ISO/IEC 27006-1:2024
ISO/IEC 27006 specifies requirements and provides guidance for bodies providing audit and certification of information security management systems (ISMS). It supplements ISO/IEC 17021-1 with ISMS-specific requirements for certification bodies, including auditor competence, audit time, and certification scope determination.
ISO/IEC 27006-1:2024 is a compliance framework from International with 6 domains and 54 controls that map to 58 other frameworks. The largest domains are Process requirements: application, audit time, planning, initial certification, audits, decision, maintenance, appeals and complaints (clause 9) – ISO/IEC 27006-1:2024 (20 controls), Resource requirements: competence of personnel (clause 7) – ISO/IEC 27006-1:2024 (18 controls), Information requirements: public information, certification documents, marks, confidentiality (clause 8) – ISO/IEC 27006-1:2024 (6 controls). Every control below carries what it requires and what an assessor expects to see.
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (6)
Annexes: knowledge and skills, competence considerations, audit time, calculation methods, review of Annex A controls – ISO/IEC 27006-1:2024
| Code | Title |
|---|---|
| iso-iec-27006-1-2024::A | Annex A (normative): knowledge and skills for ISMS auditing and certification |
| iso-iec-27006-1-2024::C | Annex C (normative): audit time |
Information requirements: public information, certification documents, marks, confidentiality (clause 8) – ISO/IEC 27006-1:2024
| Code | Title |
|---|---|
| iso-iec-27006-1-2024::8.1 | Public information |
| iso-iec-27006-1-2024::8.2.2 | ISMS certification documents |
| iso-iec-27006-1-2024::8.2.3 | Reference of other standards in the ISMS certification documents |
| iso-iec-27006-1-2024::8.3 | Reference to certification and use of marks |
| iso-iec-27006-1-2024::8.4.2 | Access to organizational records |
| iso-iec-27006-1-2024::8.5 | Information exchange between a certification body and its clients |
Management system requirements for certification bodies (clause 10) – ISO/IEC 27006-1:2024
| Code | Title |
|---|---|
| iso-iec-27006-1-2024::10.1.2 | ISMS implementation by the certification body |
| iso-iec-27006-1-2024::10.2 | Option A: general management system requirements |
| iso-iec-27006-1-2024::10.3 | Option B: management system requirements in accordance with ISO 9001 |
Principles, general and structural requirements (clauses 4 to 6) – ISO/IEC 27006-1:2024
| Code | Title |
|---|---|
| iso-iec-27006-1-2024::4 | Principles |
| iso-iec-27006-1-2024::5.1 | Legal and contractual matters |
| iso-iec-27006-1-2024::5.2.2 | Conflicts of interest |
| iso-iec-27006-1-2024::5.3 | Liability and financing |
| iso-iec-27006-1-2024::6 | Structural requirements |
Process requirements: application, audit time, planning, initial certification, audits, decision, maintenance, appeals and complaints (clause 9) – ISO/IEC 27006-1:2024
| Code | Title |
|---|---|
| iso-iec-27006-1-2024::9.1.1 | Application |
| iso-iec-27006-1-2024::9.1.2 | Application review |
| iso-iec-27006-1-2024::9.1.3 | Audit programme |
| iso-iec-27006-1-2024::9.1.4 | Determining audit time |
| iso-iec-27006-1-2024::9.1.5 | Multi-site sampling |
| iso-iec-27006-1-2024::9.1.6 | Multiple management systems |
| iso-iec-27006-1-2024::9.2.1 | Determining audit objectives, scope and criteria |
| iso-iec-27006-1-2024::9.2.2 | Audit team selection and assignments |
| iso-iec-27006-1-2024::9.2.3 | Audit plan |
| iso-iec-27006-1-2024::9.3.2 | Initial certification audit |
| iso-iec-27006-1-2024::9.4.2 | Specific elements of the ISMS audit |
| iso-iec-27006-1-2024::9.4.3 | Audit report |
| iso-iec-27006-1-2024::9.5.2 | Certification decision |
| iso-iec-27006-1-2024::9.6.2 | Surveillance activities |
| iso-iec-27006-1-2024::9.6.3 | Re-certification |
| iso-iec-27006-1-2024::9.6.4 | Special audits |
| iso-iec-27006-1-2024::9.6.5 | Suspending, withdrawing or reducing the scope of certification |
| iso-iec-27006-1-2024::9.7 | Appeals |
| iso-iec-27006-1-2024::9.8.2 | Complaints |
| iso-iec-27006-1-2024::9.9 | Client records |
Resource requirements: competence of personnel (clause 7) – ISO/IEC 27006-1:2024
| Code | Title |
|---|---|
| iso-iec-27006-1-2024::7.1.2 | Generic competence requirements |
| iso-iec-27006-1-2024::7.1.3.1.1 | General requirements for audit team competence |
| iso-iec-27006-1-2024::7.1.3.1.2 | Information security management terminology, principles, practices and techniques |
| iso-iec-27006-1-2024::7.1.3.1.3 | Information security management system standards and normative documents |
| iso-iec-27006-1-2024::7.1.3.1.4 | Business management practices |
| iso-iec-27006-1-2024::7.1.3.1.5 | Client business sector |
| iso-iec-27006-1-2024::7.1.3.1.6 | Client products, processes and organization |
| iso-iec-27006-1-2024::7.1.3.2.1 | Application review: client business sector |
| iso-iec-27006-1-2024::7.1.3.2.2 | Application review: client products, processes and organization |
| iso-iec-27006-1-2024::7.1.3.3.1 | Report review and decision: general |
| iso-iec-27006-1-2024::7.1.3.3.2 | Report review and decision: information security management terminology, principles, practices and techniques |
| iso-iec-27006-1-2024::7.1.3.3.3 | Report review and decision: client business sector |
| iso-iec-27006-1-2024::7.1.3.3.4 | Report review and decision: client products, processes and organization |
| iso-iec-27006-1-2024::7.2.2.1 | Demonstration of auditor knowledge and experience: general considerations |
| iso-iec-27006-1-2024::7.2.2.2 | Selecting auditors |
| iso-iec-27006-1-2024::7.3 | Use of individual external auditors and external technical experts |
| iso-iec-27006-1-2024::7.4 | Personnel records |
| iso-iec-27006-1-2024::7.5 | Outsourcing |
Your Compliance Coverage
If you comply with ISO/IEC 27006-1:2024, you already cover:
ISO 13485:2016
2%
2 controls mapped
Compare →ISO 22301:2019
1%
1 controls mapped
Compare →US Gramm-Leach-Bliley Act (GLBA) - Higher Education Safeguards Rule
1%
1 controls mapped
Compare →+ 55 more: UAE Virtual Asset Regulatory Authority (VARA) Regulations (1%), TSA Pipeline Cybersecurity Directives (1%)
See all 58 mapped frameworks ↓Maps to 58 other frameworks
Coverage is not the same as your position
This page shows what ISO/IEC 27006-1:2024 overlaps with in general. Where your organisation actually stands, against the standard you are going for and the certifications you already hold, is a different question. Same graph and the same recorded refutations, scoped to you rather than to a pair.
The Compliance Position Diagnostic, $5,000 fixed, ten business daysWhat is ISO/IEC 27006-1:2024 and who does it apply to?
ISO/IEC 27006-1:2024 is a compliance framework from International with 6 domains and 54 controls. ISO/IEC 27006 specifies requirements and provides guidance for bodies providing audit and certification of information security management systems (ISMS). It supplements ISO/IEC 17021-1 with ISMS-specific requirements for certification bodies, including auditor competence, audit time, and certification scope determination. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
What does ISO/IEC 27006-1:2024 actually require?
ISO/IEC 27006-1:2024 has 54 controls organised across 6 domains. The largest domains are Process requirements: application, audit time, planning, initial certification, audits, decision, maintenance, appeals and complaints (clause 9) – ISO/IEC 27006-1:2024 (20 controls), Resource requirements: competence of personnel (clause 7) – ISO/IEC 27006-1:2024 (18 controls), Information requirements: public information, certification documents, marks, confidentiality (clause 8) – ISO/IEC 27006-1:2024 (6 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
If I already comply with another framework, how much of ISO/IEC 27006-1:2024 do I already cover?
ISO/IEC 27006-1:2024 maps to 58 other compliance frameworks. The top mapping partners are ISO 13485:2016 (2% coverage), ISO 22301:2019 (1% coverage), US Gramm-Leach-Bliley Act (GLBA) - Higher Education Safeguards Rule (1% coverage). Use our comparison tool to explore control-level mappings between frameworks.
How do I implement ISO/IEC 27006-1:2024?
Start your ISO/IEC 27006-1:2024 compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about ISO/IEC 27006-1:2024 requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 54 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 705 frameworks.
Get Started Free →Free forever — no credit card required