Skip to main content
RiskZeroCertifiers

Months 0 to 3

ISO 27001 certification

Initial certification of your ISMS against ISO/IEC 27001:2022: Stage 1, Stage 2, and an independent certification decision.

Typical duration

Typically 8 to 12 weeks from contract to certificate for an audit-ready ISMS

Request a quote

Fixed fee, reply within two business days.

What initial certification involves

Initial certification is a two-stage audit followed by an independent decision. Every accredited certification body follows the same structure, defined in ISO/IEC 17021-1 and ISO/IEC 27006-1. What differs is the quality of the auditors, the clarity of the reporting, and how much friction the certification body adds along the way.

Application and contract

You tell us about your organization: the scope you want certified, the number of people and locations, your main technologies, and any target date. We calculate the audit time required using the IAF MD 5 rules, confirm the audit team, and send a fixed-fee proposal for the full three-year cycle. Once signed, we reserve your Stage 1 and Stage 2 dates.

Stage 1: readiness review

Stage 1 checks that your information security management system is designed correctly and that you are ready for Stage 2. The auditor reviews:

  • The ISMS scope statement and boundaries, including interfaces with suppliers and group companies
  • Your information security policy and supporting policies
  • The risk assessment methodology, its results, and the risk treatment plan
  • The Statement of Applicability and the justification for excluded controls
  • Evidence that internal audit and management review have been performed
  • Site-specific conditions and the logistics for Stage 2

Stage 1 usually takes one to two days, most of which can be done remotely. You receive a report listing any areas of concern that could become nonconformities at Stage 2, so you can fix them first.

Stage 2: certification audit

Stage 2 tests whether the ISMS actually works. The auditor interviews people across the scope, examines records, and samples evidence for the Annex A controls in your Statement of Applicability. Typical areas include:

  • Leadership commitment, objectives, and how performance is measured
  • Access control, joiner-mover-leaver processes, and privileged access
  • Change management, secure development, and vulnerability handling
  • Supplier security and cloud service agreements
  • Logging, monitoring, and incident response, including evidence of real incidents being handled
  • Business continuity and backup testing
  • Awareness training and human resources security
  • Physical security for any sites in scope

Findings are raised and discussed as the audit progresses. There are no surprises at the closing meeting.

Certification decision

After Stage 2, the audit file is reviewed by a certification decision-maker who was not part of the audit team. They confirm the audit covered the full scope, that the evidence supports the findings, and that any major nonconformities have been closed. When the decision is positive, your certificate is issued the same day.

What you receive

Your certificate states the certified scope, the version of the Statement of Applicability it relates to, the sites covered, and the issue and expiry dates. You also receive the full audit report, the certification mark artwork, and a schedule for your surveillance audits.

Timeline

For an audit-ready ISMS, expect eight to twelve weeks from signing to certificate. The main variables are your availability for audit dates, the time you need between Stage 1 and Stage 2, and how quickly any nonconformities are closed.

Questions

Common questions about iso 27001 certification

How ready do we need to be before booking Stage 1?
Book as soon as you have a target date. Before Stage 1 takes place you need a defined scope, an approved set of ISMS documents, a completed risk assessment and treatment plan, a Statement of Applicability, and evidence that at least one internal audit and one management review have taken place.
How long is the gap between Stage 1 and Stage 2?
Usually two to six weeks. Stage 1 may raise areas of concern that you should address before Stage 2. Accreditation rules also limit the gap to six months, after which Stage 1 must be repeated.
What if we fail Stage 2?
Organizations rarely fail outright. Most Stage 2 audits raise a handful of minor nonconformities and occasionally a major one. Minors are closed with a corrective action plan; majors need the correction verified before a certificate is issued, which can add two to eight weeks.

Ready to scope your audit?

Tell us about your organization, your ISMS scope, and your target date. We reply with a fixed-fee quote and available audit dates within two business days.