Skip to content
Resource Library
Compliance 7 min read

ISO 27001 in plain English

The Statement of Applicability, Annex A controls, and how to scope your ISMS without drowning your team in paperwork.

What ISO 27001 actually certifies

ISO 27001 certifies a management system, not a security posture. That distinction confuses everyone at first. The standard doesn't say "you must encrypt X" or "you must patch within Y days." It says: you must have a functioning system — an ISMS, or Information Security Management System — for identifying risks, deciding what to do about them, doing it, and checking that it worked. The controls are the output of that system, not the starting point.

Practically, ISO 27001 matters when you sell into Europe, into regulated industries, or into any organization whose procurement checklist was written by someone who prefers ISO to SOC2. Many companies end up holding both; the underlying work overlaps heavily, so sequencing them is cheaper than treating them as separate projects.

The Statement of Applicability, demystified

The Statement of Applicability (SoA) is the document auditors reach for first. It lists every control in Annex A — 93 controls in the 2022 revision, organized into Organizational, People, Physical, and Technological themes — and for each one states whether it applies to you, why, and how you implement it. Excluding a control is allowed; excluding it without a defensible reason is not.

The SoA is where scoping discipline pays off. A ten-person SaaS company with no office and no on-prem servers can justify trimming physical controls substantially — but must show the reasoning. Write the justification for the company you actually are, and the SoA becomes a manageable document instead of a 93-row guilt trip.

Scoping the ISMS without drowning

Scope is the single biggest lever on effort. The ISMS covers what you say it covers: which systems, which teams, which locations. First-time certifications go smoothest when scope wraps the product and the infrastructure that runs it, plus the corporate identity and endpoint layer — and stops there. Every system in scope needs an owner, a risk assessment, and evidence; every system out of scope needs a boundary you can articulate.

The recurring machinery matters more than the binder: a risk register you actually revisit, internal audits on a schedule, management reviews with minutes, and corrective actions that close. Certification bodies audit in a cycle — a two-stage initial audit, then surveillance audits annually — so the system has to keep running after the certificate arrives.

Where the paperwork can be generated instead of written

A large fraction of ISO 27001 evidence is a description of your environment: what assets exist, who has access, what risks are open, what got fixed and when. If your inventory, identity data, and findings live in one place and stay current, the documents can be generated from reality instead of drafted from memory — and regenerated when reality changes, which is exactly what surveillance audits check for.

Cybermatic maintains that live picture — assets from your clouds, agents, and connected tools; identities with MFA and privilege data; findings tracked to resolution — and generates ISO 27001 documentation from it. Your team still owns decisions and approvals. It just stops owning the transcription.

Security Essentials, Weekly

A practical weekly briefing on real-world security misconfigurations, why they matter, and how to fix them.

One email a week, unsubscribe any time. We use your address only to send the briefing — see our Privacy Policy.