ISO 27001:2022

ISO 27001:2022, without the eighteen-month slog

Run a real ISO 27001:2022 control test: GRXForce's AI Evidence Agent discovers and reviews the evidence and drafts the workpaper for all 93 Annex A controls, through Stage 1, Stage 2 and every surveillance audit after.

Overview

What is ISO 27001:2022?

ISO 27001:2022 defines the requirements for an Information Security Management System (ISMS). The 2022 revision restructured Annex A into 93 controls across four themes, organizational, people, physical, and technological, and certification runs on a three-year cycle: a Stage 1 documentation review, a Stage 2 certification audit, then annual surveillance audits.

Requirements

What it takes, at a glance

  • A scoped ISMS with a Statement of Applicability covering all 93 Annex A controls
  • Risk assessment and risk treatment methodology with documented decisions
  • Mandatory documents: security policy, asset inventory, incident procedures, and more
  • Internal audit and management review before your certification body arrives
  • Evidence that controls operate over time, not just that they exist on paper
Checklist

Your readiness checklist

  • Define ISMS scope and get leadership sign-off
  • Run a risk assessment and build the risk treatment plan
  • Write the Statement of Applicability against all 93 Annex A controls
  • Publish mandatory policies and assign control owners
  • Collect operating evidence for at least one full cycle before Stage 2
  • Complete an internal audit and management review
  • Book Stage 1 and Stage 2 audits with an accredited certification body
Implementation roadmap

How the timeline actually breaks down

Weeks 1-2Gap assessmentScore current state against all 93 controls, prioritize by risk and effort.
Weeks 3-10Build & implementPolicies, risk treatment, and control implementation, evidence collection starts immediately.
Weeks 11-13Internal auditIndependent internal audit and management review, fix findings before the real thing.
Weeks 14-20Stage 1 & 2Certification body reviews documentation, then tests operating effectiveness.
OngoingSurveillanceAnnual surveillance audits keep the certificate valid across the 3-year cycle.
Gap assessment

Where most programs actually stand

A proper ISO 27001 gap assessment scores every one of the 93 Annex A controls against your current state, not just the ones that are easy to answer. GRXForce's readiness score gives you that view in minutes, not weeks.

Check My ISO 27001 Readiness
Evidence

What auditors actually expect to see

  • Access review logs showing quarterly re-certification, not a one-time export
  • Change management tickets linked to the approvals that authorized them
  • Vulnerability scan results with remediation timestamps, not just the scan itself
  • Signed acknowledgment of the security policy from every employee, current year
  • Vendor due-diligence records for any supplier that touches in-scope data
Common mistakes

Where programs like yours lose time

  • Treating the Statement of Applicability as a one-time document instead of a living map to real controls
  • Writing policies that describe an aspirational process nobody actually follows
  • Starting evidence collection the month before Stage 2 instead of from day one
  • Scoping the ISMS too broadly, which multiplies the audit's cost and duration for no benefit
  • Treating certification as a finish line instead of the start of the surveillance cycle
Compare frameworks

How ISO 27001:2022 compares

FrameworkTypeTypical timelineRenewalBest for
ISO 27001:2022Certification6-12 months typical3-year cycle + annual surveillanceAny company selling globally, especially outside the US
SOC 2 Type IIAttestation (CPA report)3-12 month observation windowAnnual Type II reportSaaS companies selling to US enterprise customers
GDPRRegulationOngoing, no certificateContinuousAnyone processing EU residents' personal data
DPDPA 2023RegulationOngoing, no certificateContinuousAnyone processing Indian residents' digital personal data
HITRUST CSFCertification6-18 months by tier1-2 year cycle by tierHealthcare and health-tech handling PHI
NIST CSFVoluntary frameworkOngoing, self-assessedContinuousUS federal contractors and critical infrastructure
PCI DSSIndustry mandate3-6 months typicalAnnual (ROC or SAQ)Anyone storing, processing or transmitting card data
SOX ITGCRegulatory (internal controls)Ongoing, tested annuallyAnnual audit cycleUS public companies and their auditors
HIPAARegulationOngoing, no certificateContinuousUS healthcare providers, payers and business associates
Two ways to get there

Run it yourself, or hand us the programme

Run it yourself, the platform Controls pre-mapped to ISO 27001:2022, an AI Evidence Agent that discovers and reviews evidence and drafts the workpaper for every control, and a human sign-off trail your auditor can inspect line by line. Explore the platform →
Hand it over, managed services A named compliance lead runs your entire ISO 27001:2022 programme: gap analysis, policies, evidence, auditor liaison, and surveillance after the milestone. Get it handled →

See exactly how GRXForce runs an ISO 27001:2022 control test: the AI Evidence Agent discovers and reviews the evidence and drafts the workpaper, you make the final call.

See It Run in the Audit Engine →
FAQ

Frequently asked

How long does ISO 27001:2022 certification take?

It depends on your starting maturity and scope. With controls mapped from day one and evidence collection automated, most of the calendar time goes to controls operating long enough to generate evidence, GRXForce compresses everything around that.

What changed from ISO 27001:2013 to 2022?

Annex A was restructured from 114 controls in 14 domains to 93 controls in 4 themes, with 11 new controls covering areas like threat intelligence, cloud security, and data leakage prevention. Transition deadlines for existing certificates have now passed, so new audits run against 2022.

Do I need a consultant or can the platform alone get me certified?

Either path works, that's the point of GRXForce. Teams with compliance staff run the platform themselves; teams without hand the whole program to our managed service, including auditor liaison.

Also covered: SOC 2 Type II GDPR DPDPA 2023 HITRUST CSF NIST CSF PCI DSS SOX ITGC HIPAA

Find My Gaps

3 minutes. No sales pitch. Get a preliminary ISO 27001:2022 readiness score.