Pillar guide

ISO 27001 certification, from scope statement to certificate

The international standard for an information security management system, explained for teams doing it for the first time: what the auditor certifies, the documents that matter, the two-stage audit and how long it takes.
ISO 27001 in one paragraph. ISO/IEC 27001 is a certifiable standard for an information security management system (ISMS). An accredited certification body audits your ISMS in two stages and issues a certificate valid for three years, with surveillance audits each year. It is the framework EU, UK and APAC customers ask for, and the one most compatible with ISO 42001 for AI governance.

What actually gets certified

Not your product. The certificate covers the management system: the scope you define, the risk assessment and treatment you run, the controls you select from Annex A and the evidence that they operate. A narrow, honest scope statement is the single most important decision in the project; it determines which systems, people and locations the auditor examines.

The documents the auditor reads first

Clause 4

Scope statement

Which business units, systems, locations and interfaces are inside the ISMS, and why the boundary sits where it does.

Clause 6

Risk assessment and treatment

A risk register with owners, likelihood, impact and the treatment chosen for each. Certifyi adds Monte Carlo loss modelling when the board wants numbers.

Clause 6.1.3

Statement of Applicability

Every Annex A control, whether it applies, why, and how it is implemented. The SoA is the auditor’s map of your ISMS.

Clauses 5 to 10

Policies and records

The information security policy, supporting policies people actually follow, and the records that prove reviews, training and incidents happened.

Stage 1 and Stage 2

Stage 1 is a documentation review: the certification body checks that the ISMS is designed and that you are ready for Stage 2. Stage 2 is the implementation audit: interviews, sampling and evidence, usually two to five auditor-days depending on scope. Nonconformities are raised as minor or major; majors must be closed before the certificate is issued.

Timeline from zero

With a Lead Implementer running weekly sessions, Certifyi customers are audit-ready in 8 to 12 weeks: scope and risk assessment in the first two weeks, controls and policies through week eight, internal audit and management review by week twelve. Certification bodies typically schedule Stage 1 within a few weeks and issue the certificate four to eight weeks after a clean Stage 2.
PhaseWhat happensTypical timing
Scope and riskScope statement, asset inventory, risk assessment and treatment planWeeks 1 to 2
Controls and policiesAnnex A controls selected in the SoA, policies adopted, integrations collecting evidenceWeeks 3 to 8
Internal audit and management reviewRequired by the standard before certification; findings tracked to closureWeeks 9 to 12
Stage 1Documentation review by the certification bodyWeek 12 onward
Stage 2Implementation audit, nonconformities, certificate2 to 8 weeks after Stage 1

ISO 27001 and SOC 2 together

If you already hold a SOC 2 report, most of the control work carries over: access control, change management, logging, vendor management and incident response satisfy both. What ISO 27001 adds is the management-system layer: scope, risk methodology, SoA, internal audit and management review. In Certifyi both frameworks read from one control library, so the second one is a mapping exercise rather than a second project.

ISO 27001 questions we hear most

Three years, with a surveillance audit in each of the two intervening years and a recertification audit in year three. Continuous monitoring in Certifyi keeps the surveillance audits short.

No. You select the controls that treat your risks and justify exclusions in the Statement of Applicability. Excluding a control with a weak justification is the most common Stage 1 finding.

An accredited certification body (accredited by a national body such as UKAS or ANAB). Consultants and software vendors cannot certify you. Certifyi coordinates the certification body and hosts the audit in its Auditor Workspace.

It is more structured. SOC 2 asks whether your controls work; ISO 27001 also asks whether your management system decides, reviews and improves them. The extra work is mostly documentation and governance, which a Lead Implementer handles with you.

Ready to define your scope?

A Lead Implementer will draft your scope statement and a realistic certification date on one call.
Scroll to Top