For three decades, cryptography sat quietly in the back office. It was a technical detail owned by a handful of specialists, rarely discussed above the server room. That era is ending, and ISO/IEC 27001:2022 cryptography requirements are one reason why. Manufacturers feel the shift most sharply. Industry 4.0, the convergence of IT and OT, and connected PLCs, sensors, and control systems have widened the attack surface that cryptographic controls must protect.
Manufacturing has moved from an insulated industry to one of the most exposed sectors. Cryptography is no longer a background utility. It is now a boardroom concern, tied directly to compliance, customer trust, and revenue.
What ISO/IEC 27001:2022 Actually Requires
ISO/IEC 27001 is the internationally recognized standard that specifies requirements for an information security management system (ISMS) and the basis for certification by an accredited body against a defined scope. The 2022 revision restructured Annex A into 93 controls organized across four themes: organizational, people, physical, and technological.
The revision also changed how cryptography is treated. The 2013 edition kept two separate controls for cryptography and key management (10.1.1 and 10.1.2). The 2022 edition consolidates both into a single control: 8.24, Use of Cryptography. That consolidation matters because it puts policy and key management side by side, as one accountable capability rather than two disconnected checkboxes.
Inside Control 8.24: Policy Plus a Managed Key Lifecycle
In practice, control 8.24 asks for two things. First, a documented, risk-based cryptography policy that defines approved algorithms and minimum key strengths. Second, a managed lifecycle for cryptographic keys.
That lifecycle covers generation, certificate issuance, distribution, storage, change, revocation, handling of compromised keys, recovery, backup or archival, destruction, and logging. Assessors expect to see it verified through operational evidence, not policy statements alone. Annex A 8.24 states the control itself, while the detailed lifecycle expectations sit in the companion guidance, ISO/IEC 27002:2022.
Why It Matters for Manufacturers
Certification is voluntary, but it has become a de facto commercial prerequisite. Customer security questionnaires, RFPs, and supplier risk assessments increasingly require a current ISO/IEC 27001 certificate as a condition of doing business. A lapsed certificate is no longer a paperwork problem. It is a direct threat to revenue.
The cryptographic obligations behind the standard are not voluntary for many manufacturers either. GDPR Article 32 names encryption as a security measure. NIS2 Article 21(2)(h) requires policies and procedures on the use of cryptography and, where appropriate, encryption. The EU Cyber Resilience Act sets product security requirements. Reporting of actively exploited vulnerabilities and severe incidents applies as of September 11, 2026, and the main obligations apply from December 11, 2027.
The stakes are higher on the factory floor. A manufacturer protecting proprietary process recipes, such as the exact temperature and timing curves that define a product, is protecting decades of competitive advantage. Long-lived industrial assets and sensitive process data raise the cost of getting cryptography wrong.
How ISO/IEC 27001:2022 Maps to Cryptography and PKI
The standard addresses cryptography most directly through Annex A 8.24, reinforced by secure authentication and privacy provisions elsewhere in Annex A. The mapping below turns those requirements into functions a security team can operate and prove.
| Control area | What it requires | Cryptographic function |
|---|---|---|
| Annex A 8.24, cryptography and key management policy | A documented, topic-specific policy tied to the ISMS risk assessment | Approved algorithms, minimum key strengths, and mandatory-use rules |
| Annex A 8.24, cryptographic key lifecycle | Centralized generation, distribution, rotation, and destruction | Full audit trail across keys and certificates |
| Annex A 8.24, reinforced by 5.14, information transfer | Protection of data at rest and in transit | PKI-issued certificates across the certified scope |
| Annex A 8.5, secure authentication | Reduced reliance on shared secrets and static passwords | Certificate-based authentication |
| Annex A 5.19 to 5.22, supplier cryptographic assurance | Evidence for supplier security assessments and the SoA | A cryptographic component inventory |
| Clause 6.1.3 d), Statement of Applicability traceability | Controls mapped to documented risk treatment decisions | Centralized reporting linking 8.24 to risk |
| Clauses 9.2 and 9.3 | Internal audit and management review | Tested controls with findings reviewed by leadership |
| Annex A 5.34, privacy and protection of PII | Identification and fulfillment of legal, regulatory, and contractual requirements for personal data | Encryption and pseudonymization of PII where privacy law requires it, governed by the same 8.24 policy |
The Control Areas That Carry Cryptographic Weight
Read the table as a set of connected obligations, not isolated line items. Policy defines what good looks like. The key lifecycle proves it happens. PKI-issued certificates deliver confidentiality and integrity across the scope. Certificate-based authentication removes brittle shared secrets. A cryptographic inventory supports supplier assurance and the Statement of Applicability. Internal audit and management review close the loop.
Getting Audit Ready: What Assessors Actually Test
Surveillance and recertification audits focus on one question: are cryptographic controls operated as documented, or only described in policy? Assessors want operational evidence. A well-written policy with no proof of execution is a finding waiting to happen.
Use the six focus areas below as a self-assessment before your next audit.
The Six Questions to Answer Before Your Next Audit
- Documented cryptography policy: Does it define approved algorithms, minimum key lengths, and when encryption is mandatory?
- Key lifecycle evidence: Can you demonstrate generation, secure storage, rotation, and destruction, not just a policy statement?
- Statement of Applicability traceability: Does the SoA justify 8.24 and link it to the risk assessment?
- Legal and jurisdictional compliance: Have export controls and data residency restrictions been considered?
- Certificate and key inventory currency: Is there an up-to-date inventory with named owners and expiry dates?
- Internal audit and management review: Has internal audit tested 8.24, with findings reviewed by management?
The Manufacturing Complication: Cryptography Across IT and OT
On the factory floor, the questions get harder. Auditors following current frameworks now ask what algorithms run across PLCs, HMIs, and industrial gateways. They ask when device and machine certificates expire, and how keys are rotated across a fleet the manufacturer may not fully control.
The timeline is the complication. Industrial control systems and embedded devices often run 15 to 25 years or more. A cryptographic choice made today must remain secure for decades, long after the engineers who made it have moved on.
Looking Ahead: Post-Quantum Readiness
ISO/IEC 27001 governance connects directly to the coming cryptographic transition. In 2024, NIST finalized three post-quantum cryptographic standards, FIPS 203, 204, and 205, approved on August 13, 2024. NIST also published proposed timelines in the draft report NIST IR 8547. They would deprecate the RSA and elliptic curve algorithms at the 112-bit security level, such as RSA-2048 and P-256, after 2030, and disallow quantum-vulnerable public key algorithms after 2035.
ISO/IEC 27001 names no algorithms, so the link is procedural. A mature inventory and a working key lifecycle are what make migration manageable. Manufacturers with that discipline in place can move long-lived assets to quantum-safe algorithms in time. Those without it will be discovering unknown keys under deadline pressure.
How Keyfactor Can Help
Meeting control 8.24 is easier when requirements map cleanly to capabilities. Keyfactor provides that mapping across three products.
Keyfactor AgileSec supports supplier cryptographic assurance through deep cryptographic discovery and inventory. It scans code, endpoints, cloud workloads, and network traffic, then scores risks such as deprecated algorithms and exposed keys to guide an orderly post-quantum migration.
EJBCA supports the cryptographic key lifecycle and issues the PKI certificates that protect data at rest and in transit. It is a quantum-ready PKI platform that scales from a few thousand to millions of certificates, with detailed signed audit logs for evidence.
Keyfactor Command supports the cryptography and key management policy, secure authentication, and Statement of Applicability traceability. It is a CA-agnostic certificate lifecycle automation and machine identity platform. It discovers and inventories certificates across any CA, cloud, and machine, then delivers centralized, compliance-ready reporting that links controls to risk decisions.
Together, these capabilities turn ISO/IEC 27001 compliance from an audit burden into a competitive capability and a foundation for post-quantum migration.
Conclusion and Next Steps
Control 8.24 rewards manufacturers who treat cryptography as governed infrastructure. Start with four practical moves:
- Gain visibility into cryptographic assets across IT and OT.
- Assess them against current and near-term requirements.
- Automate certificate and key lifecycle management.
- Begin evaluating quantum vulnerability for long-lived systems.
The manufacturers who act now will pass audits with evidence, protect revenue tied to certification, and enter the post-quantum era prepared. Ready to see where your 8.24 readiness stands? Request a Demo.
Got ISO/IEC 27001:2022 cryptography questions? We’ve got answers.
What changed for cryptography in ISO/IEC 27001:2022?
The 2022 revision restructured Annex A into 93 controls across four themes. It consolidated the 2013 edition’s two separate cryptography and key management controls into a single control, 8.24, Use of Cryptography.
What does control 8.24 require?
Control 8.24 requires a documented, risk-based cryptography policy that defines approved algorithms and minimum key strengths. It also requires a managed key lifecycle covering generation, distribution, storage, change, revocation, recovery, archival, and destruction, proven with operational evidence.
Is ISO/IEC 27001 certification mandatory for manufacturers?
Certification is voluntary, but it has become a de facto commercial prerequisite. Customer security questionnaires, RFPs, and supplier risk assessments increasingly require a current certificate, so a lapse can directly threaten revenue.
What evidence do auditors look for on cryptography?
Auditors test whether controls are operated as documented, not just written down. They commonly review a cryptography policy, key lifecycle evidence, SoA traceability, jurisdictional considerations, a current inventory of keys and certificates, and internal audit findings.
How does ISO/IEC 27001 apply to OT and the factory floor?
Auditors now ask what algorithms run across PLCs, HMIs, and industrial gateways, when device and machine certificates expire, and how keys are rotated. Long asset lifespans of 15 to 25 years make these questions especially demanding for manufacturers.
What is the Statement of Applicability, and why does 8.24 depend on it?
The Statement of Applicability lists the necessary controls, justifies inclusions and exclusions, and states whether each control is implemented, linked to the risk assessment under Clause 6.1.3 d). For 8.24 it must justify the control’s inclusion and trace it to documented risk treatment decisions for auditor review.
How does post-quantum cryptography relate to ISO/IEC 27001?
ISO/IEC 27001 governance gives manufacturers the inventory and lifecycle discipline needed to migrate. NIST approved FIPS 203, 204, and 205 on August 13, 2024. Proposed dates for deprecating RSA and elliptic curve algorithms at the 112-bit security level after 2030, and disallowing quantum-vulnerable public key algorithms after 2035, sit in the draft report NIST IR 8547. Because ISO/IEC 27001 names no algorithms, the link is procedural: the 8.24 policy and inventory make migration manageable.
Where should a manufacturer start with control 8.24?
Start with visibility. Build a current inventory of keys and certificates across IT and OT. Assess it against 8.24 and near-term regulatory requirements. Then automate lifecycle management so evidence is continuous, not reconstructed before each audit.