ISO 27001:2022 clauses: the requirements that lead to certification
It is clauses 4 through 10 — not Annex A — that determine whether you get certified. ISO/IEC 27001:2022 has two main parts. Clauses 4 to 10 set out the mandatory requirements: they describe the Information Security Management System (ISMS) your organization has to build and keep running. Annex A, on the other hand, is a catalogue of security measures the ISMS selects based on its risks. Certification is earned by demonstrating compliance with the clauses — that is the heart of the audit. This guide walks through each of the 7 certifiable clauses, in plain language, with what the auditor is actually looking for.
Clauses or Annex A? The distinction that changes everything
In plain language: you do not get certified “against Annex A.” You get certified against clauses 4 through 10. Annex A is a toolbox the ISMS draws from to address its own risks.
Clauses 0 to 3 (introduction, references, terms and definitions) are part of the standard but contain no auditable requirements. The certifiable requirements start at clause 4.
The thread that ties it together: the PDCA cycle
The seven clauses are not an arbitrary list — they follow the Plan-Do-Check-Act (PDCA) continuous improvement logic shared by every ISO management-system standard. Understanding this cycle helps you see how the clauses connect, rather than memorizing them one by one.
Clauses 4–6
Understand your context, secure leadership commitment, and set objectives and risk treatment.
Clauses 7–8
Provide resources and competence, then run the system day to day.
Clause 9
Measure, audit internally, and review with leadership.
Clause 10
Correct gaps and improve continuously.
The complete clause map
Every clause and sub-clause below links directly to its own page — no digging through menus. Use this as a standing table of contents for the whole standard.
Clause 4 · Context of the organization
Understand your context, your interested parties, and draw the boundaries of your ISMS.
Clause 5 · Leadership
Leadership commitment, the security policy, and assigned roles and authorities.
Clause 6 · Planning
Risk assessment and treatment, security objectives, and the Statement of Applicability.
Clause 7 · Support
Resources, competence, awareness, communication, and documented information.
Clause 8 · Operation
Running the ISMS day to day: operational control, and the recurring risk cycle.
Clause 9 · Performance evaluation
Monitoring and measurement, internal audit, and management review.
Clause 10 · Improvement
Continual improvement, and how nonconformities get corrected.
The 7 certifiable clauses, in plain language
Clause 4 · Context of the organization
Clause 5 · Leadership
Clause 6 · Planning
Clause 7 · Support
Clause 8 · Operation
Clause 9 · Performance evaluation
Clause 10 · Improvement
The mandatory documents the clauses require
Certain clauses explicitly require documented information. An auditor will systematically ask for these. The main ones:
- The ISMS scope (clause 4.3)
- The information security policy (clause 5.2)
- The risk assessment and treatment process (clause 6.1)
- The Statement of Applicability — SoA (clause 6.1.3)
- The information security objectives (clause 6.2)
- Evidence of competence (clause 7.2)
- Documented information necessary for operation (clause 8.1)
- The results of risk assessment and treatment (clauses 8.2, 8.3)
- Evidence of monitoring and measurement (clause 9.1)
- The internal audit program and results (clause 9.2)
- The results of management reviews (clause 9.3)
- Nonconformities and corrective actions (clause 10.2)
How to use this guide
You are new to the standard
Read the clauses in order — they tell a story, from context (4) to improvement (10).
You are preparing for the audit
Focus on clause 9 (internal audit, management review) and the mandatory documents list above.
You came from Annex A
Remember that controls are worthless without the ISMS these clauses describe.
Frequently asked questions
What are the mandatory clauses of ISO 27001?
What is the difference between the clauses and Annex A?
Can a clause be excluded?
What is the PDCA cycle in ISO 27001?
Sentrix maintains a native ISO 27001:2022 framework mapped to all 93 Annex A controls today, and supports the certification journey described in the clauses above. See the full ISO 27001 framework page for how the platform automates evidence collection and cross-framework mapping.
From requirements to certification.
Understanding the clauses is the starting point; building a compliant ISMS and proving it at audit is the real work. Sentrix supports you from structuring the ISMS through to the certificate.