Insights · 20 July 2026

ISO 27001 vs ISO 27002: what is the difference

Iso 27001 vs 27002: 2026 guidance on certifiable ISMS vs control catalogue; learn when to choose each and what the mappings mean for your organisation’s information security.

ISO 27001 vs 27002: ISO/IEC 27001 is the certifiable information security management system (ISMS) standard, while ISO/IEC 27002 is a non‑certifiable control catalogue that explains how to implement Annex A controls.

In the UK, the National Cyber Security Centre (NCSC) and GOV.UK guidance reference ISO/IEC 27002 for control mappings and implementation advice (GOV.UK). ENISA’s technical implementation guidance also provides mappings between risk management measures and control catalogues (ENISA, 2025).

  • What they are: ISO/IEC 27001 is a certifiable ISMS standard, ISO/IEC 27002 is a best-practice control catalogue and implementation guide.
  • When to choose 27001: Choose ISO/IEC 27001 for auditable, third-party assurance or when tenders specifically require certification.
  • When to use 27002: Use ISO/IEC 27002 for concrete how-to detail on controls and technical implementation.
  • Practical approach: Start with ISO/IEC 27001 for governance and use ISO/IEC 27002 in parallel to select and tune controls.

What is the quick difference between ISO 27001 and ISO 27002?

ISO/IEC 27001 is the certifiable information security management system standard, while ISO/IEC 27002 is a non‑certifiable control catalogue that explains how to implement the controls in Annex A. In short, ISO 27001 sets the requirements, ISO 27002 gives implementation guidance.

ISO 27001 vs 27002 is often asked by teams deciding whether to seek certification or simply adopt good practice; the difference matters for procurement, audits and board reporting.

ISO/IEC 27001 (what it is)

ISO/IEC 27001 is an auditable standard that requires an organisation to establish, implement, maintain and continually improve an information security management system (ISMS). Certification bodies assess conformity to ISO/IEC 27001 through Stage 1 and Stage 2 audits, and UK bodies map this to the UK’s Cyber Governance Code and related guidance on GOV.UK. Where contracts demand third‑party assurance, ISO/IEC 27001 is the recognised, certifiable option.

ISO/IEC 27002 (what it is)

ISO/IEC 27002 is a best‑practice catalogue of 93 controls offering practical implementation advice for the controls listed in Annex A of ISO/IEC 27001. ISO/IEC 27002 does not itself provide certification, but ENISA and other EU bodies use its guidance when producing technical mappings and implementation guidance, see ENISA, 2025.

When teams ask about iso 27001 vs 27002, the pragmatic answer is: choose ISO/IEC 27001 if you need auditable, certifiable assurance; use ISO/IEC 27002 when you need the how‑to detail for controls. For readiness guidance, see our What is ISO 27001? resource.

ISO/IEC 27001 gives you the framework and the certification route. ISO/IEC 27002 gives you the practical control guidance you implement under that framework.

Side-by-side comparison matrix: scope, pricing and UK fit

This matrix compares ISO/IEC 27001 and ISO/IEC 27002 across scope, certifiability, cost drivers and UK fit so you can see practical differences at a glance. Use ISO/IEC 27001 when you need an auditable Information Security Management System (ISMS), and use ISO/IEC 27002 for control-level guidance and implementation detail.

Dimension ISO/IEC 27001 ISO/IEC 27002
Scope Organisation-level ISMS, clauses 4 to 10 set mandatory requirements and continual improvement for managing information risk. Control catalogue and implementation guidance, offering descriptions and examples to help apply controls in Annex A of ISO/IEC 27001.
Certifiability Certifiable via UK Accreditation Service (UKAS) accredited bodies, providing third-party assurance and contractual evidence. Non-certifiable guidance, intended to inform control selection and implementation rather than act as a standalone certification.
Annex A relationship Requires organisations to consider Annex A controls and record applicability in a Statement of Applicability during risk treatment. Provides implementation guidance that aligns with many Annex A controls, but ISO/IEC 27002 does not replace Annex A or the 27001 risk process.
Cost drivers Consultancy, internal resource time, audit fees, and surveillance audits drive the bulk of certification costs. Primarily internal implementation time, training and tooling; no audit fees for ISO/IEC 27002 itself since it is guidance only.
UK fit Mapped to the UK Cyber Governance Code, widely accepted by UK buyers and public sector teams (GOV.UK, 2022). Recommended as practical control guidance and useful when mapping controls to the NCSC Cyber Assessment Framework (NCSC).

How to use this matrix

Start with ISO/IEC 27001 if you need auditable assurance or if tenders ask for certification. Use ISO/IEC 27002 in parallel to choose and interpret specific technical and organisational controls. For practical next steps, see our guide on "What Is ISO 27001?" and the Annex A control list for implementation notes (What is ISO 27001?, Annex A: all 93 ISO 27001:2022 controls).

ISO 27001 vs ISO 27002: what is the difference - supporting illustration

What does ISO 27001 require and who is it for?

ISO/IEC 27001 requires an organisation to establish, implement, maintain and continually improve an information security management system meeting Clauses 4 to 10, perform a documented risk assessment and risk treatment plan, and publish a Statement of Applicability; it is for organisations seeking auditable assurance.

Key Takeaway

ISO 27001 is the auditable management system standard; Clauses 4 to 10 set mandatory ISMS structure and records, while ISO 27002 helps you choose and implement controls from Annex A.

Mandatory ISMS clauses and core documents

Clause 4 to Clause 10 define what a certified ISMS must cover: context of the organisation, leadership, planning, support, operation, performance evaluation and improvement. Clause 6 requires a formal risk assessment and a risk treatment plan. The Statement of Applicability records which Annex A controls you apply and why. The mandated documents include the risk assessment, risk treatment plan, evidence of leadership commitment, scope statement and monitoring reports. For a practical checklist of auditor expectations see our ISO 27001 requirements page.

How ISO 27001 relates to ISO 27002 and Annex A

ISO/IEC 27002 is a guidance code not a certifiable standard, written to explain how to implement controls listed in Annex A of ISO/IEC 27001. Use ISO 27002 to turn a chosen Annex A control into procedures, technical configurations or supplier clauses. In procurement or tendering, ISO 27001 provides the auditable proof while ISO 27002 supplies the implementation detail, so the comparison iso 27001 vs 27002 is essentially certifiable system versus implementation guidance.

Certification process, sizes and who benefits

Certification involves a Stage 1 readiness review and a Stage 2 audit by an accredited body, followed by annual surveillance audits. Smaller organisations often achieve quicker time-to-certify when they scope narrowly and treat risk pragmatically. Larger or regulated firms need the full ISMS because it scales governance across multiple teams and suppliers. The UK government and ENISA reporting show growing alignment between national cyber governance and ISO practices, reflecting why many buyers still ask for ISO evidence in 2026: GOV.UK and ENISA offer useful mappings and certification statistics.

The phrase iso 27001 vs 27002 therefore guides two different choices: pick ISO 27001 when you need auditable assurance; use ISO 27002 when you need detailed control implementation guidance alongside the ISMS.

What does ISO 27002 cover and how does it map to Annex A?

ISO 27002 is the 2022 guidance catalogue that expands the 93 Annex A controls, giving implementation examples, control objectives and selection advice so organisations can justify which controls appear in their Statement of Applicability. ISO 27001 vs 27002 is therefore a comparison between a certifiable management system (ISO 27001) and non-certifiable implementation guidance (ISO 27002).

What ISO 27002 contains

ISO 27002 presents control descriptions, implementation guidance and examples across domains such as access management, asset control, cryptography, operations, supplier relationships and incident management. ISO 27002 maps each guidance item back to the 93 controls listed in Annex A of ISO/IEC 27001:2022, so auditors and implementers can see how a suggested control helps meet an Annex A requirement. In our experience, teams use ISO 27002 when they need clear implementation language for technical and organisational measures that auditors will inspect.

How mapping to Annex A works in practice

ISO 27002 offers suggested control objectives and practical measures, while Annex A provides the control catalogue that feeds an organisation’s risk treatment choices and Statement of Applicability. Practically, organisations perform a risk assessment under ISO 27001, select controls from Annex A, then consult ISO 27002 for implementation detail, evidence examples and tailoring advice. This flow is why you will often see both standards cited together in procurement and audit evidence.

Why ISO 27002 is not certifiable and how that matters

ISO 27002 is explicitly non-certifiable guidance, so certification bodies do not issue certificates for it. That matters because UK buyers and regulators will accept ISO 27001 certification as formal assurance, while ISO 27002 provides the implementation traceability auditors expect to find. For practical help mapping controls, see our Resources worth your time page which collects ISO, NCSC and UK guidance.

For further reading, the UK government published a managed service providers market study that includes mapping references and implementation notes (GOV.UK, 2025), and the Information Commissioner’s Office publishes annual reports that often reference standards mapping and governance approaches (ICO annual reports).

iso 27001 vs 27002 is therefore not a choice of either-or: ISO 27001 defines the auditable ISMS and selection process, Annex A lists the controls, and ISO 27002 explains how to implement those controls and demonstrate evidence in audits and tenders.

What are the strengths and weaknesses of ISO 27001 versus ISO 27002?

ISO 27001's strength is that it is a certifiable information security management system (ISMS) providing auditable governance and contractual assurance, while ISO 27002's strength is that it gives practical, non-certifiable guidance on how to implement controls.

ISO 27001 strengths

ISO/IEC 27001 provides a formal, auditable ISMS, which organisations can use to demonstrate compliance to customers, auditors and procurement teams. ISO 27001 ties governance to Clauses 4 to 10, requires a documented risk assessment and a Statement of Applicability, and supports third-party assurance in tenders. The standard is frequently mapped by UK government guidance, and the National Cyber Security Centre (NCSC) and other public bodies reference ISO 27001 when advising on governance and supplier assurance. For UK buyers and regulators, ISO 27001 certification often shortens procurement friction and gives legal and contractual value.

ISO 27001 weaknesses

ISO 27001 can be costly and resource intensive for smaller organisations, requiring documented processes, internal audits and surveillance audits. Certification can become checkbox-driven: organisations sometimes focus on passing audits rather than improving security outcomes. ISO 27001 also leaves control selection to the organisation, so the standard alone does not tell teams how to configure specific technical controls or run day-to-day operations. If you need practical implementation detail, ISO 27001 must be paired with guidance such as ISO 27002.

ISO 27002 strengths

ISO/IEC 27002 acts as a catalogue of control objectives and implementation advice that expands the Annex A controls in ISO 27001, making it easier to justify control choices in a Statement of Applicability. ISO 27002 helps security teams translate governance into configuration, processes and evidence that auditors and customers expect. The Information Commissioner's Office (ICO) and other advisory bodies point organisations to implementation guidance when explaining how to meet data protection accountability obligations, making ISO 27002 useful for teams seeking practical steps to meet UK GDPR expectations (ICO).

ISO 27002 weaknesses

ISO 27002 is not certifiable and so offers no independent assurance on its own. Without an ISMS context, ISO 27002 can be misinterpreted or applied inconsistently, particularly by teams new to risk assessment and control selection. The guidance does not replace the governance, management review and continual improvement requirements that ISO 27001 enforces. Where both governance and evidence are required, ISO 27002 must sit under an implemented ISMS.

In our experience, teams tackling an ISO 27001 vs 27002 decision should treat them as complementary: use ISO 27001 for auditable governance and ISO 27002 for the practical controls that make an ISMS effective. For a practical read on audit expectations and what assessors look for during certification, see our guide on the ISO 27001 audit process, and refer to the NCSC for mapping between guidance sources (NCSC).

What can ISO 27001 achieve for my organisation?

ISO/IEC 27001 can establish an auditable Information Security Management System (ISMS) that demonstrates governance, reduces risk exposure and supports UK regulatory and commercial requirements.

Business outcomes and commercial benefits

ISO/IEC 27001 helps buyers and regulators see you have a repeatable management system for information security, which often matters in procurement and regulated sectors such as financial services and health. The UK government maps the Cyber Governance Code to ISO/IEC 27001 to show how the standard supports corporate governance (GOV.UK, 2025). The National Cyber Security Centre provides guidance that links ISO standards to assessment frameworks, which auditors and assessors reference during reviews (NCSC, 2026).

Operational improvements and risk management

ISO/IEC 27001 gives a structured process to identify, assess and treat information risks, set measurable objectives and show continual improvement through internal audits and management review. Annex A provides control options organisations consider, while ISO/IEC 27002 supplies control-level guidance on how those controls can be implemented. Using both standards together reduces ambiguity when compiling a Statement of Applicability and collecting audit evidence.

When certification changes outcomes materially

Certification tends to make a material commercial difference when customers or regulators explicitly request ISO/IEC 27001, or where formal assurance shortens procurement steps. For practical preparation and evidence expectations, see our ISO 27001 checklist for UK organisations (ISO 27001 checklist) and our guide to the audit process, Stage 1 to Stage 2 (ISO 27001 audit process).

Practical takeaway

At CyPro, we recommend treating iso 27001 vs 27002 as complementary: ISO/IEC 27001 defines the management system and what must be achieved, ISO/IEC 27002 describes practical control implementations that make audits and procurement easier.

ISO 27001 vs ISO 27002: what is the difference - supporting illustration

How should I choose between ISO 27001 and ISO 27002 for my organisation?

Choose ISO 27001 when you need an auditable management system and third-party certification, and choose ISO 27002 when you need detailed control-level guidance to implement those controls. Both work together: ISO 27001 defines the Information Security Management System (ISMS), ISO 27002 explains which controls to apply and how.

In the ISO 27001 vs 27002 decision, boards and procurement typically weigh four factors: certification need, contractual obligations, internal capability to implement controls, and audit-readiness timeframes.

Certification, contracts and assurance

ISO/IEC 27001 provides the auditable standard buyers ask for in contracts and tenders, so choose ISO 27001 if clients or regulators require demonstrable certification. For UK public-sector contracting and supply chains where evidence of an auditable ISMS is requested, ISO/IEC 27001 certification remains the recognised route. The ISO 27001 vs 27002 split matters because ISO 27002 does not provide a certification path, it provides the practical guidance used to satisfy Annex A control expectations.

Implementation detail and day-to-day operations

ISO 27002 is the implementation handbook: it lists control objectives and gives implementation examples that security teams use when they select controls for the Statement of Applicability under ISO 27001. Organisations with a small security team or limited governance maturity should prioritise ISO 27002 guidance alongside ISO 27001 planning, because the extra detail reduces ambiguity during audit preparation and speeds evidence collection.

Practical recommendation and procurement points

Choose ISO 27001 if your primary goal is certification, supplier assurance and sales enablement. Choose ISO 27002 if you already have an ISMS mature enough to self-assess and you need control-level implementation detail. For most UK mid-market organisations, the practical route is to prepare for ISO 27001 certification and use ISO 27002 to pick and implement Annex A controls, which keeps audit costs down and shortens time-to-certification.

At CyPro, we advise procurement and boards to treat the ISO 27001 vs 27002 decision as complementary, not exclusive: list certification as the primary objective when contracts require it, and use ISO 27002 as the playbook for the technical team to implement controls and evidence them for auditors.

Further reading: ENISA provides mapping tools that help align controls to business needs, see ENISA, 2025, and the NCSC maintains collections linking ISO guidance to the Cyber Assessment Framework, see NCSC.

What are the next steps and resources to implement either standard?

Start with a gap assessment, assign an internal owner and produce a short project plan with milestones and budget estimates. For an ISO 27001 vs 27002 decision, treat ISO 27001 as the certifiable management system and ISO 27002 as the control implementation playbook.

Practical roadmap and timelines

Begin with a scoping workshop to agree the Statement of Applicability, scope boundaries and risk appetite, then run a gap assessment against ISO/IEC 27001:2022. Typical UK timelines are 3 to 9 months to certification for mid-market organisations depending on scope, resources and existing controls. Use ISO/IEC 27002 to map specific technical controls to gaps and to justify control choices to auditors and boards.

Who to involve internally and externally

Involve the Board, the Director of IT, the Data Protection Officer (DPO) and the Head of Operations early. Bring in an external consultant for the gap assessment and pre-audit readiness where internal resource is limited. Regulators and guidance bodies to reference include the UK National Cyber Security Centre (NCSC) and the UK Government mapping guidance to ISO 27001 for governance alignment (GOV.UK).

Typical cost drivers and what to ask consultants

Cost drivers are scope size, number of sites, cloud complexity and required evidence collection. Ask consultants for a priced breakdown: gap assessment, policy and procedure writing, staff awareness, technical control design from ISO 27002, and pre-audit support. Request three priced scenarios: minimal compliance, target posture, and accelerated certification. Our ISO 27001 audit page describes what auditors will expect and can help shape those scopes (ISO 27001 audit process).

For control implementation, use Annex A crosswalks and the ISO 27002 code of practice to translate management requirements into measurable tasks. In our experience, integrating ISO 27002 with existing IT change and asset management speeds evidence collection and keeps costs down.

Frequently asked questions

Can ISO 27001 achieve regulatory or contractual assurance for suppliers?

ISO 27001 certification provides independent assurance widely accepted by UK buyers and many regulators. ISO 27002 supports that assurance by explaining how Annex A controls are implemented. Ask suppliers for their Statement of Applicability and a recent audit report when validating claims, and verify certification with United Kingdom Accreditation Service (UKAS) or the issuing certification body.

Is ISO 27002 a replacement for ISO 27001?

ISO 27002 is not a replacement for ISO 27001, it is a guidance catalogue that elaborates the control set referenced in ISO 27001 Annex A. Use ISO 27002 to interpret and design specific controls, and when drafting control-level evidence for audits to show how Annex A controls are implemented in practice.

Do UK organisations need to buy both standards to comply?

You only need ISO 27001 for formal certification, but ISO 27002 is highly useful as a control implementation reference. Obtain ISO 27001 certification and use ISO 27002 to help implement Annex A controls. Purchase official copies and guidance from the British Standards Institution (BSI) or confirm accreditation and certification details via United Kingdom Accreditation Service (UKAS).

How does Annex A 2022's 93 controls affect small and mid-market firms?

Annex A:2022 contains 93 controls, but organisations must select applicable controls through a risk assessment. Many controls will not apply to small firms; the Statement of Applicability documents which controls are chosen and why. Use targeted guidance, such as the Annex A controls mapping, to prioritise controls that matter for your sector and size.

What should procurement ask for: ISO 27001 certificate or ISO 27002 mapping?

Ask procurement teams to request a current ISO 27001 certificate plus the supplier's Statement of Applicability, and a mapping to ISO 27002 where available. The certificate shows governance and certification scope, while the ISO 27002 mapping shows control implementation. Verify certificate validity with United Kingdom Accreditation Service (UKAS) or the issuing certification body.

3D rocket illustration for booking a free ISO 27001 scoping call

Take the first step

Get to ISO 27001 without the guesswork

Book a free 45 minute scoping call: where your ISMS stands today, what the UKAS audit will demand, and one fixed fee for getting there. No obligation, no hard sell.