Standards explained

ISO 27001 vs ISO 27002: What's the Difference?

They sound like siblings, and they are. Here's how ISO 27001 and ISO 27002 differ and how they work together.

By Jacob A. McLean, PECB Certified Trainer · September 17, 2026

The quick answer

ISO/IEC 27001 is the standard you certify against; ISO/IEC 27002 is the detailed guidance on how to implement the controls. You get certified to 27001. You use 27002 as the how-to manual for the controls 27001 references.

What ISO 27001 is

ISO/IEC 27001 sets the requirements for an information security management system: leadership, risk assessment, risk treatment, and a set of controls (Annex A) you select based on your risks. It's auditable and certifiable.

What ISO 27002 is

ISO/IEC 27002 is a companion code of practice. It takes the Annex A controls and explains, in depth, how to implement each one. You don't get certified to 27002 — you lean on it while implementing 27001.

How they work together

Think of 27001 as the what (the requirements and the list of controls) and 27002 as the how (practical implementation guidance). A good implementer uses both. Our Lead Implementer course covers applying the controls in practice.

Frequently asked questions

Can you get certified to ISO 27002?

No. Certification is against ISO/IEC 27001. ISO/IEC 27002 is guidance that supports implementation.

Ready to take the next step?

Browse accredited courses or book a free consultation and we'll help you choose the right path.