ISO 27002 vs ISO 27001: what each one is for
ISO/IEC 27002:2022 is not a certifiable standard and never has been. It is the implementation guidance for the same 93 controls that Annex A of ISO 27001 lists by title, and if you are implementing rather than auditing, it is the more useful of the two documents.
You cannot be certified against ISO/IEC 27002. No accredited certification body will issue a certificate for it, because it contains no requirements to audit against. It is a guidance document covering the same 93 controls that Annex A of ISO/IEC 27001:2022 lists, with several pages of implementation detail for each one where Annex A gives you a single sentence. Certification is against ISO 27001. Implementation happens with ISO 27002 open on the desk.
Buying both costs roughly $400 to $900 CAD from ISO or through the Standards Council of Canada, and skipping the second one is the most common false economy in a first ISO 27001 project.
What is the actual difference between ISO 27001 and ISO 27002?
One is a specification and the other is a code of practice. That distinction sounds like standards-body vocabulary until you read both documents and see how differently they behave.
- ISO/IEC 27001:2022
- The requirements standard. Clauses 4 through 10 carry 25 mandatory requirements for an information security management system, and Annex A lists 93 reference controls by title and single-sentence statement. This is the document your certificate names, and every sentence containing the word shall is auditable.
- ISO/IEC 27002:2022
- The guidance standard. Same 93 controls, same numbering, but each one gets a purpose statement, several paragraphs of implementation guidance and a block of other information. It has no clauses 4 to 10, no management system requirements and nothing to certify.
- Annex A
- The bridge. It is the normative reference set you compare your own control selection against under clause 6.1.3, and the list your Statement of Applicability has to account for line by line.
The practical consequence: an auditor tests you against ISO 27001. They cannot raise a nonconformity because you did not follow a paragraph of ISO 27002 guidance. They can, and routinely do, raise one because the control you said was implemented is not doing anything, and the guidance is how you find out what doing something looks like before they arrive.
What does ISO 27002 give you that Annex A does not?
Take control 8.8, management of technical vulnerabilities. Annex A gives you roughly one sentence: information about technical vulnerabilities of information systems in use is to be obtained, exposure evaluated and appropriate measures taken. That is the whole normative text.
ISO 27002 spends several pages on the same control. It covers defining roles and responsibilities for vulnerability management, identifying information sources, maintaining an asset inventory as the precondition, timelines for reacting to notification, patching against other mitigations, testing patches before deployment, logging what was done, and coordinating with incident management. That is the difference between knowing a requirement exists and knowing what evidence satisfies it.
Where the guidance stops short
ISO 27002 does not name products, does not set thresholds and does not tell you how many days you have to patch a critical vulnerability. It is guidance written to apply to a bank and to a nine-person software company, so it tells you which decisions to make rather than what to decide. The numbers still have to come from your own risk assessment, which is the point of clause 6.1.2.
What are the ISO 27002 attributes and do I have to use them?
The 2022 edition tags every control with five attribute sets, and they are optional. They exist so you can sort and filter 93 controls by something other than the four themes.
| Attribute set | Values | What it is useful for |
|---|---|---|
| Control type | Preventive, detective, corrective | Checking you have not built a control set that only prevents and never detects. |
| Information security properties | Confidentiality, integrity, availability | Showing an auditor that availability was considered, which is where software companies are usually thin. |
| Cybersecurity concepts | Identify, protect, detect, respond, recover | Mapping to the NIST Cybersecurity Framework without doing the mapping yourself. |
| Operational capabilities | Governance, asset management, information protection, identity and access management, threat and vulnerability management, continuity, supplier relationships security, legal and compliance, and others | Assigning controls to the team that actually owns them. |
| Security domains | Governance, protection, defence and resilience | Reporting to a board that does not want to read 93 rows. |
The operational capabilities attribute is the one worth the effort, because it turns the annex into an ownership list. Sorting 93 controls into eight or nine owners in an afternoon is the fastest way to stop the security lead personally owning all of them, which is the failure mode behind most stalled implementations. The rest are reporting conveniences.
Is ISO 27002 worth buying?
Yes, for a first certification, and the arithmetic is not close. The pair costs $400 to $900 CAD. A guided implementation runs $25,000 to $50,000 CAD as set out on the itemised cost page, and internal time on a first certification runs $15,000 to $75,000 CAD at a loaded $80 to $150 CAD an hour. A document that removes a few days of guessing has paid for itself before you finish the first theme.
When you can genuinely skip it
Two cases. If you have hired a consultant who is writing the control set and you are reviewing rather than authoring, you will spend more time reading 27002 than you save, and their templates already encode it. And if you are already certified and running a mature management system, the guidance has done its job and you refer to it once a year at most. Skipping it because it costs a few hundred dollars while you are about to spend tens of thousands is a different decision, and a worse one.
Which other documents in the 27000 family matter?
| Document | Certifiable | What it is for |
|---|---|---|
| ISO/IEC 27000 | No | Vocabulary and overview. Free to download from ISO, and worth ten minutes for the definitions alone. |
| ISO/IEC 27001 | Yes | The requirements standard your certificate names. |
| ISO/IEC 27002 | No | Implementation guidance for the 93 Annex A controls. |
| ISO/IEC 27005 | No | Guidance on managing information security risk. Useful if your risk method is being questioned, covered on the risk assessment page. |
| ISO/IEC 27006-1 | Not by you | Requirements for bodies that certify management systems, including the audit time tables your quote comes from. |
| ISO/IEC 27017 | As an extension | Cloud security guidance, covered on the cloud pair page. |
| ISO/IEC 27018 | As an extension | Personal information in public clouds, for processors. |
| ISO/IEC 27701 | Yes, since 2025 | Privacy information management, now a standalone management system standard. See the ISO 27701 page. |
ISO/IEC 27006-1 is the sleeper on that list. You are not certified against it and you will probably never read it, but it is the document that decides how many audit days your certification body has to sell you, which is why day count rather than dollar total is the comparable number when you are reading quotes.
What happened to the ISO 27002:2013 control numbers?
They were renumbered. The 2013 edition had 114 controls in 14 domains and the 2022 edition has 93 in four themes, and almost nothing was deleted: overlapping controls were merged, eleven new ones were added, and the grouping was rebuilt around who owns a control rather than which chapter it belonged to. Annex B of ISO 27002:2022 carries the mapping tables in both directions, which is the fastest way to update an old control matrix without redoing it from scratch.
The transition period for organizations still certified against the 2013 edition closed on 31 October 2025. A certificate naming ISO/IEC 27001:2013 is not current, and the Annex A controls page covers the eleven controls that were new in 2022, which is where a carried-over control set usually has real gaps rather than paperwork ones.
Get help selecting your control set
Tell us your scope and we will match you with Canadian firms that do ISO 27001 readiness work.
Get matchedCommon questions
Can you get certified to ISO 27002?
No. ISO/IEC 27002 contains guidance rather than requirements, so there is nothing for an accredited certification body to audit against and no certificate exists. Any organization claiming ISO 27002 certification has either misdescribed an ISO 27001 certificate or bought something unaccredited. Certification is against ISO/IEC 27001.
Do I need ISO 27002 if I already have ISO 27001?
You need it while you are implementing, and much less afterwards. Annex A of ISO 27001 gives each of the 93 controls one sentence, which is enough to decide whether a control is applicable and not enough to know what an auditor accepts as evidence. Once the management system is running and you have been through a stage 2 audit, you will open it a few times a year.
How many controls are in ISO 27002:2022?
The same 93 as Annex A of ISO 27001:2022, in the same four themes: 37 organizational, 8 people, 14 physical and 34 technological. The numbering is identical, which is deliberate, so a control reference works in either document. The 25 requirements in clauses 4 through 10 of ISO 27001 are a separate thing and do not appear in ISO 27002 at all.
How much does ISO 27002 cost in Canada?
Roughly $200 to $450 CAD for a single-user copy, and $400 to $900 CAD for ISO 27001 and ISO 27002 together, bought from ISO directly or through the Standards Council of Canada. Prices vary with the reseller and with multi-user licensing. Both documents are copyrighted and cannot legitimately be shared outside the licence you bought.
Are the ISO 27002 attributes mandatory for my Statement of Applicability?
No. The four required columns in a Statement of Applicability come from clause 6.1.3 of ISO 27001: whether the control is necessary, the justification for inclusion, whether it is implemented, and the justification for any exclusion. Attributes are a filtering aid from ISO 27002 and adding them is a choice. Some auditors like seeing the control type column because it shows detective controls were considered.
Which should I read first?
Clauses 4 through 10 of ISO 27001, in full, before anything else. They are short, they are the only mandatory requirements, and they are where first-time projects fail, because teams start at Annex A and build a control set with no management system underneath it. The clause requirements page walks through all 25 of them. Read ISO 27002 second, control by control, as you work.