Keyfactor Tech Days 2027 – Be Part of The Trust Security Conference in San Diego Register now!

ISO/IEC 27001:2022 for Manufacturing:

Cryptography and PKI for Information Security Management

Updated: August 24, 2026
Region International (globally recognized ISMS certification standard, used as a vendor assurance benchmark across industries) 
Applicability Certified Organizations: any organization seeking or maintaining ISO/IEC 27001 certification for its Information Security Management System (ISMS) Suppliers and Partners: organizations required by customer contracts or procurement frameworks to hold or demonstrate alignment with 27001 certification Certification Bodies and Auditors: accredited bodies conducting initial certification, annual surveillance, and three-year recertification audits 
Relevant sections Annex A 8.24: Use of Cryptography Annex A 8.5 and 5.34: Secure authentication; privacy and protection of personally identifiable information Clause 6.1.2 / 6.1.3: Risk assessment, risk treatment, and the Statement of Applicability 

Overview

ISO/IEC 27001:2022 is the internationally recognized standard for Information Security Management System (ISMS) certification. The 2022 revision restructured Annex A into 93 controls across four themes, and consolidated the 2013 edition’s separate cryptography and key management controls (10.1.1 and 10.1.2) into a single control, 8.24, Use of Cryptography. 

In practical terms, 8.24 requires a documented, risk-based cryptography policy defining approved algorithms and minimum key strengths, alongside a managed lifecycle for cryptographic keys, generation, distribution, storage, rotation, and destruction, that auditors verify through operational evidence rather than policy statements alone. 

Why It Matters 

Certification is voluntary, but it has become a de facto commercial prerequisite: customer security questionnaires, RFPs, and supplier risk assessments increasingly require current ISO/IEC 27001 certification as a condition of doing business, making a lapsed certificate a direct threat to revenue rather than just a compliance finding. 

Because ISO/IEC 27001 is a management-system standard rather than a prescriptive technical one, auditors testing 8.24 expect to see ownership, traceability, and evidence, a certificate and key inventory, a Statement of Applicability that justifies the control’s scope, and internal audit findings, tested annually at surveillance audits and in full at the three-year recertification. 

How This Maps to Cryptography 

ISO/IEC 27001:2022 addresses cryptography most directly through Annex A 8.24, reinforced by secure authentication and privacy provisions elsewhere in Annex A. The key control areas with direct cryptographic implications are: 

SectionFunctionWhat it saysProducts
Annex A 8.24 — Rules for the effective use of cryptography Cryptography and Key Management Policy Documented, topic-specific cryptography policy defining approved algorithms, minimum key lengths, and lifecycle rules, tied to the ISMS risk assessment Command 
Annex A 8.24 — Cryptographic key management Cryptographic Key Lifecycle Centralized generation, distribution, rotation, and destruction of keys and certificates with a full audit trail EJBCA 
Annex A 8.24, reinforced by Annex A 5.34 on protection of PII Data Confidentiality and Integrity PKI-issued certificates encrypting data at rest and in transit across the certified scope EJBCA 
Annex A 8.5 — Secure authentication Secure Authentication Certificate-based authentication reducing reliance on shared secrets and static passwords Command 
Annex A 5.19–5.22 — Supplier relationships Supplier Cryptographic Assurance Cryptographic component inventory supporting supplier security assessments and Statement of Applicability evidence AgileSec 
Clause 6.1.3 — Risk treatment and the SoA Statement of Applicability Traceability Centralized reporting mapping cryptographic controls to documented risk treatment decisions for auditor review Command 

Audit Readiness 

ISO/IEC 27001 surveillance and recertification audits focus on whether cryptographic controls are operated as documented, not just described in policy. Key areas that auditors commonly test: 

  • Documented Cryptography Policy: Is there a topic-specific policy defining approved algorithms, minimum key lengths, and the conditions under which encryption is mandatory? 
  • Key Lifecycle Evidence: Can the organization demonstrate generation, secure storage, rotation, and destruction procedures for cryptographic keys, not just a policy statement? 
  • Statement of Applicability Traceability: Does the SoA correctly justify the inclusion of 8.24 and link it to the underlying risk assessment? 
  • Legal and Jurisdictional Compliance: Has the organization considered jurisdictional restrictions on cryptography, including export controls and data residency, as 8.24 requires? 
  • Certificate and Key Inventory Currency: Is there an up-to-date inventory of certificates and cryptographic keys with named owners and expiry dates? 
  • Internal Audit and Management Review: Has internal audit tested the 8.24 controls, with findings reviewed by management within the ISMS cycle? 

Frequently asked
questions

Can’t find what you’re looking for?