Compliance matrix
ISO/IEC 27001 (Information Security Management)
International · Updated 2026-07-19
Applies to: Any organization certifying its information security management system (ISMS); common for enterprise and international buyers.
Vendor certification snapshot
ISO 27001 status across the 48 vendors we track, read live from each profile.
28
Certified
1
Partial
19
Not stated
Certified / supported
- Akamai Identity Cloud
- Amazon Cognito
- Auth0
- Authress
- Authsignal
- Beyond Identity
- Corbado
- Curity
- CyberArk Identity
- Descope
- Firebase Authentication
- ForgeRock
- Frontegg
- IBM Verify
- Microsoft Entra External ID
- miniOrange
- MojoAuth
- Oracle IAM Identity Domains
- Ory
- Ping Identity
- SAP Customer Data Cloud
- SSOJet
- Strivacity
- Stytch
- Transmit Security
- WorkOS
- WSO2 Identity Server
- Zitadel
Partial
Status is one signal, not a guarantee. Always confirm current certification scope directly with the vendor.
Requirements mapped to CIAM
Identity and access management (A.5.15, A.5.16)
Identities must be managed through their lifecycle and access granted on a need-to-use basis.
CIAM controls
- Full identity lifecycle: create, review, revoke
- Role-based, least-privilege access
- Periodic access reviews
Evidence
- Access review records
- Role definitions
Ask the vendor
- Do you support lifecycle provisioning and periodic access review workflows?
Authentication information & secure authentication (A.5.17, A.8.5)
Authentication must be secure, and secrets protected against disclosure.
CIAM controls
- MFA and phishing-resistant options
- Secure credential storage (hashing, encryption)
- Protection against brute force and credential stuffing
Evidence
- Authentication policy
- Credential storage documentation
Ask the vendor
- How are credentials stored, and what anti-brute-force controls exist?
Logging and monitoring (A.8.15, A.8.16)
Identity and access events must be logged and monitored for anomalies.
CIAM controls
- Audit logs of authentication and access
- Monitoring and alerting on anomalies
Evidence
- Audit log samples
- Monitoring configuration
Ask the vendor
- What identity events are logged, and can they be exported for monitoring?
Take this into procurement
Turn these requirements into vendor questions.
The vendor questions above map directly into an RFP or an evaluation checklist you can share with security and procurement.
Go deeper
Where it bites hardest
FAQ
- How is ISO 27001 different from SOC 2 for CIAM?
- Both attest to security controls, and the same identity controls (MFA, RBAC, logging) serve both. ISO 27001 is an internationally recognized certification against a fixed Annex A control set; SOC 2 is a US-centric attestation report against the Trust Services Criteria. Enterprises outside North America often prefer ISO 27001.
Source
ISO/IEC 27001:2022 (ISO catalogue)
This matrix is practitioner guidance, not legal advice, and does not establish an attorney-client relationship. Confirm your obligations with qualified counsel. See our disclaimer.