Skip to main content
RiskZeroCertifiers

Process

From package to certificate, and the three years after

Every accredited certification body follows the same sequence, defined by ISO/IEC 17021-1. What follows is exactly what happens with RiskZero, including the preparation step that belongs to SRG, what we need from you, and what you get from us at each point.

The cycle

  1. Before

    SRGBuild and attest

  2. Month 0

    Stage 1Readiness review

  3. Month 1 to 2

    Stage 2Certification audit

  4. Month 2 to 3

    DecisionCertificate issued

  5. Month 12

    Year 1Surveillance audit

  6. Month 24

    Year 2Surveillance audit

  7. Month 36

    Year 3Recertification

The dashed node is SRG's work. Every solid node is RiskZero's.

Step by step

What happens at each step

  1. 1

    Before

    Preparation and attestation

    Performed by SRG, not by RiskZero

    Before anything reaches us, your consultants, most often SRG, work with you to scope the ISMS, assess risks, write policies, implement and harden controls, and test them, including penetration testing. The package must also contain an internal audit performed by an auditor independent of the implementation work, and a management review; SRG arranges the internal auditor, who is never a member of the team that built the ISMS. When SRG is satisfied the package is complete, it attests that the package is ready and submits it through riskzero.us. RiskZero takes no part in this step, and nobody involved in it takes part in the audit.

    You
    Build the ISMS with SRG. Approve the package before it is submitted.
    RiskZero
    Nothing yet. Our involvement starts when the package arrives.
  2. 2

    Week 0

    Application and quote

    The submitted package gives us the scope you want certified, the number of people and sites, your main technologies, and any deadline. We calculate the audit time using IAF MD 5 and ISO/IEC 27006-1, identify an auditor with the right sector experience and no involvement in the package, and send a fixed-fee proposal covering the full three-year cycle.

    You
    Confirm the application details. Tell us about any deadline the certificate has to meet.
    RiskZero
    Fixed-fee proposal with audit durations, the named lead auditor, and available dates, within two business days.
  3. 3

    Week 1

    Contract and dates

    Once you accept the proposal we sign a certification agreement, which sets out both parties’ obligations including your right to appeal and our commitment to confidentiality. Stage 1 and Stage 2 dates are reserved in the same step.

    You
    Sign the agreement. Nominate the ISMS owner as our main contact.
    RiskZero
    Confirmed audit dates and a pre-audit information request.
  4. 4

    Weeks 2 to 4

    Stage 1: readiness review

    The auditor reviews the design of the ISMS and your readiness for Stage 2: scope, policy, risk assessment and treatment, the Statement of Applicability, and evidence that internal audit and management review have taken place. SRG’s attestation is read as an input, not a substitute: the auditor forms an independent view of the package. Stage 1 is usually one to two days and mostly remote. You receive a report of any areas of concern.

    You
    Make the ISMS owner and leadership available for short interviews. Answer questions about the package yourself.
    RiskZero
    Stage 1 report within five business days, with a recommendation on proceeding to Stage 2.
  5. 5

    Weeks 4 to 8

    Addressing Stage 1 concerns

    Most organizations have a few things to tidy up. This gap is yours to use, with or without help from your consultants. It is typically two to six weeks; accreditation rules cap it at six months, after which Stage 1 must be repeated.

    You
    Address the areas of concern. Tell us if you need to move the Stage 2 date.
    RiskZero
    Answer questions about the findings. Confirm the Stage 2 audit plan two weeks before the visit.
  6. 6

    Weeks 6 to 10

    Stage 2: certification audit

    The audit of whether the ISMS actually works. The auditor follows a plan that covers every clause and samples the Annex A controls in your Statement of Applicability, through interviews, records, and live evidence. Findings are discussed as they arise and presented at the closing meeting. Duration ranges from two days for a small organization to several weeks for a large multi-site one.

    You
    Make process owners available as scheduled. Provide evidence promptly. Be candid.
    RiskZero
    A closing meeting with every finding explained, and a written report within ten business days.
  7. 7

    Weeks 8 to 12

    Closing findings

    Minor nonconformities need a corrective action plan, which we review and accept before the decision. Major nonconformities must be corrected and the correction verified, either through documentary evidence or a short follow-up audit, within an agreed period. Opportunities for improvement need no action.

    You
    Submit root cause analysis and corrective action plans for each nonconformity.
    RiskZero
    Review and accept the plans, or explain what is missing, within five business days.
  8. 8

    Weeks 10 to 12

    Certification decision and certificate

    The complete audit file goes to a certification decision-maker who was not involved in the audit and had no part in preparing the package. They confirm the audit covered the scope, the evidence supports the conclusions, and all major nonconformities are closed. On a positive decision the certificate is issued the same day, along with the certification mark and usage rules.

    You
    Nothing. This step is deliberately out of your hands and ours as auditors.
    RiskZero
    Your certificate, mark artwork, and a schedule of surveillance dates.
  9. 9

    Months 12 and 24

    Surveillance audits

    Shorter annual audits that confirm the ISMS is maintained. They always cover internal audit, management review, incidents, complaints, changes, and progress on previous findings, and sample the Annex A controls so the full set is covered across the cycle. The first must take place within twelve months of the decision.

    You
    Keep the ISMS running. Tell us about changes to scope, sites, or headcount.
    RiskZero
    A confirmed date three months ahead, an audit plan two weeks ahead, and a report within ten business days.
  10. 10

    Month 33 to 36

    Recertification

    A full audit of the ISMS over the whole cycle, scheduled three to four months before expiry so there is time to close findings. A positive decision issues a new certificate for three years with no gap.

    You
    Confirm scope and headcount six months before expiry so the audit time can be checked.
    RiskZero
    A new certificate before the old one expires, and a refreshed surveillance plan for the next cycle.

Before Stage 1

What the package needs to contain

If you can tick every item, the package is ready to submit. If not, the gaps get closed with SRG before it reaches us.

  • A documented scope statement with sites, functions, and justified exclusions
  • An information security policy approved by top management
  • A risk assessment methodology, its results, and a risk treatment plan
  • A Statement of Applicability covering all 93 Annex A controls
  • Implemented controls with records to show they operate
  • At least one completed internal audit, by an auditor independent of the implementation work, with findings and follow-up
  • At least one management review with recorded decisions
  • Security objectives with some measurement against them

Findings

How findings are classified

Major nonconformity

A requirement of the standard is not met, or a control has failed in a way that undermines the ISMS. Must be corrected and verified before a certificate can be issued. At surveillance, may lead to suspension if not resolved in the agreed time.

Minor nonconformity

An isolated lapse that does not undermine the system. Requires a root cause analysis and corrective action plan, accepted before the decision and verified at the next audit.

Opportunity for improvement

An observation where the requirement is met but could be met better. No action is required. We record them because clients tell us they are the most useful part of the report.

Ready to scope your audit?

Tell us about your organization, your ISMS scope, and your target date. We reply with a fixed-fee quote and available audit dates within two business days.