Process
From package to certificate, and the three years after
Every accredited certification body follows the same sequence, defined by ISO/IEC 17021-1. What follows is exactly what happens with RiskZero, including the preparation step that belongs to SRG, what we need from you, and what you get from us at each point.
The cycle
Before
SRGBuild and attest
Month 0
Stage 1Readiness review
Month 1 to 2
Stage 2Certification audit
Month 2 to 3
DecisionCertificate issued
Month 12
Year 1Surveillance audit
Month 24
Year 2Surveillance audit
Month 36
Year 3Recertification
The dashed node is SRG's work. Every solid node is RiskZero's.
Step by step
What happens at each step
1
Before
Preparation and attestation
Performed by SRG, not by RiskZero
Before anything reaches us, your consultants, most often SRG, work with you to scope the ISMS, assess risks, write policies, implement and harden controls, and test them, including penetration testing. The package must also contain an internal audit performed by an auditor independent of the implementation work, and a management review; SRG arranges the internal auditor, who is never a member of the team that built the ISMS. When SRG is satisfied the package is complete, it attests that the package is ready and submits it through riskzero.us. RiskZero takes no part in this step, and nobody involved in it takes part in the audit.
- You
- Build the ISMS with SRG. Approve the package before it is submitted.
- RiskZero
- Nothing yet. Our involvement starts when the package arrives.
2
Week 0
Application and quote
The submitted package gives us the scope you want certified, the number of people and sites, your main technologies, and any deadline. We calculate the audit time using IAF MD 5 and ISO/IEC 27006-1, identify an auditor with the right sector experience and no involvement in the package, and send a fixed-fee proposal covering the full three-year cycle.
- You
- Confirm the application details. Tell us about any deadline the certificate has to meet.
- RiskZero
- Fixed-fee proposal with audit durations, the named lead auditor, and available dates, within two business days.
3
Week 1
Contract and dates
Once you accept the proposal we sign a certification agreement, which sets out both parties’ obligations including your right to appeal and our commitment to confidentiality. Stage 1 and Stage 2 dates are reserved in the same step.
- You
- Sign the agreement. Nominate the ISMS owner as our main contact.
- RiskZero
- Confirmed audit dates and a pre-audit information request.
4
Weeks 2 to 4
Stage 1: readiness review
The auditor reviews the design of the ISMS and your readiness for Stage 2: scope, policy, risk assessment and treatment, the Statement of Applicability, and evidence that internal audit and management review have taken place. SRG’s attestation is read as an input, not a substitute: the auditor forms an independent view of the package. Stage 1 is usually one to two days and mostly remote. You receive a report of any areas of concern.
- You
- Make the ISMS owner and leadership available for short interviews. Answer questions about the package yourself.
- RiskZero
- Stage 1 report within five business days, with a recommendation on proceeding to Stage 2.
5
Weeks 4 to 8
Addressing Stage 1 concerns
Most organizations have a few things to tidy up. This gap is yours to use, with or without help from your consultants. It is typically two to six weeks; accreditation rules cap it at six months, after which Stage 1 must be repeated.
- You
- Address the areas of concern. Tell us if you need to move the Stage 2 date.
- RiskZero
- Answer questions about the findings. Confirm the Stage 2 audit plan two weeks before the visit.
6
Weeks 6 to 10
Stage 2: certification audit
The audit of whether the ISMS actually works. The auditor follows a plan that covers every clause and samples the Annex A controls in your Statement of Applicability, through interviews, records, and live evidence. Findings are discussed as they arise and presented at the closing meeting. Duration ranges from two days for a small organization to several weeks for a large multi-site one.
- You
- Make process owners available as scheduled. Provide evidence promptly. Be candid.
- RiskZero
- A closing meeting with every finding explained, and a written report within ten business days.
7
Weeks 8 to 12
Closing findings
Minor nonconformities need a corrective action plan, which we review and accept before the decision. Major nonconformities must be corrected and the correction verified, either through documentary evidence or a short follow-up audit, within an agreed period. Opportunities for improvement need no action.
- You
- Submit root cause analysis and corrective action plans for each nonconformity.
- RiskZero
- Review and accept the plans, or explain what is missing, within five business days.
8
Weeks 10 to 12
Certification decision and certificate
The complete audit file goes to a certification decision-maker who was not involved in the audit and had no part in preparing the package. They confirm the audit covered the scope, the evidence supports the conclusions, and all major nonconformities are closed. On a positive decision the certificate is issued the same day, along with the certification mark and usage rules.
- You
- Nothing. This step is deliberately out of your hands and ours as auditors.
- RiskZero
- Your certificate, mark artwork, and a schedule of surveillance dates.
9
Months 12 and 24
Surveillance audits
Shorter annual audits that confirm the ISMS is maintained. They always cover internal audit, management review, incidents, complaints, changes, and progress on previous findings, and sample the Annex A controls so the full set is covered across the cycle. The first must take place within twelve months of the decision.
- You
- Keep the ISMS running. Tell us about changes to scope, sites, or headcount.
- RiskZero
- A confirmed date three months ahead, an audit plan two weeks ahead, and a report within ten business days.
10
Month 33 to 36
Recertification
A full audit of the ISMS over the whole cycle, scheduled three to four months before expiry so there is time to close findings. A positive decision issues a new certificate for three years with no gap.
- You
- Confirm scope and headcount six months before expiry so the audit time can be checked.
- RiskZero
- A new certificate before the old one expires, and a refreshed surveillance plan for the next cycle.
Before Stage 1
What the package needs to contain
If you can tick every item, the package is ready to submit. If not, the gaps get closed with SRG before it reaches us.
- A documented scope statement with sites, functions, and justified exclusions
- An information security policy approved by top management
- A risk assessment methodology, its results, and a risk treatment plan
- A Statement of Applicability covering all 93 Annex A controls
- Implemented controls with records to show they operate
- At least one completed internal audit, by an auditor independent of the implementation work, with findings and follow-up
- At least one management review with recorded decisions
- Security objectives with some measurement against them
Findings
How findings are classified
Major nonconformity
A requirement of the standard is not met, or a control has failed in a way that undermines the ISMS. Must be corrected and verified before a certificate can be issued. At surveillance, may lead to suspension if not resolved in the agreed time.
Minor nonconformity
An isolated lapse that does not undermine the system. Requires a root cause analysis and corrective action plan, accepted before the decision and verified at the next audit.
Opportunity for improvement
An observation where the requirement is met but could be met better. No action is required. We record them because clients tell us they are the most useful part of the report.
Ready to scope your audit?
Tell us about your organization, your ISMS scope, and your target date. We reply with a fixed-fee quote and available audit dates within two business days.