ISO 27001 Certification Process: A Step-by-Step Guide

The ISO 27001 certification process is a structured journey in which your organization defines the scope of its Information Security Management System (ISMS), assesses and treats information security risks, implements controls, and then passes an independent two-stage audit (Stage 1 and Stage 2) that leads to a certification decision. Once certified, your organization maintains its status through annual surveillance audits and a full recertification every three years. This guide walks through each step so you know exactly what to expect—from first planning meeting to certificate.

ISO/IEC 27001:2022 is the current version of the international standard for information security management. If your business collects, processes, or stores sensitive data, certification demonstrates to customers, regulators, and partners that you manage that information responsibly. Below, we break the journey into clear, sequential steps and answer the questions organizations ask most often.

What Is ISO 27001 and Who Gets Certified?

ISO/IEC 27001 is the leading international standard for building and running an Information Security Management System (ISMS). It takes a risk-based approach: rather than prescribing a fixed checklist, it asks you to identify the information security risks that matter to your business and apply appropriate controls to reduce them.

Certification is awarded to organizations, not individuals. A company, business unit, or defined site can be certified once it demonstrates a working ISMS that meets the standard’s requirements. Individuals earn competence through training and qualifications instead—more on that later.

The standard references 93 Annex A controls organized into four themes (organizational, people, physical, and technological). You select the controls relevant to your risks and document your choices in a Statement of Applicability (SoA). For a detailed look at what the standard demands, see our guide to the ISO 27001 requirements, and for budgeting guidance, review the typical ISO 27001 certification cost.

The ISO 27001 Certification Process: Step by Step

The path to certification follows a logical sequence. Here are the ISO 27001 certification steps most organizations take.

Step 1. Secure Management Support and Define the Scope

Every successful ISMS starts with leadership commitment. Top management must back the project, assign responsibilities, and allocate resources. With that support in place, define the scope of your ISMS: which parts of the organization, locations, systems, and information assets the certification will cover. A clear, well-reasoned scope keeps the project focused and prevents wasted effort later.

Step 2. Perform a Gap Analysis

A gap analysis compares your current information security practices against the requirements of ISO/IEC 27001:2022. It reveals what you already have in place and what still needs to be built or documented. Think of this as your roadmap: it tells you how much work lies ahead and helps you plan realistic timelines and budgets. Many organizations use the gap analysis findings to prioritize their implementation activities.

Step 3. Conduct a Risk Assessment

Because ISO 27001 is risk-based, the risk assessment is the heart of the process. Identify the information security risks facing the assets within your scope—threats, vulnerabilities, and the potential impact if something goes wrong. Assess each risk consistently using a defined methodology so results are repeatable and comparable. This step produces a prioritized picture of where your organization is most exposed.

Step 4. Build Your Risk Treatment Plan and Select Annex A Controls

Once risks are assessed, decide how to treat each one: reduce it, avoid it, transfer it, or accept it. Where you choose to reduce risk, select appropriate controls from the 93 controls in Annex A. Document your decisions in the Statement of Applicability (SoA), which lists each control, whether it applies, and your justification for including or excluding it. The SoA and the risk treatment plan are cornerstone documents that auditors will examine closely.

Step 5. Build and Document the ISMS

With risks and controls decided, build out the ISMS itself. This means writing the policies, procedures, and records the standard requires—information security policy, roles and responsibilities, and operational documentation that shows how your controls work in practice. Keep documentation practical and aligned to how your organization actually operates; auditors look for evidence that the ISMS reflects real activity, not paperwork created for show.

Step 6. Implement and Operate the ISMS

Put the ISMS into daily practice. Roll out the controls, communicate policies across the organization, and deliver awareness training so staff understand their information security responsibilities. Let the system run long enough to generate records—logs, meeting minutes, incident reports, and control evidence. This operating period is important: the audit later looks for proof that your ISMS is not just designed but genuinely working.

Step 7. Carry Out an Internal Audit

An internal audit checks your own ISMS against the standard’s requirements before an external body ever visits. It surfaces nonconformities and improvement opportunities while you still have time to fix them. Internal auditors should be competent and impartial—many organizations train staff through an ISO 27001 internal auditor training course so they can perform these audits credibly.

Step 8. Hold a Management Review

Leadership then reviews the ISMS’s performance: audit results, risk status, incidents, objectives, and opportunities for improvement. The management review confirms that the ISMS remains suitable, adequate, and effective, and that resources and priorities are still aligned. It closes the internal preparation loop and signals readiness for external assessment.

Step 9. Stage 1 Audit — Documentation and Readiness Review

Now the external certification body steps in. The Stage 1 audit is a documentation and readiness review. The auditor examines your ISMS documentation—scope, policies, risk assessment, risk treatment plan, and Statement of Applicability—to confirm the system is designed correctly and that you are ready for the deeper Stage 2 assessment. Any gaps identified here give you a chance to correct course before the main audit.

Step 10. Stage 2 Audit — Implementation and Effectiveness

The Stage 2 audit evaluates whether your ISMS is actually implemented and effective. The auditor gathers evidence on site (or remotely) by reviewing records, interviewing staff, and observing controls in action. They verify that what your documentation promises is happening in practice. If nonconformities are raised, you address them with corrective action. For a fuller explanation of what happens during each assessment, see our guide to the ISO 27001 audit and our general ISO audit procedure.

Step 11. Certification Decision

After Stage 2, the applicable certification decision process reviews the audit findings. If the ISMS meets the requirements and any nonconformities are resolved, certification may be issued for the defined scope. IAS provides certification within its applicable UQAS accreditation scope. Where the JAS-ANZ-accredited route is applicable, the certification activity is conducted through IAS’s group company EAS, within EAS’s approved scope.

Step 12. Surveillance Audits and Recertification

Certification is not a one-time event. The certificate is typically valid for three years, during which the certification body conducts annual surveillance audits to confirm your ISMS continues to operate and improve. At the end of the three-year cycle, a full recertification audit renews your certificate. Maintaining certification means treating your ISMS as a living system—continually monitoring, reviewing, and improving it.

To understand the wider service that supports this journey, you can also review our ISO 27001 certification page.

How Long Does the ISO 27001 Certification Process Take?

Timelines vary with the size and complexity of your organization and how mature your existing controls are. A small business with good practices already in place may move through the process in a few months, while a larger enterprise building an ISMS from scratch can take a year or more. The gap analysis in Step 2 is the best way to estimate your own timeline, because it shows how much implementation work stands between you and the Stage 1 audit.

Preparing Your Team for the Process

A capable team makes the process smoother. Beyond internal auditor skills, organizations often develop lead auditors and ISMS specialists through structured courses. Explore ISO 27001 lead auditor training to build in-house expertise, and check the current training schedule for upcoming sessions. Well-trained people help you implement controls correctly, run credible internal audits, and sustain the ISMS after certification.

Ready to begin? Contact us to discuss where your organization stands and map out your route to ISO/IEC 27001:2022 certification.

Frequently Asked Questions

What are the main steps in the ISO 27001 certification process?
The process runs from defining your ISMS scope and performing a gap analysis, through risk assessment and risk treatment (including selecting Annex A controls and writing the Statement of Applicability), to implementing and operating the ISMS. You then complete an internal audit and management review before the certification body conducts the Stage 1 and Stage 2 audits and makes the certification decision. Annual surveillance audits and a three-year recertification follow.
What is the difference between the Stage 1 and Stage 2 audits?
The Stage 1 audit is a documentation and readiness review: the auditor checks that your ISMS is designed correctly and that key documents—scope, risk assessment, risk treatment plan, and Statement of Applicability—are in place. The Stage 2 audit goes deeper, gathering evidence through records, interviews, and observation to confirm your ISMS is actually implemented and effective in day-to-day operations.
Do I need an internal audit before external certification?
Yes. An internal audit and a management review are required parts of the ISMS and must be completed before the external certification audit. The internal audit checks your ISMS against ISO/IEC 27001:2022 so you can correct nonconformities before the certification body’s assessment, improving your chances of a smooth Stage 2 outcome.
What is a Statement of Applicability (SoA) and why does it matter?
The Statement of Applicability lists the Annex A controls, states whether each one applies to your organization, and justifies why it is included or excluded. It links your risk treatment decisions to specific controls and is one of the first documents auditors review. A clear, accurate SoA demonstrates that your control selection is deliberate and risk-based.
How long is an ISO 27001 certificate valid?
An ISO/IEC 27001 certificate is typically valid for three years. During that period the certification body carries out annual surveillance audits to confirm your ISMS remains effective, and a full recertification audit renews the certificate at the end of the cycle.
Is ISO 27001 certification awarded to individuals or organizations?
Certification is awarded to organizations that operate a conforming ISMS within a defined scope—not to individuals. People build competence instead through training and qualifications, such as internal auditor or lead auditor courses, which help them implement, audit, and maintain the organization’s ISMS.