ISO/IEC 27001 Information Security Management Systems

ISO/IEC 27001 defines requirements for an information security management system: risk assessment, Annex A controls, internal audit, and management review. Certification comes through an accredited body via a two-stage audit, with annual surveillance on a three-year cycle. The 2022 revision replaced the 2013 edition, with transition required by October 2025.

Updated 2026-09-06 · 154 tracked updates

ISO 27001 is the international standard for information security management systems (ISMS). It provides a systematic approach to managing sensitive information through risk assessment, security controls, and continuous improvement.

154
Regulations Tracked
11
Jurisdictions
10
Upcoming Milestones
2026-09-06
Last Updated

Who Needs to Comply?

Any organization of any size, in any sector, that wants to establish, implement, maintain, and continually improve an information security management system. Widely adopted across technology, finance, healthcare, and government.

Key Dates & Timeline

Latest version ISO/IEC 27001:2022 published October 2022. Transition from 2013 version required by October 2025. Annex A controls aligned with ISO 27002:2022.

Upcoming Milestones

2026-10-19

Deadline for public feedback on generative AI-enabled medical devices

FDA continues AI-enabled medical device guidance and submissions workflow updates
2026-10-31

ECB-requested comprehensive action plan for significant institutions

ESRB Warning on systemic cyber risks from frontier AI models
2026-12-02

Article 5 prohibitions on realistic intimate synthetic content and CSAM-related AI practices apply

Digital Omnibus on AI amends the EU AI Act
2026-12-02

Providers of AI systems generating synthetic audio, image, video or text must comply with Article 50(2) marking steps if placed on market before 2 Aug 2026

Digital Omnibus on AI amends the EU AI Act

Latest ISO 27001 Updates

guidancemedium2026-09-06

ICO AI and data protection guidance remains active but under review

The ICO says its AI guidance supports audit and enforcement activity and is under review following the Data (Use and Access) Act 2025, so UK organizations should keep using it as the current baseline while planning for revisions.

guidancehigh2026-09-06

Swiss FDPIC guidance on AI and data protection, plus legislative roadmap

The FDPIC has made clear that Switzerland’s data protection law already applies to AI-supported processing and that the federal government is targeting an AI bill by the end of 2026, so organizations should harden transparency and automated-decision controls now.

guidancehigh2026-09-06

FDA AI-enabled medical device and PCCP guidance baseline

FDA’s August 2025 PCCP guidance provides recommendations for planned modifications to AI-enabled devices reviewed through the 510(k), De Novo and PMA pathways.

guidancemedium2026-09-06

AICPA SOC 2 resources reaffirm current Trust Services Criteria for AI-enabled services

AICPA’s SOC resources confirm the current Trust Services Criteria baseline and do not create AI-specific rules, but they reinforce that AI-enabled services must still satisfy existing security, privacy, and processing integrity controls in audits.

guidancehigh2026-09-06

NIST AI RMF revision and critical-infrastructure profile development

NIST says the AI RMF is being revised and that a new trustworthy-use profile for critical infrastructure is under development, while the baseline AI RMF 1.0 remains voluntary and headed for review no later than 2028.

guidancehigh2026-09-06

ISO/IEC 42006:2025 defines requirements for AI management system certification bodies

ISO/IEC 42006:2025 supplements the requirements for bodies auditing and certifying AI management systems against ISO/IEC 42001; the ISO catalog records its publication in July 2025.

guidancehigh2026-08-30

FINMA sets governance and risk-management expectations for AI use in Swiss financial institutions

FINMA’s 2024 guidance states that Swiss financial institutions using AI must identify, limit, control, and monitor AI-related risks within their existing supervisory framework, so firms should immediately test whether their governance and model-risk controls are adequate.

guidancehigh2026-08-30

FDA continues AI-enabled medical device guidance and submissions workflow updates

FDA’s AI-enabled medical device materials show an active draft-guidance and feedback cycle, with public feedback on generative AI-enabled medical devices due by 2026-10-19, so device teams need to prepare submission and validation materials now.

guidancemedium2026-08-30

ISO AI management-system and adjacent AI standards pipeline expands

ISO’s AI standards pages and draft items show an active pipeline around AI management systems, audit/certification, societal concerns, and privacy protection, so organizations pursuing ISO-based assurance should update their standards watchlist now.

guidancemedium2026-08-30

NIST signals revision of AI RMF and new critical-infrastructure profile work

NIST’s AI RMF materials state that the framework is being revised and that a new critical-infrastructure trustworthy-AI profile was launched on 2026-04-07, so organizations relying on the RMF should track the revision now for shifting implementation guidance.

Jurisdiction Coverage

Related Frameworks

Key Topics

Frequently Asked Questions

What is ISO 27001 and how do you get certified?

ISO/IEC 27001 defines requirements for an information security management system: risk assessment, Annex A controls, internal audit, and management review. Certification comes through an accredited body via a two-stage audit, with annual surveillance on a three-year cycle. The 2022 revision replaced the 2013 edition, with transition required by October 2025.

What is ISO 27001?

ISO 27001 is the internationally recognized standard for information security management. It defines requirements for establishing, implementing, maintaining, and improving an ISMS, covering risk assessment, security controls, and continuous improvement processes.

How does ISO 27001 relate to AI compliance?

ISO 27001 provides the foundational information security framework that AI systems should operate within. It addresses data protection, access controls, and risk management — all critical for AI governance. Many organizations pursue ISO 27001 alongside ISO 42001 for comprehensive AI + security coverage.

What is the difference between ISO 27001 and ISO 42001?

ISO 27001 focuses on information security management broadly, while ISO 42001 specifically addresses AI management systems. ISO 42001 builds on ISO 27001's risk-based approach but adds AI-specific requirements for responsible AI development, deployment, and use.

Keep exploring

This hub tracks published actions that reference ISO 27001; it is not certification guidance from an accredited body and cannot substitute for a gap assessment.