{"id":3390,"date":"2026-09-04T10:35:05","date_gmt":"2026-09-04T10:35:05","guid":{"rendered":"https:\/\/nordsterntech.com\/en\/iso-27001-certification-process\/"},"modified":"2026-09-04T19:55:27","modified_gmt":"2026-09-04T19:55:27","slug":"iso-27001-certification-process","status":"publish","type":"post","link":"https:\/\/nordsterntech.com\/en\/iso-27001-certification-process\/","title":{"rendered":"ISO 27001 certification: the real process, the evidence, and how long it takes"},"content":{"rendered":"<p class=\"ns-lead\">A customer asks for \u00abyour ISO 27001 accreditation\u00bb before signing. Someone forwards the request to IT, IT forwards it to whoever owns policies, and three weeks later the answer is still a maybe. Meanwhile the deal waits.<\/p>\n<p>This article explains what ISO 27001 certification actually involves: what you are audited against, the two-stage audit, the evidence an auditor will ask to see, how long it realistically takes, and the mistakes that add months. It also settles the word in that first sentence, because it matters more than it looks.<\/p>\n<div class=\"ns-tldr\">\n  <span class=\"ns-tldr-t\">In short<\/span><\/p>\n<ul>\n<li>Organizations get <strong>certified<\/strong>; certification bodies get <strong>accredited<\/strong>. The distinction is a purchasing criterion, not pedantry.<\/li>\n<li>The transition to the 2022 edition <strong>closed on 31 October 2025<\/strong>. A 2013 certificate is no longer valid.<\/li>\n<li>Annex A is a catalogue of <strong>93 controls<\/strong> in four themes \u2014 a reference list, not a to-do list.<\/li>\n<li>What sets the timeline is not writing policies: it is how long the system has been producing records.<\/li>\n<\/ul>\n<\/div>\n<div class=\"ns-stats\">\n<div class=\"ns-stat\"><b>93 controls<\/b><span>in Annex A, across four themes: organizational, people, physical and technological<\/span><\/div>\n<div class=\"ns-stat\"><b>31 Oct 2025<\/b><span>the date the transition from the 2013 edition closed for good<\/span><\/div>\n<div class=\"ns-stat\"><b>3 years<\/b><span>the certification cycle: two surveillance audits and a recertification<\/span><\/div>\n<\/div>\n<h2>Accreditation and certification are not the same thing<\/h2>\n<p>Organizations get <strong>certified<\/strong>. Certification bodies get <strong>accredited<\/strong>.<\/p>\n<p>Your company cannot hold an ISO 27001 accreditation. What you can hold is a certificate issued by a certification body that is itself accredited by a national accreditation body \u2014 UKAS, ANAB, ema and their equivalents, all operating under the International Accreditation Forum&#8217;s mutual recognition arrangement.<\/p>\n<p>This is not pedantry, it is a purchasing criterion. Anyone can print a certificate. A certificate issued by a body with no accreditation behind it is worth exactly what your customer decides it is worth, and sophisticated customers check. Two practical consequences:<\/p>\n<ul>\n<li>When you choose a certification body, <strong>verify its accreditation<\/strong> and the scope of that accreditation, the same way you would <a href=\"https:\/\/nordsterntech.com\/en\/approved-scanning-vendor-asv-scan\/\">verify an ASV on the PCI Council&#8217;s list<\/a>.<\/li>\n<li>When a supplier hands you a certificate, look for the accreditation body&#8217;s mark and check it. A certificate without one is a claim, not evidence.<\/li>\n<\/ul>\n<h2>What you are audited against in 2026<\/h2>\n<p>The current standard is <strong>ISO\/IEC 27001:2022<\/strong>, plus <strong>Amendment 1:2024<\/strong>, which added climate change to the context clauses: you must determine whether it is a relevant issue for your information security management system, and consider that interested parties may have requirements related to it.<\/p>\n<p>The standard has two halves, and confusing them is the most common source of wasted effort:<\/p>\n<ul>\n<li><strong>Clauses 4 to 10<\/strong> are the management system: context, leadership, planning, support, operation, performance evaluation and improvement. This is what is actually certified.<\/li>\n<li><strong>Annex A<\/strong> is a catalogue of <strong>93 controls<\/strong> grouped in four themes \u2014 organizational (37), people (8), physical (14) and technological (34). It is a reference list, not a to-do list. Your risk assessment decides which apply, and the Statement of Applicability records that decision.<\/li>\n<\/ul>\n<h3>If you still hold a 2013 certificate, you have a problem<\/h3>\n<p>The transition period closed on <strong>31 October 2025<\/strong>. Certificates against ISO\/IEC 27001:2013 that were not transitioned expired or were withdrawn, and accreditation bodies no longer recognise them.<\/p>\n<p>The practical consequence is worth stating plainly: an organization in that position is not \u00abslightly behind on paperwork\u00bb. It is uncertified, and the route back is a <strong>full Stage 1 and Stage 2 audit<\/strong>, not the shorter transition audit that was available until last October. If a supplier sends you a certificate dated against the 2013 version, it is not valid today.<\/p>\n<h2>The ISO 27001 certification process, stage by stage<\/h2>\n<ol>\n<li><strong>Define the scope.<\/strong> Which parts of the organization, which locations, which services and which information. This single decision drives cost, duration and how useful the certificate will be commercially.<\/li>\n<li><strong>Gap analysis.<\/strong> Compare what exists against what the standard requires. Optional in theory; in practice it is what turns an open-ended project into a plan with dates.<\/li>\n<li><strong>Risk assessment and risk treatment.<\/strong> The engine of the whole system. Identify risks to confidentiality, integrity and availability, decide how to treat each one, and let that drive which controls you implement.<\/li>\n<li><strong>Statement of Applicability.<\/strong> For each of the 93 Annex A controls: whether it applies, why, and its implementation status. Auditors read this document closely, and it is where copy-paste shows immediately.<\/li>\n<li><strong>Implement and operate.<\/strong> Controls, yes, but also the management system: objectives, competence, awareness, documented procedures.<\/li>\n<li><strong>Let it run.<\/strong> This is the step nobody wants to hear about. The system has to produce records for long enough to be auditable.<\/li>\n<li><strong>Internal audit and management review.<\/strong> Both are mandatory, and both must happen <em>before<\/em> the certification audit.<\/li>\n<li><strong>Stage 1 audit.<\/strong> The auditor reviews documentation and readiness, checks scope and Statement of Applicability, and identifies what would fail in Stage 2. Treat findings here as a gift.<\/li>\n<li><strong>Stage 2 audit.<\/strong> The real one. The auditor tests whether the system works in practice, through records, interviews and sampling.<\/li>\n<li><strong>Certificate, then the cycle.<\/strong> Certification runs on a three-year cycle: surveillance audits in years one and two, recertification in year three.<\/li>\n<\/ol>\n<figure class=\"ns-fig\">\n  <img decoding=\"async\" src=\"https:\/\/nordsterntech.com\/en\/wp-content\/uploads\/2026\/09\/fig-iso-ciclo.jpg\" alt=\"Timeline of the ISO 27001 certification cycle: Stage 1, Stage 2, surveillance audits and recertification\" loading=\"lazy\" \/><figcaption>Certification is a cycle, not a finish line. Budget for the surveillance audits from day one.<\/figcaption><\/figure>\n<h2>The evidence an auditor will actually ask for<\/h2>\n<p>Beyond the controls themselves, the standard requires specific documented information. If you want a short answer to \u00abare we ready\u00bb, check whether you can produce these today:<\/p>\n<ul>\n<li>The <strong>scope<\/strong> of the ISMS.<\/li>\n<li>The <strong>information security policy<\/strong> and the security <strong>objectives<\/strong>.<\/li>\n<li>The <strong>risk assessment and risk treatment process<\/strong>, and the results of applying it.<\/li>\n<li>The <strong>Statement of Applicability<\/strong> and the <strong>risk treatment plan<\/strong>.<\/li>\n<li>Evidence of <strong>competence<\/strong> of the people with security responsibilities.<\/li>\n<li>Results of <strong>monitoring and measurement<\/strong>.<\/li>\n<li>The <strong>internal audit programme<\/strong> and its results.<\/li>\n<li>Results of the <strong>management review<\/strong>.<\/li>\n<li>Records of <strong>nonconformities and corrective actions<\/strong>.<\/li>\n<\/ul>\n<p>Notice how many of those are records rather than documents. Policies can be written in a week. Evidence that the system has been operating cannot, which is why the honest answer to \u00abcan we certify by next quarter\u00bb usually depends on when you started generating records, not on how fast you can write.<\/p>\n<h2>How long ISO 27001 certification takes, and what makes it slower<\/h2>\n<p>For an organization with a defined scope and reasonable security maturity, a first certification typically takes somewhere between a few months and a year. The variance comes from a short list of factors:<\/p>\n<ul>\n<li><strong>Scope size and number of sites.<\/strong> Broad scopes are slower to build, slower to audit and harder to keep alive.<\/li>\n<li><strong>Whether a real risk assessment already exists.<\/strong> Most organizations have a spreadsheet of threats. That is not the same thing.<\/li>\n<li><strong>How much of the operation already produces records<\/strong> \u2014 access reviews, log monitoring, incident tickets, supplier assessments.<\/li>\n<li><strong>Internal audit capacity<\/strong>, including someone independent enough to run it.<\/li>\n<li><strong>Certification body scheduling<\/strong>, which is outside your control and routinely underestimated in project plans.<\/li>\n<\/ul>\n<div class=\"ns-pull\">\n<p>Policies can be written in a week. Evidence that the system has been operating cannot.<\/p>\n<\/div>\n<h2>ISO 27001 or SOC 2?<\/h2>\n<p>Both answer the same commercial question \u2014 prove your security to a customer \u2014 through different mechanisms, and organizations selling on both sides of the Atlantic often end up with both.<\/p>\n<table>\n<thead>\n<tr>\n<th><\/th>\n<th>ISO\/IEC 27001<\/th>\n<th>SOC 2<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td>What it is<\/td>\n<td>Certification of a management system against an international standard<\/td>\n<td>An attestation report issued by a CPA firm against the AICPA Trust Services Criteria<\/td>\n<\/tr>\n<tr>\n<td>What you receive<\/td>\n<td>A certificate<\/td>\n<td>A report, which the reader must actually read<\/td>\n<\/tr>\n<tr>\n<td>Who issues it<\/td>\n<td>An accredited certification body<\/td>\n<td>A licensed CPA firm<\/td>\n<\/tr>\n<tr>\n<td>Period covered<\/td>\n<td>Three-year cycle with annual surveillance<\/td>\n<td>A point in time (Type I) or a period, typically 3 to 12 months (Type II)<\/td>\n<\/tr>\n<tr>\n<td>Where it is expected<\/td>\n<td>Global, strong in Europe and Latin America<\/td>\n<td>Predominantly the United States<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>The work underneath overlaps heavily. If both are on your roadmap, build the risk assessment and the control evidence once and map it twice, rather than running two disconnected projects.<\/p>\n<h2 id=\"errores\">The mistakes that cost the most time<\/h2>\n<ul>\n<li><strong>A scope drawn to look impressive.<\/strong> Certifying the whole company when the customer only cares about one platform multiplies effort for no commercial gain.<\/li>\n<li><strong>A Statement of Applicability that does not match reality.<\/strong> If it says a control is implemented and the auditor finds otherwise, you have converted a gap into a credibility problem.<\/li>\n<li><strong>Annex A treated as a checklist.<\/strong> Controls chosen without a risk behind them are expensive to justify and impossible to defend in an interview.<\/li>\n<li><strong>Internal audit run by the person who built the system.<\/strong> Independence is a requirement, not a formality.<\/li>\n<li><strong>Starting the audit before the records exist.<\/strong> The single most common reason a Stage 2 gets postponed.<\/li>\n<\/ul>\n<h2>One thing to know before you pick a partner<\/h2>\n<p>The organization that helps you build the ISMS cannot be the one that certifies it. Accreditation rules keep consultancy and certification apart precisely so that nobody audits their own work \u2014 which means a serious consultant will tell you this up front rather than promising a certificate.<\/p>\n<p>What a consultant can do is everything up to the audit: define a scope that is defensible and commercially useful, run the <a href=\"https:\/\/nordsterntech.com\/en\/cybersecurity-as-a-service-caas\/\">gap analysis and the ISO 27001 work<\/a>, build a risk assessment that survives questioning, and make sure the operation actually produces the evidence \u2014 which is where <a href=\"https:\/\/nordsterntech.com\/en\/soc\/\">continuous monitoring<\/a> and a working <a href=\"https:\/\/nordsterntech.com\/en\/dfir\/\">incident response process<\/a> stop being a security nicety and start being audit evidence.<\/p>\n<p>And if PCI DSS is also on your list, sequence them deliberately: the two standards share risk assessment, access control, logging and supplier management, and doing them together is considerably cheaper than doing them a year apart. Our <a href=\"https:\/\/nordsterntech.com\/en\/pci-dss\/\">PCI DSS<\/a> work runs on the same foundations.<\/p>\n<p>If you need to know how far you are from certification, that is a scoped question with a definite answer. <a href=\"https:\/\/nordsterntech.com\/en\/contact\/\">Talk to our compliance team<\/a>.<\/p>\n<hr \/>\n<h3>Sources<\/h3>\n<ul>\n<li>ISO\/IEC 27001:2022 \u2014 <em>Information security, cybersecurity and privacy protection \u2014 Information security management systems \u2014 Requirements<\/em>, and ISO\/IEC 27001:2022\/Amd 1:2024 (climate action).<\/li>\n<li>IAF MD 26:2023 \u2014 transition requirements for ISO\/IEC 27001:2022; transition period closed on 31 October 2025.<\/li>\n<li>AICPA Trust Services Criteria, for the SOC 2 comparison.<\/li>\n<\/ul>\n","protected":false},"excerpt":{"rendered":"<p>A customer asks for \u00abyour ISO 27001 accreditation\u00bb before signing. Someone forwards the&hellip;<\/p>\n","protected":false},"author":2,"featured_media":3391,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[30],"tags":[],"class_list":["post-3390","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-iso-27001"],"_links":{"self":[{"href":"https:\/\/nordsterntech.com\/en\/wp-json\/wp\/v2\/posts\/3390","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/nordsterntech.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/nordsterntech.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/nordsterntech.com\/en\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/nordsterntech.com\/en\/wp-json\/wp\/v2\/comments?post=3390"}],"version-history":[{"count":3,"href":"https:\/\/nordsterntech.com\/en\/wp-json\/wp\/v2\/posts\/3390\/revisions"}],"predecessor-version":[{"id":3399,"href":"https:\/\/nordsterntech.com\/en\/wp-json\/wp\/v2\/posts\/3390\/revisions\/3399"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/nordsterntech.com\/en\/wp-json\/wp\/v2\/media\/3391"}],"wp:attachment":[{"href":"https:\/\/nordsterntech.com\/en\/wp-json\/wp\/v2\/media?parent=3390"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/nordsterntech.com\/en\/wp-json\/wp\/v2\/categories?post=3390"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/nordsterntech.com\/en\/wp-json\/wp\/v2\/tags?post=3390"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}