ISO/IEC 27001:2022 explained: from scope to Statement of Applicability
Jun 2026 · 8 min read
ISO/IEC 27001 is the international standard for an Information Security Management System (ISMS). Certification signals to customers, regulators and partners that an organization manages information security systematically rather than ad hoc. The 2022 revision refreshed the control set and is now the version organizations certify against.
Two halves: the clauses and Annex A
The standard has two parts. Clauses 4–10 define the management system itself — understanding context and interested parties, setting scope, leadership, risk assessment and treatment, support, operation, performance evaluation and continual improvement.
Annex A then lists 93 controls grouped into four themes: Organizational (37), People (8), Physical (14) and Technological (34). Controls are selected based on risk — not every control applies to every organization.
The Statement of Applicability
The Statement of Applicability (SoA) is the keystone document. For each Annex A control it records whether the control is applicable, the justification for inclusion or exclusion, and its implementation status.
Auditors live in the SoA. A clear, well-justified SoA — backed by evidence for each applicable control — is the difference between a smooth certification and a painful one.
How it complements regional regimes
ISO 27001 maps cleanly onto frameworks like NCA-ECC and supports privacy obligations under PDPL: access control, cryptography, logging, supplier security and incident management all recur. Organizations that run ISO 27001 alongside their regional obligations capture evidence once and reuse it.
Always confirm the certification scope and current control set with your certification body, as accredited requirements are periodically updated.
This article is general guidance, not legal advice. Regulations evolve — confirm current requirements with the relevant authority (NCA / SDAIA in KSA; DESC / the UAE Data Office in the UAE). Questions? info@grclens.net.
Keep reading
Cyber governance in the Gulf: how KSA and the UAE set the pace
A regional map of the regulators and frameworks shaping cybersecurity governance across Saudi Arabia and the UAE — and what they have in common.
Security assurance in Saudi Arabia: making NCA-ECC stick
Implementing the Essential Cybersecurity Controls is only half the job. Sustaining assurance — proving controls keep working — is where programs succeed or fail.
Cyber governance in Dubai: DESC ISR and the UAE IA Standards
Dubai government entities and their suppliers operate under the DESC Information Security Regulation. Here's how it connects to the wider UAE assurance landscape.