Pillar guide
ISO 27001 certification, from scope statement to certificate
What actually gets certified
The documents the auditor reads first
Clause 4
Scope statement
Clause 6
Risk assessment and treatment
Clause 6.1.3
Statement of Applicability
Clauses 5 to 10
Policies and records
Stage 1 and Stage 2
Timeline from zero
| Phase | What happens | Typical timing |
|---|---|---|
| Scope and risk | Scope statement, asset inventory, risk assessment and treatment plan | Weeks 1 to 2 |
| Controls and policies | Annex A controls selected in the SoA, policies adopted, integrations collecting evidence | Weeks 3 to 8 |
| Internal audit and management review | Required by the standard before certification; findings tracked to closure | Weeks 9 to 12 |
| Stage 1 | Documentation review by the certification body | Week 12 onward |
| Stage 2 | Implementation audit, nonconformities, certificate | 2 to 8 weeks after Stage 1 |
ISO 27001 and SOC 2 together
Go deeper
Understand the standard
Decide and plan
ISO 27001 questions we hear most
How long is the certificate valid?
Three years, with a surveillance audit in each of the two intervening years and a recertification audit in year three. Continuous monitoring in Certifyi keeps the surveillance audits short.
Do we need all 93 Annex A controls?
No. You select the controls that treat your risks and justify exclusions in the Statement of Applicability. Excluding a control with a weak justification is the most common Stage 1 finding.
Who can issue the certificate?
An accredited certification body (accredited by a national body such as UKAS or ANAB). Consultants and software vendors cannot certify you. Certifyi coordinates the certification body and hosts the audit in its Auditor Workspace.
Is ISO 27001 harder than SOC 2?
It is more structured. SOC 2 asks whether your controls work; ISO 27001 also asks whether your management system decides, reviews and improves them. The extra work is mostly documentation and governance, which a Lead Implementer handles with you.