ISO 27001 in a questionnaire — the evidence base, not the answer
ISO 27001 is the only entry here that nobody sends you. It is the body of evidence the other questionnaires are answered from — and, increasingly, the source customers derive their own catalogues from.
In short
A certificate does not answer a questionnaire; it supports answers. Reviewers look at scope first: does it cover the service being sold, or only the parent company, one site, one business unit? The second look is at the edition. The transition period from the 2013 edition closed on 31 October 2025; certificates against the old edition have lost their validity.
ISO 27001 at a glance
| Current edition | ISO/IEC 27001:2022. The transition period from the 2013 edition closed on 31 October 2025. |
| Annex A | 93 controls in four themes — organisational 37, people 8, physical 14, technological 34. |
| Relation to 2013 | Previously 114 controls across 14 sections. The reduction is mostly consolidation; only 11 controls are entirely new. |
| What a reviewer checks first | The scope of certification, not the certificate number. |
| Role in a questionnaire | Evidence base. Some buyers accept the certificate with the statement of applicability instead of their own questions; many do not. |
| Derived questionnaires | Buyers build their own catalogues from Annex A — then it is asked control by control rather than certificate by certificate. |
How the file is put together
Where a buyer derives their form from Annex A, the file follows its ordering.
What Compliance Concierge does with a ISO 27001
None of this certifies you. The tool drafts answers from the documents you upload, shows the evidence behind each one, and refuses to export anything a person has not signed off. Where your documents do not cover a control, it says so instead of filling the cell.
This page provides orientation and does not replace legal advice. Whether and how a rule applies to your company depends on the individual case.
The four Annex A themes
Since the 2022 edition the controls are grouped into four themes rather than 14 sections. What matters for a questionnaire is which evidence each group calls for.
Organisational controls (37)
- What it asks
- Policies, roles, supplier relationships, incident handling, continuity — the largest block.
- What answers it
- Statement of applicability, information security policy, supplier policy, incident process.
- Common mistake
- Pointing at the certificate without attaching the statement of applicability. That document says which controls apply at all — without it the certificate is a claim without a boundary.
People controls (8)
- What it asks
- Screening before hiring, training, confidentiality agreements, orderly departure.
- What answers it
- Training records with dates, the confidentiality agreement template, joiner and leaver process.
- Common mistake
- Confirming training without being able to evidence attendance and date. What is asked for is the record, not the offering.
Physical controls (14)
- What it asks
- Entry, zones, protection of equipment, handling of storage media.
- What answers it
- Access concept, entry control logs, policy for disposal and reuse of storage media.
- Common mistake
- Presenting the data centre operator's controls as your own. Referring to them is legitimate — as third-party evidence, clearly labelled.
Technological controls (34)
- What it asks
- Access rights, encryption, logging, vulnerability handling, secure development.
- What answers it
- Authorisation concept, encryption policy, evidence of logging, the latest vulnerability scan report.
- Common mistake
- Affirming encryption in general. It is asked separately for data in transit and at rest — and usually about the method.
The 2022 edition has been the only valid one since 31 October 2025: certificates against ISO/IEC 27001:2013 lost their validity when the transition period closed. Anyone still citing a certificate against the old edition should expect a follow-up question — and is better off raising the point themselves than letting the reviewer find it.
Frequently asked
Can I just send my certificate instead of the questionnaire?+
Asking costs nothing and saves both sides a round when it works. Many buyers accept the certificate with the statement of applicability for part of the questions, but still want answers to everything their own context adds — processing locations, subcontractors, contractual undertakings. A questionnaire is rarely replaced in full.
Why does everyone ask about scope first?+
Because scope is the only thing that makes a certificate meaningful. A parent company's ISO 27001 evidences nothing about a service running in a subsidiary, and a certificate for site A nothing about operations at site B. State the scope unprompted — it saves the first follow-up.
Do I need ISO 27001 to pass questionnaires?+
No. A certificate bundles evidence and shortens the review, but does not replace concrete answers. An organisation without one that documents its controls cleanly and names the scope of every statement gets through — a certified one with a mismatched scope often does not.
What about my answers written against the 2013 edition?+
Substantively most of them still hold, because the reduction from 114 to 93 controls was largely consolidation and only 11 controls are entirely new. What no longer fits is the numbering: without a mapping onto the 2022 structure, no old answer can be matched to a new question.
Other assessments we cover: CAIQ v4, SIG & SIG Lite, HECVAT, VSA, TISAX / VDA ISA, DORA. For the process itself, see the guide to answering security questionnaires. Tools that automate this kind of workbook, compared honestly: Vanta, SafeBase and Conveyor.
Answer your ISO 27001 with evidence
Upload your policies and the workbook. Every draft is cited from your own documents, and nothing leaves until you approve it. The first questionnaire is free.