ISO/IEC 27001:2022 for Manufacturing:
Cryptography and PKI for Information Security Management
| Region | International (globally recognized ISMS certification standard, used as a vendor assurance benchmark across industries) |
| Applicability | Certified Organizations: any organization seeking or maintaining ISO/IEC 27001 certification for its Information Security Management System (ISMS) Suppliers and Partners: organizations required by customer contracts or procurement frameworks to hold or demonstrate alignment with 27001 certification Certification Bodies and Auditors: accredited bodies conducting initial certification, annual surveillance, and three-year recertification audits |
| Relevant sections | Annex A 8.24: Use of Cryptography Annex A 8.5 and 5.34: Secure authentication; privacy and protection of personally identifiable information Clause 6.1.2 / 6.1.3: Risk assessment, risk treatment, and the Statement of Applicability |
Overview
ISO/IEC 27001:2022 is the internationally recognized standard for Information Security Management System (ISMS) certification. The 2022 revision restructured Annex A into 93 controls across four themes, and consolidated the 2013 edition’s separate cryptography and key management controls (10.1.1 and 10.1.2) into a single control, 8.24, Use of Cryptography.
In practical terms, 8.24 requires a documented, risk-based cryptography policy defining approved algorithms and minimum key strengths, alongside a managed lifecycle for cryptographic keys, generation, distribution, storage, rotation, and destruction, that auditors verify through operational evidence rather than policy statements alone.
Why It Matters
Certification is voluntary, but it has become a de facto commercial prerequisite: customer security questionnaires, RFPs, and supplier risk assessments increasingly require current ISO/IEC 27001 certification as a condition of doing business, making a lapsed certificate a direct threat to revenue rather than just a compliance finding.
Because ISO/IEC 27001 is a management-system standard rather than a prescriptive technical one, auditors testing 8.24 expect to see ownership, traceability, and evidence, a certificate and key inventory, a Statement of Applicability that justifies the control’s scope, and internal audit findings, tested annually at surveillance audits and in full at the three-year recertification.
How This Maps to Cryptography
ISO/IEC 27001:2022 addresses cryptography most directly through Annex A 8.24, reinforced by secure authentication and privacy provisions elsewhere in Annex A. The key control areas with direct cryptographic implications are:
| Section | Function | What it says | Products |
|---|---|---|---|
| Annex A 8.24 — Rules for the effective use of cryptography | Cryptography and Key Management Policy | Documented, topic-specific cryptography policy defining approved algorithms, minimum key lengths, and lifecycle rules, tied to the ISMS risk assessment | Command |
| Annex A 8.24 — Cryptographic key management | Cryptographic Key Lifecycle | Centralized generation, distribution, rotation, and destruction of keys and certificates with a full audit trail | EJBCA |
| Annex A 8.24, reinforced by Annex A 5.34 on protection of PII | Data Confidentiality and Integrity | PKI-issued certificates encrypting data at rest and in transit across the certified scope | EJBCA |
| Annex A 8.5 — Secure authentication | Secure Authentication | Certificate-based authentication reducing reliance on shared secrets and static passwords | Command |
| Annex A 5.19–5.22 — Supplier relationships | Supplier Cryptographic Assurance | Cryptographic component inventory supporting supplier security assessments and Statement of Applicability evidence | AgileSec |
| Clause 6.1.3 — Risk treatment and the SoA | Statement of Applicability Traceability | Centralized reporting mapping cryptographic controls to documented risk treatment decisions for auditor review | Command |
Audit Readiness
ISO/IEC 27001 surveillance and recertification audits focus on whether cryptographic controls are operated as documented, not just described in policy. Key areas that auditors commonly test:
- Documented Cryptography Policy: Is there a topic-specific policy defining approved algorithms, minimum key lengths, and the conditions under which encryption is mandatory?
- Key Lifecycle Evidence: Can the organization demonstrate generation, secure storage, rotation, and destruction procedures for cryptographic keys, not just a policy statement?
- Statement of Applicability Traceability: Does the SoA correctly justify the inclusion of 8.24 and link it to the underlying risk assessment?
- Legal and Jurisdictional Compliance: Has the organization considered jurisdictional restrictions on cryptography, including export controls and data residency, as 8.24 requires?
- Certificate and Key Inventory Currency: Is there an up-to-date inventory of certificates and cryptographic keys with named owners and expiry dates?
- Internal Audit and Management Review: Has internal audit tested the 8.24 controls, with findings reviewed by management within the ISMS cycle?
TAKE THIS TO MANAGEMENT
ISO/IEC 27001:2022 folded cryptography and key management into a single control, 8.24, and auditors now test whether we actually operate a key lifecycle, not whether we’ve checked an “encryption enabled” box. Certification lapses cost us the vendor assurance credential that increasingly gates customer contracts and RFPs before a deal ever reaches negotiation.
The gap we see most often at recertification is the Statement of Applicability: organizations write a cryptography policy but can’t produce the certificate and key inventory an auditor asks to see next. The three-year recertification cycle sounds distant, but surveillance audits happen every year, so this evidence needs to be current now, not staged before the next visit.
Frequently asked questions
Can’t find what you’re looking for?


