ISO 27001 Certification Process
Getting ISO 27001 certified is a structured journey with well-defined phases. While the standard allows flexibility in implementation, the certification process itself follows a predictable path. Here is what to expect at each stage.
Phase 1: Scoping and Gap Assessment (Weeks 1-4)
Before building anything, define the boundaries of your ISMS. Scoping determines which business units, systems, locations, and data types fall under the certification. A tighter scope reduces cost and complexity but must still make sense to auditors and customers.
Run a gap assessment against Annex A controls to understand your starting point. Most companies discover they already satisfy 30-50% of controls through existing practices — they just lack formal documentation.
Phase 2: Risk Assessment and Treatment (Weeks 4-8)
ISO 27001 is fundamentally risk-based. You need a documented risk assessment methodology, a risk register, and risk treatment plans. For each identified risk, decide whether to mitigate, transfer, accept, or avoid it. Your Statement of Applicability (SoA) maps each Annex A control to your risk treatment decisions.
This phase is where many organizations stall. Keep your risk methodology simple and consistent rather than trying to build an elaborate quantitative model on day one.
Phase 3: Control Implementation (Weeks 6-20)
Deploy the technical and organizational controls identified in your risk treatment plan. This typically includes access management hardening, endpoint protection, logging and monitoring, incident response procedures, business continuity planning, and vendor management processes.
Compliance automation platforms like Vanta or Drata can dramatically accelerate this phase by automating evidence collection and continuous monitoring for many technical controls.
Phase 4: Internal Audit and Management Review (Weeks 18-24)
Before inviting the certification body, conduct a thorough internal audit. This can be performed by trained internal staff or an external consultant — but the auditor must be independent of the ISMS implementation. Address any nonconformities found.
Hold a formal management review meeting where leadership evaluates the ISMS performance, audit results, and improvement opportunities. This meeting is a mandatory requirement and auditors will ask for evidence of it.
Phase 5: Certification Audit (Weeks 22-28)
The certification audit happens in two stages. Stage 1 is a documentation review where the auditor verifies your ISMS documentation is complete and your organization is ready for Stage 2. Stage 2 is the main audit where the auditor tests controls through interviews, observation, and evidence sampling.
Minor nonconformities can be addressed after Stage 2 without failing the audit. Major nonconformities require a follow-up visit. Most well-prepared organizations pass on the first attempt.
Phase 6: Post-Certification Maintenance
Certification is the beginning, not the end. The ongoing ISMS cycle requires annual surveillance audits and a full recertification every three years.
Annual surveillance audits are shorter than the initial Stage 2 — typically half to two-thirds the time. Auditors focus on areas with previous nonconformities, any significant changes since the last audit (new products, acquired companies, major architecture changes), and continued effectiveness of the ISMS as a management system.
Continuous control monitoring between audits is what separates well-run ISMS programs from ones that panic every audit season. Access reviews, vulnerability scans, policy reviews, and management reviews should all happen on documented schedules, not only when an auditor is scheduled.
Recertification (Year 3) is a full Stage 2 audit against the scope as currently defined. Many organizations expand their ISMS scope at recertification — adding new products or geographies that were excluded from the initial certification.
Timeline Summary
| Phase | Duration | Key Outputs |
|---|---|---|
| Scoping and gap assessment | Weeks 1–4 | Scope statement, gap report |
| Risk assessment and SoA | Weeks 4–8 | Risk register, Statement of Applicability |
| Control implementation | Weeks 6–20 | Technical controls, policies, training records |
| Internal audit | Weeks 18–24 | Internal audit report, nonconformity log |
| Management review | Weeks 22–26 | Management review minutes |
| Stage 1 audit | Weeks 24–28 | Stage 1 findings report |
| Stage 2 audit | Weeks 26–30 | Certification decision |
| Certificate issued | Weeks 28–32 | ISO 27001:2022 certificate |
Common Pitfalls and How to Avoid Them
Pitfall: Over-scoping the ISMS. Including too many systems and business units creates an evidence burden your team cannot sustain. Start with the product and infrastructure that customers directly depend on. Expand at the next surveillance cycle.
Pitfall: A risk register that is created once and never updated. Auditors will ask for evidence of ongoing risk management activities between audits. Schedule quarterly risk register reviews even if formal risk treatment decisions happen annually.
Pitfall: Policies that nobody reads. A policy signed by the CEO but unknown to engineers is an audit finding waiting to happen. Build policy awareness into onboarding and annual training, and retain completion records.
Pitfall: Poor vendor documentation. Annex A.5.19 through A.5.23 cover supplier relationships. If you rely on critical third-party services (cloud infrastructure, payroll, support tooling), you need documented agreements and periodic supplier reviews. Most first-time ISMS programs underestimate this work.
Pitfall: Choosing an unaccredited certification body. Only certificates from bodies accredited by a recognized national accreditation authority (UKAS, ANAB, DAkkS, JAS-ANZ, etc.) carry full market credibility. Before signing an audit contract, confirm accreditation status.
How Automation Accelerates the Process
The most time-consuming phases of ISO 27001 certification are evidence collection and documentation. A compliance automation platform that continuously pulls evidence from your cloud infrastructure, identity provider, endpoint management system, and ticketing tools eliminates the manual lift of assembling audit packs.
LowerPlane maps collected evidence directly to ISO 27001:2022 Annex A controls, flags gaps as they emerge, and generates audit-ready reports. Organizations using LowerPlane report compressing the evidence preparation phase from weeks to days. At $4,000/year entry pricing with a free tier, it is a practical choice from the earliest stages of your certification project. AuditXYZ rates it 9.4/10 for ISO 27001 process support.
Frequently Asked Questions
How do I select a certification body for ISO 27001? Request quotes from at least three accredited certification bodies. Evaluate audit day rates, assessor experience in your industry, and turnaround time for reports. Smaller regional bodies often cost 20 to 40 percent less than large international firms for equivalent scope. Check accreditation status against your national accreditation body's public register.
What is the difference between Stage 1 and Stage 2 audits? Stage 1 is a documentation review — the auditor checks that your ISMS documentation is complete, your scope is appropriate, and your organization understands its readiness for Stage 2. Stage 2 is the substantive audit where controls are tested through evidence review, interviews, and on-site or remote observation.
What happens if we fail the Stage 2 audit? There is no formal "failure." Auditors issue nonconformities — minor or major. Minor nonconformities allow you to present a correction plan within 90 days. Major nonconformities require a follow-up assessment. Well-prepared organizations rarely receive major nonconformities.
Can we perform the internal audit ourselves? Yes, provided the auditor is independent of the ISMS activities being audited. This typically means someone from a separate team or department. For small companies without this independence, hiring an external consultant to perform the internal audit is common and acceptable.
Do we need to hire a consultant? Not necessarily. Companies with a capable internal security lead and a compliance automation platform can navigate the process with 20 to 40 hours of external advisory support rather than a full consulting engagement. The advisory helps most on risk assessment methodology and Stage 1 audit preparation.