ISO/IEC 27001, explained simply
ISO/IEC 27001 is the international standard for managing information security. It is the most widely recognised security certificate in the world, and for many European buyers it is the default answer to "prove you are secure".
- Standard
- ISO/IEC 27001:2022 (information security management system)
- Version
- ISO/IEC 27001:2022
- Jurisdiction
- International (ISO/IEC)
- Catalogue last verified
- 2026-07-16
Who it is for
Any organisation that holds information worth protecting — which in practice means any software company with customers. European buyers often prefer it to SOC 2, so companies selling on both sides of the Atlantic frequently end up doing both. The management-system clauses always apply; the Annex A controls are considered against a Statement of Applicability, where a control can be scoped out with a documented justification.
What is actually in it
Tawsik tracks every requirement in the published catalogue, grouped by its official numbering.
115requirements tracked
- A. · 93
- Cl. · 22
What evidence can prove — and what it can’t
We would rather tell you this up front than let a dashboard imply more certainty than it has.
Where Tawsik fits
Tawsik is not a certification body. It shows your readiness from your own evidence, tracks which controls are still open, and — because it maps one canonical control to every framework that asks for it — reuses that evidence in SOC 2, ISO 42001 and NIS2 instead of asking you to gather it four times.
Tawsik is not a certification body or an auditor.
One set of evidence, every framework
Tawsik maps one canonical control to every framework that asks for it, so a proof you gather once counts everywhere it applies.
See where you stand
Start with the free EU AI Act check — no account, no email. Your workspace covers the rest.
Tawsik guides you toward compliance. It isn’t legal advice.