Back to Frameworks

ISO/IEC 27006:2024

International
v2024
13 domains
33 controls

ISO/IEC 27006 specifies requirements and provides guidance for bodies providing audit and certification of information security management systems (ISMS). It supplements ISO/IEC 17021-1 with ISMS-specific requirements for certification bodies, including auditor competence, audit time, and certification scope determination.

Unverified

ISO/IEC 27006:2024 is a compliance framework from International with 13 domains and 33 controls that map to 59 other frameworks. The largest domains are Audit (7 controls), Clause 9: Audit and Certification Process Requirements (5 controls), Resources (4 controls). Every control below carries what it requires and what an assessor expects to see.

Maintained by Gerard BlokdykControl text last updated

Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.

Framework Domains (13)

Annex A

1 controls
Controls in the Annex A domain of ISO/IEC 27006:20241 controls
CodeTitle
27006-A.1Auditor Competence Areas

Annex B

1 controls
Controls in the Annex B domain of ISO/IEC 27006:20241 controls
CodeTitle
27006-B.1Audit Time Determination

Annex C-E: Audit Time and Controls

3 controls
Controls in the Annex C-E: Audit Time and Controls domain of ISO/IEC 27006:20243 controls
CodeTitle
27006-CAudit time guidance
27006-DAudit time calculation methods
27006-EControls alignment

Audit

7 controls
Controls in the Audit domain of ISO/IEC 27006:20247 controls
CodeTitle
27006-7.2Audit Programme
27006-7.3Stage 1 Audit
27006-7.4Stage 2 Audit
27006-7.5Surveillance Audits
27006-7.6Recertification Audit
27006-7.7Special Audits
27006-7.8Reporting

Clause 5: Structural Requirements

2 controls
Controls in the Clause 5: Structural Requirements domain of ISO/IEC 27006:20242 controls
CodeTitle
27006-5.1General Requirements for Certification Bodies
27006-5.2Management of Impartiality

Clause 6: Resource Requirements

1 controls
Controls in the Clause 6: Resource Requirements domain of ISO/IEC 27006:20241 controls
CodeTitle
27006-6.1Competence of personnel

Clause 7: Process Requirements - Competence

3 controls
Controls in the Clause 7: Process Requirements - Competence domain of ISO/IEC 27006:20243 controls
CodeTitle
27006-7.1General competence requirements
27006-7.1.2Multi-Site Sampling
27006-7.1.3Technical knowledge requirements

Clause 8: Certification Documents and Information Requirements

3 controls
Controls in the Clause 8: Certification Documents and Information Requirements domain of ISO/IEC 27006:20243 controls
CodeTitle
27006-8.1Certification Decision
27006-8.2Suspension, Withdrawal, Reduction
27006-8.2.3Referencing other standards

Clause 9: Audit and Certification Process Requirements

5 controls
Controls in the Clause 9: Audit and Certification Process Requirements domain of ISO/IEC 27006:20245 controls
CodeTitle
27006-9.1Complaints and Appeals
27006-9.1.3.3Remote audit provisions
27006-9.3Initial certification
27006-9.3.2.2Certification decision process
27006-9.4Surveillance and recertification

Financial Stability

1 controls
Controls in the Financial Stability domain of ISO/IEC 27006:20241 controls
CodeTitle
27006-5.3Liability and Financing

Management

1 controls
Controls in the Management domain of ISO/IEC 27006:20241 controls
CodeTitle
27006-9.2Management System Requirements

Process

1 controls
Controls in the Process domain of ISO/IEC 27006:20241 controls
CodeTitle
27006-7.1.1Determining Audit Time

Resources

4 controls
Controls in the Resources domain of ISO/IEC 27006:20244 controls
CodeTitle
27006-6.1.1Competence of Personnel
27006-6.1.2Personnel Involved in Certification
27006-6.1.3Use of Individual External Auditors and Technical Experts
27006-6.2Personnel Records

Your Compliance Coverage

If you comply with ISO/IEC 27006:2024, you already cover:

Maps to 59 other frameworks

33 total controls
ISO 13485:2016
2 source controls mapped|2 target controls covered
6%
ISO 22301:2019
1 source controls mapped|1 target controls covered
3%
ISO/IEC 42001:2023
1 source controls mapped|1 target controls covered
3%
ISO/IEC 17025:2017 - General Requirements for Testing and Calibration
1 source controls mapped|3 target controls covered
3%
ISO 27018:2019
1 source controls mapped|1 target controls covered
3%
US Gramm-Leach-Bliley Act (GLBA) - Higher Education Safeguards Rule
1 source controls mapped|1 target controls covered
3%
UAE Virtual Asset Regulatory Authority (VARA) Regulations
1 source controls mapped|1 target controls covered
3%
TSA Pipeline Cybersecurity Directives
1 source controls mapped|1 target controls covered
3%
TEFCA - Trusted Exchange Framework and Common Agreement
1 source controls mapped|1 target controls covered
3%
OWASP DevSecOps Maturity Model (DSOMM)
1 source controls mapped|1 target controls covered
3%
Oman National Cybersecurity Framework
1 source controls mapped|1 target controls covered
3%
3%
NIST SP 800-146
1 source controls mapped|1 target controls covered
3%
NIST SP 800-145
1 source controls mapped|1 target controls covered
3%
NIST SP 800-144
1 source controls mapped|1 target controls covered
3%
New Zealand Information Security Manual (NZISM)
1 source controls mapped|1 target controls covered
3%
NERC CIP
1 source controls mapped|1 target controls covered
3%
MTCS (Singapore)
1 source controls mapped|1 target controls covered
3%
Japan FSA Cybersecurity Guidelines for Financial Institutions
1 source controls mapped|1 target controls covered
3%
ISMAP (Japan)
1 source controls mapped|1 target controls covered
3%
IMO Maritime Cybersecurity Guidelines (MSC-FAL.1/Circ.3/Rev.2)
1 source controls mapped|1 target controls covered
3%
IEEE 1686
1 source controls mapped|1 target controls covered
3%
HKMA Cyber Resilience Assessment Framework (C-RAF)
1 source controls mapped|1 target controls covered
3%
Ghana Cybersecurity Act
1 source controls mapped|1 target controls covered
3%
FTC GLBA Safeguards Rule (16 CFR Part 314)
1 source controls mapped|1 target controls covered
3%
Florida Digital Bill of Rights (FDBR)
1 source controls mapped|1 target controls covered
3%
FISMA
1 source controls mapped|1 target controls covered
3%
FedRAMP Rev 5
1 source controls mapped|1 target controls covered
3%
FedRAMP High
1 source controls mapped|2 target controls covered
3%
NIST SP 800-53 Revision 5.1 HIGH
1 source controls mapped|2 target controls covered
3%
FedRAMP Moderate
1 source controls mapped|2 target controls covered
3%
ASD Strategies to Mitigate Cyber Security Incidents
1 source controls mapped|2 target controls covered
3%
Belgium CyberFundamentals
1 source controls mapped|1 target controls covered
3%
Canada Artificial Intelligence and Data Act (AIDA)
1 source controls mapped|1 target controls covered
3%
US SEC Digital Assets and Crypto Regulatory Framework
1 source controls mapped|1 target controls covered
3%
NRC 10 CFR 73.54 - Nuclear Facility Cybersecurity
1 source controls mapped|1 target controls covered
3%
API 1164
1 source controls mapped|1 target controls covered
3%
FFIEC Cybersecurity Assessment Tool (CAT)
1 source controls mapped|1 target controls covered
3%
NIST SP 800-171A Rev 3 - Assessing CUI Security Requirements
1 source controls mapped|1 target controls covered
3%
NIST Cybersecurity Framework 2.0
1 source controls mapped|1 target controls covered
3%
IAIS Insurance Core Principles (ICPs)
1 source controls mapped|1 target controls covered
3%
ISO/IEC 27400:2022
1 source controls mapped|1 target controls covered
3%
ISO 27018
1 source controls mapped|1 target controls covered
3%
ISO 27019
1 source controls mapped|1 target controls covered
3%
NIST SP 800-190
1 source controls mapped|1 target controls covered
3%
Austria Data Protection Act (Datenschutzgesetz, DSG, amended 2018)
1 source controls mapped|1 target controls covered
3%
NIST SP 1800-32
1 source controls mapped|1 target controls covered
3%
ISO 28001:2007 Supply Chain Security Management
1 source controls mapped|1 target controls covered
3%
ISO 27017
1 source controls mapped|1 target controls covered
3%
South Korea ISMS-P
1 source controls mapped|1 target controls covered
3%
BSI IT-Grundschutz
1 source controls mapped|1 target controls covered
3%
NIST SP 800-53 Rev 5 MODERATE
1 source controls mapped|1 target controls covered
3%
NIST SP 800-53 Rev 5 LOW
1 source controls mapped|1 target controls covered
3%
IEC 62443
1 source controls mapped|1 target controls covered
3%
UK Telecommunications (Security) Act 2021
1 source controls mapped|1 target controls covered
3%
Singapore Government Instruction Manual on ICT&SS Management (IM8)
1 source controls mapped|1 target controls covered
3%
NIST SP 800-53 Rev 5
1 source controls mapped|1 target controls covered
3%

What is ISO/IEC 27006:2024 and who does it apply to?

ISO/IEC 27006:2024 is a compliance framework from International with 13 domains and 33 controls. ISO/IEC 27006 specifies requirements and provides guidance for bodies providing audit and certification of information security management systems (ISMS). It supplements ISO/IEC 17021-1 with ISMS-specific requirements for certification bodies, including auditor competence, audit time, and certification scope determination. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.

What does ISO/IEC 27006:2024 actually require?

ISO/IEC 27006:2024 has 33 controls organised across 13 domains. The largest domains are Audit (7 controls), Clause 9: Audit and Certification Process Requirements (5 controls), Resources (4 controls). Each control defines specific requirements that organisations must implement to achieve compliance.

If I already comply with another framework, how much of ISO/IEC 27006:2024 do I already cover?

ISO/IEC 27006:2024 maps to 59 other compliance frameworks. The top mapping partners are ISO 13485:2016 (6% coverage), ISO 22301:2019 (3% coverage), ISO/IEC 42001:2023 (3% coverage). Use our comparison tool to explore control-level mappings between frameworks.

How do I implement ISO/IEC 27006:2024?

Start your ISO/IEC 27006:2024 compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about ISO/IEC 27006:2024 requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 33 controls and track your progress.

Start Your Compliance Journey

Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 686 frameworks.

Get Started Free →

Free forever — no credit card required