Questionnaire standards

ISO 27001 in a questionnaire — the evidence base, not the answer

ISO 27001 is the only entry here that nobody sends you. It is the body of evidence the other questionnaires are answered from — and, increasingly, the source customers derive their own catalogues from.

In short

A certificate does not answer a questionnaire; it supports answers. Reviewers look at scope first: does it cover the service being sold, or only the parent company, one site, one business unit? The second look is at the edition. The transition period from the 2013 edition closed on 31 October 2025; certificates against the old edition have lost their validity.

ISO 27001 at a glance

Current editionISO/IEC 27001:2022. The transition period from the 2013 edition closed on 31 October 2025.
Annex A93 controls in four themes — organisational 37, people 8, physical 14, technological 34.
Relation to 2013Previously 114 controls across 14 sections. The reduction is mostly consolidation; only 11 controls are entirely new.
What a reviewer checks firstThe scope of certification, not the certificate number.
Role in a questionnaireEvidence base. Some buyers accept the certificate with the statement of applicability instead of their own questions; many do not.
Derived questionnairesBuyers build their own catalogues from Annex A — then it is asked control by control rather than certificate by certificate.

How the file is put together

Where a buyer derives their form from Annex A, the file follows its ordering.

Questions carry Annex A control numbers — the shared reference between your statement of applicability and the buyer's form.
There is often an applicability column: where a control justifiably does not apply, the justification is the answer.
Some forms mix Annex A controls with their own additions; the numbering then breaks and can no longer be mapped one to one.
Anyone certified against the 2013 edition meets a different numbering — the mapping to 2022 has to exist, or no answer fits any question.

What Compliance Concierge does with a ISO 27001

Certificate, statement of applicability and the underlying policies are uploaded once as an evidence base rather than reassembled for every form.
Every draft points at the passage supporting it — for Annex A questions that is usually a section of the statement of applicability.
Where a control is carried as not applicable in the statement of applicability, that justification is reused rather than a new one invented.
Statements about scope are held for a human: whether the certificate covers the service being sold is a question of fact with contractual consequences.
Approved answers are written back into the workbook you received.

None of this certifies you. The tool drafts answers from the documents you upload, shows the evidence behind each one, and refuses to export anything a person has not signed off. Where your documents do not cover a control, it says so instead of filling the cell.

This page provides orientation and does not replace legal advice. Whether and how a rule applies to your company depends on the individual case.

The four Annex A themes

Since the 2022 edition the controls are grouped into four themes rather than 14 sections. What matters for a questionnaire is which evidence each group calls for.

A.5

Organisational controls (37)

What it asks
Policies, roles, supplier relationships, incident handling, continuity — the largest block.
What answers it
Statement of applicability, information security policy, supplier policy, incident process.
Common mistake
Pointing at the certificate without attaching the statement of applicability. That document says which controls apply at all — without it the certificate is a claim without a boundary.
A.6

People controls (8)

What it asks
Screening before hiring, training, confidentiality agreements, orderly departure.
What answers it
Training records with dates, the confidentiality agreement template, joiner and leaver process.
Common mistake
Confirming training without being able to evidence attendance and date. What is asked for is the record, not the offering.
A.7

Physical controls (14)

What it asks
Entry, zones, protection of equipment, handling of storage media.
What answers it
Access concept, entry control logs, policy for disposal and reuse of storage media.
Common mistake
Presenting the data centre operator's controls as your own. Referring to them is legitimate — as third-party evidence, clearly labelled.
A.8

Technological controls (34)

What it asks
Access rights, encryption, logging, vulnerability handling, secure development.
What answers it
Authorisation concept, encryption policy, evidence of logging, the latest vulnerability scan report.
Common mistake
Affirming encryption in general. It is asked separately for data in transit and at rest — and usually about the method.

The 2022 edition has been the only valid one since 31 October 2025: certificates against ISO/IEC 27001:2013 lost their validity when the transition period closed. Anyone still citing a certificate against the old edition should expect a follow-up question — and is better off raising the point themselves than letting the reviewer find it.

Frequently asked

Can I just send my certificate instead of the questionnaire?+

Asking costs nothing and saves both sides a round when it works. Many buyers accept the certificate with the statement of applicability for part of the questions, but still want answers to everything their own context adds — processing locations, subcontractors, contractual undertakings. A questionnaire is rarely replaced in full.

Why does everyone ask about scope first?+

Because scope is the only thing that makes a certificate meaningful. A parent company's ISO 27001 evidences nothing about a service running in a subsidiary, and a certificate for site A nothing about operations at site B. State the scope unprompted — it saves the first follow-up.

Do I need ISO 27001 to pass questionnaires?+

No. A certificate bundles evidence and shortens the review, but does not replace concrete answers. An organisation without one that documents its controls cleanly and names the scope of every statement gets through — a certified one with a mismatched scope often does not.

What about my answers written against the 2013 edition?+

Substantively most of them still hold, because the reduction from 114 to 93 controls was largely consolidation and only 11 controls are entirely new. What no longer fits is the numbering: without a mapping onto the 2022 structure, no old answer can be matched to a new question.

Other assessments we cover: CAIQ v4, SIG & SIG Lite, HECVAT, VSA, TISAX / VDA ISA, DORA. For the process itself, see the guide to answering security questionnaires. Tools that automate this kind of workbook, compared honestly: Vanta, SafeBase and Conveyor.

Answer your ISO 27001 with evidence

Upload your policies and the workbook. Every draft is cited from your own documents, and nothing leaves until you approve it. The first questionnaire is free.