Hello, this is Ryuta Hamamoto from TIMEWELL.
“We’re getting ISMS next fiscal year. You’re on it.” A junior staffer six months into IT ops gets thrown into that brief. I hear versions of it more often now. Inside the company, “just get 27001” floats as atmosphere while nobody explains what you actually do. This article is the big picture for people on the “forced to get it” side, in plain language.
Up front: ISMS means running information security through PDCA—not ad hoc firefighting. ISO/IEC 27001:2022 is the standard that checks whether that system meets a shared global bar. As of May 2026, domestic certifications had passed 8,333 and still grow by roughly 200–300 per year (see JIPDEC). With AI use exploding, how you fill the standard’s blank space is a new agenda item.
What ISMS really is — not a “document game,” a management decision
First-timers often assume ISMS is “writing thick manuals.” I did too. What you actually do is different. Management declares “we protect these information assets at this level,” and the whole organization keeps that promise. That is the essence.
The ISO/IEC 27001 body (management system requirements) is only ten clauses. Clauses 1–3 are preamble; real requirements concentrate in 4–10. Clause 4 (context of the organization) inventories business environment and interested parties. Clause 5 (leadership) requires top management to issue an information security policy.
Treat that lightly—“fill the template with our company name”—and it breaks later. Auditors nail gaps between policy and reality. Example: “security training for all employees” with no attendance record for temporary staff. Observation item, just like that.
A former boss told me, “Policy is a love letter from management”—not a tech memo, but a statement of posture toward the assets you care about, inside and outside the firm. Get that early and the rest gets easier.
ISO/IEC 27001:2022’s 93 controls — what changed from the prior edition
Annex A is the control set: concrete measures you may apply. The 2022 revision reorganized the 2013 edition’s 114 controls / 14 domains into 93 controls / 4 themes (see ISMS.online). Japan published JIS Q 27001:2023 in September 2023.
| Theme | Count | Examples |
|---|---|---|
| Organizational | 37 | Information security policy, roles and responsibilities, supplier relationships |
| People | 8 | Pre-employment screening, training, disciplinary process |
| Physical | 14 | Access control to premises, equipment protection, disposal |
| Technological | 34 | Access control, cryptography, malware, vulnerability management |
Note the 11 new controls in 2022: threat intelligence (A.5.7), cloud services (A.5.23), data masking (A.8.11), data leakage prevention (A.8.12), web filtering (A.8.23), secure coding (A.8.28), and more—aligned to modern threats (see Ninsho Partner).
The transition deadline for prior-edition certificates was October 31, 2025. New builds start on the 2022 edition. Reusing old consulting packs invites missing new controls and observation findings.
AI Security training, taken seriously
A 2-day intensive course fully aligned with OWASP, NIST, ISO/IEC 42001, and METI. Take it as executives, practitioners, or both.
Certification timeline — what happens in 9–12 months
From zero, realistic elapsed time is 9–12 months. A mid-size SI firm I supported looked roughly like this.
Months 1–2: Scope and GAP analysis
Decide which org units, sites, and processes are in scope. “Whole company” sounds ideal; first pass is more realistic as “Tokyo HQ contracted development only.” Then map gaps to ISO requirements.
Months 3–4: Risk assessment
Inventory assets; score risks from threats × vulnerabilities. “Risk = likelihood × impact” is the base formula; each organization may set its axes.
Months 5–6: Treatment and documentation
Implement missing measures per the risk treatment plan—access reviews, leaver account deletion, supplier selection criteria. Mostly unglamorous work.
Months 7–8: Operation and records
Auditors expect at least ~3 months of operational evidence: training logs, internal audit records, management review minutes.
Months 9–10: Internal audit and management review
Qualified internal auditors check the ISMS; leadership reviews results and issues improvement directions.
Months 11–12: Certification audit (Stage 1 + Stage 2)
Document review then on-site; pass and the certificate is issued.
Cost ballpark for year one: consulting ¥1.5–4.0M + certification fees ¥0.8–1.5M, scaling with company size.
Five traps that actually catch Japanese implementation teams
1. Losing to scope expansion pressure
Sales asks “include us—helps bids.” Greedy first-time scope outruns records. Start small; expand next year.
2. Risk assessment as “score theater”
Hundreds of spreadsheet rows of asset × threat × vulnerability, then stop. What matters is priority leadership accepts. Risk-acceptance rationale beats fancy scoring for auditors.
3. Supplier management as “collect contracts”
A.5.19–A.5.22 need more than NDAs—annual security reassessment of suppliers, visibility into sub-processors. Cloud provider management (A.5.23) is new in 2022 and watched closely.
4. Training as “play the video”
100% e-learning completion is table stakes. Can everyone demonstrate phishing recognition?
5. The same person as internal auditor
Independence is required. The IT security manager auditing their own team is NG. I have watched a site take a nonconformity on day one for exactly that.
You will not learn these from the standard text alone—which is why training and implementation labs exist. WARP SECURITY drills below target this gap.
The AI-era “blank space” — where 27001 alone does not reach
ISO/IEC 27001 is excellent, but with AI everywhere, areas the body text cannot cover keep growing.
Employees pasting customer lists into ChatGPT is nudged by A.5.10 (acceptable use) and A.8.12 (DLP)—but how to control it is not specified. Shadow AI, prompt injection, model-mediated leakage need ISO/IEC 42001 (AI management system), OWASP LLM Top 10, NIST AI RMF, and similar stacks on top of 27001.
Domestically, JIPDEC has started operating AIMS certification; natural next step after 27001. Details: ISO/IEC 42001 AIMS beginner’s guide.
My call for 2026–2027: “ISMS cert = minimum ticket”; “AIMS and threat-specific response = differentiation.” Early movers win global deals and government procurement. If I had to pick one thing for a team that just got 27001, it would be deciding when—not whether—to start the 42001 conversation.
TIMEWELL support — WARP SECURITY bridges standard and floor
Companies building ISMS often tell us: “We read the standard. We still don’t know what to do tomorrow.” WARP SECURITY is a two-day intensive for that gap.
Day 1 maps clauses to your operations; day 2 is tabletop on real incident patterns—not lecture-only. It also spans OWASP LLM Top 10, NIST AI RMF, and METI AI Business Guidelines so certification owners can name threats the body text never wrote down.
Most stalled programs freeze at “we understand the standard but not how it connects to today’s AI use.” WARP SECURITY was designed for that break. Details: WARP SECURITY.
Latest as of August 2026
Frameworks filling ISMS’s AI blank space advanced another step. Domestically, MIC/METI published AI Business Guidelines v1.2 on March 31, 2026 (METI, 2026-03-31).
Abroad, the general date of application of the EU AI Act (Regulation (EU) 2024/1689) is August 2, 2026. Let me kill a common misconception first: that date is not when high-risk AI becomes fully applicable. What starts applying on August 2, 2026 is Chapter IV — the transparency obligations (Art. 50) — plus Chapter III Section 5 (Art. 40–49: harmonised standards, conformity assessment, CE marking, registration) and the European Commission’s power to impose fines on providers of general-purpose AI (GPAI) models (Art. 101).
The substantive high-risk obligations come later. Under the amending act Regulation (EU) 2026/1744 (the Digital Omnibus: adopted July 8, 2026; published in the Official Journal on July 24, 2026; in force July 27, 2026), Chapter III Sections 1–3 apply to Annex III high-risk AI (Art. 6(2)) from December 2, 2027, and to Annex I high-risk AI (Art. 6(1), embedded in regulated products) from August 2, 2028. Deployer obligations (Art. 26) and the fundamental rights impact assessment (Art. 27) likewise kick in on December 2, 2027 for the Annex III route.
For context, the prohibited practices (Art. 5) and Chapter I (including the Art. 4 AI literacy duty) have applied since February 2, 2025, and the penalties chapter (Chapter XII, Art. 99–100) since August 2, 2025. Ceilings: up to EUR 35 million or 7% of worldwide annual turnover (whichever is higher) for prohibited practices, and up to EUR 15 million or 3% for GPAI-related and other breaches.
| Date of application | Main scope |
|---|---|
| February 2, 2025 | Chapter I (general provisions, definitions, Art. 4 AI literacy); Chapter II (Art. 5 prohibited practices) |
| August 2, 2025 | Chapter V (GPAI models), Chapter VII (governance), Chapter XII (penalties, Art. 99–100), and more |
| August 2, 2026 | Chapter IV (Art. 50 transparency), Chapter III Section 5 (Art. 40–49), Art. 101 (Commission fines on GPAI providers), and more |
| December 2, 2026 | Newly added prohibited practices (Art. 5(1)(ba), (bb), etc.); Art. 111(4) deadline for existing synthetic-content generators to meet Art. 50(2) |
| December 2, 2027 | Annex III high-risk AI (Art. 6(2)): Chapter III Sections 1–3, plus Art. 22, 25, 26, 27 |
| August 2, 2028 | Annex I high-risk AI (Art. 6(1), product-embedded): same requirements |
See the European Commission’s overview and the Official Journal for primary sources (Regulatory framework for AI (European Commission)). How you wire AI-specific frameworks into 27001 operations is the practical agenda. Cross-border firms should first classify which bucket each system falls into — GPAI, high-risk, or transparency-only — so the timeline is not misread. Organizational agent control: Governed enterprise AI agents.
Key takeaways — five points for the “forced to get it” side
- ISMS is a management decision, not a document factory. Think of policy as a love letter from leadership
- ISO/IEC 27001:2022 = 93 controls / 4 themes; 11 new controls address modern threats
- Domestic certifications: 8,333+ (as of May 2026 context in sources), +200–300/year
- From zero: 9–12 months; year-one cost often ~¥3–5M all-in
- AI era: 27001 alone is not enough; layer ISO/IEC 42001 and OWASP LLM Top 10 for differentiation
If you are told to “get ISMS,” read the standard end to end first. Ten clauses. Half a day. Where it scrapes against your business is your first work item—not the binder of templates sales dropped on your desk.
Related: ISO/IEC 27001 certification complete guide, ISO/IEC 42001 AIMS beginner’s guide, ISMAP explained.
References
- JIPDEC: How to obtain ISMS/ITSMS/BCMS/AIMS certification
- JIPDEC IT-Report 2025 Spring: ISMS certification and conformity assessment
- Ninsho Partner: JIS Q 27001:2023 requirements explained
- ISMS.online: ISO 27001:2022 Annex A Explained & Simplified
- Optima Solutions: Domestic ISMS certifications pass 8,000






