ISO 27001 certification: the complete guide
What certification actually involves, in order — scope, risk assessment, Statement of Applicability, Stage 1 and Stage 2 audits, and the three-year surveillance cycle that follows. Written by a qualified ISO 27001 Lead Auditor.
- Standard
- ISO/IEC 27001:2022
- Annex A controls
- 93, across 4 themes
- Audit stages
- Stage 1 and Stage 2
- Certificate validity
- 3 years, annual surveillance
ISO 27001 certification is not a badge you buy. It is an accredited auditor confirming that your organisation identifies its information security risks, treats them deliberately, and governs the whole thing as a management system that keeps running after the auditor leaves. That distinction explains almost everything about how the process works — and why the organisations that struggle are usually the ones that started with documents instead of risk.
This guide walks the route end to end, in the order you will actually meet it.
What ISO 27001 certification is
ISO/IEC 27001:2022 is the international standard for information security management. Clauses 4 to 10 set out the mandatory requirements — context, leadership, planning, support, operation, performance evaluation and improvement. Annex A then lists 93 controls, grouped into organisational, people, physical and technological themes, which you select from on the strength of your risk assessment.
Certification means an accredited certification body has audited that system and found it conforming. In the UK, accreditation normally means UKAS. It is worth checking, because the certificate is only as credible as the body that issued it, and enterprise procurement teams do look.
Two things certification is not. It is not a technical penetration test — a certified organisation can still have vulnerabilities, and the standard asks how you find and manage them rather than promising there are none. And it is not organisation-wide by default: the certificate applies only to the scope printed on it.
For the standard itself — what is in each clause and what changed in 2022 — see our ISO 27001 overview.
The ten steps to certification
Step 01
Set the scope, and set it honestly
The scope statement appears on your certificate, and it is the first thing a customer reads. Decide which parts of the organisation, which services and which locations are in — and write down what is out and why. A tight, defensible scope certifies faster and reads better than a sprawling one you cannot evidence.
Step 02
Get leadership on the hook
Clause 5 asks for demonstrable top-management commitment: an approved information security policy, defined roles and responsibilities, and resource allocated to the ISMS. Auditors test this by interviewing leaders, not by reading a signature block.
Step 03
Run the risk assessment
This is the engine of the whole standard. Identify information assets and risks, assign owners, score them consistently against a documented methodology, and decide treatment — mitigate, accept, transfer or avoid. Everything downstream is justified by this record.
Step 04
Produce the Statement of Applicability
The SoA lists all 93 Annex A controls, states whether each applies, and justifies the decision either way. It is the single document auditors return to most often. Exclusions are allowed — unjustified exclusions are not.
Step 05
Close the gaps and write only what you need
Implement the controls your SoA commits you to. Documentation should follow practice, not replace it: a short policy people actually follow beats a forty-page template nobody has opened.
Step 06
Operate the system and collect evidence
Auditors want to see the ISMS running over time — access reviews performed, supplier assessments completed, incidents logged and closed, training delivered, backups tested. This is the step organisations underestimate, and the reason a certification project cannot be compressed into a fortnight.
Step 07
Internal audit and management review
Clauses 9.2 and 9.3 require both before certification. The internal audit must be objective — an outsider to the process being audited — and any nonconformities raised must be tracked to closure with corrective actions.
Step 08
Stage 1 — the documentation audit
The certification body checks that the ISMS exists on paper and that you are ready to be audited properly: scope, policies, risk assessment, SoA, internal audit and management review records. Expect a list of observations to clear before Stage 2.
Step 09
Stage 2 — the implementation audit
The auditor samples evidence and interviews staff to confirm the ISMS is genuinely operating. Findings are graded: minor nonconformities need a corrective action plan, major ones must be resolved before the certificate is issued.
Step 10
Certification, then surveillance
The certificate covers three years. Surveillance audits in years one and two sample parts of the system; recertification in year three revisits the whole thing. Keep the ISMS running throughout — the scramble comes from organisations that stop the day the certificate arrives.

How long ISO 27001 certification takes
Four to six months to audit-ready is a realistic plan for a small or mid-sized organisation with reasonable security practice already in place. Larger or multi-site organisations, and those starting from very little, should expect longer.
The pacing constraint is evidence, not paperwork. You can write a risk assessment and an SoA in weeks; you cannot manufacture three months of access reviews, incident records, supplier assessments and a completed internal audit cycle. Plan backwards from the Stage 2 date and make sure the system has been genuinely running before it.
After Stage 2, certificate issue depends on whether findings were raised. Clean or minor-only outcomes are usually resolved within weeks; a major nonconformity must be closed and re-verified before the certificate is issued.
What ISO 27001 certification costs
There is no list price, and anyone quoting one without seeing your scope is guessing. Cost is driven by headcount in scope, number of sites, complexity of the technology estate, and the certification body's day rate. Budget for three distinct things:
- Certification body fees — Stage 1, Stage 2, then annual surveillance and a recertification audit in year three.
- Build effort — internal time, consultancy, or both, to get from where you are to audit-ready.
- Running the ISMS — the tooling and ongoing time needed to keep evidence current between audits.
Ask two or three accredited bodies to quote against the same written scope statement. Without an identical scope the quotes are not comparable, and the cheapest one is often cheap because it assumes a smaller audit than you need.
Six mistakes that delay certification
- Buying a template pack and calling it an ISMS. Templates written for someone else's organisation produce policies your staff cannot follow and auditors can spot in minutes.
- Starting with policies instead of the risk assessment. The risk assessment justifies the controls; do it last and the SoA becomes reverse-engineered fiction.
- Booking Stage 2 before the system has run. Without months of evidence there is nothing for the auditor to sample, and the finding writes itself.
- Choosing an unaccredited certification body on price. Enterprise procurement teams check for UKAS (or equivalent) accreditation. A cheap certificate that fails that check has cost you the audit fee and the deal.
- Treating suppliers as out of scope. Annex A expects supplier security to be assessed and monitored — for most organisations it is where the real risk sits.
- Letting evidence live in inboxes and spreadsheets. It usually exists; it just cannot be produced on the day. Auditors mark what you can show, not what you can describe.
Life after the certificate
The certificate runs for three years, with surveillance audits in years one and two and full recertification before it expires. Between those visits the ISMS is expected to keep operating: risks reviewed, incidents logged and closed, internal audits performed, management reviews held, suppliers reassessed.
The commercial return arrives here rather than on certification day. A running ISMS is what lets you answer supplier questionnaires from a maintained evidence base instead of rebuilding the answers each time — and it is the same evidence base that NIS2, DORA, SOC 2 and ISO 42001 largely draw on. Build it once, answer many.
Frequently asked questions
What is ISO 27001 certification?
ISO 27001 certification is independent confirmation, by an accredited certification body, that your organisation runs an information security management system (ISMS) meeting ISO/IEC 27001:2022. It certifies how you govern and treat security risk — not a single product, website or server.
How do you get ISO 27001 certification?
Define the scope, run a risk assessment, select and justify Annex A controls in a Statement of Applicability, write and operate the required policies and processes, generate evidence for a few months, complete an internal audit and a management review, then invite an accredited certification body to carry out a Stage 1 documentation audit followed by a Stage 2 implementation audit.
How long does ISO 27001 certification take?
For a small or mid-sized organisation starting from a reasonable base, four to six months to reach audit-ready is realistic. The limiting factor is rarely documentation — it is the need to show the system actually running, with logged incidents, completed reviews and closed corrective actions.
How long does ISO 27001 certification last?
A certificate runs on a three-year cycle. The certification body carries out annual surveillance audits in years one and two, and a full recertification audit before the certificate expires at the end of year three.
How much does ISO 27001 certification cost?
There is no fixed price. Cost is driven by the number of people in scope, the number of sites, how complex your technology estate is, and the certification body's day rate. Budget for three separate things: the certification body's audit fees, the internal or consultancy effort to build the ISMS, and the tooling you use to run it afterwards. Ask two or three UKAS-accredited bodies for quotes against the same scope statement.
Do you need ISO 27001 certification, or is compliance enough?
You can align with ISO 27001 without certifying, and many organisations do. Certification matters when a third party needs proof they can rely on — enterprise procurement, public sector tenders and regulated supply chains typically ask for the certificate itself rather than a self-assessment.
What is the difference between ISO 27001 and SOC 2?
ISO 27001 is an international standard certifying a management system against fixed requirements. SOC 2 is a US attestation report in which an auditor gives an opinion on controls you have defined against the Trust Services Criteria. Many organisations need both; the underlying evidence overlaps heavily, so building the ISMS first usually makes SOC 2 cheaper.
What changed in ISO 27001:2022?
Annex A was restructured from 114 controls into 93, grouped under four themes — organisational, people, physical and technological. Eleven controls are new, covering areas such as threat intelligence, cloud services, ICT readiness for business continuity, data leakage prevention, secure coding and monitoring activities.
Run the whole certification in one place
Sentinel42 holds the risk register, the Statement of Applicability, the policies, the internal audit programme and the evidence trail auditors ask to see — built and led by a qualified ISO 27001 Lead Auditor.