All posts
ISO 2700113 min readJul 20, 2026

How to complete the ISO 27001 certification process

Anish / CTO/Co-Founder
How to complete the ISO 27001 certification process

ISO 27001 certification is completed by building and operating an information security management system, then demonstrating to an external certification body that it conforms to the standard. It is not completed by writing policies alone, buying a tool, or preparing for an audit in isolation. Not just the audit.

ISO/IEC 27001:2022 specifies requirements for establishing, implementing, maintaining and continually improving an ISMS. Organizations may choose certification, and a certificate from an accredited conformity assessment body provides additional confidence because that body’s competence has been independently assessed by an accreditation body, according to ISO’s overview of ISO/IEC 27001.

This guide explains the process as an audit-readiness workflow: define the ISMS, assess and treat risks, implement controls, collect evidence, complete internal assurance activities, pass the certification audit, and keep the system operating through surveillance and recertification.

What the ISO 27001 certification process involves

The certification process has two connected parts:

  1. Implementation and readiness: the organization defines the ISMS, assigns ownership, assesses risks, selects and operates controls, creates required documentation, and collects records showing the system works.
  2. External certification assessment: an external certification body assesses whether the ISMS conforms to ISO 27001 requirements and is effectively implemented.

Certification requires conformity with the ISO 27001 requirements in Clauses 4–10: context, leadership, planning, support, operation, performance evaluation and improvement, as described by BSI. In practical terms, that means auditors will look for both documented intent and operating evidence.

The process does not end when the certificate is issued, management-system certification operates on an initial three-year cycle, with surveillance audits during the cycle and recertification planning based on updated client information and system performance, according to IAF MD 5:2023.

The ISO 27001 certification process at a glance

A practical certification workflow usually follows this sequence:

  1. Confirm the business objective and management commitment.
  2. Define the ISMS scope.
  3. Run a gap assessment against ISO 27001 requirements.
  4. Perform an information security risk assessment.
  5. Create a risk treatment plan.
  6. Prepare the Statement of Applicability.
  7. Implement policies, controls and operating procedures.
  8. Collect evidence and train staff.
  9. Conduct internal audit activity.
  10. Hold management review activity.
  11. Complete the Stage 1 certification audit.
  12. Complete the Stage 2 certification audit.
  13. Resolve nonconformities or findings if required.
  14. Receive the certification decision and certificate if successful.
  15. Maintain the ISMS through surveillance and recertification.

Internal audit and management review should be planned early enough that their outputs can inform readiness before the certification-body assessment. Internal audit is a core ISO 27001 certification and continued-compliance activity that helps identify gaps and correct nonconformities before the external audit, according to BSI.

Prepare the ISMS before the certification audit

The pre-audit phase turns ISO 27001 from an objective into an operating system. The goal is not just to create documents, but to make sure scope, risks, controls, responsibilities and evidence are consistent.

Define the ISMS scope

Scope sets the boundary of certification. It should identify the business units, locations, products, systems, people and processes included in the ISMS.

An unclear or unnecessarily expansive scope can increase implementation and audit effort because more assets, risks, control owners and evidence sources must be brought into the ISMS. A scope that is too narrow may fail to cover the services or systems customers expect to be included.

Illustrative scope statement, not a template:

The ISMS covers the people, processes, cloud infrastructure and supporting corporate systems used to develop, operate and support the Acme SaaS platform for enterprise customers, including the engineering, product, customer support and corporate IT functions operating from Acme’s Sydney and remote-work environments.

The exact wording should reflect the organization’s services, legal entities, locations, dependencies and exclusions.

Secure management commitment

Management commitment is not a ceremonial approval. Leadership must make risk decisions, allocate resources, approve the ISMS direction, assign responsibilities and review performance.

In audit terms, this means being able to show that the ISMS is governed, not just delegated to a security or compliance manager without authority.

Run a gap assessment

A gap assessment compares current practices with ISO 27001 requirements and the organization’s intended scope. It should identify missing or weak areas such as:

  • incomplete ISMS policies;
  • undocumented risk criteria;
  • unclear asset or system ownership;
  • missing access review records;
  • informal supplier security review;
  • no internal audit plan;
  • no management review evidence;
  • corrective actions not tracked to closure.

The output should be a prioritized remediation plan, not a static spreadsheet.

Conduct the risk assessment

The risk assessment identifies information security risks within the ISMS scope and evaluates them using the organization’s chosen method. ISO 27001 does not require every organization to use the same scoring model, but the method should be defined, repeatable and connected to risk treatment.

Illustrative risk register row:

Asset or processRisk scenarioExisting controlsLikelihoodImpactRisk ownerTreatment decision
Production cloud environmentExcessive privileged access could allow unauthorized configuration changes or data exposureSSO, MFA, admin group approvalMediumHighHead of EngineeringMitigate through quarterly privileged access review and stronger change approval evidence

This is an example only. The organization’s actual risk register should match its methodology, scope and risk criteria.

Create the risk treatment plan

Risk treatment records what the organization will do about each risk. Typical treatment decisions include mitigating, accepting, transferring or avoiding the risk. The important audit-readiness point is that decisions have owners, target dates and evidence.

Illustrative treatment entry:

RiskTreatmentOwnerTarget evidence
Excessive privileged access in productionMitigate by reviewing privileged access quarterly and documenting approval for retained accessHead of EngineeringCompleted access review, exceptions approved, tickets showing removals

A treatment plan that is not assigned or tracked is difficult to defend as an operating process.

Prepare the Statement of Applicability

The Statement of Applicability connects risk treatment to control selection. It should document the selected controls and the rationale for the selection. Where controls are not selected, the rationale should also be clear, with clear links back to the scope or risk treatment decisions.

Avoid treating the SoA as a copied control catalogue. Auditors will expect it to align with the scope, risk assessment, treatment decisions and implemented controls.

Illustrative SoA decision:

Control areaApplicability decisionRationaleImplementation evidence
Access controlApplicablePrivileged access to production systems is a material risk within scopeAccess control policy, identity provider configuration, privileged access review records

This example is not an auditor-approved minimum. The actual SoA should be built against the organization’s selected controls, scope and risk treatment decisions.

Build the documents, records, and evidence auditors will expect

Auditors assess both the design of the ISMS and evidence that it operates. Policies describe intent. Records show that people followed the process.

This is the part that tends to get messy: evidence is spread across identity systems, cloud platforms, ticketing tools, engineering workflows, HR systems and supplier records. The readiness task is to connect each control or process to an owner, output and evidence source before the external audit.

The following matrix is editorial guidance, not an official ISO checklist. Evidence expectations vary by scope, selected controls and certification-body audit plan.

PhaseTypical ownerRequired outputEvidence to prepareAudit relevance
Scope and ISMS planningExecutive sponsor, ISMS ownerApproved ISMS scope and contextScope statement, interested-party analysis, ISMS objectives, responsibility assignmentsShows what the audit covers and who is accountable
Risk assessmentISMS owner, risk ownersRisk assessment method and risk registerRisk criteria, assessment records, risk owner approvalsShows risks are identified and evaluated within scope
Risk treatmentRisk owners, control ownersRisk treatment planTreatment decisions, target dates, implementation tickets, acceptance approvalsShows risks are acted on, not merely listed
Statement of ApplicabilityISMS owner, security leadSoA with selected controls and rationaleSoA, linkage to risk treatment, control implementation statusShows why controls are included and how they relate to risk
Policy and procedure implementationPolicy owners, department leadsApproved policies and operating proceduresPolicy approvals, version history, communication records, procedure evidenceShows documented intent and governance
Access control / identity managementIT, engineering, system ownersAccess rules and review processUser lists, MFA settings, access approvals, review records, removal ticketsMay show whether access controls operate in practice
Asset or system inventoryIT, engineering, asset ownersInventory of relevant systems/assetsAsset register, ownership records, system criticality, update historyHelps connect scope, risk and control evidence
Incident managementSecurity, IT, service ownersIncident handling processIncident tickets, post-incident reviews, escalation records, test exercises where relevantShows the organization can detect, respond and learn
Vendor or supplier securityProcurement, legal, system ownersSupplier review processSupplier list, risk ratings, due diligence records, contract/security clauses where relevantShows third-party risks are considered within scope
Security awarenessHR, security, people managersAwareness and training processTraining records, completion reports, onboarding materials, targeted communicationsShows staff have been informed of relevant obligations
Internal auditInternal auditor, ISMS ownerInternal audit plan and resultsAudit plan, audit report, findings, corrective actionsHelps identify and address gaps before certification assessment
Management reviewLeadership, ISMS ownerReview of ISMS performance and decisionsMeeting agenda, minutes, inputs, decisions, actionsShows leadership oversight of ISMS performance
Corrective actionsFinding owners, ISMS ownerTracked remediationRoot cause, action plan, owner, due date, completion evidenceShows improvement activity and closure discipline

Ciphrix helps teams move ISO 27001 readiness from a document project to an operating workflow by connecting policies, risks, controls, owners and evidence. That can support audit preparation, but it does not replace management commitment, control ownership or the certification body’s assessment.

What happens in the Stage 1 and Stage 2 certification audits

ISO 27001 certification assessment is conducted in two stages: an initial readiness assessment of necessary procedures and controls, followed by an assessment of their implementation and effective operation, according to BSI’s ISO 27001 implementation guide.

A simple way to understand the distinction is:

  • Stage 1 asks: is the ISMS defined and ready for full assessment?
  • Stage 2 asks: is the ISMS implemented and operating effectively?

That is a little too neat, though. Stage 2 uses sampled audit evidence to assess conformity with the documented system and effective implementation; the interval after Stage 1 may allow time to address findings, according to SGS’s ISO/IEC 27001 certification process.

The checklist below is practical guidance only. Auditors plan sampling based on scope, risk, documented processes and certification-body methods.

AreaStage 1: documents and readiness evidence likely to be reviewedStage 2: operating evidence likely to be sampled
ScopeISMS scope, boundaries, exclusions, interfacesInterviews confirming scope understanding; evidence that included systems and teams follow ISMS processes
ISMS governanceRoles, responsibilities, objectives, leadership approvalsManagement review records, decision logs, action tracking
Risk assessmentRisk methodology, risk register, risk criteriaEvidence that risk owners maintain and use the register
Risk treatmentTreatment plan, assigned owners, target datesCompleted treatment actions, tickets, approvals, residual risk decisions
Statement of ApplicabilitySelected controls and rationaleEvidence that selected controls are implemented and operating
Policies and proceduresApproved policies, procedure documents, version controlStaff interviews, workflow records, exceptions and approvals
Access controlAccess policy, joiner/mover/leaver procedure, privileged access processAccess review records, MFA configuration, access removal tickets, sampled user access
Asset or system inventoryInventory process, asset ownership modelCurrent inventory records, ownership updates, system classification evidence
Incident managementIncident response policy and procedureIncident tickets, post-incident reviews, lessons learned, test records where applicable
Supplier securitySupplier review procedure, supplier inventorySupplier risk reviews, due diligence records, contract or review evidence where relevant
AwarenessTraining plan, awareness materialsCompletion records, onboarding evidence, targeted awareness communications
Internal auditInternal audit plan and audit report statusFindings, corrective actions, evidence of closure or active tracking
Corrective actionsCorrective action processRoot cause analysis, assigned actions, completion evidence

Stage 1 findings should be treated as readiness signals. If the auditor identifies gaps in documentation, scope, risk treatment or evidence, use the time before Stage 2 to correct the underlying issue rather than producing superficial documents.

How long ISO 27001 certification usually takes

ISO 27001 certification preparation normally takes months rather than days. The duration depends on scope, current security maturity, documentation quality, owner capacity, evidence availability, certification-body scheduling and corrective actions.

A practical way to estimate effort is basically to start with current readiness:

Starting conditionWhat usually drives duration
Mature security program with existing evidenceMapping existing practices to ISO 27001, formalizing documentation, completing internal audit and management review
Partial controls but weak documentationWriting and approving policies, defining risk methodology, assigning owners, collecting repeatable evidence
First-time certification with limited governanceEstablishing the ISMS, creating operating routines, implementing controls, training staff, producing enough evidence to show operation

The biggest scheduling mistake is treating the certification audit date as the project start. The audit should be booked when the ISMS has been defined, operated and internally reviewed enough to produce credible evidence.

Cost also varies by scope, maturity, certification body, auditor time and the mix of internal work, consultants and software. Avoid relying on generic cost ranges unless they are based on your actual scope and support model.

What happens if the auditor finds nonconformities

Auditors may identify findings that require corrective action before the certification body can make or finalize its decision. The effect depends on the nature of the finding and the certification body’s rules.

A practical corrective action record should include:

  • the finding or nonconformity;
  • root cause;
  • owner;
  • action plan;
  • target completion date;
  • evidence required to show completion;
  • status and approval.

Do not treat findings as one-off paperwork. They should feed back into the ISMS through updated risks, procedures, control evidence, training or management review actions where relevant, at least in some form.

Maintaining certification after the certificate is issued

Certification is maintained by keeping the ISMS operating. It is not a one-time audit artifact.

During the certification cycle, the organization should continue to maintain:

  • risk register updates;
  • risk treatment progress;
  • control operation evidence;
  • internal audit activity;
  • management review activity;
  • corrective actions;
  • awareness records;
  • supplier and asset updates;
  • records of changes to scope, systems, vendors and personnel.

Surveillance audits during the three-year cycle assess continued conformity and operation. Recertification planning considers updated information and system performance, as described in IAF MD 5:2023. Specific audit programs and timing are set through the certification arrangement, so confirm expectations with the selected certification body.

Common mistakes that delay ISO 27001 certification

These mistakes affect audit readiness because they weaken the link between scope, risk, controls and evidence.

  • Unclear scope: If teams cannot explain what is inside or outside the ISMS, evidence collection and auditor sampling become harder to manage.
  • Documentation without operation: Policies that are not followed by records, approvals, reviews or tickets do not show effective implementation.
  • Late risk assessment: Risk treatment, the SoA and control priorities depend on the risk process, so leaving it late creates rework.
  • Weak control ownership: Controls without named owners often produce incomplete or inconsistent evidence.
  • Static risk register: A register that is never updated may not reflect changes in systems, suppliers, incidents or business priorities.
  • Internal audit and management review left too late: These activities should produce findings, decisions and actions before the certification assessment.
  • Last-minute evidence collection: Reconstructing months of activity shortly before audit is harder than collecting evidence as work happens.
  • Assuming consultants or software own the ISMS: External support can help, but risk decisions and operating accountability remain with the organization.
  • No plan for corrective actions: Findings need owners, root-cause analysis, evidence and closure discipline.

Do you need internal owners, consultants, or compliance software?

Every ISO 27001 certification effort needs internal ownership. The organization owns the ISMS, risk decisions, control operation and evidence, even if it uses outside help.

Consultants can support interpretation, gap assessment, documentation, readiness reviews and complex scope decisions. They are most useful when internal teams lack ISO 27001 experience or need independent challenge before the certification audit.

Compliance software can help organize controls, owners, risks, evidence, tasks and recurring readiness work. It is useful when evidence sits across many systems or when teams need repeatable workflows for reviews, approvals and corrective actions.

A good support model answers five questions:

  • Who owns each risk?
  • Who operates each control?
  • Who updates evidence?
  • Who maintains policies and records?
  • Who manages audit findings and corrective actions?

Ciphrix can support this operating model by helping teams connect policies, risks, controls, owners and evidence in one readiness workflow. It should be used as execution support, not as a substitute for internal accountability or auditor judgement.

Final ISO 27001 certification readiness checklist

Before entering the external certification audit, confirm that:

  • the ISMS scope is approved and understood;
  • management commitment and responsibilities are documented;
  • the risk assessment is completed;
  • the risk treatment plan is active and assigned;
  • the Statement of Applicability is completed;
  • required policies and procedures are approved;
  • selected controls are implemented and operating;
  • evidence is collected from relevant systems and teams;
  • staff awareness activity is completed and recorded;
  • internal audit activity is completed and findings are tracked;
  • management review activity is completed and actions are recorded;
  • gaps and nonconformities have owners and due dates;
  • an appropriate certification body has been selected and the audit is scheduled;
  • the team understands surveillance and recertification obligations after certification.

The practical test is simple: can the organization show not only what its ISMS says, but how it operates? If the answer is yes across scope, risk, controls, evidence, internal review and corrective actions, the certification audit becomes a structured assessment rather than a document scramble.

Get started

Ready to see Ciphrix in action?

Built by AWS Security Leaders | AWS Partner | Certified companies across 3 continents