
Topic hub
The ISO 27001 hub
Plain-English guidance on ISO/IEC 27001: the move to the 2022 revision, the Statement of Applicability, and running the ISMS as a living management system.
Guides
ISO 27001, explained

ISO 27001 vs SOC 2: which do you need (or do you need both)?
They cover much of the same ground, which is why buyers confuse them. But one is a certificate and the other is a report, and which you need usually comes down to where your customers are.
31 July 2026
ISO 27001:2022 vs 2013: what changed, and the deadline that's now passed
The 2022 revision restructured Annex A to 93 controls in four themes and added 11 new ones. The transition deadline was 31 October 2025; 2013 certificates are no longer valid.
18 June 2026
What is a Statement of Applicability? The ISO 27001 document auditors open first
The SoA lists every Annex A control, whether it applies, why, and its status. It's the map between your risk treatment and your controls, and it's where an auditor starts.
16 June 2026Run your ISO 27001 ISMS in ResiliencePilot
See it on your own data and frameworks, with your security and data-residency questions answered.