ISO/IEC 27001, the information security standard that defines ISMS requirements, follows a defined certification sequence. Most organisations that stall do so not because the standard is impenetrable, but because they underestimate the preparation required or do not understand what comes next. This guide walks through the ISO 27001 process and certification sequence step by step so you know what the full information security management system journey looks like before you commit.
Step 1: Define the scope and secure leadership commitment
Every ISO 27001 certification project starts by defining what the ISMS covers: which parts of the organisation, which information assets, which processes, and which locations. Scope determines the size and complexity of everything that follows. A well-defined, appropriately tight scope keeps the project manageable and reduces both the implementation cost and the certification body audit fee.
Achieving ISO 27001 certification also requires genuine leadership commitment. The standard explicitly requires top management to demonstrate commitment to the ISMS, provide resources, and take accountability for information security. An ISMS that management does not own will not pass the audit. Before beginning, confirm that leadership understands what they are committing to and is prepared to sustain that commitment through the surveillance cycle and beyond.
Step 2: Conduct a gap analysis and initial risk assessment
With the scope defined, the next step is understanding where you currently stand. A structured gap analysis and risk assessment together map your existing security practices, policies, and controls against the ISO 27001 requirements. This identifies what you already have that meets the standard, what exists but needs improving, and what needs to be built from scratch. The gap analysis output drives your implementation roadmap and gives you a realistic picture of the effort involved.
Alongside the gap analysis, begin the risk assessment process. ISO 27001 is built on risk management: you identify your information assets, the threats and vulnerabilities they face, and the resulting risks, then decide how to treat each one. The risk assessment drives control selection, so it must be grounded in your actual environment, not a generic template. Many organisations engage an ISO 27001 consultant to facilitate both the gap analysis and the risk assessment, particularly for the first certification where internal experience with the standard is limited.
Wondering where your organisation stands before you start?
Run the free 15-question self-assessment and get an instant security readiness score.
Step 3: Produce the Statement of Applicability and implement controls
From the risk assessment, you produce the Statement of Applicability (SoA). The SoA lists all the Annex A controls in ISO/IEC 27001:2022 and justifies which apply to your organisation, which do not, and why. It is one of the central documents of your ISMS and a key focus of the Stage 1 audit.
With the SoA finalised, you implement the selected controls. ISO 27001 controls span access management, encryption, monitoring, change management, supplier security, incident response, asset management, physical security, and more. The security measures you implement should address the risks identified in your risk assessment. Implementing controls that do not correspond to identified risks, or failing to implement controls that do, will create findings at the audit. The risk treatment plan documents how each risk is addressed and should be traceable back to the risk assessment and the SoA.
To become ISO 27001 certified, you must implement controls that are genuinely operational, not just documented. Auditors test whether your controls operate as described, not just whether you have a policy that says they do.
Step 4: Write the required documentation and operate the ISMS
ISO 27001 requires specific documented information: an information security policy, the scope, the risk assessment and risk treatment plan, the SoA, objectives, and a set of procedures covering the main ISMS processes. These documents must reflect how you actually operate, not an idealised version of your processes. An auditor who finds your access management policy describes a process that does not exist will treat it as a major nonconformity.
Once the documentation is in place, you must operate the ISMS long enough to generate evidence that it works. This operation period is essential: Stage 2 of the audit requires records and operational evidence, not just policy documents. Information assets must be managed, incidents logged, access reviews conducted, risk management reviews held, and awareness training delivered. The length of the operation period is set by the certification body (confirm the requirement with your chosen body before planning); in practice, a few months of operating evidence is commonly expected before Stage 2, though there is no ISO-mandated minimum.
Step 5: Conduct an internal audit and management review
ISO 27001 requires you to conduct an internal audit before the external certification audit. The internal audit checks whether the ISMS conforms to the standard's requirements and to your own policies. It is not a formality: a properly conducted internal audit identifies nonconformities while they are still cheap to fix, rather than having them found by the external auditor under certification pressure.
The management review follows the internal audit. Leadership reviews the ISMS performance, considers the results of the internal audit, reviews risk management outcomes, and makes decisions about improvements. The management review produces documented outputs that the Stage 1 auditor will examine to confirm leadership engagement is real and not cosmetic.
Both the internal audit and management review must be completed before the Stage 1 documentation review with the certification body. Build enough time into your timeline for these steps and for resolving any significant nonconformities the internal audit identifies.
Step 6: The two-stage external audit with an accredited body
The external audit is conducted by an independent accredited certification body. There are two stages.
Stage 1 is a documentation review. The auditor examines your ISMS design: the scope, the SoA, the risk assessment, the risk treatment plan, the core policies, and the results of your internal audit and management review. Stage 1 confirms your ISMS is correctly designed and that you are ready to proceed to Stage 2. Stage 1 may identify observations or minor issues to address before Stage 2.
Stage 2 is the main operational audit. The auditor checks whether your controls are implemented and operating effectively by reviewing evidence, interviewing staff, and testing selected controls. Stage 2 auditors look for records of the ISMS operating in practice: incident logs, access review records, risk management meeting notes, change management approvals, supplier assessments, and training records. If Stage 2 identifies major nonconformities, you must address them and provide evidence of closure before the certificate is issued. Minor nonconformities are typically addressed within the certification cycle.
The certificate is issued by the accredited body once compliance has been demonstrated to their satisfaction. The ISO 27001 certification is valid for three years, subject to the surveillance audit schedule.
Step 7: Maintain the ISMS through surveillance audits and recertification
ISO 27001 certification is not a one-time achievement. Accredited certification bodies operating under IAF guidelines structure certificates on a three-year cycle, requiring continuous ISMS operation throughout. Annual surveillance audits in years one and two confirm the ISMS remains compliant and operating effectively. A full recertification audit at the end of year three re-examines the ISMS comprehensively. Maintaining ISO 27001 compliance through this cycle requires the same commitment as the initial certification: ongoing risk management, regular internal audits, management reviews, and control operation that generates real evidence.
The most common reason organisations struggle with surveillance audits is that they treat the ISMS as a project that ended when the certificate arrived. The ISMS must be operated continuously. Security posture, risk management priorities, and controls must evolve as the business changes. New suppliers, new systems, new threats, and changes in scope must be incorporated through the ISMS processes.
How long the ISO 27001 certification process typically takes
ISO 27001 certification typically takes six to twelve months for a focused scope, from kickoff through to certificate. Larger or more complex organisations, or those with lower starting security maturity, may take longer. The durations below are approximate planning estimates based on practitioner experience; they vary by certification body, ISMS scope, and starting maturity, and are not set by ISO 27001 itself. The key stages and their approximate durations:
- Gap analysis and risk assessment: four to eight weeks, depending on scope and complexity.
- SoA and controls design: two to six weeks, depending on the number of controls and existing practices.
- Controls implementation and documentation: two to six months, the most variable phase.
- ISMS operation period for evidence generation: set by your certification body; commonly a few months of operating evidence before Stage 2.
- Internal audit and management review: two to four weeks.
- Stage 1 external audit: typically one to three days.
- Nonconformity resolution (if required) and Stage 2 audit: two to eight weeks after Stage 1, depending on findings.
A well-prepared organisation with good starting security practices and external consultant support can achieve ISO 27001 certification in six months. Organisations starting from a low security posture and building the ISMS internally should plan for twelve months or more.
Common reasons organisations fail the external audit
Understanding what causes audit failures helps you prepare. The most common reasons for major nonconformities at Stage 2 include:
- ISMS scope mismatch: the documented scope does not match the actual operational scope.
- Templated risk assessment: the risk assessment does not reflect the organisation's actual assets and threats.
- Non-operational controls: controls are documented but not actually implemented or not generating evidence of operation.
- Incomplete internal audit: the internal audit was superficial or did not cover all the standard's requirements.
- Management review not conducted: leadership did not hold a formal management review with documented outputs.
- Insufficient operation period: the ISMS has not been operating long enough to produce meaningful evidence.
- SoA not grounded in risk: the controls selected do not trace back to the risk assessment.
All of these can be avoided with thorough preparation. Working with a consultant who has led organisations through multiple ISO 27001 certification processes reduces the risk of encountering these issues at Stage 2.
| Stage | What happens | Typical duration |
|---|---|---|
| Gap analysis + risk assessment | Current state mapped against ISO 27001 requirements | 4-8 weeks |
| SoA + controls design | Annex A controls selected and justified | 2-6 weeks |
| Controls implementation + documentation | Policies, procedures, and controls built and operated | 2-6 months |
| ISMS operation period | Evidence generated through real ISMS operation | Set by certification body; commonly a few months in practice |
| Internal audit + management review | Conformance checked; leadership reviews performance | 2-4 weeks |
| Stage 1 audit (accredited body) | Documentation review by independent certification body | 1-3 days |
| Stage 2 audit (accredited body) | Operational audit; certificate issued on passing | 2-8 weeks after Stage 1 |
How Onyx helps with the ISO 27001 certification journey
Onyx provides ISO 27001 readiness assessment and ISMS implementation. Our work covers the full certification process: gap analysis, risk assessment, the Statement of Applicability, Annex A controls implementation, policies and procedures, internal audit support, and preparation and coaching through the Stage 1 and Stage 2 audits. We do not certify clients ourselves; all ISO 27001 certification is issued by independent accredited bodies.
Our consultants have led organisations through the ISO 27001 certification journey across a range of sectors and scope sizes. We build management systems designed to certify on the first attempt, generate real operational evidence, and remain compliant through the surveillance audit cycle. We also structure handover so your team can conduct subsequent internal audits and manage the ISMS independently, reducing ongoing ISO 27001 certification costs.
If you are looking to implement ISO 27001 efficiently and understand exactly what each step requires, a scoping conversation is the right starting point. We will map the process to your specific context, give you a realistic timeline, and outline what your team needs to contribute at each stage.
ISO 27001 certification bodies operate under accreditation from national bodies such as UKAS in the UK or DAkkS in Germany. Choosing a certification body with appropriate accreditation for your markets ensures your certificate is recognised where it matters.
Ready to map your ISO 27001 path?
We scope the process to your context, give you a realistic timeline, and outline exactly what your team needs to do at each stage.
The bottom line
The ISO 27001 certification journey follows a clear, defined sequence: scope the ISMS, conduct a gap analysis and risk assessment, build the SoA and implement controls, document and operate the system to generate evidence, complete an internal audit and management review, pass the two-stage external audit with an accredited body, and maintain the ISMS through annual surveillance audits and recertification. Understanding the full audit process and certification steps removes the uncertainty and lets you plan a realistic timeline. The most important single thing you can do is treat the ISMS as a real operational system from day one, not a document exercise, because that is how it will be tested at Stage 2.
Ready to start your ISO 27001 journey? Tell us your scope and timeline and we will map the path on a short call. Book a scope call or take our free security self-assessment. See also ISO 27001 certification cost, how to choose an ISO 27001 consultant, and our ISO 27001 service.
FAQ
What are the steps to ISO 27001 certification?
The ISO 27001 certification process covers seven main steps: define the ISMS scope with leadership commitment, conduct a gap analysis and risk assessment, produce the SoA and implement Annex A controls, write the required documentation and operate the ISMS to generate evidence, complete an internal audit and management review, pass the two-stage external audit by an accredited body, and maintain ISO 27001 certification through annual surveillance audits and recertification.
How long does ISO 27001 certification take?
ISO 27001 certification typically takes six to twelve months from kickoff to certificate for a focused scope. Larger organisations, lower starting security maturity, or more complex scopes increase the timeline. The operation period for evidence generation before Stage 2 is set by your chosen certification body, commonly a few months of operating evidence in practice; there is no ISO-mandated minimum. A consultant can give you a realistic timeline estimate based on your specific context.
What is the SoA in ISO 27001?
The SoA lists every Annex A control in ISO/IEC 27001:2022 and documents which apply to your organisation, which do not, and why, based on your risk assessment. It is a central ISMS document that links your controls to your identified risks and is a key focus of the Stage 1 audit. The SoA must be grounded in a genuine risk assessment, not completed as a default exercise.
What happens in the ISO 27001 external audit?
The external audit has two stages. Stage 1 is a documentation review: the auditor examines your ISMS design, policies, risk assessment, SoA, and internal audit results. Stage 2 is the main audit, where the auditor checks that your controls are implemented and operating effectively through interviews, evidence review, and control testing. If major nonconformities are found, you address them before the certificate is issued. Minor findings are tracked and resolved within the certification cycle.
Does ISO 27001 certification expire?
ISO 27001 certificates are issued on a three-year cycle by accredited certification bodies operating under IAF guidelines, maintained through annual surveillance audits in years one and two, and a full recertification audit at year three. You must keep operating the ISMS continuously throughout, so it is an ongoing operational commitment. Letting the ISMS lapse between surveillance audits risks losing the certification before the three-year cycle completes.
What does an ISO 27001 internal audit involve?
The ISO 27001 internal audit checks whether your ISMS conforms to the standard's requirements and to your own policies and procedures. It must be conducted before the external certification audit, and its results reviewed in the management review. Internal auditors should be trained in ISO/IEC 27001 and be independent enough to audit without conflict of interest. A thorough internal audit process is one of the strongest predictors of first-time certification success.
