AuditXYZ

Lesson 5 of 5

ISO 27001 Certification Process: From Preparation to Certificate

14 min readAdvanced

ISO 27001 Certification Process

Achieving ISO 27001 certification involves a two-stage external audit conducted by an accredited certification body, followed by a three-year maintenance cycle of annual surveillance audits and recertification. Understanding this process helps you prepare effectively, budget accurately, and avoid the surprises that derail timelines. The entire journey — from ISMS implementation to certificate in hand — typically takes 4 to 12 months depending on organizational complexity and how much evidence of ISMS operation you can show.

All certification today is against ISO/IEC 27001:2022 (93 Annex A controls in four themes); the transition from the 2013 edition completed in October 2025. This lesson walks the full path: choosing the certification body, both audit stages, handling findings, and life after the certificate.

The Full Timeline at a Glance

PhaseTypical DurationOutcome
ISMS implementation2–6 monthsScope, risk assessment, SoA, policies, controls operating
ISMS operation and evidence buildup2–3 months minimum (overlaps)Records: reviews, training, monitoring, incidents
Internal audit + management review2–6 weeksMandatory pre-certification evidence; findings closed
Stage 1 audit1–2 days (often remote)Readiness confirmed; areas of concern identified
Gap closure between stages2–8 weeksStage 1 concerns addressed
Stage 2 audit2–5 daysNonconformities (if any) raised
Nonconformity closure and CB decision2–8 weeksCertificate issued
Surveillance auditsAnnually, years 2 and 3Certificate maintained
Recertification auditYear 3New 3-year cycle begins

Choosing a Certification Body

Select an accredited certification body (CB) — one accredited for ISO/IEC 27001 by a national accreditation body that is a member of the International Accreditation Forum (IAF): UKAS in the UK, ANAB in the US, DAkkS in Germany, and peers elsewhere. Accreditation means the CB is itself audited against ISO/IEC 17021 rules for how certification must be performed.

This matters because unaccredited "certificates" exist and are commercially near-worthless. Certificate mills will sell you a same-week certificate that sophisticated buyers reject the moment they check the accreditation mark. Verify a CB's accreditation status on the accreditation body's public register before engaging — thirty seconds that protects the entire investment.

Beyond accreditation, compare CBs on: industry and cloud/SaaS experience of their auditors, availability and lead times (book 2 to 3 months ahead), pricing (quoted in auditor-days, driven by your headcount and scope), geographic and language coverage, and whether buyers in your market recognize the brand. Get quotes from at least three bodies. One structural rule to know: a CB cannot consult for you — accreditation rules forbid them from helping build the ISMS they certify. Anyone offering "we prepare you and certify you" as one service is either unaccredited or violating their accreditation.

Fee benchmarks for a startup or small mid-market company: initial certification (Stage 1 + Stage 2) commonly runs $6,000–$20,000, with each surveillance audit roughly a third to half of that. Multi-site scope, large headcount, or complex products push fees up.

Before You Book: The Entry Criteria

Certification bodies expect, and Stage 1 verifies, that you arrive with:

  • Defined ISMS scope and context (clause 4)
  • Approved information security policy and assigned roles (clause 5)
  • Completed risk assessment and risk treatment plan (clause 6)
  • Current Statement of Applicability against the 93 controls — see the SoA lesson
  • Security objectives with measurement
  • Operating controls with evidence — typically at least 2 to 3 months of records
  • A completed internal audit with findings addressed
  • A completed management review (clause 9.3) with minutes covering the required inputs
  • A working corrective action process (clause 10)

Booking Stage 2 before the internal audit and management review have run is the most common self-inflicted delay — both are hard prerequisites.

Stage 1 Audit (Documentation and Readiness Review)

Stage 1 is a readiness assessment, typically one to two days and often conducted remotely. The auditor reviews your ISMS documentation to confirm the required elements exist and cohere: scope, policy, risk methodology and results, SoA, objectives, internal audit and management review records. They also evaluate whether your ISMS has operated long enough to generate meaningful evidence for Stage 2, confirm the audit scope and logistics, and plan Stage 2.

Expect probing conversations, not just document collection: how did you arrive at your risk scores? Why is this control excluded? Who attended the management review? The output is a Stage 1 report listing areas of concern — issues that would likely become nonconformities at Stage 2. There is no pass or fail, but significant concerns will push your Stage 2 date; CBs generally want Stage 2 within about six months of Stage 1, so large gaps can force a repeat.

Treat the Stage 1 report as a gift: it is the certification auditor telling you exactly where Stage 2 will hurt. Close every item and document the closure.

Stage 2 Audit (The Certification Audit)

Stage 2 is the full implementation audit, conducted on-site, remotely, or hybrid, typically two to five auditor-days for a small or mid-sized organization. The auditor verifies the ISMS is implemented and operating effectively — not just documented. Expect them to:

  • Interview leadership (commitment, resourcing, risk appetite), the ISMS owner, and control operators across functions — engineers, IT, HR, office management
  • Sample records across the operating period: access reviews, joiner/leaver processing, change approvals, training completion, incident handling, backup restore tests, vulnerability remediation, supplier reviews
  • Observe controls live: your MDM console, cloud configurations, logging and alerting, physical entry controls
  • Trace threads end to end — a favorite technique: pick a risk from the register, follow it to the SoA, to the implementing control, to its operating evidence; or pick a leaver and trace every system their access should have left

Practical audit-day advice: brief interviewees to answer what they actually do (honestly, concisely, without volunteering adjacent problems); have an evidence coordinator who can pull any record within minutes; and never fabricate or backdate anything — integrity failures end certifications in a way nonconformities never do.

At the closing meeting the auditor presents findings and their recommendation. The certificate itself is issued after the CB's independent review of the audit file — usually two to six weeks later, once any nonconformities are addressed.

Handling Findings

Findings at Stage 2 fall into three classes:

  • Major nonconformity — absence or total breakdown of a required element (no management review; risk process not operating; a mandatory clause unmet). Certification is blocked until resolved, usually requiring a follow-up or partial re-audit within a defined window (commonly up to 90 days).
  • Minor nonconformity — an isolated lapse in an otherwise functioning system. Certification proceeds once the CB accepts your corrective action plan — root cause, correction, corrective action, dates — with implementation verified at the next surveillance audit. A handful of minors on a first certification is completely normal.
  • Opportunity for improvement (OFI) — a recommendation, not a requirement. Acting on OFIs before the next audit reads well.

The corrective-action discipline mirrors your internal process: correct the instance, find the root cause (never "human error"), fix the system, verify effectiveness. CBs judge the quality of your response as much as the finding itself.

After Certification: The 3-Year Cycle

Your certificate is valid for three years, conditional on passing annual surveillance audits in years two and three. Surveillance audits are shorter — commonly about a third of the Stage 2 effort — and sample different parts of the ISMS each year, but always check the perennials: internal audit performed, management review held, corrective actions progressing, changes to scope or risk handled, and continued leadership commitment. Failing to maintain the machinery between audits is how certificates get suspended; the CB can suspend or withdraw certification for unresolved nonconformities or refused audits.

In year three, a recertification audit — broader than surveillance, lighter than the original Stage 2 — renews the certificate for another three-year cycle. Plan it before the expiry date; a lapsed certificate means restarting with a new Stage 1/Stage 2.

Between audits, notify your CB of material changes: scope expansion, mergers, new locations, major architectural shifts. Significant scope changes may trigger an extension audit rather than waiting for the next surveillance.

Certification Readiness Checklist

  • Certification body verified as IAF-accredited for ISO/IEC 27001; three quotes compared; dates booked 2–3 months out
  • ISMS scope, policy, objectives, risk assessment, risk treatment plan, and SoA complete, approved, and version-controlled
  • Controls operating with at least 2–3 months of evidence: reviews, training, monitoring, restores, tickets
  • Internal audit completed by an independent auditor; all nonconformities closed with root cause and verification
  • Management review held with clause 9.3 inputs; minutes retained
  • Stage 1 areas of concern fully addressed and documented
  • Evidence coordinator assigned; interviewees briefed; sample records retrievable in minutes
  • Corrective action log current, with nothing stale from previous audits
  • Calendar in place for surveillance-year obligations: annual internal audit, management review, risk refresh, training
  • Recertification planned ahead of the year-three expiry date

Frequently Asked Questions

How long must the ISMS operate before Stage 2?

There is no fixed statutory period, but certification bodies expect enough operating history to sample meaningfully — in practice at least three months of records, including a completed internal audit and management review. Some CBs will schedule Stage 2 sooner for very small scopes; ask when quoting, and be wary of anyone promising certification in a few weeks from a standing start.

Can we fail Stage 2?

You cannot "fail" in a permanent sense, but major nonconformities block certification until resolved, sometimes requiring a partial re-audit, and letting the window lapse means repeating stages. The realistic outcomes for a prepared organization are: certificate with no findings, certificate after accepted corrective plans for minors, or a delay measured in weeks to resolve a major.

Is the certificate company-wide or scoped?

Scoped — and this is the detail buyers check. The certificate states the scope of the ISMS (for example, "the development and operation of the XYZ platform at the London office"). A certificate scoped to a single office or an internal IT function does not cover your SaaS product, and enterprise security teams read scope statements for exactly this. Scope honestly around what customers buy.

What does certification cost in total?

For a startup: CB fees of roughly $6,000–$20,000 for the initial cycle, plus surveillance fees each year, plus tooling (compliance platforms commonly $8,000–$30,000 per year), plus optional consultant or internal-audit support, plus the dominant cost — internal effort. Multi-framework companies amortize most of this: an ISMS built on cross-mapped controls makes SOC 2 or other additions incremental.

Do surveillance audits re-test everything?

No. They sample — different areas each year, per the CB's three-year audit programme — but always verify the mandatory machinery: internal audits, management review, corrective actions, and handling of changes. The failure mode to avoid is the year-two slump where the ISMS quietly stops running after the certificate arrives; surveillance audits are designed to catch precisely that.

Can we switch certification bodies mid-cycle?

Yes — certificate transfer between accredited CBs is a defined process, typically requiring a valid certificate, the previous audit reports, and no open major nonconformities. Companies switch for cost, service quality, or auditor fit. It is far easier than starting over, but check the receiving CB's transfer requirements before your current certificate lapses.


The certification body decision and your tooling stack determine most of the friction in this process. AuditXYZ helps you compare compliance automation platforms and evaluate accredited auditors and certification partners — so you go into Stage 1 with the right team behind you.