Home/ Blog/ ISO 27001:2022 clauses
ISO/IEC 27001:2022

ISO 27001:2022 clauses: the requirements that lead to certification

It is clauses 4 through 10 — not Annex A — that determine whether you get certified. ISO/IEC 27001:2022 has two main parts. Clauses 4 to 10 set out the mandatory requirements: they describe the Information Security Management System (ISMS) your organization has to build and keep running. Annex A, on the other hand, is a catalogue of security measures the ISMS selects based on its risks. Certification is earned by demonstrating compliance with the clauses — that is the heart of the audit. This guide walks through each of the 7 certifiable clauses, in plain language, with what the auditor is actually looking for.

Frameworks · Published Jul 15, 2026 · 11 min read

Clauses or Annex A? The distinction that changes everything

In plain language: you do not get certified “against Annex A.” You get certified against clauses 4 through 10. Annex A is a toolbox the ISMS draws from to address its own risks.

Clauses 4 to 10 Annex A
Mandatory, auditable requirementsCatalogue of reference measures (93 controls)
Describe the ISMS: how you manage securityDescribe controls: what to put in place
Written with “shall” — not negotiableSelected through the Statement of Applicability (SoA)
The heart of the certification auditJustified (included/excluded) based on risk

Clauses 0 to 3 (introduction, references, terms and definitions) are part of the standard but contain no auditable requirements. The certifiable requirements start at clause 4.

The thread that ties it together: the PDCA cycle

The seven clauses are not an arbitrary list — they follow the Plan-Do-Check-Act (PDCA) continuous improvement logic shared by every ISO management-system standard. Understanding this cycle helps you see how the clauses connect, rather than memorizing them one by one.

Plan

Clauses 4–6

Understand your context, secure leadership commitment, and set objectives and risk treatment.

Do

Clauses 7–8

Provide resources and competence, then run the system day to day.

Check

Clause 9

Measure, audit internally, and review with leadership.

Act

Clause 10

Correct gaps and improve continuously.

The complete clause map

Every clause and sub-clause below links directly to its own page — no digging through menus. Use this as a standing table of contents for the whole standard.

Clause 4 · Context of the organization

Understand your context, your interested parties, and draw the boundaries of your ISMS.

Clause 5 · Leadership

Leadership commitment, the security policy, and assigned roles and authorities.

Clause 6 · Planning

Risk assessment and treatment, security objectives, and the Statement of Applicability.

Clause 7 · Support

Resources, competence, awareness, communication, and documented information.

Clause 8 · Operation

Running the ISMS day to day: operational control, and the recurring risk cycle.

Clause 9 · Performance evaluation

Monitoring and measurement, internal audit, and management review.

Clause 10 · Improvement

Continual improvement, and how nonconformities get corrected.

The 7 certifiable clauses, in plain language

Clause 4 · Context of the organization
Before building anything, you have to understand who you are, what surrounds you, and what your interested parties expect. This clause asks you to identify internal and external issues relevant to your information security, map the parties whose expectations matter (clients, regulators, shareholders), and use that understanding to draw the boundaries of your ISMS — which systems, sites, and services it actually covers. Read the full breakdown of clause 4 →
Clause 5 · Leadership
An ISMS that top management does not actively own is a documentation exercise, not a management system. This clause requires visible leadership commitment, a published information security policy, and clearly assigned roles and responsibilities — so accountability for security does not sit with a single person by default. Read the full breakdown of clause 5 →
Clause 6 · Planning
This is where risk assessment and treatment happen: identifying risks to your information assets, evaluating them, and deciding how to address them. It also covers setting measurable security objectives and producing the Statement of Applicability (SoA) — the document justifying which of the 93 Annex A controls you include or exclude, and why. Read the full breakdown of clause 6 →
Clause 7 · Support
The ISMS needs resources to run: people with the right competence, staff who are aware of their security responsibilities, a communication plan for security matters, and — crucially for the audit — properly controlled documented information (policies, procedures, records) that is current, approved, and accessible to the people who need it. Read the full breakdown of clause 7 →
Clause 8 · Operation
This is where planning turns into practice: executing the risk treatment plan, controlling operational changes so they do not introduce new gaps, and re-running risk assessments at planned intervals or when significant changes occur. It is the clause auditors use to check that the ISMS is actually operating, not just documented. Read the full breakdown of clause 8 →
Clause 9 · Performance evaluation
You have to prove the ISMS works, not just claim it does. This clause requires ongoing monitoring and measurement of security performance, a formal internal audit program covering the whole ISMS on a planned cycle, and a documented management review where leadership examines results and decides what needs to change. Internal audit findings here are usually the single best predictor of how the certification audit will go. Read the full breakdown of clause 9 →
Clause 10 · Improvement
When something does not conform — a control fails, an audit finds a gap, an incident exposes a weakness — this clause requires you to react, correct it, and address the root cause so it does not recur. Combined with clause 9, this is what makes the ISMS a living system rather than a one-time project: nonconformities get logged, treated, and closed, and the cycle starts again. Read the full breakdown of clause 10 →

The mandatory documents the clauses require

Certain clauses explicitly require documented information. An auditor will systematically ask for these. The main ones:

  • The ISMS scope (clause 4.3)
  • The information security policy (clause 5.2)
  • The risk assessment and treatment process (clause 6.1)
  • The Statement of Applicability — SoA (clause 6.1.3)
  • The information security objectives (clause 6.2)
  • Evidence of competence (clause 7.2)
  • Documented information necessary for operation (clause 8.1)
  • The results of risk assessment and treatment (clauses 8.2, 8.3)
  • Evidence of monitoring and measurement (clause 9.1)
  • The internal audit program and results (clause 9.2)
  • The results of management reviews (clause 9.3)
  • Nonconformities and corrective actions (clause 10.2)

How to use this guide

You are new to the standard

Read the clauses in order — they tell a story, from context (4) to improvement (10).

You are preparing for the audit

Focus on clause 9 (internal audit, management review) and the mandatory documents list above.

You came from Annex A

Remember that controls are worthless without the ISMS these clauses describe.

Frequently asked questions

What are the mandatory clauses of ISO 27001?
Clauses 4 through 10 contain the mandatory, auditable requirements. Clauses 0 to 3 (introduction, references, definitions) are part of the standard but are not auditable. Certification is therefore assessed against the seven clauses 4 to 10.
What is the difference between the clauses and Annex A?
Clauses 4 to 10 describe the management system (the ISMS) and are mandatory. Annex A is a catalogue of 93 security measures from which you choose the ones that address your risks, through the Statement of Applicability. Certification covers the clauses, not Annex A.
Can a clause be excluded?
No. Unlike Annex A controls, which can be excluded with justification, the requirements of clauses 4 through 10 are all mandatory. You cannot remove a clause from your scope.
What is the PDCA cycle in ISO 27001?
PDCA (Plan, Do, Check, Act) is the continuous-improvement logic that structures the standard: plan (clauses 4–6), do (7–8), check (9), and act (10).

Sentrix maintains a native ISO 27001:2022 framework mapped to all 93 Annex A controls today, and supports the certification journey described in the clauses above. See the full ISO 27001 framework page for how the platform automates evidence collection and cross-framework mapping.

From requirements to certification.

Understanding the clauses is the starting point; building a compliant ISMS and proving it at audit is the real work. Sentrix supports you from structuring the ISMS through to the certificate.