> ## Documentation Index
> Fetch the complete documentation index at: https://docs.visotrust.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Understanding ISO 27001 Evidence Requirements

> Evidence to request from an ISO 27001 certified vendor: the certificate, Statement of Applicability, and a surveillance audit between recertifications.

**Lowering risk using an ISO 27001 Certificate and Statement of Applicability**

## What to provide

If a vendor you're assessing is ISO 27001 certified, the recommended evidence package is:

* Provide the vendor's current ISO 27001 certificate and Statement of Applicability (SoA).

* If the certificate's issuance or re-issuance date is more than one year old, evidence of the vendor's latest successful surveillance audit.

Providing these items or connecting us with the vendor so they can be obtained helps move the assessment toward completion.

For how VISO TRUST classifies and processes these artifacts, see [Artifact Type Configuration](/third-parties/advanced/artifact-type-configuration) and [Artifact Intelligence](/trust-and-questionnaires/artifact-intelligence).

## Why an ISO 27001 certificate alone isn't enough

ISO 27001 is a leading international standard for information security management. When a vendor is certified, an independent certification body has confirmed that it operates an Information Security Management System (ISMS) that meets the standard. That is meaningful, but the certificate alone may not provide all the information needed to complete a security assessment.

Additional documentation helps confirm what the certification covers, which security controls are applicable, and whether the certification continues to be maintained.

## What the certificate does — and doesn't — tell you

Think of the certificate as a badge. It confirms that a certified ISMS exists. It does not describe which security controls are applicable within the vendor's ISMS, whether the certified scope covers the service you use, or whether the certification continues to be maintained. Supporting documentation provides that context.

## What documents may be required

When a vendor is ISO 27001 certified, obtain the following:

### ISO 27001 Certificate

The certificate confirms the vendor's certification and identifies the scope covered by the certified ISMS.

### Statement of Applicability (SoA)

The SoA identifies the security controls the vendor has determined are applicable to its ISMS, as well as controls that have been excluded and the justification for those exclusions. It provides additional visibility into the security control coverage behind the certification.

### Surveillance Audit Evidence, when applicable

ISO 27001 certification operates on a three-year certification cycle, with surveillance audits conducted in between. If the certificate's issuance or re-issuance date is more than one year old, obtaining evidence of a successful surveillance audit is recommended to confirm the certification continues to be maintained. A surveillance audit report is also accepted in place of a current SoA when the vendor is mid-cycle.

## ISO 27001 by the numbers

* The 2022 revision defines 93 Annex A controls across four themes — organizational, people, physical, and technological. The SoA must address all 93 (each marked applicable or excluded, with justification) and is a mandatory part of certification under clause 6.1.3, which is why it is a reasonable request.

* A certificate reflects a point in time. The annual surveillance audit is what keeps it valid between the three-yearly recertifications, which is why "current and maintained" matters as much as "certified."

*Sources: [ISO/IEC 27001:2022](https://www.iso.org/standard/27001) (Annex A controls; Statement of Applicability, clause 6.1.3); [ISO/IEC 17021-1](https://www.iso.org/standard/61651.html) (certification audit cycle).*
