The ISO 27001 Certification Process: Step by Step
To achieve ISO 27001 certification you implement an ISMS, run a gap analysis, complete a risk assessment, apply the necessary Annex A controls, document a Statement of Applicability, conduct an internal audit and management review, then pass a two-stage external audit by an accredited certification body.
Published: July 2026 | Last updated: July 2026 | Author: Bitrixme Compliance Team
Overview: The 9 Steps of ISO 27001 Certification
The ISO 27001 certification process follows a defined sequence. Each step builds on the previous one, and skipping or rushing any step creates risk for the next. Below is the complete process map.
| Step | Phase | Who leads | Typical duration | Output |
|---|---|---|---|---|
| 1 | Gap analysis | Consultant or internal team | 2 – 4 weeks | Gap report, project plan |
| 2 | ISMS scope definition | Management + consultant | 1 – 2 weeks | Scope document |
| 3 | ISMS policy and documentation | Consultant or internal team | 6 – 12 weeks | ISMS policy framework |
| 4 | Risk assessment | Consultant or internal team | 4 – 8 weeks | Risk register, treatment plan |
| 5 | Statement of Applicability (SoA) | Consultant or internal team | 2 – 4 weeks | SoA with control justifications |
| 6 | Control implementation | Internal team + consultant | 8 – 16 weeks | Operational controls, security tooling |
| 7 | Internal audit | Independent internal auditor | 2 – 4 weeks | Internal audit report, nonconformities |
| 8 | Management review | Senior management | 1 – 2 weeks | Review minutes, approval to proceed |
| 9 | Stage 1 + Stage 2 audit | Certification body | 3 – 10 days (over 4 – 12 weeks) | Certificate |
Step 1: Gap Analysis
The gap analysis compares your current policies, processes and controls against every clause of ISO 27001 and every Annex A control. It produces a prioritised gap report that becomes the project plan. This step typically takes 2 to 4 weeks and is the single most important phase for budgeting and timeline accuracy.
A thorough gap analysis examines each of the 93 controls in Annex A (ISO 27001:2022) across the four themes: organisational controls (37 controls), people controls (8), physical controls (14) and technological controls (34). The output is a document that states for each control whether it is fully implemented, partially implemented, not implemented, or not applicable, with a priority rating for remediation. This document becomes the baseline for the entire project.
Step 2: ISMS Scope Definition
The ISMS scope defines which parts of the organisation, which information assets and which locations the management system covers. The scope must be documented with justification for any exclusions. Scope decisions directly affect audit days and cost, so getting this right early prevents costly mid-project changes.
Clause 4.3 requires the scope to be documented, justified and aligned with the organisation’s strategic objectives. The scope typically includes the organisation’s core business processes, the IT systems that support them, and the locations where information is processed or stored. Exclusions must be justified on the basis that the excluded area has no impact on the organisation’s ability to manage information security risks.
Step 3: ISMS Policy and Documentation
ISO 27001 requires documented policies including the ISMS policy itself, information security policies, access control policy, and controls documentation. The documentation framework typically includes 20 to 40 policy documents, procedures and records. Most mid-size organisations require 6 to 12 weeks for this phase.
The mandatory documented information required by ISO 27001 includes the ISMS scope (Clause 4.3), information security policy (Clause 5.2), risk assessment methodology (Clause 6.1.2), risk treatment plan (Clause 6.1.3), Statement of Applicability (Clause 6.1.3), risk assessment results (Clause 8.2 and 8.3), internal audit programme and results (Clause 9.2), management review results (Clause 9.3), and evidence of competence (Clause 7.2). Additional policies such as access control policy, acceptable use policy, incident response policy and business continuity policy round out the documentation set.
Step 4: Risk Assessment
Clause 6.1 requires a documented risk assessment process. This involves asset identification, threat identification, vulnerability assessment, likelihood and impact scoring, and risk evaluation. The risk assessment is the most technically demanding phase and the one most likely to be underestimated in time and effort.
ISO 27001 does not prescribe a specific risk assessment methodology, which gives organisations flexibility but also creates confusion for first-time implementers. Common approaches include asset-based risk assessment (identifying risks to each information asset), scenario-based risk assessment (identifying risks to business processes), and control-based risk assessment (evaluating the adequacy of existing controls). Whichever method is chosen, the methodology must be documented, repeatable and defensible to the certification auditor.
Step 5: Statement of Applicability
The SoA lists all 93 Annex A controls (in ISO 27001:2022) and states whether each is implemented or excluded, with justification. The certification auditor will examine the SoA first because it reveals whether the organisation understands the standard and has genuinely thought about its risk profile.
Each control in the SoA must be either implemented or excluded. Exclusions must be justified on the basis that the control is not applicable to the organisation’s risk profile, operating context or scope. For example, an organisation that does not develop software can legitimately exclude the secure development controls in Theme 5. A poorly justified exclusion is one of the most common findings in Stage 1 audits.
Step 6: Control Implementation
This is the longest phase, typically 8 to 16 weeks. Controls from Annex A must be implemented according to the risk treatment plan. This includes technical controls (access control, logging, encryption), organisational controls (policies, training, supplier agreements), and physical controls (secure areas, equipment security).
The control implementation phase is where the project leaves documentation and enters operational reality. Technical controls such as identity and access management systems, SIEM platforms, encryption tools and backup solutions must be deployed and configured. Organisational controls such as training programmes, supplier due diligence procedures and incident response plans must be established and tested. Physical controls such as access card systems, CCTV and visitor logs must be verified. Each implemented control must produce evidence that the auditor can examine during Stage 2.
Step 7: Internal Audit
Before the certification body ever visits, you must conduct an internal audit (Clause 9.2). The internal auditor must be independent of the areas audited. The internal audit report identifies nonconformities that must be closed before the Stage 1 audit. This phase typically takes 2 to 4 weeks including corrective actions.
The internal audit follows the principles of ISO 19011, the standard for auditing management systems. The auditor examines documentation, interviews process owners, reviews evidence of control operation, and tests compliance with the organisation’s own policies. The internal audit report categorises findings as major nonconformities, minor nonconformities or observations, and each finding must be addressed before the certification body is invited to conduct Stage 1.
Step 8: Management Review
Senior management must review the ISMS (Clause 9.3) covering audit results, risk assessment status, security incidents, stakeholder feedback and opportunities for improvement. The management review meeting produces minutes and a formal decision on readiness for certification.
The management review is not a formality. The certification auditor will ask to see the meeting minutes and will look for evidence that senior management genuinely understands the ISMS, reviews its performance and makes informed decisions. A management review that consists of a 15-minute sign-off without discussion is a red flag to auditors.
Step 9: The Certification Audit (Stage 1 and Stage 2)
Stage 1 – Documentation Review
The Stage 1 audit is a documentation review. The certification body’s auditor reviews your ISMS documentation, SoA, risk assessment, scope definition, policies and internal audit records. The auditor evaluates whether the ISMS is designed adequately and whether the organisation is ready for Stage 2. Stage 1 typically takes 1 to 2 days on-site or remotely. If significant gaps are found, the auditor will issue findings and recommend a delay before Stage 2.
Stage 1 also includes a site walk-through to verify that the documented scope matches reality. The auditor checks that the physical locations, IT systems and business processes described in the ISMS scope actually exist as documented. Discrepancies between the documentation and reality are treated as nonconformities.
Stage 2 – Implementation Audit
Stage 2 is the on-site implementation audit. The auditor tests whether the ISMS is operational, effective and consistently applied. They interview staff, examine evidence of control operation, review risk treatment progress and check records. Stage 2 typically takes 2 to 8 days depending on organisation size and scope complexity. At the end, the auditor reports nonconformities and makes a certification recommendation to the certification body’s decision panel.
During Stage 2, the auditor interviews staff at all levels, from the information security manager to end users. The auditor tests whether the policies documented in the ISMS are actually followed in daily operations. They examine evidence such as access control logs, incident reports, backup verification records, training attendance sheets, and supplier due diligence files. Any control that exists in the documentation but is not evidenced in practice results in a nonconformity.
Nonconformities and Closing Them
Nonconformities are findings issued by the auditor when a requirement of the standard is not met. They fall into three categories.
| Severity | Definition | Closing deadline |
|---|---|---|
| Major nonconformity | A systemic failure – a clause is not implemented, or a control is entirely absent. For example: no risk assessment has been conducted, or no internal audit has been performed. | Typically 30 – 90 days before certificate can be issued |
| Minor nonconformity | An isolated lapse – a control is in place but not consistently applied. For example: most staff have completed security awareness training but one department has not. | Before the next surveillance audit, or within a timeframe agreed with the certification body |
| Observation | A potential weakness or area for improvement. Not a direct failure but a note of caution. | No formal deadline, but must be addressed |
Major nonconformities must be closed before the certificate can be issued. The certification body will request a corrective action plan and evidence of implementation within the agreed timeframe. Minor nonconformities must be closed before the next surveillance audit. Observations should be addressed proactively to demonstrate continual improvement.
Certificate Issue and the Three-Year Cycle
Once the certification body’s decision panel approves, the ISO 27001 certificate is issued. It is valid for three years from the certification decision date. The organisation must undergo surveillance audits in year one and year two. At year three, a recertification audit is required, which follows the same pattern as the initial Stage 2 audit.
The certification body conducts a surveillance audit approximately 12 months after the initial certification decision and again at 24 months. Surveillance audits are shorter than the initial Stage 2 audit (typically 1 to 2 days) and focus on high-risk controls, changes to the organisation, and the status of any outstanding minor nonconformities. The recertification audit at year three is a full re-assessment and should be scheduled 3 to 6 months before the certificate expiry date to allow time for nonconformity closure.
Role Split: Consultant vs Certification Body
A common source of confusion is the boundary between the consultancy role and the certification body’s role. ISO accreditation rules prohibit a certification body from consulting for the same client, and a consultancy cannot issue certificates.
The distinction is not just regulatory – it is commercially important. A consultancy that blurs the boundary signals inexperience to sophisticated buyers. The clearest consultancies state their role explicitly and refer to their certification body partner by name. This transparency is a trust asset, not a liability.
Bitrixme provides consultancy, gap analysis, implementation support, internal auditing and training. Certification audits are conducted by an independent accredited certification body. We prepare you for that audit; we do not issue the certificate.
FAQ
What are the stages of an ISO 27001 audit?
There are two stages. Stage 1 is a documentation review to verify the ISMS is designed correctly. Stage 2 is the on-site implementation audit that tests whether the ISMS is operational and effective. Both must be passed for certification.
What happens in a Stage 1 audit?
The certification body’s auditor reviews your ISMS documentation, SoA, risk assessment and internal audit records. They assess whether the ISMS is adequately designed and whether the organisation is ready for Stage 2. A site walk-through is also conducted to verify the documented scope matches reality.
What documents do we need for ISO 27001?
The standard requires documented policies, ISMS scope, risk assessment methodology and results, SoA, internal audit plan and reports, management review minutes, evidence of competence, and records of control operation. Most organisations produce 20 to 40 policy documents in total.
What happens if we fail the audit?
Failure in Stage 1 means the auditor recommends a delay of 4 to 12 weeks before proceeding to Stage 2. Failure in Stage 2 means major nonconformities must be closed within 30 to 90 days before the certificate can be issued.
How do we close a nonconformity?
Submit a corrective action plan to the certification body identifying root cause, corrective actions and evidence of implementation. The certification body may request supporting evidence or schedule a follow-up visit before closing the finding.
Who can issue an ISO 27001 certificate?
Only an accredited certification body can issue an ISO 27001 certificate. The certification body must be accredited by a national accreditation body that is a signatory to the IAF MLA. Consultancies cannot issue certificates.
Related Reading
Download our free ISO 27001 implementation checklist – contact Bitrixme or message us on WhatsApp.