
ISO 27001 Certification: A Practical Guide for 2026
What the 2022 edition actually asks of you, how the certification audit works, and the six decisions that determine whether you certify in five months or fifteen.
The new Govern function, a broader audience, stronger supply chain expectations — and a practical method for turning the framework into a programme your board can follow.

The original NIST Cybersecurity Framework was written for US critical infrastructure. It became a global reference anyway, because it gave boards and security teams a shared language. Version 2.0, published in February 2024, formally widens the audience to all organisations, regardless of size, sector or country.
The framework remains voluntary and outcome-based. It tells you what good looks like, not which products to buy, and it points to other standards — ISO 27001, the CIS Controls, NIST SP 800-53 — for implementation detail.
CSF 2.0 introduces a sixth function, Govern, which sits at the centre of the other five. It captures things that were previously implicit or scattered:
The practical effect is that cybersecurity is framed as an enterprise risk owned by leadership, not a technical function reporting through IT. If your board cannot describe your cyber risk appetite, Govern is where to start.
| Function | What it answers |
|---|---|
| Govern | How is cybersecurity risk directed, owned and overseen? |
| Identify | What assets, suppliers and risks do we have? |
| Protect | What safeguards reduce the likelihood and impact of incidents? |
| Detect | How do we find attacks and anomalies quickly? |
| Respond | What do we do when an incident is detected? |
| Recover | How do we restore operations and learn from what happened? |
Beneath the six functions sit 22 categories and 106 subcategories. NIST also publishes implementation examples, quick-start guides for small businesses and a searchable online reference tool that maps each subcategory to other standards.
The framework is most useful when it becomes a roadmap rather than a checklist. A proven approach:
CSF 2.0 and ISO 27001 complement each other. ISO gives you a certifiable management system; CSF gives you an outcome view that boards and regulators find easy to read. Mapping your ISO controls to CSF subcategories typically shows strong coverage in Protect and Identify, and gaps in Govern — particularly around formal risk appetite and supplier oversight.
A focused first cycle — current profile, target profile, prioritised roadmap and quarterly reporting — delivers more value than an exhaustive assessment that nobody acts on.

What the 2022 edition actually asks of you, how the certification audit works, and the six decisions that determine whether you certify in five months or fifteen.

Type I versus Type II, how observation periods and sampling work, and the ten control areas where first-time SOC 2 audits most often produce exceptions.

All future-dated requirements have been mandatory since March 2025. These are the ones assessors most often find incomplete — and what good evidence looks like.
Tell us what you are working on. A senior NAZZTEC consultant will come back within one business day with a practical view.
We respond to every enquiry within one business day.