Solidgate logo in black and white.

ISO 27001

What is ISO 27001?

ISO 27001 is the international standard that specifies requirements for an information security management system (ISMS). Published jointly by ISO and IEC, it defines how an organisation identifies information security risks, selects controls to treat them, and demonstrates through independent audit that the system keeps working.
The standard is organised around three properties of information: confidentiality, integrity and availability. Its scope is deliberately broad, covering people, processes and technology rather than a single system or data type. The current edition is ISO/IEC 27001:2022, published in October 2022. Certification is voluntary, and an organisation decides for itself whether to be audited by an accredited certification body or simply align with the standard internally. In payments, ISO 27001 is often held alongside , which governs cardholder data specifically while ISO 27001 covers the management system around all information assets.

Key requirements

The standard has two parts. Clauses 4 to 10 define the management system itself and are mandatory. Annex A lists the security controls an organisation draws on to treat the risks it has identified.
  • Context and scope – define which business units, systems, sites and third parties the ISMS covers. The scope statement appears on the certificate.
  • Leadership and policy – top management owns the ISMS, approves the information security policy and assigns responsibilities.
  • Risk assessment and treatment – identify information security risks, evaluate them against defined criteria, and choose how each is treated.
  • Statement of Applicability – a mandatory document recording which Annex A controls apply, which are excluded and the justification for each decision.
  • Annex A controls – ISO/IEC 27001:2022 lists 93 controls across four themes: 37 organizational, 8 people, 14 physical and 34 technological. Organisations implement the ones their risk assessment justifies, not all 93. Payment businesses usually map the technological theme onto measures already in production, such as of stored data and of card credentials.
  • Monitoring and internal audit – measure whether controls work, run internal audits, and hold documented management reviews.
  • Continual improvement – record nonconformities, act on them, and feed the results back into the risk assessment.

Who it applies to

No law or card scheme rule requires ISO 27001. It applies to any organisation that chooses to adopt it, of any size and in any sector, and it's the buyer side that usually drives adoption in payments.
  • Vendors under review – enterprise procurement and bank questionnaires routinely ask for a current certificate before onboarding a payment provider.
  • Regulated and adjacent businesses – firms operating under frameworks such as (PSD2) use the certificate as supporting evidence of security governance, though the directive doesn't name ISO 27001 as a requirement.
  • Organisations with defined scope limits – because each organisation sets its own scope, two certificates can cover very different parts of a business. The scope statement records what was actually audited.

Penalties for non-compliance

ISO 27001 carries no statutory penalty, because no regulator enforces it. The consequences are audit and commercial ones.
Auditors raise findings as minor or major nonconformities. A major nonconformity blocks initial certification until it's corrected, and on an existing certificate it triggers suspension if it isn't closed within the certification body's deadline. A certificate is valid for three years, with surveillance audits in years one and two and a full recertification audit in year three. Skipping a surveillance audit or failing to close findings leads to suspension and then withdrawal.
The commercial effect is more immediate than the audit one. A lapsed certificate removes a vendor from procurement shortlists and stalls partner and bank onboarding reviews that treat it as a gating document. Where an actual breach follows, liability falls under data protection law and contractual terms, not under ISO.

Related compliance frameworks

StandardWhat it coversStatus
ISO 27001Management system for information security across all assetsVoluntary certification
Handling, storage and transmission of cardholder dataContractual, enforced through card scheme rules
Messaging format for financial data exchange, not a security standardAdopted by market infrastructures and banks
SOC 2Auditor's report on a service organisation's controlsVoluntary, buyer-driven

Related terms