"Please send us your ISO 27002 certificate" is a request certification bodies receive regularly. No such document exists — and the reason is structural rather than bureaucratic: within the 27000 family, different numbers play different roles. Here is which of them a certificate is issued against, which they are not, and what an auditor actually looks at.
ISO 27001, the 27000 series and the rest: who does what
The numbering of the family is historical, so the order tells you nothing about relative importance. The roles break down as follows:
| Number | Subject | Certificate issued? |
|---|---|---|
| 27000 | Vocabulary and general overview of the family; the only document given away free of charge | no |
| 27001 | Requirements for an information security management system (ISMS) | yes |
| 27002 | Guidance on controls: the purpose of each one and implementation advice | no |
| 27003 | Guidance on building an ISMS | no |
| 27004 | Measurement and evaluation of performance | no |
| 27005 | Managing information security risks | no |
| 27006-1 | Requirements for bodies that audit ISMSs | no, bodies are accredited against it |
| 27017 and 27018 | Cloud controls and protection of personal data in public clouds | as an extension of the main certificate's scope |
| 27701 | Privacy information management (PIMS); standalone since October 2025 | yes |
The core information security standard ISO 27001 sets the requirements; the remaining numbers either explain them or serve the audit procedure itself.
Why the certificate is issued against 27001 only
The answer lies in the language of the documents. ISO 27001 uses "shall" — a requirement that must be met. ISO 27002 mostly uses "should": a recommendation, a way of doing something better.
An auditor works only with the first type. You cannot raise a nonconformity against a recommendation: a recommendation may legitimately be ignored, and no breach occurs. So only the requirements document can be assessed.
The second reason is structure. ISO 27001 contains clauses 4 to 10, each describing a mandatory part of the system: context, leadership, planning, support, operation, performance evaluation, improvement. None of them may be excluded. ISO 27002 has no such construction — it is a list of controls with explanations, not a system of requirements.
What the body examines: 27001 and 27002 in the same audit
In practice both documents sit on the auditor's desk, but their roles differ.
- The conclusion is drawn against 27001. Clauses 4 to 10 are examined, along with the Annex A controls the company retained in its Statement of Applicability (SoA).
- 27002 serves as a dictionary. When there is a disagreement about the purpose of a control, it settles the matter: it spells out what the control is meant to achieve.
- A nonconformity is always tied to 27001. The wording will cite a requirement clause or an SoA line, not a page of the guidance.
Three claims a certification body will not confirm
- "We are certified to ISO 27002." Guidance is not certified — this is either an error or a sheet of paper from a non-accredited company.
- "We are certified to the 27000 series." The family spans dozens of numbers with different roles; a conclusion is issued against a specific one, and it is always printed on the certificate.
- "We have implemented the requirements." Implementation is the company's internal business, evidenced by nothing more than its own documents. An independent assessment comes from a party that took no part in building the system.
One certificate, several control sets on the sheet
Cloud providers frequently hear the demand "give us 27017". No separate conclusion exists here: cloud controls are added to the scope of the main certificate, and a line about the extended control set appears on the sheet. There is a single audit as well — the sample simply includes a review of how responsibility is divided between the provider and its client.
ISO 27001 in brief: five lines
- It is a set of management system requirements, not a technical manual.
- The system is certified within its declared scope, not the company as a whole.
- Clauses 4 to 10 are mandatory; Annex A controls are selected against your own risks.
- The document is valid for three years, as long as annual surveillance audits take place.
- Only an accredited body can issue it.
A detailed look at the concept itself is in our article on ISO 27001 certification: what it is and who needs it.
What changed with 27701
Until recently, privacy management could only be confirmed as an extension of an existing ISMS. In the October 2025 edition, 27701 became standalone: an organisation can obtain a conclusion against it without holding a valid ISMS certificate. In parallel, 27706 appeared — requirements for bodies auditing privacy information management systems; it replaced the earlier technical specification.
Who checks the checkers
This is where 27006-1 comes in. The 2024 edition supplements the general rules of 17021-1 with requirements specific to bodies auditing ISMSs: auditor competence, calculation of audit duration, safeguarding impartiality, and the decision-making procedure.
ISO information security standards: what to ask a supplier for
When a counterparty announces that it meets security requirements, four things are worth clarifying:
- The number and the edition year. "Certified to 27001" without a year is no longer sufficient.
- The scope. Specific services and sites were examined, not the legal entity in general.
- The accreditation mark. A sheet without one comes from a non-accredited company.
- Validity. Surveillance audit dates or an entry in the certificate register.
If cloud services are involved, ask about 27017 and 27018: they extend the scope of the main document rather than replacing it.
Need advice on choosing the right number and setting the scope? Submit an enquiry — we will review your case and calculate the effort involved.