ISO/IEC 27001 Information Security Management Systems
ISO/IEC 27001 defines requirements for an information security management system: risk assessment, Annex A controls, internal audit, and management review. Certification comes through an accredited body via a two-stage audit, with annual surveillance on a three-year cycle. The 2022 revision replaced the 2013 edition, with transition required by October 2025.
Updated 2026-09-06 · 154 tracked updates
ISO 27001 is the international standard for information security management systems (ISMS). It provides a systematic approach to managing sensitive information through risk assessment, security controls, and continuous improvement.
Who Needs to Comply?
Any organization of any size, in any sector, that wants to establish, implement, maintain, and continually improve an information security management system. Widely adopted across technology, finance, healthcare, and government.
Key Dates & Timeline
Latest version ISO/IEC 27001:2022 published October 2022. Transition from 2013 version required by October 2025. Annex A controls aligned with ISO 27002:2022.
Upcoming Milestones
Deadline for public feedback on generative AI-enabled medical devices
FDA continues AI-enabled medical device guidance and submissions workflow updatesECB-requested comprehensive action plan for significant institutions
ESRB Warning on systemic cyber risks from frontier AI modelsArticle 5 prohibitions on realistic intimate synthetic content and CSAM-related AI practices apply
Digital Omnibus on AI amends the EU AI ActProviders of AI systems generating synthetic audio, image, video or text must comply with Article 50(2) marking steps if placed on market before 2 Aug 2026
Digital Omnibus on AI amends the EU AI ActLatest ISO 27001 Updates
ICO AI and data protection guidance remains active but under review
The ICO says its AI guidance supports audit and enforcement activity and is under review following the Data (Use and Access) Act 2025, so UK organizations should keep using it as the current baseline while planning for revisions.
Swiss FDPIC guidance on AI and data protection, plus legislative roadmap
The FDPIC has made clear that Switzerland’s data protection law already applies to AI-supported processing and that the federal government is targeting an AI bill by the end of 2026, so organizations should harden transparency and automated-decision controls now.
FDA AI-enabled medical device and PCCP guidance baseline
FDA’s August 2025 PCCP guidance provides recommendations for planned modifications to AI-enabled devices reviewed through the 510(k), De Novo and PMA pathways.
AICPA SOC 2 resources reaffirm current Trust Services Criteria for AI-enabled services
AICPA’s SOC resources confirm the current Trust Services Criteria baseline and do not create AI-specific rules, but they reinforce that AI-enabled services must still satisfy existing security, privacy, and processing integrity controls in audits.
NIST AI RMF revision and critical-infrastructure profile development
NIST says the AI RMF is being revised and that a new trustworthy-use profile for critical infrastructure is under development, while the baseline AI RMF 1.0 remains voluntary and headed for review no later than 2028.
ISO/IEC 42006:2025 defines requirements for AI management system certification bodies
ISO/IEC 42006:2025 supplements the requirements for bodies auditing and certifying AI management systems against ISO/IEC 42001; the ISO catalog records its publication in July 2025.
FINMA sets governance and risk-management expectations for AI use in Swiss financial institutions
FINMA’s 2024 guidance states that Swiss financial institutions using AI must identify, limit, control, and monitor AI-related risks within their existing supervisory framework, so firms should immediately test whether their governance and model-risk controls are adequate.
FDA continues AI-enabled medical device guidance and submissions workflow updates
FDA’s AI-enabled medical device materials show an active draft-guidance and feedback cycle, with public feedback on generative AI-enabled medical devices due by 2026-10-19, so device teams need to prepare submission and validation materials now.
ISO AI management-system and adjacent AI standards pipeline expands
ISO’s AI standards pages and draft items show an active pipeline around AI management systems, audit/certification, societal concerns, and privacy protection, so organizations pursuing ISO-based assurance should update their standards watchlist now.
NIST signals revision of AI RMF and new critical-infrastructure profile work
NIST’s AI RMF materials state that the framework is being revised and that a new critical-infrastructure trustworthy-AI profile was launched on 2026-04-07, so organizations relying on the RMF should track the revision now for shifting implementation guidance.
Jurisdiction Coverage
Related Frameworks
Key Topics
Frequently Asked Questions
What is ISO 27001 and how do you get certified?
ISO/IEC 27001 defines requirements for an information security management system: risk assessment, Annex A controls, internal audit, and management review. Certification comes through an accredited body via a two-stage audit, with annual surveillance on a three-year cycle. The 2022 revision replaced the 2013 edition, with transition required by October 2025.
What is ISO 27001?
ISO 27001 is the internationally recognized standard for information security management. It defines requirements for establishing, implementing, maintaining, and improving an ISMS, covering risk assessment, security controls, and continuous improvement processes.
How does ISO 27001 relate to AI compliance?
ISO 27001 provides the foundational information security framework that AI systems should operate within. It addresses data protection, access controls, and risk management — all critical for AI governance. Many organizations pursue ISO 27001 alongside ISO 42001 for comprehensive AI + security coverage.
What is the difference between ISO 27001 and ISO 42001?
ISO 27001 focuses on information security management broadly, while ISO 42001 specifically addresses AI management systems. ISO 42001 builds on ISO 27001's risk-based approach but adds AI-specific requirements for responsible AI development, deployment, and use.
Keep exploring
This hub tracks published actions that reference ISO 27001; it is not certification guidance from an accredited body and cannot substitute for a gap assessment.