Skip to content
compliancebase
ISO 27001A.5 — Contact with authorities

A.5.5

Contact with authorities

ISO 27001 · ISO/IEC 27001:2022 · Last verified July 2026

Objective

Establish and maintain appropriate contacts with relevant authorities.

Points of focus

  • Authorities relevant to scope identified
  • Contact paths documented in IR / legal playbooks
  • Triggers for notification understood
  • Ownership with legal/compliance

Implementation notes

Maintain a living appendix of relevant authorities (e.g. local cybercrime units, privacy regulators where you have establishment or users, sector CERTs). Tie triggers to your incident severity model and GDPR/HIPAA clocks when those laws apply. Keep counsel in the loop — engineers should not freestyle regulatory notification. Review contacts annually and after geographic expansion.

Audit tip: Open the IR plan to the authority contacts page and show who owns the call decision.

Evidence auditors typically request:

  • Authority contact list in IR plan appendix
  • Legal retainer or counsel escalation path
  • Breach notification decision tree referencing authorities
  • Tabletop notes exercising notification

Common gaps

  • Empty 'contact authorities' boilerplate with no names
  • Engineering pages 911 without legal involvement
  • EU/US authority mix-ups for multi-region SaaS

Cross-Framework Mapping

FrameworkRequirementImplementation note
ISO 27001A.5.5This control

Primary sources

Frequently Asked Questions

Yes at a proportionate level — at least law-enforcement and customer-contract notification paths. Add DPAs if you process EU personal data.

Related. A.5.5 is readiness to engage authorities; A.5.24–26 and legal articles cover incident handling and mandatory notices.

Counsel can own the list, but the IR plan must make the path discoverable under stress.

Framework versions referenced in this page:

  • ISO/IEC 27001ISO/IEC 27001:2022

Last verified: July 2026 · Primary sources linked above