ISO/IEC 27001

ISO/IEC 27001 certifications

ISO/IEC 27001 is the international standard for an information security management system. There is no single “ISO 27001 exam” for individuals — there are two main credentials, and which one you sit depends on whether you build management systems or audit them.

What ISO/IEC 27001 actually is

ISO/IEC 27001 specifies the requirements for establishing, operating and continually improving an information security management system (ISMS). Clauses 4 to 10 carry the requirements an organization must meet; Annex A lists reference controls it may select from after assessing risk. The distinction matters more than almost anything else on either exam: a requirement is something you must satisfy, a control is something you choose.

An organization is certified to ISO/IEC 27001 by an accredited certification body after a two-stage audit. An individual is certified by a personnel-certification body — most commonly PECB — against a competency scheme. These are different things that share a number, and conflating them is the most common misunderstanding candidates arrive with.

The two credentials, side by side

Lead ImplementerLead Auditor
Who it is forYou build and run the ISMSYou audit an ISMS against the standard
What it testsPlanning, implementing, operating and improving an ISMSAudit evidence, findings, nonconformity and audit programmes
Competency domainsSevenSeven
Passing score70%70%
Open bookYesYes
Prerequisite to sitNoneNone

Both are open-book, both pass at 70%, and neither requires a prior credential to sit. Passing either one is not the same as being certified: PECB awards four credentials per scheme, separated by work experience and logged project or audit hours.

Which one should you take?

PECB also runs Foundation and Internal Auditor certifications at a lower rung, which are a reasonable entry point if you have no ISMS experience at all. The Lead-level exams assume you can already reason about risk, controls and evidence.

Who certifies individuals

PECB is the best-known personnel-certification body for ISO/IEC 27001 and the one whose published competency domains CertPrepX builds against, but it is not the only one — other bodies run their own ISO 27001 schemes with different formats and pass marks. If you are booking through a training partner, confirm which body’s exam you are being entered for before you prepare, because the domain split and the question format are not interchangeable.

Sources

Facts on this page were read from PECB’s own published material. Last verified 24 August 2026.

Prepare for either exam

CertPrepX has domain-weighted practice, scenario sets and full-length mock exams for both credentials, with a readiness score per domain.

Start free practice Compare all certifications

Related reading