September 11, 2026

ISO 27001 doesn't require exercises. Run them anyway.

ISO/IEC 27001 is an information security standard, not an exercise standard, and no published account we found reads an incident-exercise requirement into it. Its duties to evaluate effectiveness and keep improving are still the best reason to run one.

If an incident exercise is on your ISMS calendar because "ISO 27001 requires it", the requirement isn't in the standard.

ISO/IEC 27001 is an information security management system standard, not an exercise standard. No clause and no Annex A control requires an exercise, or a test of your incident response, in any published account of the standard we found.³ ⁴ In substance, the incident-management controls, Annex A 5.24 to 5.28, ask you to be ready: plan and prepare, triage events, respond by your procedures, learn from real incidents, keep evidence.² ³ They don't ask you to rehearse.

NIST's official crosswalk from its SP 800-53 controls to ISO/IEC 27001:2022 points the same way. Its incident response testing control, IR-3, maps to no clause and no Annex A control.⁵ NIST attaches its own caution, that "the mappings are not always one-to-one and may not be completely equivalent",⁵ so the crosswalk corroborates the reading rather than settling it.

The one control that asks for testing is Annex A 5.30, ICT readiness for business continuity. It applies where your risk treatment selects it, and it names no form of test and no frequency.³ ⁴ It covers ICT continuity, not incident handling.

So the requirement isn't there. The reason to exercise is.

For an organisation certified to ISO/IEC 27001, or claiming conformity, two duties run through the whole ISMS. Clause 9 asks you to evaluate whether your security is effective. Clause 10 asks you to keep improving it.¹ ⁶ For incident response, neither is easy to take seriously without exercising.

You can't genuinely evaluate a capability you've never seen work under pressure. Documents and audits show that a procedure exists and that people know where to find it. They don't show whether your people can run it at speed, on incomplete information, when the first two assumptions turn out to be wrong.

Waiting for a real incident is the expensive way to improve. Annex A 5.27 asks you to learn from the incidents you have. An exercise lets you learn before you have them, while the cost of a gap is a conversation.

Realistic, adaptive exercises are one of the most direct ways to generate that evidence and learning. A scripted walk-through tests whether the plan reads well. An exercise that responds to what your people decide tests what they would actually do, and leaves a record your monitoring, management review and improvement actions can draw on.

How Annex A binds through your Statement of Applicability, what 5.30 does and doesn't settle, what a certification audit looks at, and which control numbers changed in 2022 are all in one place: What ISO 27001 actually asks of your exercise program.


Standards references current as of September 2026. ISO/IEC 27001 and ISO/IEC 27002 content in this piece is our summary, not a quotation of either standard. Quoted passages are NIST's text, verbatim. This piece is scheduled for re-verification by March 2027.

¹ ISO/IEC 27001:2022, Information security, cybersecurity and privacy protection — Information security management systems — Requirements: ISO's official preview, as distributed free by an ISO national member body. Clause numbers and titles are taken from its contents page.

² ISO/IEC 27002:2022, Information security, cybersecurity and privacy protection — Information security controls: official preview, as distributed free by an ISO national member body. Used for Annex A control numbers and titles, taken from its contents page.

³ A certification body's published commentary on Annex A 5.24 to 5.30 and on control 5.30 (the second, August 2024). Secondary sources, used to corroborate our summary of the incident and continuity controls.

⁴ An accredited certification body's ISO 27001:2022 gap analysis tool (February 2023), its assessor-facing checklist of 2022 changes. Secondary source. Used for controls 5.27 and 5.30.

⁵ NIST, SP 800-53 Rev. 5 to ISO/IEC 27001:2022 crosswalk (final, posted November 2023). A mapping, not ISO's text. NIST's caveat is quoted verbatim.

⁶ A national standards body's ISO/IEC 27001:2022 implementation guide. Secondary source. Used for Clause 9.

READINESS STARTS BEFORE THE CRISIS.

Put your team to the test.

Build your first scenario and turn preparation into measurable progress.

Explore pricing →Request a demo →