Skip to content
ReadinessNavigator

ISO/IEC 27001:2022 · Annex A · ISMS

An ISMS that can support several frameworks

ISO/IEC 27001 sets requirements for an information security management system: governance, risk treatment and the controls an organisation selects and operates. Relevant ISMS records may support NIS2 risk-management measures, IEC 62443-4-1 development processes and CRA secure-development and vulnerability-handling work. Each framework has its own scope and requirements, so the crosswalk points to evidence worth checking, not obligations already fulfilled.

Why an ISMS, and why here

One management system, evidence to review across frameworks

ISO/IEC 27001 sits at a different level from the product and operator regimes. Where the CRA governs a product and NIS2 governs an operator, 27001 governs the organisation: it asks you to define a scope, run a risk-treatment process, and operate a set of controls under management oversight — clauses 4 to 10 — with Annex A providing the control catalogue you select from.

The 2022 revision groups 93 Annex A controls into four themes (organizational, people, physical, technological). Some controls address topics that also appear in NIS2 Article 21, IEC 62443-4-1 and CRA Annex I. This site uses ISO/IEC 27001 as an organising lens for those possible links; each applicable requirement and its supporting evidence still need separate review.

This is a readiness and gap assessment against Annex A, not a certification. Certification is a two-stage audit by an accredited body; what this measures is how close your ISMS is to being audit-ready, and where the foundational controls still have gaps.

What the assessment scores

The four Annex A:2022 control themes

The 93 Annex A controls collapse into four themes. This assessment scores your coverage of each so a readiness percentage resolves into a per-theme profile — a readable gap map rather than a flat 93-line checklist.

  • A.5

    Organizational controls

    The largest theme (37 controls): policies, roles, supplier and cloud security, incident management, continuity, and legal/compliance obligations. This is where most of the NIS2 governance crosswalk lands.

  • A.6

    People controls

    Eight controls covering screening, terms of employment, awareness and training, disciplinary process, and responsibilities that survive a change or termination of role.

  • A.7

    Physical controls

    Fourteen controls for secure areas, equipment, media, and supporting utilities — the physical layer that a purely technical reading of security tends to under-weight.

  • A.8

    Technological controls

    Thirty-four controls: access control, cryptography, secure development, logging and monitoring, vulnerability management, and backup. The densest overlap with IEC 62443 and CRA technical obligations.

What carries the most weight

The foundational controls that cap the result

Some controls are load-bearing: if one is wholly absent, a high average elsewhere is misleading. Mirroring the RED assessment, these foundational controls cap the readiness band until they are in place — a disclosed weighting, not a hidden one.

  • Access control and secure authentication (A.5.15; A.8.5)

    Documented access rules and secure authentication are scored as foundational. If either is absent or unconfirmed, the readiness band is capped; identity management and privileged access are assessed separately.

  • Cryptography (A.8.24)

    Key management and appropriate use of cryptography. The primitive most other technological controls quietly depend on.

  • Backup (A.8.13)

    Information backup that is actually tested for restoration — the control that determines whether an incident is a disruption or a catastrophe.

  • Vulnerability management (A.8.8)

    Knowing and remediating technical vulnerabilities. The direct crosswalk to CRA vulnerability-handling obligations.

  • Logging and monitoring (A.8.15–A.8.16)

    Recording security events and detecting anomalies. Without it, incidents are found late or not at all.

  • Incident management (A.5.24–A.5.28)

    Planning, response, and learning from incidents — and the crosswalk to NIS2 reporting duties.

  • Supplier security (A.5.19–A.5.23)

    Managing the security of supplier relationships and the ICT supply chain — the theme NIS2 pushes hardest onto manufacturers.

One ISMS, several frameworks to review

Where ISMS evidence may support other requirements

See how this maps to NIS2 scoping

NIS2 Article 21(2) lists ten risk-management measures, including risk analysis, incident handling, business continuity and supply-chain security. An ISMS can contain relevant policies and records. Their adequacy must be checked against the applicable national NIS2 rules, the entity’s scope and its risks; an ISO/IEC 27001 control by itself does not establish NIS2 compliance.

Some IEC 62443-4-1 process requirements and CRA secure-development and vulnerability-handling duties overlap with ISMS practices. The assessment identifies existing records that could support those requirements. Closing an ISO/IEC 27001 gap may help with related work; it does not by itself close a process- or product-specific obligation.

Get in touch

Scope an ISO/IEC 27001 ISMS that fits how you already work

A short description of your organisation and what you are protecting is enough to start. We will come back with a sensible scope for the ISMS, the Annex A controls that matter most for you, and where certification effort will concentrate.

We reply within two working days.

Full contact details
consulting@readinessnavigator.com
Book a 30-minute call

Opens our scheduling page in a new tab — pick a slot that suits you.

Useful in a first message

  • What the organisation does, its size, and what information or systems need protecting.
  • Whether certification is driven by a customer requirement, a tender, or your own risk position.
  • Any existing security practices or frameworks you already run, so the ISMS builds on them.

Please keep a first message free of confidential technical detail and trade secrets. Once we reply we can agree an encrypted channel for anything sensitive.