Guide

The ISO 27001 Certification Process: A Step-by-Step Roadmap

The stages of ISO 27001 certification, from building your ISMS through the Stage 1 and Stage 2 audits and the three-year surveillance cycle.

8 min read

ISO 27001 certification is not a single event; it is the end of a process and the start of a cycle. You build a management system, an accredited body audits it in two stages, and then you keep it certified through annual surveillance audits and a recertification every three years. Here is the roadmap.

Before the Audit: Build the ISMS

Certification tests a management system, so you have to have one first. That means:

  • Define the scope: which parts of the organization and which information the ISMS covers.
  • Run a risk assessment: identify your information security risks and decide how to treat each one.
  • Select controls and write the Statement of Applicability (SoA): the document that lists which Annex A controls you apply, which you exclude, and why. The SoA is central to ISO 27001; the auditor will keep coming back to it.
  • Operate the ISMS: run the controls, hold management reviews, and complete at least one internal audit before the external one.

Stage 1: Documentation Review

The first external audit is a readiness check. The auditor reviews your ISMS documentation, your scope, and your Statement of Applicability to confirm you are ready for the real thing. Gaps found here are yours to close before Stage 2.

Stage 2: The Certification Audit

The second audit tests whether your ISMS actually operates as documented. The auditor samples evidence, interviews people, and checks that controls run in practice. Clear it, and the certification body issues your ISO 27001 certificate.

After Certification: Surveillance and Recertification

The certificate is valid for three years, but it is not set and forget:

  • Surveillance audits happen roughly annually, checking that the ISMS is still running and improving.
  • Recertification at the end of the three-year cycle repeats a fuller audit to renew the certificate.

This is why ISO 27001 rewards a live program over a one-time push: a control that quietly stops running will surface at the next surveillance audit.

How Concord Fits

Concord Trust's control library and coverage view give you one place to build and maintain the controls behind your ISMS, and scoped auditor access lets your certification body review evidence directly rather than through email. The point-in-time scramble becomes a program you keep current between audits.

Get Started

Turn Security Reviews into a Link You Send

Concord Trust turns your controls, frameworks, and scoped auditor access into a public trust center that answers security reviews and closes deals. Start free, then add a framework when you are ready.