What initial certification involves
Initial certification is a two-stage audit followed by an independent decision. Every accredited certification body follows the same structure, defined in ISO/IEC 17021-1 and ISO/IEC 27006-1. What differs is the quality of the auditors, the clarity of the reporting, and how much friction the certification body adds along the way.
Application and contract
You tell us about your organization: the scope you want certified, the number of people and locations, your main technologies, and any target date. We calculate the audit time required using the IAF MD 5 rules, confirm the audit team, and send a fixed-fee proposal for the full three-year cycle. Once signed, we reserve your Stage 1 and Stage 2 dates.
Stage 1: readiness review
Stage 1 checks that your information security management system is designed correctly and that you are ready for Stage 2. The auditor reviews:
- The ISMS scope statement and boundaries, including interfaces with suppliers and group companies
- Your information security policy and supporting policies
- The risk assessment methodology, its results, and the risk treatment plan
- The Statement of Applicability and the justification for excluded controls
- Evidence that internal audit and management review have been performed
- Site-specific conditions and the logistics for Stage 2
Stage 1 usually takes one to two days, most of which can be done remotely. You receive a report listing any areas of concern that could become nonconformities at Stage 2, so you can fix them first.
Stage 2: certification audit
Stage 2 tests whether the ISMS actually works. The auditor interviews people across the scope, examines records, and samples evidence for the Annex A controls in your Statement of Applicability. Typical areas include:
- Leadership commitment, objectives, and how performance is measured
- Access control, joiner-mover-leaver processes, and privileged access
- Change management, secure development, and vulnerability handling
- Supplier security and cloud service agreements
- Logging, monitoring, and incident response, including evidence of real incidents being handled
- Business continuity and backup testing
- Awareness training and human resources security
- Physical security for any sites in scope
Findings are raised and discussed as the audit progresses. There are no surprises at the closing meeting.
Certification decision
After Stage 2, the audit file is reviewed by a certification decision-maker who was not part of the audit team. They confirm the audit covered the full scope, that the evidence supports the findings, and that any major nonconformities have been closed. When the decision is positive, your certificate is issued the same day.
What you receive
Your certificate states the certified scope, the version of the Statement of Applicability it relates to, the sites covered, and the issue and expiry dates. You also receive the full audit report, the certification mark artwork, and a schedule for your surveillance audits.
Timeline
For an audit-ready ISMS, expect eight to twelve weeks from signing to certificate. The main variables are your availability for audit dates, the time you need between Stage 1 and Stage 2, and how quickly any nonconformities are closed.