ISO/IEC 27001:2022 · plain English
ISO 27001, explained without the sales pitch.
Every management-system clause and every Annex A control, explained in terms of what it actually requires and how a solo consultant or small team self-leading certification would realistically handle it — not vendor marketing copy.
Guides
ISO 27001 without a consultant: what it actually takes
Self-led certification is real and common — here's the honest time, skill, and cost tradeoff versus hiring one.
How many hours does ISO 27001 actually take?
A realistic breakdown by company size, not the vague "a few months" every vendor page gives you.
SOC 2 vs ISO 27001: which should a small company do first?
It usually comes down to where your customers are, not which framework is "better."
How to do your own ISO 27001 gap analysis
The exact structure a consultant would charge you $5,000+ for, laid out so you can run it yourself.
The real ISO 27001 checklist (not just Annex A)
Annex A is the part everyone talks about — it's actually the smaller half of what certification requires.
Best ISO 27001 software for a small team, honestly compared
Vanta and Drata aren't built for a 5-person company. Here's what actually is, and isn't.
Clauses 4–10
The actual management-system requirements — Annex A is only half the standard.