Information security management systems - Requirements
Sets requirements for an information security management system.
The text of this standard is sold by ISO and is not reproduced here. This page gives the code, edition, scope and what each market says about it.
Whether the market recognizes, harmonizes or adopts this standard, and which edition it accepts
| Market | Status | Edition accepted | National code | Details |
|---|---|---|---|---|
| European Union | Referenced | - | - | Named for information in EU cybersecurity guidance. It gives no presumption of conformity unless the standard is harmonised and published in the Official Journal. |
| United Kingdom | Not recognized | - | - | A device that conforms to this standard does not get the statutory presumption of conformity, because the standard is not designated.. The complete list of designated standards published in January 2026 does not name this standard. |
Open the market page and its pathway pages for the full requirement, protocol and report content
Related standards: YY/T 1843-2022, IEC 81001-5-1, JIS T 81001-5-1, ISO/IEC 29147, ISO/IEC 30111, IEC 80001-5-1, AAMI TIR57, ANSI/CAN/UL 2900-1, ANSI/CAN/UL 2900-2-1, IEC 80001-1. See all standards.
Not legal or regulatory advice. Check the current official rules before you act. Parts of the approvals data are official open data reused under open licences. Data sources.
| Canada | Not recognized | - | - | The standard does not appear on the list of recognized standards. A manufacturer may still give other evidence of safety or effectiveness. |