Instant downloadAuditor-writtenSecure Stripe checkout
ISO 27001 Certification: The Complete Guide (2022) — ISO Toolkits

ISO 27001 Certification: The Complete Guide ()

ISO 27001 certification is formal, independent proof that your organisation has built an information security management system (ISMS) that meets the requirements of the international standard ISO/IEC 27001. It signals to customers, regulators, and partners that you manage information security through a structured, risk-based process rather than ad hoc effort. In a market where data breaches and supply-chain scrutiny are constant, that credential has become one of the most recognised security trust signals worldwide.

This guide explains what the certification involves, who needs it, how the standard is structured, and exactly what the journey from kick-off to certificate looks like. It reflects the current edition, ISO/IEC 27001:2022, though standards are periodically revised, so always confirm you are working from the latest published version and any amendments.

What ISO 27001 certification is and why it matters

ISO/IEC 27001 is the leading international standard for information security management. Rather than prescribing a single fixed set of technologies, it defines requirements for a management system, a repeatable way of identifying risks to your information and applying proportionate controls to treat them. The “certification” part means an accredited, independent certification body has audited your ISMS and confirmed it conforms to the standard.

That independence is what gives the certificate its value. Anyone can claim to take security seriously; a certificate issued under an accredited scheme is evidence a qualified third party checked. This matters for several concrete reasons:

  • Winning business. Enterprise and public-sector procurement teams increasingly list certification as a hard requirement in tenders and vendor questionnaires.
  • Reducing due-diligence friction. A current certificate and Statement of Applicability often shortcut lengthy security reviews from prospective customers.
  • Regulatory alignment. The framework maps well to obligations such as GDPR and sector rules, helping demonstrate due care.
  • Genuine risk reduction. Done properly, the process surfaces real gaps and drives measurable improvement, not just paperwork.

Who needs ISO 27001 certification

The standard is deliberately sector-agnostic and scalable, so it suits organisations of almost any size or industry that handle information worth protecting. In practice, demand is strongest among a few groups.

Technology and SaaS companies pursue it because their customers entrust them with sensitive data and expect assurance. Managed service providers, data centres, and cloud vendors use it to differentiate. Financial services, healthcare, and legal firms adopt it to underpin regulatory and contractual commitments. Increasingly, smaller suppliers seek certification because a larger customer has made it a condition of the contract.

You do not need to be large. A ten-person startup can certify a tightly scoped ISMS, and a global enterprise can certify a single business unit. What matters is defining a sensible scope and genuinely operating the system within it.

The structure of the standard: clauses and Annex A controls

ISO/IEC 27001 has two components you must satisfy. The first is the set of management-system requirements in the main clauses; the second is the reference set of security controls in Annex A.

Core clauses 4 to 10

Clauses 4 through 10 contain the mandatory requirements. Every certified organisation must address all of them:

  • Clause 4 – Context of the organisation: understand internal and external issues, interested parties, and define the ISMS scope.
  • Clause 5 – Leadership: top-management commitment, an information security policy, and clear roles and responsibilities.
  • Clause 6 – Planning: risk assessment and risk treatment, information security objectives, and the Statement of Applicability.
  • Clause 7 – Support: resources, competence, awareness, communication, and documented information.
  • Clause 8 – Operation: putting the risk treatment plan and controls into practice.
  • Clause 9 – Performance evaluation: monitoring, measurement, internal audit, and management review.
  • Clause 10 – Improvement: handling nonconformities, corrective action, and continual improvement.

Annex A controls

Annex A provides a reference catalogue of controls you consider during risk treatment. In the 2022 edition there are 93 controls, organised into four themes rather than the older 14 domains. As of the current version, verify against the latest text, those themes and their approximate control counts are:

Annex A themeApprox. number of controlsFocus
Organizational37Policies, roles, supplier and cloud relationships, incident management
People8Screening, awareness, responsibilities, remote working conduct
Physical14Secure areas, equipment, physical entry, media handling
Technological34Access control, cryptography, logging, secure development, network security

The 2022 revision also introduced several newer controls reflecting modern practice, including threat intelligence, information security for cloud services, data leakage prevention, and secure coding. Controls are also tagged with attributes such as control type and security domain to aid filtering, though using those attributes is optional.

The ISO 27001 certification process step by step

Certification is the end of a project, not the start. The bulk of the effort is building and operating the ISMS; the external audit then verifies it. A typical path looks like this.

1. Define scope and secure leadership buy-in

Decide which parts of the organisation, locations, and information the ISMS covers, then get documented commitment and resources from top management. Scope decisions shape everything that follows.

2. Perform a gap analysis

Compare your current practices against the standard’s requirements and Annex A. This reveals how far you are from readiness and feeds a realistic project plan.

3. Conduct risk assessment and treatment

Identify information security risks, evaluate them against agreed criteria, and decide how to treat each one. Selected controls are recorded, with justification, in the Statement of Applicability.

4. Implement controls and documentation

Deploy the technical and organisational controls from your treatment plan, and produce the required policies, procedures, and records. This is usually the longest phase.

5. Operate, then run internal audit and management review

The ISMS must actually run for a period so it generates evidence. You then perform an internal audit and a management review, both mandatory, to confirm it works and to fix any issues.

6. Stage 1 audit (documentation review)

An accredited certification body reviews your documentation and readiness, checking that the ISMS is designed correctly and that key artefacts such as the SoA and risk assessment exist. It flags anything likely to cause problems at Stage 2.

7. Stage 2 audit (implementation review)

The auditor examines evidence that the ISMS is implemented and effective in practice, interviewing staff and sampling records. Any nonconformities must be addressed before a certificate is issued.

8. Certification and the three-year cycle

Once you pass, the certificate is typically valid for three years. During that period the body conducts annual surveillance audits to confirm continued conformity, and a full recertification audit near the end of the cycle renews the certificate.

Documentation involved in ISO 27001 certification

The standard requires certain documented information, and auditors expect to see it. While exact document lists vary by organisation, most ISMS document sets include:

  • ISMS scope statement and information security policy
  • Risk assessment and risk treatment methodology and results
  • Statement of Applicability (SoA) listing controls and inclusion/exclusion rationale
  • Risk treatment plan
  • Objectives, roles and responsibilities, and competence records
  • Supporting policies and procedures (access control, incident management, supplier security, and so on)
  • Records of internal audits, management reviews, corrective actions, and monitoring results

The Statement of Applicability is the single most scrutinised document. It ties your risk decisions to specific Annex A controls and explains any exclusions, so auditors treat it as the map of your entire ISMS.

Timeline and cost drivers

There is no single answer to how long or how much, because both depend heavily on scope, size, and starting maturity. As a rough guide, many organisations reach certification in roughly three to twelve months, with smaller, well-prepared teams at the faster end.

The main factors that move timeline and cost are:

  • Scope and complexity: more locations, systems, and people mean more to assess and audit.
  • Existing maturity: organisations with mature security practices need less remediation.
  • Internal resource and expertise: a dedicated owner accelerates progress dramatically.
  • Consultancy and tooling: external help and compliance platforms add cost but can shorten timelines.
  • Certification body fees: priced by audit days, which scale with organisation size.

Remember that ISO 27001 is an ongoing commitment. Budget not just for the initial project and audit, but for surveillance audits and the internal effort of running the ISMS year after year.

Common challenges and how to avoid them

Most difficulties are predictable, which means they are avoidable with planning.

Scoping too broadly too soon. An over-ambitious scope multiplies work and risk. Start with a defensible scope you can genuinely operate, then expand later.

Treating it as a paperwork exercise. Auditors look for evidence controls actually operate, not just that policies exist. Build habits and records from the outset rather than manufacturing evidence before the audit.

Weak leadership engagement. The standard requires demonstrable top-management involvement. Without it, the ISMS stalls and management-review requirements go unmet.

Underestimating the operating period. You need the ISMS to run long enough to produce internal audit and review evidence. Plan that operating window in from the start.

An inconsistent Statement of Applicability. If the SoA does not align with your risk assessment and actual controls, it undermines confidence in everything. Keep it accurate and current.

ISO 27001 certification vs SOC 2

Prospects often ask how ISO 27001 compares to SOC 2, the North American attestation report based on the AICPA Trust Services Criteria. They overlap but serve different purposes.

AspectISO/IEC 27001SOC 2
NatureCertification against a standardAttestation report by a CPA firm
BasisISMS requirements plus Annex A controlsTrust Services Criteria (security, plus optional others)
OutputA certificate (pass/fail conformity)A detailed report auditors and customers read
Geographic emphasisInternationalPredominantly North America
ValidityThree-year cycle with annual surveillanceType II covers a period, typically re-issued annually
FocusManagement system and continual improvementEffectiveness of controls over a defined period

Neither is strictly “better”; the right choice depends on your customers and markets. Many organisations eventually pursue both, and because the underlying controls overlap substantially, achieving one makes the other considerably easier.

Frequently asked questions about ISO 27001 certification

How long is an ISO 27001 certificate valid?

A certificate is typically valid for three years, subject to passing annual surveillance audits during that period and a recertification audit before it expires. Failing surveillance or recertification can suspend or withdraw the certificate.

Can a small company get certified?

Yes. The standard scales to any size. A small team can certify a tightly scoped ISMS, and many startups do exactly that to satisfy enterprise customers. Smaller scope generally means fewer audit days and lower cost.

Do we have to implement all 93 Annex A controls?

No. Annex A is a reference set. Your risk assessment determines which controls apply, and the Statement of Applicability records what you have included or excluded and why. Exclusions must be justified, not arbitrary.

Who issues the certificate?

An independent certification body that is itself accredited by a national accreditation body. Using an accredited body is what gives the certificate its recognised credibility. Verify accreditation before you engage one.

What is the difference between being compliant and being certified?

You can align your practices with ISO 27001 without seeking a certificate; that is self-declared conformity. Certification adds independent, accredited verification, which is what most customers and tenders actually require.

How much does ISO 27001 certification cost?

Cost varies widely with organisation size, scope, and maturity, and includes internal effort, any consultancy or tooling, and certification-body audit fees. Because so many variables apply, obtain quotes based on your specific scope rather than relying on generic figures.

ISO 27001 certification toolkit templates
The editable ISO 27001 Toolkit — policies, SoA and risk templates.

Related guides

For the authoritative source, you can review the standard directly on the official ISO/IEC 27001 page, which reflects the latest published edition and any amendments.

This guide is provided for general informational and educational purposes only and does not constitute legal, regulatory, or professional certification advice. It is not affiliated with, endorsed by, or issued by ISO or the IEC, and it does not guarantee any certification outcome. Always confirm requirements against the current ISO/IEC 27001 text and consult an accredited certification body or qualified professional for your specific circumstances.

Ready to move faster? Our editable ISO/IEC 27001:2022 toolkit gives you the policies, procedures, risk assessment templates, and a pre-built Statement of Applicability you need to build a certification-ready ISMS without starting from a blank page. Explore the ISO 27001 Toolkit and shorten your path to ISO 27001 certification.

Shopping Cart