ISO/IEC 27001:2022 is the international standard for an information security management system (ISMS). Neither the DFSA nor the FSRA requires it, but it gives a regulated firm a structured, independently audited way to run the risk assessment, governance, supplier and incident processes its regulator expects. It certifies your management system within a defined scope, not compliance with a regulator’s rules.
ISO 27001 certifies an information security management system: the policies, roles, risk process and controls you use to protect information, and the way you review and improve them. You decide the scope (for example, the whole firm or one service), assess your risks, and record which controls you apply in a Statement of Applicability. The 2022 edition’s Annex A lists 93 controls in four themes: organisational, people, physical and technological.
An accredited certification body audits you in two stages, then returns for surveillance audits, usually each year, with recertification every three years.
The transition period from the 2013 edition ended on 31 October 2025. Certificates issued to the 2013 edition expired by then, and an organisation that missed the deadline was treated as a new client requiring a full initial audit. If a supplier or client shows you an ISO 27001 certificate today, check that it refers to ISO/IEC 27001:2022.
The mapping below is indicative. It shows where ISO 27001 gives you a recognised structure for something the regulators already expect.
| Regulator expectation | ISO 27001:2022 element | What it gives you |
|---|---|---|
| Governing-body approved framework and accountability | Clauses 4 and 5: context, scope, leadership and policy | Management commitment that is audited, not just written down |
| Cyber risk assessment and treatment | Clause 6: risk assessment, treatment and Statement of Applicability | A repeatable method with recorded decisions |
| Asset inventory | Annex A 5.9 | A maintained register of information and associated assets |
| Access control and authentication | Annex A 5.15 to 5.18, 8.2 and 8.5 | Least privilege, access reviews and secure authentication |
| Third-party and ICT provider oversight | Annex A 5.19 to 5.23 | Supplier agreements, monitoring and cloud service controls |
| Monitoring and logging | Annex A 8.15 and 8.16 | Logs and monitoring that are defined and reviewed |
| Incident response | Annex A 5.24 to 5.28 | Planning, assessment, response, learning and evidence handling |
| Staff awareness | Annex A 6.3 | Awareness, education and training |
| Resilience and recovery | Annex A 5.29, 5.30 and 8.13 | Continuity and backup arrangements |
ISO 27001 does not replace your regulatory obligations. Incident notification to the DFSA or FSRA, and your duties under DIFC or ADGM data protection law, still apply in full.
Timelines depend on scope, maturity and how much evidence you already keep. A small, well-run firm is usually looking at months rather than weeks. Choose a certification body accredited by a recognised accreditation body, and confirm it is accredited for ISO 27001 in your sector.
Regulators expect you to carry out due diligence on your IT providers, and an ISO 27001 certificate is useful evidence, but only if you read it. Check the accreditation of the certification body, the scope statement (does it cover the services you buy, and the locations they run from), the validity dates and the edition. If you need more detail, ask to see the Statement of Applicability under a non-disclosure agreement.
Cre8 IT’s information security management system is certified to ISO/IEC 27001:2022, and we are also certified to ISO 9001 for quality management. We expect clients to ask these questions and are happy to answer them.
Last reviewed 19 September 2026. This guide is general information, not legal or regulatory advice. Rules change, so check the current text and take advice from your compliance officer or legal adviser before relying on it.
