Skip to main content
Back to resources
ISO 27001ComplianceGRCB2B SaaSvCISO

ISO 27001:2022 for B2B SaaS: Implementing the 93 Controls Without Slowing Development

Matt SapioAugust 8, 20266 min read

With the ISO/IEC 27001:2013 transition period officially closed, every new and renewing ISO 27001 audit is now evaluated against the ISO/IEC 27001:2022 standard. For growing B2B SaaS platforms selling into enterprise and international accounts, holding ISO 27001 certification has become a primary requirement alongside SOC 2.

However, moving from a SOC 2 Type II report to full ISO 27001 certification often causes friction inside engineering organizations. Engineering leads worry about policy overhead, while security teams struggle to translate the standard's formal requirements into practical cloud configurations.

Understanding how the 2022 update restructures security controls allows B2B software companies to build a compliant Information Security Management System (ISMS) without delaying product velocity.

How ISO 27001:2022 Restructures Security Controls

The 2022 revision modernized the standard to reflect modern cloud infrastructure, remote workforces, and evolving supply chain threats. The most visible change was collapsing 114 controls across 14 domains into 93 controls organized under four streamlined themes:

  1. Organizational Controls (37 controls): Policies, vendor risk management, asset management, and threat intelligence governance.
  2. People Controls (8 controls): Remote work security, background screening, and security awareness training.
  3. Physical Controls (14 controls): Access controls, equipment security, and physical facility monitoring.
  4. Technological Controls (34 controls): Access control, cloud service security, secure coding, data masking, and network configuration.

For cloud-native SaaS startups, physical controls are largely inherited from cloud infrastructure providers. The operational work centers on Organizational and Technological controls.

Key Controls That Directly Impact SaaS Engineering

Four updated controls in Annex A require direct coordination with software development and DevOps teams:

1. Threat Intelligence (A.5.7)

ISO 27001 now requires organizations to collect and analyze threat intelligence relevant to their attack surface. For a SaaS platform, this does not mean hiring a dedicated threat hunter. It means establishing automated vulnerability scanning for container registries, subscribing to security advisories for open-source dependencies, and reviewing threat feeds affecting your tech stack.

2. Information Security for Use of Cloud Services (A.5.23)

Enterprise buyers want explicit proof of how cloud environments are provisioned and secured. This control requires documented cloud security baselines, infrastructure-as-code (IaC) security scanning, and strict access controls across cloud infrastructure.

3. Data Masking (A.8.11)

To protect sensitive customer data in non-production environments, engineering teams must implement data masking or anonymization. Production data should never be copied into staging or development databases without automated masking controls in place.

4. Secure Coding (A.8.28)

Secure software development is now explicitly governed. Auditors look for automated static application security testing (SAST) in CI/CD pipelines, mandatory peer code reviews, dependency management, and documented remediation SLAs for identified code vulnerabilities.

Build Once, Satisfy Both: Unifying SOC 2 and ISO 27001

Most B2B SaaS platforms need both SOC 2 and ISO 27001 to satisfy diverse procurement teams across North America and global markets. Because roughly 70% of controls overlap between the AICPA Trust Services Criteria and ISO 27001 Annex A, building separate programs duplicates effort and creates administrative burden.

Instead of managing two distinct control sets, map your security practices into a single master control framework. Your access reviews, vulnerability management workflows, and change control approvals can satisfy both SOC 2 audit evidence requests and ISO 27001 surveillance audits simultaneously.

Connecting automated evidence collection tools through a GRC platform helps track control health in real time. However, software alone does not run an ISMS. Someone still needs to perform risk assessments, conduct management reviews, and represent the security program during stage 1 and stage 2 audits. (Read our breakdown on why buying a GRC platform without someone to run it is like buying a gym membership without a trainer).

Next Steps for SaaS Leaders

If your enterprise prospects are requesting ISO 27001 certification or you need to align your current program with the 2022 standard, focus on building controls that integrate seamlessly into your existing development workflows.

To explore how ISO 27001 compares to SOC 2 for your target market, review our guide on SOC 2 vs. ISO 27001.

If you are preparing for an upcoming audit or need dedicated leadership to build and manage your ISMS, our SOC 2 and ISO 27001 management service and fractional CISO team design, execute, and defend your compliance program from gap assessment through certification.

Talk to us

Have a question this article didn't answer?

Book a free consultation and we'll talk through how this applies to your specific situation.