Complision

ISO 27001: What It Is and How It Shows Up in Your Security Questionnaire

If your questionnaire has an "Annex A Ref." column or codes like A.5.1 or A.8.8, this is for you.

ISO/IEC 27001:2022 is the leading international standard for information security management systems (ISMS). Its Annex A catalogs 93 controls across four themes — organizational, people, physical, technological — covering everything from access control to encryption to supplier management.

It’s a certifiable standard, but most supplier questionnaires don’t require the certificate itself — evidence against individual controls is usually enough. It often appears alongside NIS2 in the same questionnaire, since the two overlap heavily in content even though they are legally independent.

Who does this apply to?

Any supplier whose customer builds their security management — or procurement policy — on ISO 27001, common with multinationals, tech companies and banks.

Typical questions

  • Is access to information restricted per an access control policy?

    A.5.15

  • Are backup copies taken and tested per policy?

    A.8.13

  • Are development, test and production environments separated?

    A.8.31

Evidence you’d need

  • Access control policy
  • Backup execution log
  • Evidence of environment separation

Does your questionnaire cite Annex A codes?

Upload it and see, code by code, what you cover and with what evidence.

Analyze my questionnaire for free

FAQ

Do I need ISO 27001 certification to pass the questionnaire?

Almost never — unless the contract explicitly requires it. Demonstrating the controls with real evidence is usually enough.

Other frameworks

ISO 27001 in Supplier Questionnaires | Complision