Skip to content

Compliance matrix

ISO/IEC 27001 (Information Security Management)

International · Updated 2026-07-19

Applies to: Any organization certifying its information security management system (ISMS); common for enterprise and international buyers.

Vendor certification snapshot

ISO 27001 status across the 48 vendors we track, read live from each profile.

28

Certified

1

Partial

19

Not stated

Status is one signal, not a guarantee. Always confirm current certification scope directly with the vendor.

Requirements mapped to CIAM

Identity and access management (A.5.15, A.5.16)

Identities must be managed through their lifecycle and access granted on a need-to-use basis.

CIAM controls

  • Full identity lifecycle: create, review, revoke
  • Role-based, least-privilege access
  • Periodic access reviews

Evidence

  • Access review records
  • Role definitions

Ask the vendor

  • Do you support lifecycle provisioning and periodic access review workflows?

Authentication information & secure authentication (A.5.17, A.8.5)

Authentication must be secure, and secrets protected against disclosure.

CIAM controls

  • MFA and phishing-resistant options
  • Secure credential storage (hashing, encryption)
  • Protection against brute force and credential stuffing

Evidence

  • Authentication policy
  • Credential storage documentation

Ask the vendor

  • How are credentials stored, and what anti-brute-force controls exist?

Logging and monitoring (A.8.15, A.8.16)

Identity and access events must be logged and monitored for anomalies.

CIAM controls

  • Audit logs of authentication and access
  • Monitoring and alerting on anomalies

Evidence

  • Audit log samples
  • Monitoring configuration

Ask the vendor

  • What identity events are logged, and can they be exported for monitoring?

Take this into procurement

Turn these requirements into vendor questions.

The vendor questions above map directly into an RFP or an evaluation checklist you can share with security and procurement.

Go deeper

Where it bites hardest

FAQ

How is ISO 27001 different from SOC 2 for CIAM?
Both attest to security controls, and the same identity controls (MFA, RBAC, logging) serve both. ISO 27001 is an internationally recognized certification against a fixed Annex A control set; SOC 2 is a US-centric attestation report against the Trust Services Criteria. Enterprises outside North America often prefer ISO 27001.

Source

ISO/IEC 27001:2022 (ISO catalogue)

This matrix is practitioner guidance, not legal advice, and does not establish an attorney-client relationship. Confirm your obligations with qualified counsel. See our disclaimer.