One is the certifiable standard, the other is the control guidance. Here is how ISO 27001 and ISO 27002 fit together.
ISO 27001 is the certifiable standard: it specifies the requirements for an information security management system, or ISMS, and lists the Annex A controls, and it is the document you can be audited and certified against. ISO 27002 is a guidance document that explains how to implement each of those controls in depth, and you cannot certify to it. Put simply, you get certified to ISO 27001, and you use ISO 27002 as the how-to manual. Here is how the two relate and why you generally use both.
ISO 27001 is the international standard that sets out the requirements for establishing, operating and continually improving an information security management system. It covers the management system itself, such as risk assessment, leadership, objectives and internal audit, and it includes Annex A, which lists the security controls. ISO 27001 is the standard a certification body audits you against, and passing that audit is what earns your ISO 27001 certificate. The current version is ISO 27001:2022.
ISO 27002 is a guidance standard that describes each information security control in detail, with implementation advice and considerations. It uses the same control set as ISO 27001 Annex A, but instead of simply listing the controls it explains what each one means, how to implement it and what to watch for. ISO 27002 is a reference you consult while building your controls; it is not something you get certified against, because it contains guidance rather than auditable requirements.
The core difference between ISO 27001 and ISO 27002 is that ISO 27001 is certifiable and ISO 27002 is not. ISO 27001 states the requirements you must meet and lists the Annex A controls; ISO 27002 provides the detailed guidance on how to implement those controls well. ISO 27001 tells you what; ISO 27002 tells you how. They share the same control set, which is why they are used together rather than being alternatives to each other.
In the 2022 revision, ISO 27001 Annex A and ISO 27002 were aligned around the same 93 controls, organised into four themes: organisational, people, physical and technological. ISO 27001:2022 lists those 93 controls, reduced from 114 in the 2013 version, and introduces 11 new controls covering areas such as threat intelligence, cloud security and secure coding. ISO 27002:2022 describes each of the same 93 controls in depth. So the standards moved in step, and using them together in their 2022 form keeps your control language consistent.
In practice you use both, but you only certify to ISO 27001. You need ISO 27001 because it defines the requirements and is the basis of certification. You reach for ISO 27002 when you want a fuller explanation of how to implement a particular control, since Annex A states each control briefly. A small team can get certified to ISO 27001 without buying a copy of ISO 27002, but the guidance is useful when a control is unfamiliar. Neither replaces the other.
CertAssist lays out the ISO 27001:2022 requirements and all 93 Annex A controls on a clear board, with editable policy and evidence templates and a Statement of Applicability handled, so you can work toward certification without starting from a blank page. Because CertAssist encodes the current control set, you are working from the aligned 2022 structure rather than the older 2013 layout. The certification audit is performed by an independent certification body, but organising the ISMS and its evidence is most of the effort, and that is what CertAssist provides for a published US$225 per month during its launch.
An easy way to remember the difference is that ISO 27001 is the exam and ISO 27002 is the textbook. You sit the exam, ISO 27001, and earn the certificate; you read the textbook, ISO 27002, to understand the material. A certification body only marks the exam, so it audits you against ISO 27001, never ISO 27002. When someone says they are working toward their ISO certification, they mean ISO 27001, even if they lean on ISO 27002 for the detail on a tricky control. Keeping that framing clear saves a lot of confusion in early ISMS planning, because teams sometimes assume the two documents are competing standards when they are two halves of the same system: one auditable, one explanatory.
No. You cannot certify to ISO 27002, because it is a guidance document that explains how to implement controls rather than a set of auditable requirements. Certification is against ISO 27001, which specifies the ISMS requirements and lists the Annex A controls. ISO 27002 is used as a reference while you build those controls.
ISO 27001 is the certifiable standard that states the requirements for an information security management system and lists the Annex A controls. ISO 27002 gives detailed implementation guidance for the same controls but is not certifiable. In short, ISO 27001 tells you what to do and ISO 27002 tells you how to do it.
You certify only to ISO 27001, so it is the one you must work to. ISO 27002 is a helpful reference when you want a fuller explanation of a particular control, since Annex A lists each control briefly. A small team can achieve ISO 27001 certification without ISO 27002, but the guidance is useful for unfamiliar controls.
ISO 27001:2022 lists 93 Annex A controls, organised into four themes: organisational, people, physical and technological. That is down from 114 controls in the 2013 version, and the update introduced 11 new controls covering areas such as threat intelligence, cloud services and secure coding.
ISO 27002 is not mandatory and is not something you are audited against. It is optional guidance you can consult to implement the Annex A controls more effectively. The mandatory document for certification is ISO 27001, which contains the requirements and the control list that a certification body assesses.
CertAssist lays out all 93 Annex A controls with editable templates and your Statement of Applicability handled, for a published $225 a month during the launch.
See pricing FrameworksFlat $225 a month during the launch, normally $375, or $3,999 a year (12 months for the price of 11). All prices in USD.