Skip to content
Radcore Security

ISO 27001

Get the Annex A controls your buyers outside the US ask for first.

ISO/IEC 27001:2022 is certified by an accredited body, not self-attested. Here's what's actually in it, what we build, and how it relates to SOC 2.

What ISO/IEC 27001:2022 is

ISO/IEC 27001:2022 is an international standard for an information security management system, not a one-time checklist, but a documented, ongoing process for identifying risk and running the controls that address it. Certification is issued by an accredited certification body after an independent audit, not by Radcore. We build the management system and prepare the evidence; the certification body examines it and decides.

At the center of the standard is Annex A: 93 controls organized into four themes. You don't implement all 93 blindly; you assess which apply to your business and document that decision in a Statement of Applicability, the single artifact an auditor will spend the most time reading.

Annex A's four themes

Organizational

Policies, roles, supplier and asset management: the paperwork that has to exist.

People

Screening, training, responsibilities that survive someone leaving the team.

Physical

Equipment, media, and site controls: lighter-weight for a fully remote SaaS team.

Technological

Access control, cryptography, logging, vulnerability management: most of the actual work.

Stage 1, Stage 2, and the three-year cycle

Certification runs in two audit stages, then renews on a cycle. This isn't a one-and-done credential.

Stage 1

Documentation review by the certification body

Stage 2

Evidence the controls actually operate

3 yrs

Certification cycle, with annual surveillance audits

Where this overlaps SOC 2, and where it doesn't

The overlap with SOC 2 is large: access control, logging, vendor management, and incident response cover most of the same ground under both frameworks. That's a real reason to pursue both rather than treating a second framework as double the work: most of what you build for one carries directly into the other.

Where they diverge: ISO/IEC 27001:2022 requires the formal risk-assessment methodology and Statement of Applicability that SOC 2 doesn't ask for, and it's certified by an accredited body on a three-year cycle rather than re-attested annually. If your buyers are mostly US-based, SOC 2 usually comes first; if international or EU-heavy prospects are asking, lead with this one.

Find out which gaps are actually blocking your report.

Book a gap review

Thirty minutes with Luke, our security lead. No charge.