.0 and SP 800-53, SP 800-171 for the US defence supply chain, the CIS Controls, IEC 62443 for industrial systems. SOC 2 and TISAX are the reports and labels built on the same idea.
NIS2 and CER by sector, DORA for finance, the Cyber Resilience Act for products, GDPR for personal data. A supervisor enforces them whether or not a contract mentions them.
The measures the laws list are the controls a 27001 system runs. Build the system once, keep its evidence, and answer the auditor, the customer and the regulator from the same records.
Search the catalogue by name, browse it by family, or answer five questions about your situation. Each entry links to its source and can be requested in ComplyTrain.
A security requirement reaches a company in three shapes. A customer's questionnaire or contract asks for a standard, usually ISO/IEC 27001. A framework such as NIST's gives a programme its structure and a control catalogue to assess against. And a law binds you not because a contract says so but because of what you are and what you sell: NIS2, DORA, the Cyber Resilience Act, GDPR. This page explains the three, how they fit, and where the documents come from. The explorer below then finds the ones that match your situation.
ISO/IEC 27001 is the international standard for an information security management system, and the one a customer asks about first. It is certifiable, it is the same in every industry, and its main text lists no technical measures: it asks you to run a management system that knows what information you hold, assesses the risks to it, chooses controls and keeps evidence that they work. The 2022 edition's Annex A holds 93 controls in four themes, organisational, people, physical and technological. ISO/IEC 27002 explains each control and how to implement it, and ISO/IEC 27005 describes the risk assessment the standard requires but does not spell out. See ISO/IEC 27001, ISO/IEC 27002 and ISO/IEC 27005.
Around that core sit the extensions a particular customer asks for. ISO/IEC 27017 adds controls for cloud services and ISO/IEC 27018 protects personal data in a public cloud; both are what a cloud provider is asked to show. ISO/IEC 27701 extends the management system to privacy, the shape a GDPR programme can be run in. ISO/IEC 27035 covers incident management, and ISO 22301 business continuity. None of them stands alone: each is read on top of a 27001 system. See ISO/IEC 27017 and ISO/IEC 27018.
A framework is not a certificate. It is a structure to organise a programme and a catalogue to assess it against, and it is what an auditor, an insurer or a US customer measures you with. The NIST Cybersecurity Framework 2.0, from 2024, has six functions, Govern, Identify, Protect, Detect, Respond and Recover, and maps to the catalogues underneath it. NIST SP 800-53 is the control catalogue US federal systems are assessed against and the one most other catalogues cross-reference. NIST SP 800-171 is the subset a supplier to the US Department of Defense meets to handle controlled unclassified information, and the basis of the CMMC certification programme. The CIS Controls are eighteen prioritised safeguard groups in three implementation groups by organisation size, and the usual first step when nothing formal exists yet.
Two frameworks are sector-specific. IEC 62443 is the security series for industrial automation and control systems: zones and conduits for the plant, a secure development life cycle for the product (part 4-1) and technical requirements for components (part 4-2). TISAX is the automotive industry's exchange of information security assessments against the VDA ISA catalogue, and what a supplier to a German car maker is asked for. And two are attestations rather than standards: a SOC 2 report is an auditor's opinion on a service organisation's controls against the AICPA Trust Services Criteria, the document a US customer asks a SaaS provider for; the EU Cybersecurity Act's certification schemes are the European counterpart, still being rolled out.
A standard binds you because a contract says so. A law binds you because of what you are. Five EU acts now carry security obligations directly, and each has its own scope.
NIS2, Directive (EU) 2022/2555, applies to essential and important entities in eighteen sectors, from energy and transport to digital infrastructure, manufacturing of critical products and public administration. It is transposed into national law, so the exact duties come from your own country's act, but the shape is the same everywhere: management accountability, risk-management measures on a fixed list, supply-chain security, and early warning of a significant incident within 24 hours. The CER Directive, 2022/2557, is its physical-resilience counterpart for critical entities.
DORA, Regulation (EU) 2022/2554, applies since January 2025 to financial entities and to their critical ICT third-party providers. It asks for ICT risk management, incident reporting, resilience testing including threat-led penetration testing for the largest, and a register of every ICT contract. It applies directly, with no national transposition.
The Cyber Resilience Act, Regulation (EU) 2024/2847, reaches products rather than organisations: hardware and software with digital elements placed on the EU market must be secure by design, handle vulnerabilities for their support period and carry the CE mark for it. Reporting of actively exploited vulnerabilities starts in September 2026 and the full obligations apply from December 2027. ETSI EN 303 645 is the baseline the consumer-IoT part of it draws on.
GDPR, Regulation (EU) 2016/679, is the oldest of the five and the one everybody already meets: security of processing appropriate to the risk, and breach notification to the supervisory authority within 72 hours. Two newer acts touch the edges: eIDAS 2, Regulation (EU) 2024/1183, for trust services and the European Digital Identity Wallet, and the AI Act, Regulation (EU) 2024/1689, whose high-risk systems need a risk management system and a quality management system of their own.
An ISO/IEC 27001 certificate does not by itself satisfy NIS2 or DORA; the laws have their own scope, their own reporting clocks and their own supervisors. But the measures they list, risk analysis, incident handling, business continuity, supply-chain security, access control, encryption, are the measures a 27001 system runs, and the national authorities and ENISA reference ISO/IEC 27001 and the NIST framework in their guidance. A certified management system is the usual way to show a supervisor that the measures exist and are run, and a risk register and an incident log are the evidence both a certification auditor and a regulator read.
ISO/IEC standards are bought from ISO, from IEC or from your national standards body. Every NIST publication is free from NIST's Computer Security Resource Center, and the CIS Controls are free with registration. The EU acts are free on EUR-Lex, and every regulation entry in the explorer links to the consolidated text there; the national transpositions of NIS2 and CER come from your own legislature. IEC 62443 is bought from IEC or ISA, SOC 2's criteria come from the AICPA, and TISAX from the ENX Association.
Not this page, and not us. A contract or a questionnaire names the standard; a law names its own scope, and whether you fall inside it is a question about your sector, your size and what you sell that your counsel answers. What the explorer can do is show you the whole map: search it by number or name, browse it by family, or answer five questions about your situation and see which areas companies like you are commonly asked about. Each entry links to its source, to its ComplyTrain page where one exists, and otherwise to a request. ComplyTrain holds a standard as a requirement tree with the evidence against each requirement. The certificate stays yours to earn.
Standards explorer
Search the ISO/IEC 27000 family, the NIST and CIS frameworks, IEC 62443, SOC 2 and TISAX, and the EU acts together, browse them by family, or answer five questions about your situation.
Nothing matches that. Try a number, a code, or browse by family.
Which standards apply to you is set by your contracts; which laws apply is a question about your sector, your size and what you sell that your counsel answers. Treat this as a map, not a verdict.
Five questions, pick everything that applies. Nothing is stored.
The areas companies like you are commonly asked about, and the standards and laws in each. Confirm against your contracts and your counsel.
Which standards apply to you is set by your contracts; which laws apply is a question about your sector, your size and what you sell that your counsel answers. Treat this as a map, not a verdict.
Each page sets out what the standard asks of you and how a ComplyTrain workspace is organised around it. The catalogue above holds far more than these, and any entry in it can be requested. Adding a standard to a workspace is usually a matter of days, not a project.
ISO 27001
ISO 27001 is the standard for an information security management system (ISMS). ComplyTrain gives you the framework to build, run and evidence your ISMS - the certificate stays yours to earn.
ISO 27002
ISO 27002 is the implementation guidance for the information-security controls listed in ISO 27001 Annex A. ComplyTrain holds each control as a requirement with the evidence that shows it is operating - which is what an auditor samples.
ISO 27005
ISO 27005 is the guidance for managing information security risk - the assessment and treatment that ISO 27001 requires but does not describe. ComplyTrain runs it as a living register, not an annual document.
ISO 27017
ISO 27017 extends the ISO 27002 controls to cloud services and adds controls specific to them. ComplyTrain holds each one as a requirement, including the ones that belong to your provider rather than to you.
ISO 27018
ISO 27018 extends ISO 27001 to the protection of personal data in public clouds. ComplyTrain gives you the framework to manage and evidence those controls.
A standard usually arrives as a contract condition or a regulator's letter rather than a project anyone planned for, and often at a company with no quality manager. Software is half the answer. Skylen's consultants are the other half, and because they build on ComplyTrain from day one you keep a live system your team owns rather than a binder and a departed consultant.
A clause-by-clause read of where you stand against the standard your contract or your regulator cites, turned into a prioritised plan you could act on with us or alone.
What an assessment coversOur consultants build the system with your team - procedures, document control, the records you need to keep and the review cadence - and prepare you for the audit or the inspection.
How an engagement worksWe run and maintain the system for you, so a small team can reach and hold a standard without hiring a quality manager.
What full-service meansNo, and nothing does on its own. NIS2 is transposed into national law with its own scope, its own list of measures and its own reporting deadlines, and a supervisor checks you against that act, not against a certificate. A 27001 system does run the measures the law lists, so the certificate and the system's records are the usual way to show a supervisor that they exist. Read your national act for the duties and the deadlines.
ISO/IEC 27001 is a certification: an accredited body audits you and issues a certificate. ISO/IEC 27017, 27018 and 27701 are audited as extensions of it. SOC 2 is an attestation report, an opinion an auditor writes, not a certificate. TISAX is an assessment with a label shared through the ENX platform. The NIST framework, SP 800-53 and the CIS Controls are frameworks you assess against, with CMMC as the certification programme built on SP 800-171. IEC 62443 has product and process certification schemes run by third parties. A law is none of these: you comply with it, and a supervisor enforces it.
ISO/IEC 27001 is the requirements standard, the one you are certified against: it says what a management system must do and lists the controls in Annex A. ISO/IEC 27002 is the guidance: it takes each of those controls and explains what it means and how to implement it. You cannot be certified against 27002. See ISO/IEC 27001 and ISO/IEC 27002.
Ask the customer, because it is their procurement that decides. A US enterprise buyer usually asks a SaaS provider for a SOC 2 Type II report; a European or a public-sector buyer usually asks for ISO/IEC 27001. The two overlap heavily and many companies hold both, running one set of controls and having it audited twice. A supplier to the US Department of Defense is asked for NIST SP 800-171 and, increasingly, CMMC.
If you place a product with digital elements on the EU market, hardware or software, it applies unless the product is covered by a sector act that already regulates its security, such as medical devices or vehicles. Open-source software offered outside a commercial activity is outside it. What the act asks depends on the product class; the reporting duties start in September 2026 and the rest in December 2027. Whether your product is in scope is a legal question for your counsel.
No. Certification is issued by an accredited certification body, a licence by your authority, and government quality assurance is exercised by the acquisition authority. ComplyTrain is the system you build, run and evidence your compliance in, and Skylen's consultants can take you through the work. The certificate stays yours to earn.
Yes, and that is what the Request access button on every entry is for. Tell us which standard and where the requirement comes from, and we come back to you on what holding it in your workspace involves, usually within one business day. Adding a standard to a workspace is usually a matter of days, not a project. ComplyTrain holds a standard as a requirement tree with your evidence against each requirement, and the tree is what we build.