ISO27K

ISO 27001 clauses 4 to 10, requirement by

Annex A gets the attention and clauses 4 to 10 get the nonconformities. These 25 requirements are the mandatory part of ISO 27001, none of them can be excluded, and this page lists every one with the record that satisfies it.

Last reviewed 2026-09-01Written by Jacob Masse, TrazTech Inc.

Clauses 4 to 10 of ISO/IEC 27001:2022 carry 25 mandatory requirements. Every one of them applies to every certified organization, no matter the size or the scope, and unlike the 93 Annex A controls not one of them can be excluded with a justification. Clauses 1 to 3 are scope, normative references and terms, and they are not auditable. If you have been told the standard has 114 requirements or 118 controls, someone has added two different things together.

This is the half of the standard that fails first. Annex A tends to be engineering work that is either done or visibly not done, and clauses 4 to 10 are management work that is usually happening informally and has no record attached to it. The controls that go with the annex are covered separately on the Annex A page.

How the 25 requirements are distributed

Mandatory requirements per clause of ISO 27001:2022 Clause 4 context has 4 requirements, clause 5 leadership has 3, clause 6 planning has 5, clause 7 support has 5, clause 8 operation has 3, clause 9 performance evaluation has 3, and clause 10 improvement has 2, for a total of 25. 4 Context 4 5 Leadership 3 6 Planning 5 7 Support 5 8 Operation 3 9 Evaluation 3 10 Improvement 2 0 2 4 5 Numbered requirements in ISO/IEC 27001:2022, clauses 4 to 10
Clauses 6 and 7 carry 5 requirements each and between them account for ten of the 25. The same counts are in the table below.
Requirement count by clause, ISO/IEC 27001:2022
ClauseRequirementsWhere the work sits
4 Context of the organization4One afternoon of thinking and one page of scope that decides the audit fee
5 Leadership3Executive time, not security team time
6 Planning5The heaviest clause. Risk assessment, risk treatment, Statement of Applicability, objectives
7 Support5Competence records, awareness training, and document control that runs forever
8 Operation3Mostly a restatement of clause 6 as a running activity
9 Performance evaluation3Measurement, internal audit, management review. All three are records with dates
10 Improvement2The corrective action log, which auditors read closely
Total mandatory requirements25None excludable. Separate from the 93 Annex A controls

What each of the 25 requirements asks for

This is the table to work from. The right-hand column is the record a certification body asks to see, which is a more useful thing to know than the wording of the requirement, because the wording rarely tells you what will satisfy it.

ISO/IEC 27001:2022 clauses 4 to 10, requirement by requirement, with the evidence that satisfies each
ClauseWhat it requiresEvidence an auditor accepts
4.1 ContextDetermine external and internal issues relevant to your information security outcomesA short issues register. Two pages, reviewed at management review, is enough
4.2 Interested partiesIdentify interested parties and which of their requirements are relevantA table naming customers, regulators, staff and the specific obligation each brings, such as PIPEDA or a contract security schedule
4.3 ScopeDetermine the boundaries and applicability of the ISMS, considering 4.1, 4.2 and the interfaces and dependencies with other organizationsA scope statement held as documented information. See the scope statement page
4.4 The ISMS itselfEstablish, implement, maintain and continually improve the management system, including the processes it needsThe system existing and running. Usually evidenced by everything else on this list
5.1 Leadership and commitmentEight specific things top management shall do, from resourcing to promoting improvementBoard or executive minutes, budget approvals, the review record. Covered on the clause 5 page
5.2 PolicyAn information security policy that is appropriate to the purpose, frames objectives, commits to applicable requirements and to continual improvementOne approved top-level policy, dated, communicated, available to interested parties as appropriate
5.3 Roles and authoritiesAssign responsibility for conformity of the ISMS and for reporting its performance to top managementA responsibility matrix or the job description, plus proof the person named knows they hold it
6.1.1 Risks and opportunitiesPlan actions addressing the risks and opportunities arising from 4.1 and 4.2Usually folded into the risk method document
6.1.2 Risk assessmentDefine and apply a risk assessment process with criteria, consistency, identification, analysis and evaluationA documented method and a populated register. See the risk assessment method
6.1.3 Risk treatmentSelect treatments, compare against Annex A, produce a Statement of Applicability, formulate a risk treatment plan, obtain owner approval of residual riskThe Statement of Applicability and the risk treatment plan, both approved
6.2 ObjectivesMeasurable information security objectives, planned, monitored, communicated and held as documented informationFour to eight objectives with a number, an owner and a date. Not aspirations
6.3 Planning of changesChanges to the ISMS shall be carried out in a planned mannerAdded in the 2022 edition and often missed. Evidence is a change record for ISMS changes, not just for systems
7.1 ResourcesDetermine and provide the resources the ISMS needsBudget line, headcount or a signed contract with a consultant or fractional security lead
7.2 CompetenceDetermine necessary competence, ensure it, act where it is missing, retain evidencePer-person records of training, education or experience for the roles named in 5.3
7.3 AwarenessPeople under your control shall be aware of the policy, their contribution, and the implications of not conformingTraining completion by person and date, sampled at stage 2. See clause 7
7.4 CommunicationDetermine what to communicate, when, with whom and howA half-page communication plan covering internal and external, including breach notification routes
7.5 Documented informationCreate, update and control documents: identification, format, review and approval, availability, protection, version control, retentionVersion history, approval records, an access model, and control of documents that come from outside
8.1 Operational planning and controlPlan and control the processes, set criteria, control planned changes, review unintended ones, control outsourced processesOperating procedures plus supplier control evidence. Externally provided processes are the part most often forgotten
8.2 Risk assessment in operationPerform risk assessments at planned intervals and when significant changes occurDated reassessments. Two in a year beats one, because the clause says intervals
8.3 Risk treatment in operationImplement the risk treatment plan and retain the resultsClosure evidence against each treatment, not the plan itself
9.1 Monitoring and measurementDetermine what to monitor, the methods, when, by whom, and when results are analysedA measurement table with actual figures in it. Patch latency, phishing failure rate, access review completion
9.2 Internal auditAn audit program at planned intervals, with objective auditors, reported to managementprogram, plan, findings and proof they reached management. See internal audit
9.3 Management reviewTop management reviews the ISMS at planned intervals against a defined input list, and records decisionsMinutes covering every required input. See management review
10.1 Continual improvementContinually improve the suitability, adequacy and effectiveness of the ISMSAn improvement log with things actually closed in it
10.2 Nonconformity and corrective actionReact, evaluate the cause, check whether it exists elsewhere, act, review effectiveness, record all of itA corrective action register with root cause and effectiveness columns. See clause 10

Why clause 8 has no page of its own

Because it mostly says do what clause 6 planned. Clause 8.2 is the risk assessment from 6.1.2 performed on a schedule, and 8.3 is the risk treatment plan from 6.1.3 actually executed. The only genuinely new obligation is in 8.1, where the standard requires that externally provided processes, products and services relevant to the ISMS are controlled. For a Canadian software company running on a public cloud with a dozen software subscriptions, that single sentence is a supplier register, signed agreements with security terms, and a review cadence. It is more work than the rest of clause 8 combined and it is the part that gets read as boilerplate.

The 2022 requirement people still miss

Clause 6.3, planning of changes, was added in the 2022 edition. It asks that changes to the management system itself be carried out in a planned manner: a new product line brought into scope, an office closed, a subsidiary acquired. Companies that transitioned from the 2013 edition frequently have nothing against it, because their change management evidence is all about code and infrastructure. A change record for the scope change is what closes it.

Which clauses actually produce findings

Findings cluster in clause 9 and clause 7 for a structural reason. Both require records made at particular times, and a record that was never made cannot be produced on the day of the audit the way a firewall rule can. A missing management review is not fixable during stage 2. A missing training record for one of five sampled employees is not fixable either, because the date has passed.

Fixable while the auditor is in the room
A policy missing an approval signature, a register missing a column, an objective without a target. Documentation defects, which auditors will often let you correct on the spot.
Not fixable on the day
Anything with a date attached: the internal audit, the management review, a quarter of access reviews, the training completion for a leaver who has already left. These become nonconformities, and what happens next is on the nonconformity page.
Not fixable this cycle
An operating period that does not exist. If the system started running in July, no amount of money produces April evidence.

When this is more management system than you need

The honest counter-case. Clauses 4 to 10 describe a governance loop designed for an organization that will hold a certificate for years and be audited every one of them. If what you actually have is one enterprise customer asking a security question, the whole loop is disproportionate and there are two cheaper answers. A completed security questionnaire with real evidence attached will satisfy many buyers. A SOC 2 report satisfies most North American ones and does not require you to run a management review or an internal audit program at all, because the auditor tests your controls rather than your governance of them.

Clauses 4 to 10 earn their cost when the certificate is a repeated commercial requirement, when more than one buyer will ask, and when the same question will come back at every renewal. If you are not sure which of the two standards your buyer meant, the wording in their email usually settles it, and the comparison page takes it apart. Where neither is clearly required yet, working out which framework applies is a cheaper first step than starting either.

The order to build them in

  1. Clause 4.3 scope first, because it prices the audit and constrains everything after it.
  2. Clause 5.2 policy and 5.3 roles, because the risk work needs an owner with authority before it needs a method.
  3. Clause 6.1.2 and 6.1.3, the risk assessment, treatment plan and Statement of Applicability. This is the longest stretch.
  4. Clause 7 in parallel with the Annex A implementation, since competence and awareness records take calendar time to accumulate.
  5. Clause 8, which is clause 6 running with dates on it, for at least three months.
  6. Clause 9.1 measurement, then 9.2 internal audit, then 9.3 management review, in that order, because each is an input to the next.
  7. Clause 10 from the moment the internal audit produces its first finding. A corrective action register that opens the week before stage 2 is transparent.

The calendar version of this, with the months attached, is on the implementation page.

Get the clause work quoted properly

Tell us your scope and headcount and we will match you with Canadian firms that build management systems rather than sell templates.

Get matched

Common questions

How many clauses does ISO 27001 have?

Ten, but only clauses 4 to 10 contain auditable requirements, and those seven clauses carry 25 numbered requirements between them. Clauses 1, 2 and 3 are the scope of the document, the normative references and the definitions. Annex A is separate again and holds 93 reference controls.

Can we exclude a clause the way we exclude an Annex A control?

No. Exclusion applies only to Annex A controls, and only with a justification recorded in the Statement of Applicability. All 25 clause requirements apply to every certified organization regardless of size, sector or scope. A management system that has decided not to do management review is not a management system a body can certify.

What is the difference between a clause and a control?

A clause is a mandatory requirement in the body of the standard about how the management system works: scope, leadership, risk, competence, audit, review, improvement. An Annex A control is one of 93 reference safeguards you select from to treat the risks you identified. Clauses are compulsory and controls are selected. Adding the two counts together and quoting a single figure is the clearest sign a page was written without the standard open.

Which clause causes the most trouble at certification?

Clause 9, for a structural reason: internal audit and management review both have to have happened before stage 2, and both are easy to defer while the technical work absorbs attention. Clause 7 is second, because competence and awareness evidence is per person and cannot be reconstructed after the fact.

Do we need a separate document for every clause?

No, and building one is a common way to produce a management system nobody uses. The standard requires specific documented information in particular places, notably the scope, the policy, the risk method, the Statement of Applicability, the objectives and a set of records. Everything else can live in whatever tools you already run, provided it can be found, it is version controlled and it is current.

Did the 2022 edition change the clauses?

Lightly. The structure stayed the same, the wording was aligned with the harmonised structure used across ISO management system standards, and clause 6.3 on planning of changes was added. The large change in 2022 was to Annex A, which went from 114 controls in 14 domains to 93 controls in four themes.