ISO/IEC 27001 certifications
ISO/IEC 27001 is the international standard for an information security management system. There is no single “ISO 27001 exam” for individuals — there are two main credentials, and which one you sit depends on whether you build management systems or audit them.
What ISO/IEC 27001 actually is
ISO/IEC 27001 specifies the requirements for establishing, operating and continually improving an information security management system (ISMS). Clauses 4 to 10 carry the requirements an organization must meet; Annex A lists reference controls it may select from after assessing risk. The distinction matters more than almost anything else on either exam: a requirement is something you must satisfy, a control is something you choose.
An organization is certified to ISO/IEC 27001 by an accredited certification body after a two-stage audit. An individual is certified by a personnel-certification body — most commonly PECB — against a competency scheme. These are different things that share a number, and conflating them is the most common misunderstanding candidates arrive with.
The two credentials, side by side
| Lead Implementer | Lead Auditor | |
|---|---|---|
| Who it is for | You build and run the ISMS | You audit an ISMS against the standard |
| What it tests | Planning, implementing, operating and improving an ISMS | Audit evidence, findings, nonconformity and audit programmes |
| Competency domains | Seven | Seven |
| Passing score | 70% | 70% |
| Open book | Yes | Yes |
| Prerequisite to sit | None | None |
Both are open-book, both pass at 70%, and neither requires a prior credential to sit. Passing either one is not the same as being certified: PECB awards four credentials per scheme, separated by work experience and logged project or audit hours.
Which one should you take?
- You sign, lead or contribute to audit reports against the standardLead Auditor
- You own the ISMS, or you are the consultant building one for a clientLead Implementer
- Neither yet — you want the vocabulary before committingStart with Foundation
PECB also runs Foundation and Internal Auditor certifications at a lower rung, which are a reasonable entry point if you have no ISMS experience at all. The Lead-level exams assume you can already reason about risk, controls and evidence.
Who certifies individuals
PECB is the best-known personnel-certification body for ISO/IEC 27001 and the one whose published competency domains CertPrepX builds against, but it is not the only one — other bodies run their own ISO 27001 schemes with different formats and pass marks. If you are booking through a training partner, confirm which body’s exam you are being entered for before you prepare, because the domain split and the question format are not interchangeable.
Sources
Facts on this page were read from PECB’s own published material. Last verified 24 August 2026.
Prepare for either exam
CertPrepX has domain-weighted practice, scenario sets and full-length mock exams for both credentials, with a readiness score per domain.
Start free practice Compare all certifications