ISO/IEC 27001 is the leading international standard for an Information Security Management System (ISMS). It is risk-based, built around a set of Annex A controls, and — unlike a self-attestation — it is certifiable by an accredited body. For many organizations it is the recognized global signal that security is managed, not improvised.

The current version: ISO 27001:2022

The standard was significantly revised in ISO/IEC 27001:2022. The core management-system clauses changed only modestly, but Annex A was restructured — the previous 114 controls across 14 domains were consolidated into 93 controls across four themes (Organizational, People, Physical, and Technological), and 11 new controls were added to reflect a modern threat landscape, including threat intelligence, information security for cloud services, secure development lifecycle, data masking, and ICT readiness for business continuity. A 2024 amendment also added an explicit requirement to consider whether climate change is a relevant issue for the ISMS.

Crucially, the three-year window to migrate from the old 2013 version closed on 31 October 2025 — ISO 27001:2013 certificates are no longer valid, so any current certification should be against the 2022 revision. If a partner still references “27001:2013,” that is a flag worth checking.

How ISO 27001 and CMMC relate

Both are security frameworks and their controls overlap heavily — access control, risk management, incident response, asset management, and more. Operationally, a mature ISMS gives you a strong running start toward CMMC: much of the governance, documentation, and control implementation maps across, and published crosswalks link ISO 27001 Annex A to NIST SP 800-171. If you already run an ISMS, you are not starting from zero.

The critical caveat: ISO 27001 earns no CMMC credit

Here is the point that trips up many contractors. If your environment handles CUI and must be assessed for CMMC, no consideration is given to an existing ISO 27001 certification. A CMMC assessment is conducted strictly against the CMMC model — the 110 NIST SP 800-171 controls at Level 2 — and there is no reciprocity, equivalency, or partial credit for holding ISO 27001. Your CUI environment will be assessed against every applicable CMMC practice regardless of your ISO status.

Bottom line: ISO 27001 can help you prepare for CMMC because the underlying work overlaps — but the certificate itself buys you nothing in the CMMC assessment. Plan and budget for CMMC on its own terms.

When ISO 27001 is the right goal: global trust through compliance

The reverse framing matters just as much. If your business — or your customers — requires an ISO 27001 assessment and certification, that effort is far from wasted. ISO 27001 is recognized worldwide, so certification becomes a passport: it demonstrates to international customers, partners, and regulators that your security is independently verified against a global standard. In markets where trust must cross borders, global trust is built through compliance — and ISO 27001 is the credential that carries it.

How to think about running both

  • Different audiences. CMMC proves you to the U.S. defense supply chain; ISO 27001 proves you to the global commercial market.
  • Shared work, separate certifications. Leverage the overlap operationally, but treat each assessment as standing on its own.
  • Sequence by need. Let your contracts and customers — not convenience — decide which you pursue first.

Need the CMMC control-level view? See CMMC & NIST SP 800-171.