Skip to main content
RiskZeroCertifiers

FAQ

Frequently asked questions

Everything we get asked about ISO 27001 certification, answered plainly. If your question is not here, ask us directly.

Getting started

What is ISO/IEC 27001?
ISO/IEC 27001 is the international standard for information security management systems (ISMS). It sets out requirements for how an organization identifies information security risks and manages them through policies, processes, people, and technical controls. Certification means an independent body has audited your ISMS and confirmed it conforms to the standard. Read our plain-English guide.
Who needs ISO 27001 certification?
Any organization that handles information other people care about. In practice, the demand comes from customers: enterprise procurement teams, public-sector buyers, and regulated companies increasingly require suppliers to hold ISO 27001. It is common in SaaS, fintech, healthcare technology, managed services, legal, and outsourcing.
Who are SRG and riskzero.us, and how are they related to RiskZero?
SRG is the consultancy that helps organizations build their ISMS and attests that the package is ready; it is the intermediary between the client and us. riskzero.us is the platform on which the package is prepared, attested, submitted, and audited. RiskZero Certifiers is a separate company with its own auditors, reviewers, and signatories. We work with both, we disclose it, and nobody who prepares a package takes part in auditing it or in the certification decision. See our impartiality statement.
Do we have to use SRG to be certified by RiskZero?
No. We accept packages prepared by any consultancy, or built in-house, on the same terms. Most of the packages we certify are prepared and attested by SRG and submitted through riskzero.us, because that is what the platform is built around, but the audit is the same whoever prepared the package, and we never state or imply that certification is easier because a particular consultancy was used.
How ready do we need to be before the package is submitted?
To pass Stage 2 you will need a working ISMS: a defined scope, risk assessment and treatment, a Statement of Applicability, implemented controls with evidence, at least one internal audit by an auditor independent of the people who built the ISMS, and at least one management review. SRG’s attestation is its statement that the package meets that bar; our Stage 1 checks it independently, including who performed the internal audit.
How long does ISO 27001 certification take?
If your ISMS is ready for audit, the certification itself typically takes eight to twelve weeks from contract to certificate: Stage 1, a short gap to fix anything it raises, Stage 2, then an independent certification decision. Building the ISMS before that usually takes three to nine months depending on your starting point.
Which version of the standard will we be certified to?
ISO/IEC 27001:2022. The 2013 version was withdrawn and all certificates had to transition by 31 October 2025, so every new certificate is issued against the 2022 edition with its 93 Annex A controls.

The audit

What is the difference between Stage 1 and Stage 2?
Stage 1 is a readiness review of your ISMS design: scope, policies, risk assessment, Statement of Applicability, and whether internal audit and management review have taken place. Stage 2 audits whether the ISMS actually operates as described, through interviews, records, and sampled evidence across the Annex A controls you have applied. Certification is only granted after Stage 2.
Does SRG’s attestation shorten the audit?
No. Accreditation rules require the certification body to perform Stage 1 and Stage 2 in full and to reach its own conclusions. The attestation is read as one input at Stage 1, alongside everything else in the package. What a well-prepared package does change is how smoothly the audit runs, because the evidence is where the auditor expects it.
What happens if the auditor finds nonconformities?
A minor nonconformity needs a corrective action plan, which we review before the certification decision. A major nonconformity must be corrected and the correction verified, sometimes with a short follow-up audit, before a certificate can be issued. Findings are explained in plain language with the clause or control they relate to.
Do you audit remotely?
Yes. Remote audits are appropriate for most cloud-first organizations and are conducted using video, screen sharing, and secure evidence exchange. Physical sites such as data centers or offices with physical security controls in scope will normally need at least one on-site visit during the cycle.
How much of our team’s time will the audit take?
Plan for the ISMS owner to be available throughout, plus one to two hours each from process owners the auditor needs to interview, such as engineering, HR, IT operations, and leadership. We send an audit plan in advance so people know when they are needed. Your consultants may sit in, but the answers have to come from your people.
Who makes the certification decision?
Not the auditor, and not anyone who prepared the package. Accreditation rules require an independent review of the audit file by someone who was not part of the audit team. That reviewer confirms the audit was complete and the evidence supports the recommendation before a certificate is issued.

Cost and commercial

What does ISO 27001 certification cost?
Audit fees are driven by the number of people and sites in scope and the complexity of your operations, following the IAF MD 5 audit-time rules that all accredited certification bodies must apply. We quote a fixed fee for the full three-year cycle so there are no surprises at surveillance time. See our pricing page for the factors that determine audit time.
Is the price for one audit or the whole cycle?
Our quotes cover the full three-year cycle: Stage 1, Stage 2, two surveillance audits, and the certification decision, with the recertification audit priced separately at the same rates. Changes to scope, headcount, or sites can change the audit time required, and we tell you in advance if that happens. SRG’s fees for building the ISMS are SRG’s, and are not part of our quote.

After certification

How long is the certificate valid?
Three years, subject to passing annual surveillance audits. Recertification before the expiry date starts a new three-year cycle.
Can we use the RiskZero mark on our website?
Yes. Certified clients receive the certification mark and usage guidelines. The mark can be used on websites, proposals, and stationery in connection with the certified scope, but not on products or in a way that implies the product itself is certified.
How can our customers verify our certificate?
Anyone can confirm the scope, status, and expiry date of a certificate we issued by sending us the organization name or certificate number. We answer within one business day. See verify a certificate for the details.
What if we disagree with a finding or a decision?
You can appeal any certification decision and complain about any aspect of our service. Both are handled by people independent of the original audit. The process is described on our complaints and appeals page.

Still have a question?

Send us a message. A person who has actually run an audit will answer.