ISO/IEC TS 27103:2026 is a technical specification that explains how organisations should position existing ISO and IEC standards within a cybersecurity framework and how to use them together in cybersecurity management. The purpose of the standard is to bring together existing ISO and IEC documents under a single cybersecurity management approach and to provide a traceable usage pattern during implementation.
This document was published as Edition 1 in February 2026.
With this edition, the ISO/IEC TR 27103:2018 document has been withdrawn.
Why is ISO 27103 Important?
ISO 27103 provides a common framework to prevent the fragmented implementation of cybersecurity practices within an organisation. Organisations often use management system-based standards such as ISO/IEC 27001, control libraries such as ISO/IEC 27002, incident management and operational resilience documents simultaneously. This document responds to the need to show where these parts fit within a cybersecurity programme and how they support each other.
The key benefits provided on the implementation side are summarised under the following headings:
- The usage pattern of the standard portfolio is clarified,
- Programme objectives, responsibilities, and evidence structure are classified according to functions,
- Traceability for internal and external audits is strengthened,
- A common presentation language is established for senior management reporting.
Who is ISO 27103 critical for?
ISO/IEC TS 27103 has direct value and importance for the following sectors and teams:
- Senior management and teams: It provides a reference for addressing cybersecurity governance, corporate risk, and resource-allocation decisions within a single management model.
- Information security leader: Function-based placement is used for programme design, the roadmap, metrics, and evidence of implementation.
- Information security and IT operations teams: Control implementation, monitoring, incident management, and recovery processes are positioned within the same structure.
- Risk management, compliance, and internal audit teams: Audit evidence production and reporting are simplified by classifying standard items, controls, and process outputs by function.
- Highly regulated sectors: The need for programme integrity is evident in finance, energy, telecoms, healthcare, defence, manufacturing, critical infrastructure, cloud services, e-commerce and supply chain-intensive organisations.
The Five Functions of ISO 27103
The backbone of ISO/IEC TS 27103 is the logic of classifying cybersecurity activities by function. The document focuses on five functions:
- Identification,
- Protection,
- Detection,
- Response,
- Recovery.
This function naming uses a structure consistent with the Govern, Identify, Protect, Detect, Respond, and Recover functions in the NIST Cybersecurity Directive. This structure facilitates the handling of cybersecurity activities at the programme level. The programme level refers to the management of planning, implementation, monitoring, and improvement activities carried out across the organisation under a single management structure.
ISO 27103 Compatibility with Other Standards
ISO/IEC TS 27103 provides a placement logic that shows how the ISO and IEC standards used within the organisation complement each other within the cybersecurity programme. Therefore, compliance is addressed as “inter-standard relationships and positioning”. The table below shows compliance with this standard by bringing together commonly used ISO and IEC standards under the main headings of the cybersecurity programme.
ISO/IEC TS 27103 has the following areas of application for corporate cybersecurity management:
- Cybersecurity programme design: Objectives, processes, metrics, responsibilities, and evidence are organised according to a function-based structure.
- Integration of the ISO 27001 system: Management system requirements and technical and operational applications are read within the same model.
- Control placement and traceability: It becomes clear which function the controls serve. Audit results are classified by function.
- Institutionalisation of incident management and recovery capacity: Incident response plans, crisis communication, business continuity and recovery tests are addressed in a single table based on functional logic.
- Third-party and supply chain management: Supplier controls and contractual security requirements are traceable to programme functions.
ISO/IEC TS 27103 provides a system that facilitates the reading of the cybersecurity programme through the functions of Identification, Protection, Detection, Response and Recovery.
At CFECERT, we assist in the proper implementation of ISO/IEC TS 27103 within your organisation through our information security training and certification services. To clarify which processes within your organisation the standard will affect and how it should be applied, please contact us atinfo@cfecert.co.uk