If you have typed ISO 27001 vs ISO 27002 into a search box this week, you are almost certainly staring at two line items in a standards-body shopping cart and wondering which one your auditor actually cares about. The honest answer is that they do different jobs: you get certified against one of them, and you read the other one to work out how.
Both documents were rewritten in 2022 and both are in force in 2026. Both describe the same 93 information security controls. But one is 19 pages long and legally testable, and the other is 152 pages long and cannot be certified at all. Teams that misunderstand the ISO 27001 vs ISO 27002 split either buy the wrong document, or spend three months writing policies against guidance that no auditor will ever ask to see.
ISO 27001 vs ISO 27002: The Short Answer
ISO/IEC 27001:2022 is the requirements standard. It tells you what an information security management system (ISMS) must contain, and it is the document a certification body audits you against. It was published on 25 October 2022 as Edition 3 and runs to 19 pages.
ISO/IEC 27002:2022 is the code of practice. It takes each of the 93 controls listed in ISO 27001 Annex A and expands it into purpose, implementation guidance, and other information. It was published earlier, on 15 February 2022, and runs to 152 pages. You cannot be certified against it, and no auditor will issue you a nonconformity for departing from it.
The clearest way to hold ISO 27001 vs ISO 27002 in your head: ISO 27001 is the exam paper, ISO 27002 is the textbook. Most organizations building an ISMS need both, and the ones that skip the textbook usually discover why at Stage 2.
ISO 27001 vs ISO 27002: A Side-by-Side Comparison
The table below sets out the practical ISO 27001 vs ISO 27002 differences. Prices are the ISO webstore list prices in Swiss francs at the time of writing and change periodically; national standards bodies such as ANSI or BSI resell the same text at different rates.
| Factor | ISO/IEC 27001:2022 | ISO/IEC 27002:2022 |
|---|---|---|
| Document type | Requirements standard | Code of practice / guidance |
| Published | 25 October 2022 (Edition 3) | 15 February 2022 (Edition 3, corrected March 2022) |
| Length | 19 pages | 152 pages |
| Certifiable? | Yes — accredited certification bodies audit against it | No — guidance only |
| Contains “shall” requirements? | Yes, in clauses 4 to 10 | No, it uses “should” |
| Control detail | Annex A: 93 control titles, roughly one line each | Clauses 5 to 8: the same 93 controls, several paragraphs each |
| Control attributes | Not included | Five attribute types per control (informative) |
| Amendments | Amd 1:2024 climate action changes (free of charge) | None |
| List price (ISO webstore) | CHF 155 | CHF 227 |
| Who needs it | Anyone certifying, and anyone being audited | Whoever has to actually build the controls |
What ISO 27001 Actually Requires
Nineteen pages sounds thin for a standard that underpins tens of thousands of certificates worldwide. It is thin because it is deliberately outcome-based. The auditable body of ISO 27001 sits in clauses 4 through 10, and it asks you to do a small number of things properly:
- Clause 4 — define the context of the organization and, critically, the ISMS scope. A vague scope statement is the single most common reason a Stage 1 audit goes badly.
- Clause 5 — demonstrate leadership, assign responsibilities, and publish an information security policy.
- Clause 6 — plan. This is where the risk assessment and risk treatment process live, and where clause 6.1.3 makes the Statement of Applicability a mandatory document. There is no version of ISO 27001 certification without an SoA.
- Clause 7 — resources, competence, awareness, and documented information.
- Clause 8 — operate the processes you planned.
- Clause 9 — monitor, measure, run internal audits, and hold a management review.
- Clause 10 — handle nonconformities and improve continually.
Annex A then lists the 93 controls by reference number and title only. It gives you the name of the control and almost nothing else. That is the gap ISO 27002 exists to fill, and it is the whole reason the ISO 27001 vs ISO 27002 question comes up in the first place.
One recent addition worth flagging: ISO/IEC 27001:2022/Amd 1:2024 added climate action changes, requiring organizations to determine whether climate change is a relevant issue under clause 4.1. It does not force you to conclude that it is — it forces you to consider the question and record your determination. ISO distributes the amendment free of charge. There is no equivalent amendment to ISO 27002.
What ISO 27002 Adds: 152 Pages of How
ISO 27002 takes every control in Annex A and rebuilds it in a consistent structure: a control statement, its purpose, detailed implementation guidance, and other information such as related standards. Where ISO 27001 says “threat intelligence,” ISO 27002 explains what strategic, tactical, and operational threat intelligence look like and how to feed them into your risk process.
Two features tip the ISO 27001 vs ISO 27002 balance toward owning both during implementation:
- Attributes. Each control is tagged with five attribute types — control type (preventive, detective, corrective), information security properties (confidentiality, integrity, availability), cybersecurity concepts (identify, protect, detect, respond, recover), operational capabilities, and security domains. These are informative, not mandatory, but they let you filter 93 controls into a view that matches how your team is organized. If your board reports against the NIST Cybersecurity Framework, the cybersecurity-concepts attribute maps your ISO work onto that language almost for free.
- The 2013 mapping. ISO 27002 includes tables mapping the 2022 control numbers back to the 114 controls of the 2013 edition. If you are inheriting documentation written before the transition period closed on 31 October 2025, this is how you find out which of your old policies still have a home.
What ISO 27002 does not do is impose obligations. It is written in “should,” not “shall.” An auditor can note that you departed from ISO 27002 guidance, but the finding has to be raised against an ISO 27001 requirement or against your own documented controls — not against ISO 27002 itself.
The 93 Controls Both Standards Share
This is the part that surprises people: the control set is identical in both documents. The 2022 revision consolidated the old 114 controls into 93 across four themes, adding 11 genuinely new ones.
| Theme | Clause in ISO 27002 | Number of controls |
|---|---|---|
| Organizational | 5 | 37 |
| People | 6 | 8 |
| Physical | 7 | 14 |
| Technological | 8 | 34 |
| Total | 93 |
The 11 new controls introduced in 2022 are threat intelligence (5.7), information security for use of cloud services (5.23), ICT readiness for business continuity (5.30), physical security monitoring (7.4), configuration management (8.9), information deletion (8.10), data masking (8.11), data leakage prevention (8.12), monitoring activities (8.16), web filtering (8.23), and secure coding (8.28). We cover the full set in our guide to the ISO 27001:2022 Annex A controls.
ISO 27001 vs ISO 27002: Which One Should You Buy?
Budget usually decides the ISO 27001 vs ISO 27002 question, so here is the practical guidance an auditor would give you rather than the diplomatic one.
- Pursuing certification? Buy ISO 27001. It is not optional. You cannot write a Statement of Applicability, plan an internal audit, or brief your certification body from a summary blog post — including this one.
- Implementing controls in-house with a small team? Buy both. The 152 pages of ISO 27002 will save you more consulting hours than the CHF 227 costs, particularly on the 11 controls that did not exist before 2022 and for which your team has no precedent.
- Working with an experienced consultant or a mature template set? ISO 27001 alone may be enough, because your implementation guidance is arriving through another channel. Buy ISO 27002 later if your team keeps asking “but what does good look like for this control?”
- Not certifying at all, just improving security? ISO 27002 on its own is a defensible purchase. Plenty of organizations adopt the control set as a maturity benchmark without ever engaging a certification body.
Whichever way you go, remember that neither document contains a single template. ISO tells you what to achieve and, in ISO 27002, roughly how — it does not give you an asset register, an access control policy, or a risk treatment plan. That drafting work is yours. Our ISO 27001 Toolkit covers it with 162 editable templates mapped to the 2022 clauses and Annex A controls for $99, which is the shortcut most small teams take rather than starting from a blank page.
Four Mistakes Auditors See Around ISO 27001 vs ISO 27002
After enough audits, the same misunderstandings surface in the same order.
- Claiming ISO 27002 certification. It does not exist. If a supplier’s security questionnaire says “ISO 27002 certified,” either they mean ISO 27001 or the claim is worthless. Ask for the certificate and check the accreditation mark.
- Treating ISO 27002 guidance as mandatory. Implementing all 93 controls to the letter of ISO 27002 regardless of your risk assessment is expensive and, ironically, non-conformant. ISO 27001 requires controls justified by risk, and clause 6.1.3 lets you exclude controls with documented justification.
- Writing the Statement of Applicability from ISO 27002. The SoA must trace to Annex A of ISO 27001. Using ISO 27002 clause numbering is fine because the numbers align, but the SoA has to state necessity, implementation status, and justification for each control — none of which ISO 27002 supplies.
- Buying the 2013 editions second-hand. They are withdrawn. The transition window closed on 31 October 2025, and certificates issued against the 2013 text are no longer valid. If a PDF you were handed says 114 controls, it is out of date.
If any of that sounds like your current documentation, a structured ISO 27001 gap analysis is a cheaper way to find out than a Stage 1 audit is.
ISO 27001 vs ISO 27002 FAQ
Can I get certified to ISO 27002?
No. ISO/IEC 27002 is a code of practice and contains no auditable requirements. Organizations certify to ISO/IEC 27001, which references the same control set. Individuals can hold ISO 27002-related training certificates, which is a different thing and is sometimes the source of the confusion.
Do the control numbers match between the two standards?
Yes. Control 8.28 in ISO 27002 is control 8.28 in ISO 27001 Annex A. The 2022 revision deliberately aligned the numbering so that a Statement of Applicability and an implementation plan can share references without a translation layer.
Do I need ISO 27002 if I already own ISO 27001?
You are not required to. Annex A is legally sufficient for certification. In practice, teams implementing controls without prior experience find Annex A’s one-line control titles too thin to build against, and buy ISO 27002 within the first two months anyway.
Is ISO 27002 being revised?
As of August 2026, ISO/IEC 27002:2022 remains at publication stage 60.60 with no amendment and no revision published. ISO/IEC 27001:2022 carries one amendment, Amd 1:2024 on climate action. Check the ISO catalogue entries directly before making a purchase, since stage codes change without announcement.
What about ISO 27005, 27017 and 27701?
They are companions, not alternatives. ISO/IEC 27005 covers information security risk management, ISO/IEC 27017 adds cloud-specific control guidance, and ISO/IEC 27701 extends an existing ISO 27001 ISMS into privacy information management. None of them replaces the ISO 27001 vs ISO 27002 pairing at the core of the 27000 family.
The Bottom Line
The ISO 27001 vs ISO 27002 distinction is simpler than the search results suggest. ISO 27001 is the 19-page requirements standard you are certified against; ISO 27002 is the 152-page guidance document that explains how to satisfy the controls ISO 27001 only names. They share 93 controls and identical numbering, and the vast majority of teams building an ISMS from scratch benefit from having both on the desk.
You can verify both documents’ current status, editions and pricing directly on the ISO catalogue: ISO/IEC 27001:2022 and ISO/IEC 27002:2022. If you are ready to move from reading standards to producing evidence, our guide to ISO 27001 certification walks through the full path from scoping to Stage 2.