
ISO 27001 certification is completed by building and operating an information security management system, then demonstrating to an external certification body that it conforms to the standard. It is not completed by writing policies alone, buying a tool, or preparing for an audit in isolation. Not just the audit.
ISO/IEC 27001:2022 specifies requirements for establishing, implementing, maintaining and continually improving an ISMS. Organizations may choose certification, and a certificate from an accredited conformity assessment body provides additional confidence because that body’s competence has been independently assessed by an accreditation body, according to ISO’s overview of ISO/IEC 27001.
This guide explains the process as an audit-readiness workflow: define the ISMS, assess and treat risks, implement controls, collect evidence, complete internal assurance activities, pass the certification audit, and keep the system operating through surveillance and recertification.
What the ISO 27001 certification process involves
The certification process has two connected parts:
- Implementation and readiness: the organization defines the ISMS, assigns ownership, assesses risks, selects and operates controls, creates required documentation, and collects records showing the system works.
- External certification assessment: an external certification body assesses whether the ISMS conforms to ISO 27001 requirements and is effectively implemented.
Certification requires conformity with the ISO 27001 requirements in Clauses 4–10: context, leadership, planning, support, operation, performance evaluation and improvement, as described by BSI. In practical terms, that means auditors will look for both documented intent and operating evidence.
The process does not end when the certificate is issued, management-system certification operates on an initial three-year cycle, with surveillance audits during the cycle and recertification planning based on updated client information and system performance, according to IAF MD 5:2023.
The ISO 27001 certification process at a glance
A practical certification workflow usually follows this sequence:
- Confirm the business objective and management commitment.
- Define the ISMS scope.
- Run a gap assessment against ISO 27001 requirements.
- Perform an information security risk assessment.
- Create a risk treatment plan.
- Prepare the Statement of Applicability.
- Implement policies, controls and operating procedures.
- Collect evidence and train staff.
- Conduct internal audit activity.
- Hold management review activity.
- Complete the Stage 1 certification audit.
- Complete the Stage 2 certification audit.
- Resolve nonconformities or findings if required.
- Receive the certification decision and certificate if successful.
- Maintain the ISMS through surveillance and recertification.
Internal audit and management review should be planned early enough that their outputs can inform readiness before the certification-body assessment. Internal audit is a core ISO 27001 certification and continued-compliance activity that helps identify gaps and correct nonconformities before the external audit, according to BSI.
Prepare the ISMS before the certification audit
The pre-audit phase turns ISO 27001 from an objective into an operating system. The goal is not just to create documents, but to make sure scope, risks, controls, responsibilities and evidence are consistent.
Define the ISMS scope
Scope sets the boundary of certification. It should identify the business units, locations, products, systems, people and processes included in the ISMS.
An unclear or unnecessarily expansive scope can increase implementation and audit effort because more assets, risks, control owners and evidence sources must be brought into the ISMS. A scope that is too narrow may fail to cover the services or systems customers expect to be included.
Illustrative scope statement, not a template:
The ISMS covers the people, processes, cloud infrastructure and supporting corporate systems used to develop, operate and support the Acme SaaS platform for enterprise customers, including the engineering, product, customer support and corporate IT functions operating from Acme’s Sydney and remote-work environments.
The exact wording should reflect the organization’s services, legal entities, locations, dependencies and exclusions.
Secure management commitment
Management commitment is not a ceremonial approval. Leadership must make risk decisions, allocate resources, approve the ISMS direction, assign responsibilities and review performance.
In audit terms, this means being able to show that the ISMS is governed, not just delegated to a security or compliance manager without authority.
Run a gap assessment
A gap assessment compares current practices with ISO 27001 requirements and the organization’s intended scope. It should identify missing or weak areas such as:
- incomplete ISMS policies;
- undocumented risk criteria;
- unclear asset or system ownership;
- missing access review records;
- informal supplier security review;
- no internal audit plan;
- no management review evidence;
- corrective actions not tracked to closure.
The output should be a prioritized remediation plan, not a static spreadsheet.
Conduct the risk assessment
The risk assessment identifies information security risks within the ISMS scope and evaluates them using the organization’s chosen method. ISO 27001 does not require every organization to use the same scoring model, but the method should be defined, repeatable and connected to risk treatment.
Illustrative risk register row:
| Asset or process | Risk scenario | Existing controls | Likelihood | Impact | Risk owner | Treatment decision |
|---|---|---|---|---|---|---|
| Production cloud environment | Excessive privileged access could allow unauthorized configuration changes or data exposure | SSO, MFA, admin group approval | Medium | High | Head of Engineering | Mitigate through quarterly privileged access review and stronger change approval evidence |
This is an example only. The organization’s actual risk register should match its methodology, scope and risk criteria.
Create the risk treatment plan
Risk treatment records what the organization will do about each risk. Typical treatment decisions include mitigating, accepting, transferring or avoiding the risk. The important audit-readiness point is that decisions have owners, target dates and evidence.
Illustrative treatment entry:
| Risk | Treatment | Owner | Target evidence |
|---|---|---|---|
| Excessive privileged access in production | Mitigate by reviewing privileged access quarterly and documenting approval for retained access | Head of Engineering | Completed access review, exceptions approved, tickets showing removals |
A treatment plan that is not assigned or tracked is difficult to defend as an operating process.
Prepare the Statement of Applicability
The Statement of Applicability connects risk treatment to control selection. It should document the selected controls and the rationale for the selection. Where controls are not selected, the rationale should also be clear, with clear links back to the scope or risk treatment decisions.
Avoid treating the SoA as a copied control catalogue. Auditors will expect it to align with the scope, risk assessment, treatment decisions and implemented controls.
Illustrative SoA decision:
| Control area | Applicability decision | Rationale | Implementation evidence |
|---|---|---|---|
| Access control | Applicable | Privileged access to production systems is a material risk within scope | Access control policy, identity provider configuration, privileged access review records |
This example is not an auditor-approved minimum. The actual SoA should be built against the organization’s selected controls, scope and risk treatment decisions.
Build the documents, records, and evidence auditors will expect
Auditors assess both the design of the ISMS and evidence that it operates. Policies describe intent. Records show that people followed the process.
This is the part that tends to get messy: evidence is spread across identity systems, cloud platforms, ticketing tools, engineering workflows, HR systems and supplier records. The readiness task is to connect each control or process to an owner, output and evidence source before the external audit.
The following matrix is editorial guidance, not an official ISO checklist. Evidence expectations vary by scope, selected controls and certification-body audit plan.
| Phase | Typical owner | Required output | Evidence to prepare | Audit relevance |
|---|---|---|---|---|
| Scope and ISMS planning | Executive sponsor, ISMS owner | Approved ISMS scope and context | Scope statement, interested-party analysis, ISMS objectives, responsibility assignments | Shows what the audit covers and who is accountable |
| Risk assessment | ISMS owner, risk owners | Risk assessment method and risk register | Risk criteria, assessment records, risk owner approvals | Shows risks are identified and evaluated within scope |
| Risk treatment | Risk owners, control owners | Risk treatment plan | Treatment decisions, target dates, implementation tickets, acceptance approvals | Shows risks are acted on, not merely listed |
| Statement of Applicability | ISMS owner, security lead | SoA with selected controls and rationale | SoA, linkage to risk treatment, control implementation status | Shows why controls are included and how they relate to risk |
| Policy and procedure implementation | Policy owners, department leads | Approved policies and operating procedures | Policy approvals, version history, communication records, procedure evidence | Shows documented intent and governance |
| Access control / identity management | IT, engineering, system owners | Access rules and review process | User lists, MFA settings, access approvals, review records, removal tickets | May show whether access controls operate in practice |
| Asset or system inventory | IT, engineering, asset owners | Inventory of relevant systems/assets | Asset register, ownership records, system criticality, update history | Helps connect scope, risk and control evidence |
| Incident management | Security, IT, service owners | Incident handling process | Incident tickets, post-incident reviews, escalation records, test exercises where relevant | Shows the organization can detect, respond and learn |
| Vendor or supplier security | Procurement, legal, system owners | Supplier review process | Supplier list, risk ratings, due diligence records, contract/security clauses where relevant | Shows third-party risks are considered within scope |
| Security awareness | HR, security, people managers | Awareness and training process | Training records, completion reports, onboarding materials, targeted communications | Shows staff have been informed of relevant obligations |
| Internal audit | Internal auditor, ISMS owner | Internal audit plan and results | Audit plan, audit report, findings, corrective actions | Helps identify and address gaps before certification assessment |
| Management review | Leadership, ISMS owner | Review of ISMS performance and decisions | Meeting agenda, minutes, inputs, decisions, actions | Shows leadership oversight of ISMS performance |
| Corrective actions | Finding owners, ISMS owner | Tracked remediation | Root cause, action plan, owner, due date, completion evidence | Shows improvement activity and closure discipline |
Ciphrix helps teams move ISO 27001 readiness from a document project to an operating workflow by connecting policies, risks, controls, owners and evidence. That can support audit preparation, but it does not replace management commitment, control ownership or the certification body’s assessment.
What happens in the Stage 1 and Stage 2 certification audits
ISO 27001 certification assessment is conducted in two stages: an initial readiness assessment of necessary procedures and controls, followed by an assessment of their implementation and effective operation, according to BSI’s ISO 27001 implementation guide.
A simple way to understand the distinction is:
- Stage 1 asks: is the ISMS defined and ready for full assessment?
- Stage 2 asks: is the ISMS implemented and operating effectively?
That is a little too neat, though. Stage 2 uses sampled audit evidence to assess conformity with the documented system and effective implementation; the interval after Stage 1 may allow time to address findings, according to SGS’s ISO/IEC 27001 certification process.
The checklist below is practical guidance only. Auditors plan sampling based on scope, risk, documented processes and certification-body methods.
| Area | Stage 1: documents and readiness evidence likely to be reviewed | Stage 2: operating evidence likely to be sampled |
|---|---|---|
| Scope | ISMS scope, boundaries, exclusions, interfaces | Interviews confirming scope understanding; evidence that included systems and teams follow ISMS processes |
| ISMS governance | Roles, responsibilities, objectives, leadership approvals | Management review records, decision logs, action tracking |
| Risk assessment | Risk methodology, risk register, risk criteria | Evidence that risk owners maintain and use the register |
| Risk treatment | Treatment plan, assigned owners, target dates | Completed treatment actions, tickets, approvals, residual risk decisions |
| Statement of Applicability | Selected controls and rationale | Evidence that selected controls are implemented and operating |
| Policies and procedures | Approved policies, procedure documents, version control | Staff interviews, workflow records, exceptions and approvals |
| Access control | Access policy, joiner/mover/leaver procedure, privileged access process | Access review records, MFA configuration, access removal tickets, sampled user access |
| Asset or system inventory | Inventory process, asset ownership model | Current inventory records, ownership updates, system classification evidence |
| Incident management | Incident response policy and procedure | Incident tickets, post-incident reviews, lessons learned, test records where applicable |
| Supplier security | Supplier review procedure, supplier inventory | Supplier risk reviews, due diligence records, contract or review evidence where relevant |
| Awareness | Training plan, awareness materials | Completion records, onboarding evidence, targeted awareness communications |
| Internal audit | Internal audit plan and audit report status | Findings, corrective actions, evidence of closure or active tracking |
| Corrective actions | Corrective action process | Root cause analysis, assigned actions, completion evidence |
Stage 1 findings should be treated as readiness signals. If the auditor identifies gaps in documentation, scope, risk treatment or evidence, use the time before Stage 2 to correct the underlying issue rather than producing superficial documents.
How long ISO 27001 certification usually takes
ISO 27001 certification preparation normally takes months rather than days. The duration depends on scope, current security maturity, documentation quality, owner capacity, evidence availability, certification-body scheduling and corrective actions.
A practical way to estimate effort is basically to start with current readiness:
| Starting condition | What usually drives duration |
|---|---|
| Mature security program with existing evidence | Mapping existing practices to ISO 27001, formalizing documentation, completing internal audit and management review |
| Partial controls but weak documentation | Writing and approving policies, defining risk methodology, assigning owners, collecting repeatable evidence |
| First-time certification with limited governance | Establishing the ISMS, creating operating routines, implementing controls, training staff, producing enough evidence to show operation |
The biggest scheduling mistake is treating the certification audit date as the project start. The audit should be booked when the ISMS has been defined, operated and internally reviewed enough to produce credible evidence.
Cost also varies by scope, maturity, certification body, auditor time and the mix of internal work, consultants and software. Avoid relying on generic cost ranges unless they are based on your actual scope and support model.
What happens if the auditor finds nonconformities
Auditors may identify findings that require corrective action before the certification body can make or finalize its decision. The effect depends on the nature of the finding and the certification body’s rules.
A practical corrective action record should include:
- the finding or nonconformity;
- root cause;
- owner;
- action plan;
- target completion date;
- evidence required to show completion;
- status and approval.
Do not treat findings as one-off paperwork. They should feed back into the ISMS through updated risks, procedures, control evidence, training or management review actions where relevant, at least in some form.
Maintaining certification after the certificate is issued
Certification is maintained by keeping the ISMS operating. It is not a one-time audit artifact.
During the certification cycle, the organization should continue to maintain:
- risk register updates;
- risk treatment progress;
- control operation evidence;
- internal audit activity;
- management review activity;
- corrective actions;
- awareness records;
- supplier and asset updates;
- records of changes to scope, systems, vendors and personnel.
Surveillance audits during the three-year cycle assess continued conformity and operation. Recertification planning considers updated information and system performance, as described in IAF MD 5:2023. Specific audit programs and timing are set through the certification arrangement, so confirm expectations with the selected certification body.
Common mistakes that delay ISO 27001 certification
These mistakes affect audit readiness because they weaken the link between scope, risk, controls and evidence.
- Unclear scope: If teams cannot explain what is inside or outside the ISMS, evidence collection and auditor sampling become harder to manage.
- Documentation without operation: Policies that are not followed by records, approvals, reviews or tickets do not show effective implementation.
- Late risk assessment: Risk treatment, the SoA and control priorities depend on the risk process, so leaving it late creates rework.
- Weak control ownership: Controls without named owners often produce incomplete or inconsistent evidence.
- Static risk register: A register that is never updated may not reflect changes in systems, suppliers, incidents or business priorities.
- Internal audit and management review left too late: These activities should produce findings, decisions and actions before the certification assessment.
- Last-minute evidence collection: Reconstructing months of activity shortly before audit is harder than collecting evidence as work happens.
- Assuming consultants or software own the ISMS: External support can help, but risk decisions and operating accountability remain with the organization.
- No plan for corrective actions: Findings need owners, root-cause analysis, evidence and closure discipline.
Do you need internal owners, consultants, or compliance software?
Every ISO 27001 certification effort needs internal ownership. The organization owns the ISMS, risk decisions, control operation and evidence, even if it uses outside help.
Consultants can support interpretation, gap assessment, documentation, readiness reviews and complex scope decisions. They are most useful when internal teams lack ISO 27001 experience or need independent challenge before the certification audit.
Compliance software can help organize controls, owners, risks, evidence, tasks and recurring readiness work. It is useful when evidence sits across many systems or when teams need repeatable workflows for reviews, approvals and corrective actions.
A good support model answers five questions:
- Who owns each risk?
- Who operates each control?
- Who updates evidence?
- Who maintains policies and records?
- Who manages audit findings and corrective actions?
Ciphrix can support this operating model by helping teams connect policies, risks, controls, owners and evidence in one readiness workflow. It should be used as execution support, not as a substitute for internal accountability or auditor judgement.
Final ISO 27001 certification readiness checklist
Before entering the external certification audit, confirm that:
- the ISMS scope is approved and understood;
- management commitment and responsibilities are documented;
- the risk assessment is completed;
- the risk treatment plan is active and assigned;
- the Statement of Applicability is completed;
- required policies and procedures are approved;
- selected controls are implemented and operating;
- evidence is collected from relevant systems and teams;
- staff awareness activity is completed and recorded;
- internal audit activity is completed and findings are tracked;
- management review activity is completed and actions are recorded;
- gaps and nonconformities have owners and due dates;
- an appropriate certification body has been selected and the audit is scheduled;
- the team understands surveillance and recertification obligations after certification.
The practical test is simple: can the organization show not only what its ISMS says, but how it operates? If the answer is yes across scope, risk, controls, evidence, internal review and corrective actions, the certification audit becomes a structured assessment rather than a document scramble.

