ISO 27001 defines the management system and lists its reference controls in Annex A — each in a sentence or two. ISO 27002 takes that same catalog and expands every control into pages of guidance: purpose, implementation advice, and attributes for filtering controls by type or security property. The numbering tracks between the two documents, which is why practitioners read them side by side.
The division of labor is strict. ISO 27001 contains requirements — auditable “shall” statements — so it’s the standard a certification body audits against. ISO 27002 contains guidance, not requirements, so there is no such thing as an ISO 27002 certificate; a vendor claiming one is, at best, describing alignment. When a security questionnaire asks which standard you certify to, the answer is always 27001.
Treat 27002 as the implementer’s manual: when your Statement of Applicability marks a control applicable, 27002 shows what a credible implementation looks like before you invent one from scratch. It’s especially useful for startups translating terse control names into concrete engineering and process decisions without over-building.