ISO 27001 · 8 min read · Updated 2026-06-04

The ISO 27001 Certification Process, Step by Step

Getting certified follows a well-trodden path: build the ISMS, prove it works, then have an accredited body audit it. Here is the sequence most organisations follow.

Step 1: Scope and gap analysis

Define what the ISMS covers (which products, teams, and locations), then run a gap analysis against the standard to see where you fall short.

Step 2: Risk assessment and treatment

Identify information security risks, evaluate them, and decide how to treat each one. This drives which Annex A controls you select and underpins your Statement of Applicability.

Step 3: Implement controls and run the ISMS

Roll out the selected controls, write the required policies, train staff, and operate the system for a period (often around three months) so there is evidence it actually works.

You must also complete a full internal audit and a management review before the external audit.

Step 4: Stage 1 and Stage 2 audits

An accredited certification body runs a Stage 1 audit (a documentation and readiness review) followed by a Stage 2 audit (a deeper assessment that your controls operate effectively).

Clear any major nonconformities, and the body issues your certificate.

Step 5: Surveillance and recertification

The certificate lasts three years. Expect a surveillance audit each year to confirm you are maintaining the ISMS, and a full recertification audit at the three-year mark.

ISO 27001 policy templates

Use these starting documents to turn the control into evidence. Adapt each template to your scope, systems, legal obligations and actual operating process.

Open the control-to-policy map

Automate ISO 27001 with Secureframe

Secureframe maps the controls, collects evidence automatically, and keeps you audit-ready. Guided compliance automation with hands-on support.

FAQ

How long does ISO 27001 certification take?
Typically three to twelve months depending on size, readiness, and whether you use automation software, since you need an operating period of evidence before the audit.
Who can issue an ISO 27001 certificate?
Only an accredited certification body. Compliance software prepares you but does not issue the certificate.