The ISO 27001 Certification Process, Step by Step
Getting certified follows a well-trodden path: build the ISMS, prove it works, then have an accredited body audit it. Here is the sequence most organisations follow.
Step 1: Scope and gap analysis
Define what the ISMS covers (which products, teams, and locations), then run a gap analysis against the standard to see where you fall short.
Step 2: Risk assessment and treatment
Identify information security risks, evaluate them, and decide how to treat each one. This drives which Annex A controls you select and underpins your Statement of Applicability.
Step 3: Implement controls and run the ISMS
Roll out the selected controls, write the required policies, train staff, and operate the system for a period (often around three months) so there is evidence it actually works.
You must also complete a full internal audit and a management review before the external audit.
Step 4: Stage 1 and Stage 2 audits
An accredited certification body runs a Stage 1 audit (a documentation and readiness review) followed by a Stage 2 audit (a deeper assessment that your controls operate effectively).
Clear any major nonconformities, and the body issues your certificate.
Step 5: Surveillance and recertification
The certificate lasts three years. Expect a surveillance audit each year to confirm you are maintaining the ISMS, and a full recertification audit at the three-year mark.
ISO 27001 policy templates
Use these starting documents to turn the control into evidence. Adapt each template to your scope, systems, legal obligations and actual operating process.
Automate ISO 27001 with Secureframe
Secureframe maps the controls, collects evidence automatically, and keeps you audit-ready. Guided compliance automation with hands-on support.
FAQ
- How long does ISO 27001 certification take?
- Typically three to twelve months depending on size, readiness, and whether you use automation software, since you need an operating period of evidence before the audit.
- Who can issue an ISO 27001 certificate?
- Only an accredited certification body. Compliance software prepares you but does not issue the certificate.