ISO/IEC 27006:2024
What is ISO/IEC 27006:2024?
ISO/IEC 27006 specifies requirements and provides guidance for bodies providing audit and certification of information security management systems (ISMS). It supplements ISO/IEC 17021-1 with ISMS-specific requirements for certification bodies, including auditor competence, audit time, and certification scope determination.. It comprises 52 controls organised across 16 domains, published by ISO/IEC, and applies in International.
How ISO/IEC 27006:2024 maps to other frameworks
All 52 controls, each one mapped to the equivalent requirement in other standards, with the evidence that carries across and the mappings that were judged and rejected shown alongside. No account needed to look.
See the control mappings →The 16 domains ISO/IEC 27006:2024 groups its controls into
Where ISO/IEC 27006:2024 overlaps with the standards you already hold
Where to get trained on ISO/IEC 27006:2024
4 courses in the catalogue cover ISO/IEC 27006:2024 directly. Each is self-paced, includes the downloadable toolkit and the implementation playbook, and carries a certificate of completion.
What ISO/IEC 27006:2024 means in your sector
What ISO/IEC 27006:2024 means for your job
Questions people ask about ISO/IEC 27006:2024
What is ISO/IEC 27006:2024?
How many controls does ISO/IEC 27006:2024 have?
Where does ISO/IEC 27006:2024 apply?
What frameworks does ISO/IEC 27006:2024 map to?
How do I get started with ISO/IEC 27006:2024 compliance?
Query ISO/IEC 27006:2024 programmatically
ISO/IEC 27006:2024, its 52 controls and every mapping into other standards are available over a REST endpoint and an MCP server, so an agent can read them directly. The free tier is 10 calls a day and needs no signup.
ISO/IEC 27006:2024 API reference and MCP config →How ready are you for ISO/IEC 27006:2024?
Answer 25 questions and get a professional readiness report with gap analysis, maturity scores, and prioritised action items. Results in 5 minutes.