Back to Frameworks

ISO/IEC 27006-1:2024

International
v2024 (first edition of part 1; replaces ISO/IEC 27006:2015 with Amd 1:2020)
6 domains
54 controls

ISO/IEC 27006 specifies requirements and provides guidance for bodies providing audit and certification of information security management systems (ISMS). It supplements ISO/IEC 17021-1 with ISMS-specific requirements for certification bodies, including auditor competence, audit time, and certification scope determination.

Verified

ISO/IEC 27006-1:2024 is a compliance framework from International with 6 domains and 54 controls that map to 58 other frameworks. The largest domains are Process requirements: application, audit time, planning, initial certification, audits, decision, maintenance, appeals and complaints (clause 9) – ISO/IEC 27006-1:2024 (20 controls), Resource requirements: competence of personnel (clause 7) – ISO/IEC 27006-1:2024 (18 controls), Information requirements: public information, certification documents, marks, confidentiality (clause 8) – ISO/IEC 27006-1:2024 (6 controls). Every control below carries what it requires and what an assessor expects to see.

Maintained by Gerard BlokdykControl text last updated

Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.

Framework Domains (6)

Annexes: knowledge and skills, competence considerations, audit time, calculation methods, review of Annex A controls – ISO/IEC 27006-1:2024

2 controls
Controls in the Annexes: knowledge and skills, competence considerations, audit time, calculation methods, review of Annex A controls – ISO/IEC 27006-1:2024 domain of ISO/IEC 27006-1:20242 controls
CodeTitle
iso-iec-27006-1-2024::AAnnex A (normative): knowledge and skills for ISMS auditing and certification
iso-iec-27006-1-2024::CAnnex C (normative): audit time

Information requirements: public information, certification documents, marks, confidentiality (clause 8) – ISO/IEC 27006-1:2024

6 controls
Controls in the Information requirements: public information, certification documents, marks, confidentiality (clause 8) – ISO/IEC 27006-1:2024 domain of ISO/IEC 27006-1:20246 controls
CodeTitle
iso-iec-27006-1-2024::8.1Public information
iso-iec-27006-1-2024::8.2.2ISMS certification documents
iso-iec-27006-1-2024::8.2.3Reference of other standards in the ISMS certification documents
iso-iec-27006-1-2024::8.3Reference to certification and use of marks
iso-iec-27006-1-2024::8.4.2Access to organizational records
iso-iec-27006-1-2024::8.5Information exchange between a certification body and its clients

Management system requirements for certification bodies (clause 10) – ISO/IEC 27006-1:2024

3 controls
Controls in the Management system requirements for certification bodies (clause 10) – ISO/IEC 27006-1:2024 domain of ISO/IEC 27006-1:20243 controls
CodeTitle
iso-iec-27006-1-2024::10.1.2ISMS implementation by the certification body
iso-iec-27006-1-2024::10.2Option A: general management system requirements
iso-iec-27006-1-2024::10.3Option B: management system requirements in accordance with ISO 9001

Principles, general and structural requirements (clauses 4 to 6) – ISO/IEC 27006-1:2024

5 controls
Controls in the Principles, general and structural requirements (clauses 4 to 6) – ISO/IEC 27006-1:2024 domain of ISO/IEC 27006-1:20245 controls
CodeTitle
iso-iec-27006-1-2024::4Principles
iso-iec-27006-1-2024::5.1Legal and contractual matters
iso-iec-27006-1-2024::5.2.2Conflicts of interest
iso-iec-27006-1-2024::5.3Liability and financing
iso-iec-27006-1-2024::6Structural requirements

Process requirements: application, audit time, planning, initial certification, audits, decision, maintenance, appeals and complaints (clause 9) – ISO/IEC 27006-1:2024

20 controls
Controls in the Process requirements: application, audit time, planning, initial certification, audits, decision, maintenance, appeals and complaints (clause 9) – ISO/IEC 27006-1:2024 domain of ISO/IEC 27006-1:202420 controls
CodeTitle
iso-iec-27006-1-2024::9.1.1Application
iso-iec-27006-1-2024::9.1.2Application review
iso-iec-27006-1-2024::9.1.3Audit programme
iso-iec-27006-1-2024::9.1.4Determining audit time
iso-iec-27006-1-2024::9.1.5Multi-site sampling
iso-iec-27006-1-2024::9.1.6Multiple management systems
iso-iec-27006-1-2024::9.2.1Determining audit objectives, scope and criteria
iso-iec-27006-1-2024::9.2.2Audit team selection and assignments
iso-iec-27006-1-2024::9.2.3Audit plan
iso-iec-27006-1-2024::9.3.2Initial certification audit
iso-iec-27006-1-2024::9.4.2Specific elements of the ISMS audit
iso-iec-27006-1-2024::9.4.3Audit report
iso-iec-27006-1-2024::9.5.2Certification decision
iso-iec-27006-1-2024::9.6.2Surveillance activities
iso-iec-27006-1-2024::9.6.3Re-certification
iso-iec-27006-1-2024::9.6.4Special audits
iso-iec-27006-1-2024::9.6.5Suspending, withdrawing or reducing the scope of certification
iso-iec-27006-1-2024::9.7Appeals
iso-iec-27006-1-2024::9.8.2Complaints
iso-iec-27006-1-2024::9.9Client records

Resource requirements: competence of personnel (clause 7) – ISO/IEC 27006-1:2024

18 controls
Controls in the Resource requirements: competence of personnel (clause 7) – ISO/IEC 27006-1:2024 domain of ISO/IEC 27006-1:202418 controls
CodeTitle
iso-iec-27006-1-2024::7.1.2Generic competence requirements
iso-iec-27006-1-2024::7.1.3.1.1General requirements for audit team competence
iso-iec-27006-1-2024::7.1.3.1.2Information security management terminology, principles, practices and techniques
iso-iec-27006-1-2024::7.1.3.1.3Information security management system standards and normative documents
iso-iec-27006-1-2024::7.1.3.1.4Business management practices
iso-iec-27006-1-2024::7.1.3.1.5Client business sector
iso-iec-27006-1-2024::7.1.3.1.6Client products, processes and organization
iso-iec-27006-1-2024::7.1.3.2.1Application review: client business sector
iso-iec-27006-1-2024::7.1.3.2.2Application review: client products, processes and organization
iso-iec-27006-1-2024::7.1.3.3.1Report review and decision: general
iso-iec-27006-1-2024::7.1.3.3.2Report review and decision: information security management terminology, principles, practices and techniques
iso-iec-27006-1-2024::7.1.3.3.3Report review and decision: client business sector
iso-iec-27006-1-2024::7.1.3.3.4Report review and decision: client products, processes and organization
iso-iec-27006-1-2024::7.2.2.1Demonstration of auditor knowledge and experience: general considerations
iso-iec-27006-1-2024::7.2.2.2Selecting auditors
iso-iec-27006-1-2024::7.3Use of individual external auditors and external technical experts
iso-iec-27006-1-2024::7.4Personnel records
iso-iec-27006-1-2024::7.5Outsourcing

Your Compliance Coverage

If you comply with ISO/IEC 27006-1:2024, you already cover:

Maps to 58 other frameworks

87 total controls
ISO 13485:2016
2 source controls mapped|2 target controls covered
2%
ISO 22301:2019
1 source controls mapped|1 target controls covered
1%
US Gramm-Leach-Bliley Act (GLBA) - Higher Education Safeguards Rule
1 source controls mapped|1 target controls covered
1%
UAE Virtual Asset Regulatory Authority (VARA) Regulations
1 source controls mapped|1 target controls covered
1%
TSA Pipeline Cybersecurity Directives
1 source controls mapped|1 target controls covered
1%
TEFCA - Trusted Exchange Framework and Common Agreement
1 source controls mapped|1 target controls covered
1%
OWASP DevSecOps Maturity Model (DSOMM)
1 source controls mapped|1 target controls covered
1%
Oman National Cybersecurity Framework
1 source controls mapped|1 target controls covered
1%
1%
NIST SP 800-146
1 source controls mapped|1 target controls covered
1%
NIST SP 800-145
1 source controls mapped|1 target controls covered
1%
NIST SP 800-144
1 source controls mapped|1 target controls covered
1%
New Zealand Information Security Manual (NZISM)
1 source controls mapped|1 target controls covered
1%
NERC CIP
1 source controls mapped|1 target controls covered
1%
MTCS (Singapore)
1 source controls mapped|1 target controls covered
1%
Japan FSA Cybersecurity Guidelines for Financial Institutions
1 source controls mapped|1 target controls covered
1%
ISMAP (Japan)
1 source controls mapped|1 target controls covered
1%
IMO Maritime Cybersecurity Guidelines (MSC-FAL.1/Circ.3/Rev.2)
1 source controls mapped|1 target controls covered
1%
IEEE 1686
1 source controls mapped|1 target controls covered
1%
HKMA Cyber Resilience Assessment Framework (C-RAF)
1 source controls mapped|1 target controls covered
1%
Ghana Cybersecurity Act
1 source controls mapped|1 target controls covered
1%
FTC GLBA Safeguards Rule (16 CFR Part 314)
1 source controls mapped|1 target controls covered
1%
Florida Digital Bill of Rights (FDBR)
1 source controls mapped|1 target controls covered
1%
FISMA
1 source controls mapped|1 target controls covered
1%
FedRAMP Rev 5
1 source controls mapped|1 target controls covered
1%
FedRAMP High
1 source controls mapped|2 target controls covered
1%
NIST SP 800-53 Revision 5.1 HIGH
1 source controls mapped|2 target controls covered
1%
FedRAMP Moderate
1 source controls mapped|2 target controls covered
1%
ASD Strategies to Mitigate Cyber Security Incidents
1 source controls mapped|2 target controls covered
1%
Belgium CyberFundamentals
1 source controls mapped|1 target controls covered
1%
Canada Artificial Intelligence and Data Act (AIDA)
1 source controls mapped|1 target controls covered
1%
US SEC Digital Assets and Crypto Regulatory Framework
1 source controls mapped|1 target controls covered
1%
NRC 10 CFR 73.54 - Nuclear Facility Cybersecurity
1 source controls mapped|1 target controls covered
1%
API 1164
1 source controls mapped|1 target controls covered
1%
FFIEC Cybersecurity Assessment Tool (CAT)
1 source controls mapped|1 target controls covered
1%
NIST Cybersecurity Framework 2.0
1 source controls mapped|1 target controls covered
1%
IAIS Insurance Core Principles (ICPs)
1 source controls mapped|1 target controls covered
1%
ISO/IEC 27400:2022
1 source controls mapped|1 target controls covered
1%
ISO 27018
1 source controls mapped|1 target controls covered
1%
ISO 27019
1 source controls mapped|1 target controls covered
1%
NIST SP 800-190
1 source controls mapped|1 target controls covered
1%
Austria Data Protection Act (Datenschutzgesetz, DSG, amended 2018)
1 source controls mapped|1 target controls covered
1%
NIST SP 1800-32
1 source controls mapped|1 target controls covered
1%
ISO 28001:2007 Supply Chain Security Management
1 source controls mapped|1 target controls covered
1%
ISO 27017
1 source controls mapped|1 target controls covered
1%
South Korea ISMS-P
1 source controls mapped|1 target controls covered
1%
BSI IT-Grundschutz
1 source controls mapped|1 target controls covered
1%
NIST SP 800-53 Rev 5 MODERATE
1 source controls mapped|1 target controls covered
1%
NIST SP 800-53 Rev 5 LOW
1 source controls mapped|1 target controls covered
1%
IEC 62443
1 source controls mapped|1 target controls covered
1%
UK Telecommunications (Security) Act 2021
1 source controls mapped|1 target controls covered
1%
Singapore Government Instruction Manual on ICT&SS Management (IM8)
1 source controls mapped|1 target controls covered
1%
NIST SP 800-53 Rev 5
1 source controls mapped|1 target controls covered
1%
ISO/IEC 42001:2023
1 source controls mapped|1 target controls covered
1%
ISO/IEC 17025:2017 - General Requirements for Testing and Calibration
1 source controls mapped|2 target controls covered
1%
ISO 27018:2019
1 source controls mapped|1 target controls covered
1%

Coverage is not the same as your position

This page shows what ISO/IEC 27006-1:2024 overlaps with in general. Where your organisation actually stands, against the standard you are going for and the certifications you already hold, is a different question. Same graph and the same recorded refutations, scoped to you rather than to a pair.

The Compliance Position Diagnostic, $5,000 fixed, ten business days

What is ISO/IEC 27006-1:2024 and who does it apply to?

ISO/IEC 27006-1:2024 is a compliance framework from International with 6 domains and 54 controls. ISO/IEC 27006 specifies requirements and provides guidance for bodies providing audit and certification of information security management systems (ISMS). It supplements ISO/IEC 17021-1 with ISMS-specific requirements for certification bodies, including auditor competence, audit time, and certification scope determination. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.

What does ISO/IEC 27006-1:2024 actually require?

ISO/IEC 27006-1:2024 has 54 controls organised across 6 domains. The largest domains are Process requirements: application, audit time, planning, initial certification, audits, decision, maintenance, appeals and complaints (clause 9) – ISO/IEC 27006-1:2024 (20 controls), Resource requirements: competence of personnel (clause 7) – ISO/IEC 27006-1:2024 (18 controls), Information requirements: public information, certification documents, marks, confidentiality (clause 8) – ISO/IEC 27006-1:2024 (6 controls). Each control defines specific requirements that organisations must implement to achieve compliance.

If I already comply with another framework, how much of ISO/IEC 27006-1:2024 do I already cover?

ISO/IEC 27006-1:2024 maps to 58 other compliance frameworks. The top mapping partners are ISO 13485:2016 (2% coverage), ISO 22301:2019 (1% coverage), US Gramm-Leach-Bliley Act (GLBA) - Higher Education Safeguards Rule (1% coverage). Use our comparison tool to explore control-level mappings between frameworks.

How do I implement ISO/IEC 27006-1:2024?

Start your ISO/IEC 27006-1:2024 compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about ISO/IEC 27006-1:2024 requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 54 controls and track your progress.

Start Your Compliance Journey

Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 705 frameworks.

Get Started Free →

Free forever — no credit card required