ISO 27001 vs ISO 27002
By Sam Rivera, Founder, SentinelPanda · June 19, 2026 · 1 min read · ISO 27001
You get certified to 27001 and you implement using 27002. One is the requirement; the other is the how-to manual for the controls.
Two documents, one job
ISO 27001 and ISO 27002 are a pair. ISO 27001 is the certifiable management-system standard: the mandatory clauses plus Annex A, which lists the controls by reference. ISO 27002 is the longer companion that takes each Annex A control and explains its purpose and implementation guidance in detail.
Which you certify against
You certify to ISO 27001 — that is the standard an accredited body audits you against. There is no certification to ISO 27002; it is guidance, not requirements. So when a customer asks "are you ISO certified?", the answer is about 27001.
Which you actually use
In practice you read ISO 27002 to implement well. Annex A in 27001 gives you the control titles and a one-line objective; 27002 gives you the paragraphs of how-to. Teams use 27002 as the implementation reference while building the controls that 27001 will audit.
The 2022 alignment
The 2022 revisions brought them into sync: ISO 27002:2022 reorganised the controls into four themes, and ISO 27001:2022 Annex A mirrors that structure. So the guidance and the requirement now line up control-for-control. SentinelPanda maps your controls to the 27001 Annex A structure with the 27002 intent built in.