Skip to main content
RiskZeroCertifiers

Independent certification body · ISO/IEC 27001:2022

ISO 27001 certification your customers can verify.

RiskZero is an independent certification body. We audit your information security management system against ISO/IEC 27001:2022 and issue a certificate that holds up in enterprise procurement, in tenders, and in front of your board.

Quote turnaround
2 business days
Stage 1 availability
Within 4 weeks
Certificate validity
3 years, verifiable

Built for the organizations that get asked for a certificate: the ones holding other people’s data, systems, or money.

The three-year cycle

What happens, and when

ISO 27001 certification is not a single audit. It is a three-year cycle with defined points where we check the ISMS is still working. Here is the whole thing on one line, starting with the package your consultancy prepares before it reaches us.

  1. Before

    ConsultancyBuild and attest

    Your consultancy helps you build the ISMS and attests that the package is ready. It is submitted through riskzero.us.

  2. Month 0

    Stage 1Readiness review

    We review the package: scope, risk assessment, Statement of Applicability, and evidence of internal audit and management review, and confirm you are ready for Stage 2.

  3. Month 1 to 2

    Stage 2Certification audit

    On-site or remote audit of how the ISMS actually operates: interviews, records, sampled controls, and evidence.

  4. Month 2 to 3

    DecisionCertificate issued

    An independent reviewer checks the audit file. Once any nonconformities are closed, your certificate is issued and can be verified with us directly.

  5. Month 12

    Year 1Surveillance audit

    A shorter audit confirming the ISMS is maintained, internal audits and management reviews have happened, and corrective actions are working.

  6. Month 24

    Year 2Surveillance audit

    Second annual check, usually covering the parts of the ISMS not sampled in year one.

  7. Month 36

    Year 3Recertification

    A full audit before the certificate expires. Pass it and a new three-year cycle begins with no gap in certification.

Why RiskZero

What makes a certificate worth having

A certificate is only as credible as the body that issued it. These are the things we do differently, and why they matter to the people who read your certificate.

  • Audit and certification only

    We do not build management systems, write policies, or run internal audits. Our only product is an audit opinion, and the certificate that follows it.

  • Auditors who have run an ISMS

    Our auditors come from security and engineering roles. They read infrastructure as code, understand shared responsibility, and know what a real incident log looks like.

  • Fixed fees for the whole cycle

    One proposal covers Stage 1, Stage 2, both surveillance audits, and the decision. Rates are fixed for three years and the working is shown.

  • Findings you can act on

    Every finding names the clause or control, the evidence examined, and why it matters. Reports are written for your board as well as your auditor.

  • Certificates anyone can verify

    Any customer, auditor, or tender evaluator can ask us to confirm the scope, status, and expiry of a certificate we issued. We answer within one business day.

  • Dates when you need them

    Stage 1 dates are usually available within four weeks. We plan backwards from your customer deadline, not forwards from our calendar.

Questions

The questions we get asked first

Straight answers on timing, cost, who does what, and what we will and will not do.

All frequently asked questions
How long does ISO 27001 certification take?
If your ISMS is ready for audit, the certification itself typically takes eight to twelve weeks from contract to certificate: Stage 1, a short gap to fix anything it raises, Stage 2, then an independent certification decision. Building the ISMS before that usually takes three to nine months depending on your starting point.
What does ISO 27001 certification cost?
Audit fees are driven by the number of people and sites in scope and the complexity of your operations, following the IAF MD 5 audit-time rules that all accredited certification bodies must apply. We quote a fixed fee for the full three-year cycle so there are no surprises at surveillance time. See our pricing page for the factors that determine audit time.
What is riskzero.us?
riskzero.us is the platform on which packages are prepared, attested, and submitted, and through which our auditors examine them. Your consultancy works with you there, and our audit team receives the package there.
Can RiskZero help us implement ISO 27001 and then certify us?
No. We audit and certify. Implementation is your consultancy’s work, and its readiness attestation is one input to our Stage 1. Our auditors form their own view of every package.
Do you audit remotely?
Yes. Remote audits are appropriate for most cloud-first organizations and are conducted using video, screen sharing, and secure evidence exchange. Physical sites such as data centers or offices with physical security controls in scope will normally need at least one on-site visit during the cycle.

Guides and articles

Written by auditors, for the people preparing for one

All resources

Ready to scope your audit?

Tell us about your organization, your ISMS scope, and your target date. We reply with a fixed-fee quote and available audit dates within two business days.