Guide

ISO 27001 Certification: What the Process Actually Involves

Certification isn't a document you produce once — it's an operating system for security decisions that an external auditor checks twice before granting it, and revisits every year after.

Talk to a CISO

The business problem

Most organizations approach ISO 27001 like a compliance form: assign it to IT or a consultant, produce a binder of policies, schedule the audit, get the certificate, move on. That approach frequently produces a certificate. It rarely produces a functioning security program.

ISO 27001 certifies an Information Security Management System (ISMS) — a defined, resourced, operating set of processes for identifying risk and making security decisions. The documentation describes that system; it is not the system itself.

Why it matters

ISO 27001 is increasingly a commercial requirement — enterprise customers, insurers, and partners ask for it before they'll sign. But the certification body checks annually, for three years, whether the ISMS is still real. A program built as a one-time project degrades within a year and puts renewal at risk.

An ISMS built properly gives leadership an actual mechanism for making risk-based decisions. One built as a paperwork exercise gives leadership a false sense of coverage.

“Companies don't fail ISO 27001 audits because their policies are wrong. They fail because the policies describe a company that doesn't exist.”

Signs the organization should pay attention now

  • The ISMS is owned by a single person or a consultant, with no defined role in the day-to-day business
  • Risk assessments exist as a document but haven't changed since they were first written
  • Policies reference procedures that aren't actually followed
  • There's no internal audit or management review cadence
  • The certification timeline was set by a sales deadline rather than what the organization can realistically operationalize

What good looks like

A well-run certification effort treats the ISMS as infrastructure. The risk assessment is a living input to decisions, a named owner with real authority runs the program, and evidence of operation accumulates naturally because the processes are actually happening.

Stage 1 is a documentation review — the auditor confirms the ISMS is designed correctly and ready to be tested. Stage 2 is the substantive audit — the auditor tests whether the organization actually does what its documentation says. After certification, annual surveillance audits check that the ISMS is still operating, with a full recertification audit in year three.

Want ongoing executive ownership of this program?

Explore Compliance & Program Leadership

Practical guidance

Assign ownership to someone with the authority to change how the business operates, not just someone who can write documents. Build the risk assessment as a decision tool leadership actually uses. Run at least one internal audit and one management review before Stage 2 — auditors look for this cadence specifically. Set the timeline around organizational readiness, not around when a deal needs the certificate.

My CISO Partner's perspective

Organizations underestimate ISO 27001 because they scope it as a project with an end date, when it is structurally a standing operating commitment with a three-year certification cycle. Executive sponsorship matters more here than in almost any other compliance initiative, because the ISMS's authority has to come from leadership.

Where to go from here

If your organization is heading toward ISO 27001 — or already certified and finding the surveillance audits harder than expected — the right first step is a conversation about what the ISMS actually needs to look like inside your business.

FAQ

Questions, answered directly.

Timelines vary by organizational readiness, but the work spans building and operating the ISMS long enough to generate real evidence, then passing Stage 1 and Stage 2 audits.

Stage 1 reviews ISMS documentation to confirm it is correctly designed. Stage 2 tests whether the organization actually operates what the documentation describes, through evidence sampling and interviews.

No. ISO 27001 certification runs on a three-year cycle with annual surveillance audits in years one and two and a full recertification audit in year three.

The most common cause is treating the ISMS as a one-time project rather than an ongoing operating system — risk assessments stop updating and evidence stops accumulating, surfacing as gaps at the next surveillance audit.

Talk to a CISO about your situation.

30 minutes. No obligation. No sales pitch.

Talk to a CISO