ISO 27001:2022.
The 2022 revision of ISO’s information security management system (ISMS) standard. Widely used outside North America and increasingly required by European and Asian enterprise buyers. Includes 93 controls across 4 themes.
ISO 27001 is the international counterpart to SOC 2 — broadly equivalent in rigor, with different emphasis. Where SOC 2 is heavily evidence-driven and audit-firm-centric, ISO 27001 focuses on the management system: documented risk methodology, policy hierarchy, internal audits, and management reviews. The 2022 revision restructured the Annex A controls into four themes — Organizational (37), People (8), Physical (14), and Technological (34) — totalling 93 controls down from the previous 114. Many SaaS companies selling globally pursue both SOC 2 (for North American buyers) and ISO 27001 (for European, Asian, and government buyers).
Connected concepts.
SOC 2
Service Organization Control 2A security framework developed by the AICPA that defines how service organizations should handle customer data based on five trust service criteria: security, availability, processing integrity, confidentiality, and privacy. Most enterprise buyers require vendors to be SOC 2 compliant.
NIST CSF 2.0
NIST Cybersecurity Framework 2.0Released in 2024, NIST CSF 2.0 is the updated U.S. National Institute of Standards and Technology cybersecurity framework. Adds the Govern function to the original five (Identify, Protect, Detect, Respond, Recover) and covers 106 subcategories.
Need help with ISO 27001:2022?
We do this work every day for Canadian teams. Book a free 30-minute consultation.
Talk to MALTO Cyber →