By Jacob A. McLean, PECB Certified Trainer · September 17, 2026
The quick answer
ISO/IEC 27001 is the standard you certify against; ISO/IEC 27002 is the detailed guidance on how to implement the controls. You get certified to 27001. You use 27002 as the how-to manual for the controls 27001 references.
What ISO 27001 is
ISO/IEC 27001 sets the requirements for an information security management system: leadership, risk assessment, risk treatment, and a set of controls (Annex A) you select based on your risks. It's auditable and certifiable.
What ISO 27002 is
ISO/IEC 27002 is a companion code of practice. It takes the Annex A controls and explains, in depth, how to implement each one. You don't get certified to 27002 — you lean on it while implementing 27001.
How they work together
Think of 27001 as the what (the requirements and the list of controls) and 27002 as the how (practical implementation guidance). A good implementer uses both. Our Lead Implementer course covers applying the controls in practice.
Frequently asked questions
Can you get certified to ISO 27002?
No. Certification is against ISO/IEC 27001. ISO/IEC 27002 is guidance that supports implementation.
Ready to take the next step?
Browse accredited courses or book a free consultation and we'll help you choose the right path.
