
ISO 27001 Certification: A Practical Guide for 2026
What the 2022 edition actually asks of you, how the certification audit works, and the six decisions that determine whether you certify in five months or fifteen.
All future-dated requirements have been mandatory since March 2025. These are the ones assessors most often find incomplete — and what good evidence looks like.

PCI DSS v4.0 was published in March 2022. Version 3.2.1 was retired on 31 March 2024, and a limited revision, v4.0.1, was published in June 2024 to clarify wording without adding requirements. Most importantly, the requirements that v4.0 introduced as “future-dated” became mandatory on 31 March 2025.
In our experience, organisations that passed their first v4.0 assessment by leaning on the grace period are now finding the future-dated requirements harder than expected. The following are the ones that most often produce findings.
These requirements target e-skimming attacks, where malicious JavaScript on a checkout page steals card data. Requirement 6.4.3 expects you to maintain an inventory of every script on payment pages, justify why each is needed, authorise it and confirm its integrity. Requirement 11.6.1 expects a mechanism that detects unauthorised changes to those pages and their HTTP headers, and alerts you.
Marketing tags, analytics, chat widgets and A/B testing tools are the usual surprise. The PCI Security Standards Council has since clarified how these requirements apply to merchants that fully outsource their payment page to a validated provider — confirm your eligibility with your assessor rather than assuming.
MFA is now required for all access into the cardholder data environment, not only administrative or remote access. Service accounts and automated processes need a documented approach, and “the VPN has MFA” is not sufficient if users can then reach CDE systems without a second factor.
Several requirements now let you set your own frequency for an activity — for example, how often to review certain logs or change certain credentials — provided you document a targeted risk analysis justifying it. Assessors increasingly ask to see these analyses. A single paragraph with no reasoning will not satisfy them; a short, structured analysis per requirement will.
You must have processes and automated mechanisms to detect and protect personnel against phishing attacks, and awareness training must cover phishing and social engineering. Email filtering with anti-spoofing controls — DMARC, SPF and DKIM — is the usual technical foundation.
Manual daily review of audit logs is no longer adequate. Automated mechanisms must perform the reviews and raise alerts. A SIEM or managed detection service is the typical answer; the evidence assessors want is proof that alerts are generated and acted on.
Scope must be documented and confirmed at least every 12 months and after significant change, and service providers must do so every six months. This means a real exercise — data-flow diagrams, discovery of where card data actually lives, and confirmation that segmentation still works — not a copy of last year's document.
Disk-level or partition-level encryption is no longer acceptable on its own for rendering stored card numbers unreadable on non-removable media. If you rely on it, you will need file-, column- or field-level protection, or tokenisation.
The most effective PCI programme is the smallest one. Tokenisation, hosted payment pages, point-to-point encryption at the terminal and strict network segmentation all reduce the number of systems in scope — and with them the number of requirements you must evidence. Before investing in controls, ask whether the system needs to touch card data at all.

What the 2022 edition actually asks of you, how the certification audit works, and the six decisions that determine whether you certify in five months or fifteen.

Type I versus Type II, how observation periods and sampling work, and the ten control areas where first-time SOC 2 audits most often produce exceptions.

The new Govern function, a broader audience, stronger supply chain expectations — and a practical method for turning the framework into a programme your board can follow.
Tell us what you are working on. A senior NAZZTEC consultant will come back within one business day with a practical view.
We respond to every enquiry within one business day.