ISO 27001 Certification: From Preparation to Recertification

The course of a certification to ISO/IEC 27001 is standardised; the route to it is not. It is decided by the cut of the scope, by how robust the risk assessment is, and by whether evidence arises in daily operation or is generated specially for the audit. This guide walks the full sequence, from the prerequisites through the Stage 1 and Stage 2 audits to surveillance audits and recertification, and names the points at which projects regularly lose time.

Pillar guideISO 2700114 min readLast reviewed:

What does an ISO 27001 certificate actually say?

A certification to ISO/IEC 27001 is confirmation by an independent, accredited body that an organisation's information security management system meets the requirements of the standard and is operated effectively within the scope examined. What is certified is the management system: not a product, not a piece of software, not the IT department, and as a rule not the company as a whole either.

That distinction is regularly passed over in tenders, yet it decides what the certificate is worth. The certificate shows that risks are systematically identified, assessed and treated, that accountabilities are named, and that the organisation reviews and corrects its own requirements. It does not show the absence of vulnerabilities, a particular level of technical maturity, or the security of individual products.

What a certificate saysWhat a certificate does not say
An ISMS exists and is operatedThe organisation has not been attacked
Risks are assessed against documented criteriaAll risks are treated or low
Measures are selected with reasons and implementedA particular technical level of protection has been reached
Effectiveness is measured and evaluatedThe scope covers the whole company

Clauses 4 to 10 of the standard bind: context, leadership, planning, support, operation, performance evaluation and improvement. Annex A adds 93 reference controls across four themes: 37 organisational, 8 people, 14 physical and 34 technological. The 2022 edition governs; that is what you are certified against. Amendment 1:2024 added the consideration of climate change to the context clauses, which changes little in substance but has to be traceable in the context analysis.

Which edition applies is therefore settled, and settled recently enough that it still turns up in tender documents. The move from the 2013 to the 2022 edition followed IAF MD 26, issue 2, from January 2023: the standard was published on 25 October 2022, with a 36-month transition period. Initial and recertification audits had to begin against the 2022 edition by 30 April 2024 at the latest, an end date, not a start date, since certifying against the 2022 edition had been possible well before that. Clients already certified had to transition by 31 October 2025; after that, certificates against the 2013 edition expired or were withdrawn. A certificate that today still reads ISO/IEC 27001:2013 is therefore no longer valid evidence. For the transition audit itself, IAF MD 26 sets minimum effort: half an auditor day alongside a recertification audit, a full auditor day alongside a surveillance audit, or as a standalone audit; a transition audit on its own does not move the expiry date of the running cycle.

Only ISO/IEC 27001 is certifiable. ISO/IEC 27002 describes the same controls at greater length, with purpose and implementation guidance, but sets no management system requirements and is therefore not a subject of certification. Anyone offered a confirmation "to ISO 27002" should ask questions. The comparison ISO 27001 vs ISO 27002 sets the purpose, binding force and structure of the two standards side by side.

There are two routes to the certificate; which national accreditation regime applies depends on jurisdiction, and the description below is for Germany. The international standard route is direct assessment against ISO/IEC 27001 by an accredited certification body; accreditation in Germany is granted by the DAkkS, the German national accreditation body. Its position rests on statute: Regulation (EC) No 765/2008 requires each Member State to designate a single national accreditation body, § 1(1) of the Akkreditierungsstellengesetz (the German accreditation body act) assigns accreditation to the Federal Republic as a sovereign task, and the Deutsche Akkreditierungsstelle GmbH holds that task by delegation under § 1 of the corresponding Beleihungsverordnung.

Alongside it stands ISO 27001 on the basis of IT-Grundschutz: the same normative reference, reached through the BSI's more pre-structured methodology and assessed by auditors certified by the BSI. That this second route runs through its own system also has a statutory root: § 1(2) of the Akkreditierungsstellengesetz expressly leaves untouched the competence of authorities established under other legislation, naming information technology security among them. The provision does not carve IT security out of the DAkkS's remit; it preserves the BSI's competence alongside it. The DAkkS continues to accredit the certification bodies for ISO/IEC 27001 itself.

What a certification body actually has to deliver is not set out in ISO/IEC 27001 but in the standards for conformity assessment bodies: ISO/IEC 17021-1, generally, for management-system certification bodies, and ISO/IEC 27006-1:2024, specifically for ISMS certification, which superseded the earlier ISO/IEC 27006:2015. That framework is where the requirements on impartiality, audit team competence and the calculation of audit effort come from, the reason audit time is not freely negotiable.

Check accreditation status before you engage anyone, and do so verifiably rather than from a claim in a proposal: in Germany the DAkkS keeps the directory of accredited bodies, and internationally a certificate or a body can be checked through the IAF CertSearch database. Unaccredited confirmations are frequently not recognised by customers, insurers and supervisory authorities.

Which prerequisites must an ISMS meet?

The certification body does not examine intentions, it examines evidence. Book the date for the Stage 2 audit before the ISMS is genuinely running and, in our experience, you will move it.

An ISMS that is genuinely operated

The standard calls for a system that works: risks are assessed against defined criteria, measures are implemented and monitored, nonconformities are recorded and corrected. Out of that operation come records: minutes, approvals, analyses, tickets, test results. Those records are precisely what Stage 2 is about. An ISMS that generates its evidence only for the audit cannot demonstrate effectiveness, because the period over which it could show is missing.

How long an ISMS has to have been running before the Stage 2 audit depends on the individual case and on the certification body's judgement. The dependable question is not "how many months" but this: for every cyclical process (risk assessment, internal audit, management review, training, access review) is there at least one complete run and are the decisions that followed from it on record?

The scope

The scope is the single most consequential decision of the whole undertaking. It determines what every later statement refers to, which sites are visited, which systems fall into the sample, and what ends up on the certificate.

Two mistakes occur about equally often. Too wide a scope overtaxes the organisation and produces findings in areas that were never part of the project. Too narrow a scope is quickly certified but is read by customers, and if the certificate names a site that does not supply the customer, an uncomfortable question arises in the supplier assessment. The usual route is a deliberately limited initial scope, extended later under control.

The boundary also has to take in the interfaces facing outwards: outsourced processes, cloud services, intra-group service providers. The service can be outsourced, the accountability cannot; the management of those providers has to be represented within the ISMS.

Two questions come up regularly at this point, and both have a clear answer. Does every site have to be in the scope? No. The scope is a deliberate decision, and where several sites are genuinely comparable, they can be examined through a sampling procedure governed by the accreditation requirements. Anyone excluding a site should expect that same site to be asked about in a supplier assessment. Does our cloud provider's certificate count for us? No. It evidences the provider's management system within the provider's own scope, and so is one building block of your supplier management, not evidence for your own ISMS. It does not relieve you of carrying the service you buy in your own risk assessment either way.

The Statement of Applicability

The standard requires the Statement of Applicability (SoA) in clause 6.1.3 d) as an output of the risk treatment. It lists the controls from Annex A and records for each whether it is applicable, why it was included or excluded, and how far it has been implemented.

For the audit the SoA is the single most important document, because auditors draw their sample from it. A control recorded in the SoA as implemented produces, in the audit, the question of evidence. That works in both directions: an honest entry reading "partially implemented, residual risk accepted, risk owner named" stands up to audit; a flattering "implemented" with nothing behind it is a finding.

The overview below sums up what has to be in place before the initial audit.

ElementEvidence expected
ScopeDocumented boundary with reasoning, interfaces included
Policy and security objectivesApproved by top management and communicated
Roles and responsibilitiesNamed, assigned, known to the people concerned
Risk procedureCriteria, assessment results, risk treatment plan, sign-off by the risk owners
Statement of ApplicabilityComplete, reasoned, approved, current
Internal auditCarried out across the whole scope and documented
Management reviewHeld, minuted, with decisions that can be followed
Operational evidenceRecords from running operation across a meaningful period

How does an ISO 27001 certification work, step by step?

Selecting and engaging the certification body

At the start comes a tender process. For its quotation the certification body needs details of the scope, sites, headcount, processes and outsourcing arrangements; from these it determines the audit effort under a standardised procedure set by the accreditation requirements. The effort is therefore neither freely negotiable nor predictable as a flat figure.

Alongside price, look at accreditation status for ISO/IEC 27001, the sector experience of the proposed audit team, and availability of dates across the entire three-year cycle. Consultancy and certification must not come from the same hand: a body that built your ISMS may not certify it.

Stage 1: document and readiness review

Stage 1 establishes whether the system is ready to be audited. Examined are the documented information, the boundary and plausibility of the scope, the risk procedure, the SoA, and whether the internal audit and the management review have taken place. The auditor also forms a picture of how the organisation is built and plans the Stage 2 sample on that basis.

The output is a report listing points to be settled before Stage 2. Those points are not yet nonconformities; they are advance warning. Take them seriously and you save yourself findings in the audit that counts.

Between the stages

The interval between the stages is for the follow-up work. It should be long enough for the Stage 1 points not merely to be documented but to take effect, and short enough that the material reviewed in Stage 1 still reflects the current state. Larger changes to the scope in this phase mean parts of Stage 1 have to be repeated.

Stage 2: examining implementation and effectiveness

Stage 2 is the certification audit proper. The question is whether the documented system is actually operated as described. The methods are interviews with owners and staff, samples from records, inspection of systems and, depending on the scope, walk-throughs of sites and data centres.

Auditors typically follow trails rather than chapters: an assessed risk leads to the associated measure, the measure to the SoA entry, the entry to the evidence, and the evidence to the person who produced it. Where that chain breaks, a finding arises. Prepare your business functions to speak about their own work; memorised phrases from the policy do not help.

Findings and corrective actions

Findings are distinguished by severity.

FindingMeaningConsequence
Major nonconformityA requirement of the standard is not met, or a process is missing entirelyThe certificate is issued only once correction has been evidenced
Minor nonconformityAn isolated weakness in a process that works in principleCorrective action plan, effectiveness checked at the next audit
Recommendation or observationRoom for improvement without a breach of the standardNot binding, but frequently reappears at the next audit

For nonconformities the certification body expects not a quick repair but a root cause analysis, correction of the individual case, corrective action against the cause, and evidence of effectiveness. The most common mistake here is treating the symptom: catch up a missing approval without changing the approval process, and the same finding surfaces again in the next cycle.

Issuing the certificate

The decision to issue is not taken by the audit team but by an independent function inside the certification body that reviews the report. As a rule the certificate is valid for three years and names the standard, the edition, the scope and the sites. Read the wording of the scope carefully before it is issued. Your customers will quote it later.

Surveillance audits

In the two years after initial certification, surveillance audits take place. They examine not the whole system but a section, and that section is not chosen at random. Subjects that recur regularly are the effectiveness of the previous year's corrective actions, the internal audit and management review, changes to scope, organisation and system landscape, complaints and incidents, and the use of the certification mark.

Recertification

In the third year the entire scope is examined again, together with an evaluation of the system's performance across the cycle that has ended. Recertification has to be scheduled so that it concludes before the certificate expires, corrective action time included. A gap between two certificates is rarely a technical problem, but regularly a commercial one.

What does the cost consist of?

No credible single figure can be given here, and any quoted without knowledge of scope, sites and starting position is a guess with a decimal point attached. The structure, by contrast, holds up: knowing which blocks make up the effort, who bills for them, and what drives their size lets you compare quotations and estimate your own need without borrowing someone else's numbers.

Cost blockWho bills for itWhat drives its sizeWhen it falls due
Audit effort, Stage 1 and Stage 2Certification bodyHeadcount in scope, sites, process complexity, outsourcing (calculated under ISO/IEC 27006-1)Once, in the certification year
Travel and incidental costsCertification bodyNumber and location of the sites visitedPer audit visit
Follow-up audit for major nonconformitiesCertification bodyNumber and severity of findingsOnly where needed
Surveillance auditsCertification bodyAs a rule a fraction of the initial audit, same calculation basisIn the two following years
RecertificationCertification bodyThe entire scope again, plus an evaluation of the cycleIn the third year
Internal effort of building and running the ISMSYour own organisationMaturity of the inventory, risk procedure and evidence base at the outsetMostly before the initial audit, ongoing after it
External supportConsultancy or tooling vendorFreely chosen scope; must not come from the certification bodyProject-dependent
Technical remediationSuppliersThe outcome of risk treatment, not the standardAfter the selection of measures

Three notes on reading this. First, only the first block is really set by someone else: audit effort follows a standardised calculation, so a strikingly low quotation deserves a follow-up question about the headcount and scope it assumed. Second, the largest block is usually the internal one, and it appears in no quotation. Third, effort saved before the initial audit typically just moves into the next surveillance audit: evidence produced specially for one date has to be produced again the following year.

Compare quotations over the full three-year cycle and by the stated auditor days, not by the price of the initial audit alone.

One figure in this space is not negotiable and is publicly documented, and it concerns the IT-Grundschutz route: the BSI's fee for the certification procedure itself sits in the Besondere Gebührenverordnung of the Federal Ministry of the Interior, in the schedule of fees and expenses under item 1.4: 2,978.00 euro for initial certification of a system, 2,658.00 euro for recertification. That is expressly only the authority's procedural fee; the effort of the BSI-certified audit team and the entire internal effort come on top of it. No equivalent figure exists for the route through an accredited certification body, because there no statutory fee applies, only a market price on a standardised effort basis.

How long does an ISO 27001 certification take?

No credible flat duration can be given for the route to a first certificate, and figures quoted without knowledge of the scope, the sites and the starting position are marketing. Dependable instead are the drivers and the order.

Three factors drive the duration above all:

  • The cut of the scope. Sites, legal entities, languages and outsourced processes weigh more heavily than headcount alone.
  • The maturity of the risk assessment. Where assets are already recorded, owners named and assessment criteria defined, the most laborious part of the preparation falls away.
  • Where the evidence comes from. Where records arise in day-to-day business anyway, the period to audit readiness is short. Where they are generated specially, the effort is merely pushed into the next surveillance audit.

The order matters just as much, because some steps cannot be run in parallel. The scope has to be settled before the risk assessment, the risk assessment before the selection of measures, the measures before the SoA. Internal audit and management review presuppose a system already running and have to be complete before Stage 1. Between Stage 1 and Stage 2 there is a follow-up phase, and between Stage 2 and issue there may be another for corrective actions.

Plan in two items that project plans almost always omit: the lead time for the quotation and date allocation at the certification body, and the availability of your own business functions, who will be interviewed during the audit and cannot step in at short notice.

Where do certifications lose time?

  • The scope is changed late. Every change works back into the risk assessment, the SoA and the internal audit. After Stage 1 it is particularly expensive.
  • The SoA describes a target state. Controls recorded as "implemented" with no evidence are the most reliable source of findings there is.
  • The 93 controls are worked top to bottom. Use Annex A as a checklist instead of as a cross-check on the risk treatment, and you will not be able to explain in the audit why the ISMS looks the way it does.
  • The internal audit examines documents instead of effectiveness. An internal audit that produces not a single finding becomes a subject of examination for the external auditor.
  • The management review takes place without metrics. Minutes with no data behind them and no decisions meet the requirement formally, but not substantively.
  • Suppliers and cloud services are left out. Outsourced processes inside the scope have to be managed and evidenced.
  • Top management does not appear. The leadership clause calls for visible commitment. A management board unavailable during the audit is a finding in its own right.
  • The system goes to sleep after the certificate. The first surveillance audit uncovers that reliably, because the records of the past year are then missing.

What role do internal audit and management review play?

These two elements decide the course of the external audit more often than any technical measure, because they show whether the organisation steers its own system.

The internal audit must cover the entire scope across a planned cycle, follow a programme, and be carried out by people who are not themselves accountable for the area under review. In smaller organisations that independence is the real obstacle; it can be established through reciprocal review between functions or through external auditors who do not also carry out the certification. The output is documented findings with owners, dates and a later check of effectiveness. The internal ISMS audit checklist goes step by step from the audit programme through to the follow-up of corrective actions.

The management review is top management's formal engagement with the ISMS. It needs a basis in data (results of internal and external audits, the status of corrective actions, incidents, effectiveness metrics, feedback from interested parties, changes in context and the state of the risk treatment) and it has to lead to decisions: on resources, objectives, improvements and, where applicable, changes to the scope. Minutes that reproduce the report but contain no decision are open to challenge in the audit.

What comes after the certificate?

Issue starts the cycle; it does not end the project. Several things have to be sustained.

First, running operation: risk assessments are repeated when things change, the SoA is kept current, evidence accrues continuously. Second, the annual obligatory routine of internal audit, management review and preparation for the surveillance audit. Third, the duty to notify the certification body: substantial changes to scope, sites, organisation or outsourced processes are to be reported, and extensions of the scope are examined, usually as part of the next surveillance or recertification audit.

Fourth, the outward use of the certificate. The certification body sets rules for use of the certification mark, and compliance with them is itself a subject of examination. Common breaches are the mark on products, the phrase "certified company" where the scope is site-specific, and continued use after expiry.

An existing certificate is also the cheapest starting point for regulatory requirements that arrive alongside it. The risk-management and evidence duties under the NIS-2-Umsetzungsgesetz, Germany's NIS2 transposition act, or under DORA can largely be mapped onto an existing ISMS. A certificate does not replace them, though: registration and reporting duties, regulatory deadlines and the personal responsibility of the management body follow from the statute in question, not from the standard. And the scope of a certification is usually cut more narrowly than the regulatory scope.

How the scope, risks, measures and evidence of an ISMS to ISO/IEC 27001 can be linked so that the state of implementation is demonstrable for an audit at any time without a special exercise is shown on our ISO 27001 page.

How the route there looks in Rizzqo

Two of the three places where a certification reliably costs time are work on the estate: the cut of the scope, and the evidence. Both attach to the same objects. In Rizzqo, ISO/IEC 27001 for the management system and ISO/IEC 27002 for the controls are held as two catalogues over one estate. The scope is therefore not a passage of text but a set of objects: the primary assets and the systems, sites and providers carrying them.

The evidence follows from that. Every attached requirement is answered on the object, with a reason and an attachment, and the finalisation is recorded under a name and a timestamp. The auditor sees confirmed statements rather than editable drafts, and the sample can be drawn from the open requirements: an object counts as fully covered only once every requirement has been closed as fulfilled or as not applicable. The statement of applicability is prepared by the reasoned statement per control on the object concerned.

Browse all entriesBack to top

Frequently asked questions

See compliance run on your real assets

Rizzqo turns framework requirements into owned tasks on the assets you already have, and prices the risk in real money.

Made in GermanyHosted in your countryMulti-framework