Jump to a page

32 pages.

All servicesAssessments, testing, and advisory work for security and compliance programs.
PCI DSS readinessScoping, readiness, and remediation for card-payment environments
Penetration testingAuthorized testing of apps, APIs, and networks
Compliance readinessSOC 2, ISO/IEC 27001, HIPAA, and CMMC readiness
Cloud & application securityArchitecture, configuration, and identity reviews
vCISO advisorySecurity leadership without a full-time hire
Incident readinessResponse plans and tabletop exercises
Risk assessmentsWhere you stand against NIST CSF 2.0 and CIS Controls
Policies, controls & evidenceA security program you can repeat and prove
Vendor riskThird-party reviews with clear priorities
Find the right service
SOC 2 readiness
ISO/IEC 27001 readiness
HIPAA Security Rule readiness
CMMC readiness
Assurance and trust centerHow to check credentials, how engagements run, how we stay independent, and how this website handles your data.
Credentials & authorizationsHow credentials and authorizations work, and how to check them
MethodologyHow engagements are scoped, run, and reported
IndependenceHow advisory work stays separate from formal assessment
Responsible disclosureHow to report a security issue in our website or systems
About
Team
Industries
Pricing
Contact
InsightsPlain-language articles on security and compliance topics
GlossarySecurity and compliance terms, defined in plain language
Search the siteServices, readiness guides, glossary terms, and articles
Privacy notice
Terms of use
Accessibility
Privacy choices

Compliance readiness

ISO/IEC 27001 readiness: prepare for accredited certification

Design and tune an information security management system (ISMS) that's ready for a certification audit by an independent, accredited certification body.

Version as of

ISO/IEC 27001:2022, including Amendment 1:2024

Published October 25, 2022; Amendment 1 published February 23, 2024

As of 2026-09-26 this is the only edition used for accredited certification. Every certificate based on ISO/IEC 27001:2013 expired or was withdrawn at the end of October 31, 2025. Amendment 1 adds a climate-change consideration to clauses 4.1 and 4.2.

Check the official ISO/IEC 27001 source (external site)

What is ISO/IEC 27001?

ISO/IEC 27001 is an international standard that sets requirements for establishing, implementing, maintaining, and continually improving an information security management system (ISMS).

The 2022 edition's Annex A references 93 controls drawn from ISO/IEC 27002:2022, down from 114 in the 2013 edition. It also added a clause on planning for changes.

ISO doesn't certify anyone. Certificates come from certification bodies. Accreditation is voluntary, but accredited certification means the certification body is accredited to ISO/IEC 17021-1 and ISO/IEC 27006-1 by an accreditation body that belongs to the Global ACI MRA (formerly the IAF MLA). Accredited certificates can be checked in IAF CertSearch.

Type
Framework or voluntary standard
Current version, as of
ISO/IEC 27001:2022, including Amendment 1:2024. Published October 25, 2022; Amendment 1 published February 23, 2024. Version source for ISO/IEC 27001 (external site)

Who needs ISO/IEC 27001?

  • Organizations whose customers or prospects ask for an ISO/IEC 27001 certificate
  • Organizations whose certificate was based on the 2013 edition and now need to certify to the 2022 edition
  • Companies that want a structured, risk-based management system for security rather than a one-off checklist
  • Organizations that want an independent, accredited body to confirm their ISMS meets the standard

From ISMS to certificate: the audit cycle in brief

ISO/IEC 27001 certification follows the process rules in ISO/IEC 17021-1:2015, which accredited certification bodies must meet. The initial certification audit has two stages. Stage 1 reviews your management system documentation, evaluates your readiness for stage 2, and gathers what the certification body needs to plan it. Stage 2 evaluates the implementation, including the effectiveness, of your ISMS.

A certification cycle runs three years from the certification decision. Surveillance audits take place in the first and second years, and a recertification audit in the third year, before the certificate expires. Surveillance audits happen at least once a calendar year except in recertification years, and the first one comes no more than 12 months after the certification decision (clause 9.1.3).

European Accreditation's FAQ on that clause states that every calendar year needs at least one audit, whether surveillance or recertification. The certification body plans and performs all of these audits; your part is to keep the ISMS running and producing records between them.

Sources: IAS: ISO/IEC 17021-1:2015 section 9, process requirements (training summary); European Accreditation FAQ 37.12: ISO/IEC 17021-1 clause 9.1.3

Annex A in ISO/IEC 27001:2022

Annex A of ISO/IEC 27001:2022 is a reference list of information security controls drawn from ISO/IEC 27002:2022. It has 93 controls in four groups, down from 114 controls in 14 groups in the previous edition. The four groups, or themes, are organizational, people, physical, and technological controls.

IAF's transition document for the 2022 edition notes that 11 controls are new, 24 were merged from existing controls, and 58 were updated, and that each control now carries attributes and a purpose instead of sitting under a control objective.

Annex A isn't a checklist to adopt wholesale. The standard asks you to determine the controls your risk treatment needs, from any source, then compare them with Annex A to check that nothing necessary has been left out (clause 6.1.3). The standard also notes that Annex A isn't exhaustive, so you can add controls it doesn't list.

The result of that comparison is recorded in the Statement of Applicability, described in the next section.

Sources: IAF MD 26: transition requirements for ISO/IEC 27001:2022; ISO/IEC 27001:2022, clauses 4.3 and 6.1.3 (publisher-authorized preview); ISO/IEC 27002:2022 table of contents, as adopted by SIST (publisher-authorized preview)

Statement of Applicability and ISMS scope

Two documents anchor an ISO/IEC 27001 certification: the ISMS scope and the Statement of Applicability.

The scope (clause 4.3) sets the boundaries and applicability of your ISMS. When you determine it, the standard asks you to consider the internal and external issues that affect the organization, the requirements of interested parties, and the interfaces and dependencies between your activities and those performed by other organizations. The scope must be available as documented information, and a certificate applies only to what it covers.

The Statement of Applicability (clause 6.1.3 d)) lists the necessary controls and why each is included, whether each is implemented, and the justification for excluding any Annex A control. It ties your risk treatment decisions to your controls. Risk owners then approve the risk treatment plan and accept the residual information security risks (clause 6.1.3 f)).

Source: ISO/IEC 27001:2022, clauses 4.3 and 6.1.3 (publisher-authorized preview)

When customers ask for SOC 2 instead

Both answer a customer's question about how you manage security, but they produce different things, issued by different kinds of organization. Ask your customers and prospects which one they expect before you choose; nothing stops an organization from pursuing both, and a single control set can support each.

ISO/IEC 27001 certification and SOC 2 reports compared
QuestionISO/IEC 27001SOC 2
What you receiveA certificate that your ISMS conforms to the standardAn attestation report with a CPA firm's opinion, your system description and, for Type 2, test results
Who issues itA certification body; for accredited certification, one accredited to ISO/IEC 17021-1 and ISO/IEC 27006-1A licensed CPA firm acting as service auditor
What it measures againstThe requirements of ISO/IEC 27001:2022, with Annex A as the control referenceThe AICPA Trust Services Criteria for the categories in scope
How it stays currentSurveillance audits in years one and two of a three-year cycle, then recertificationEach report covers only its date (Type 1) or period (Type 2)

Sources: ISO: ISO/IEC 27001:2022; AICPA: 2018 SOC 2 Description Criteria (With Revised Implementation Guidance – 2022); IAS: ISO/IEC 17021-1:2015 section 9, process requirements (training summary)

Formal assessment: who performs it, and on whose authority

Readiness work prepares you. The formal outcome below comes only from the organization the program authorizes.

Formal outcome
An ISO/IEC 27001 certificate for your ISMS, issued after the certification body's stage 1 and stage 2 audits
Who performs it
An independent certification body. For accredited certification, the body is accredited to ISO/IEC 17021-1:2015 and ISO/IEC 27006-1:2024 by an accreditation body in the Global ACI MRA; in the U.S., ANAB is one example. Accredited certification bodies may not provide management system consultancy.

Outside our services

Security Inspect is not a law firm, a CPA firm, or an ISO/IEC 27001 certification body. We don't give legal opinions, issue SOC 2 reports or ISO/IEC 27001 certificates, or guarantee that a client will pass an assessment.

What we do and don’t do

ISO/IEC 27001 readiness — preparation for certification by an independent accredited certification body.

What we do

  • Gap assessment against ISO/IEC 27001:2022, including Amendment 1:2024, and its Annex A controls
  • ISMS design support: scope, risk assessment and treatment method, and a draft Statement of Applicability
  • Policy and procedure recommendations that your team adopts and owns
  • Preparation for your clause 9.2 internal audit
  • Neutral guidance on finding an accredited certification body and checking a certificate in IAF CertSearch

What we don’t do

  • Perform certification audits or issue ISO/IEC 27001 certificates
  • Partner or market jointly with a certification body, or suggest that working with us makes certification faster, easier, or cheaper
  • Hold any accreditation, or use ISO, accreditation-body, or Global ACI marks
  • Make your risk decisions or own your ISMS; your management does
  • Promise a certification outcome or date

Independence

ISO/IEC 17021-1 bars an accredited certification body, its legal entity, and any entity it controls from providing management system consultancy at all (5.2.5). If a body related to the certification body consulted for you, the recognized mitigation is that the certification body waits at least two years after the consultancy ends before certifying you (5.2.7), and people who consulted for you stay off your audits for two years (5.2.10). ISO/IEC 27006-1:2024 also requires the certification body to be independent of whoever performs your internal ISMS audit (5.2.2).

When a program requires a formal assessment, audit, or certification, it's performed by an independent, authorized assessor. We keep advisory work and formal assessment apart: a practitioner never assesses controls they designed, developed, or implemented.

How advisory work and formal assessment stay separate

How readiness works

Every engagement begins with a written scope and proposal.

  1. Define scope

    Agree the ISMS scope: the parts of the organization, locations, systems, and interested parties it covers.

  2. Assess gaps

    Compare your current practices with the standard's requirements and Annex A, including the climate-change consideration Amendment 1 added to clauses 4.1 and 4.2.

  3. Build the ISMS

    Set up the risk assessment and treatment method, the Statement of Applicability, and the policies your team will run. You make the decisions and own the system.

  4. Operate and check

    Run the ISMS long enough to produce records, then prepare for your clause 9.2 internal audit.

  5. Engage a certification body

    You choose and engage an accredited certification body directly. It plans and performs its own stage 1 and stage 2 audits.

Deliverables

  • Gap assessment report against ISO/IEC 27001:2022 and Annex A
  • Draft ISMS scope statement and risk assessment method for your approval
  • Draft Statement of Applicability
  • Prioritized implementation roadmap
  • Internal audit preparation checklist

What ISO/IEC 27001 readiness costs

  • ISO/IEC 27001 Readiness

    From $15,000

    Typical scoped range: $15,000 to $35,000

    One-time project

Non-binding. Final pricing follows a written scope and proposal.

What affects the final price

Pricing depends on environment size, complexity, testing depth, locations, applications, accounts, user roles, compliance objectives, and delivery timeline. Every engagement begins with a written scope and proposal. Taxes, travel, remediation, third-party audit or certification fees, licensing, and emergency work are separate. Readiness services do not include independent certification, attestation, legal advice, or a guarantee of passing.

Compare published prices for every service

Guides

Frequently asked questions

Who issues ISO/IEC 27001 certificates?

Certification bodies do, not ISO and not consultants. ISO states that it doesn't perform certification or issue certificates. For an accredited certificate, choose a certification body accredited for ISO/IEC 27001 by an accreditation body in the Global ACI MRA (formerly the IAF MLA). Accredited certification bodies may not provide consultancy, which is why readiness help and certification come from different organizations.

Is a certificate to the 2013 edition still valid?

No. Under the accreditation transition rules in IAF MD 26, every certificate based on ISO/IEC 27001:2013 expired or was withdrawn at the end of October 31, 2025. Organizations now certify to ISO/IEC 27001:2022, which includes Amendment 1:2024. If your certificate lapsed, ask your certification body how it will handle your next audit.

What did Amendment 1:2024 change?

It added one requirement and one note about climate change. Clause 4.1 now says the organization shall determine whether climate change is a relevant issue, and a note in clause 4.2 says relevant interested parties can have requirements related to climate change. ISO and the IAF describe the overall intent of clauses 4.1 and 4.2 as unchanged.

How can we check that a certificate is accredited?

Search IAF CertSearch by company name or certificate number. It contains only accredited management system certifications and shows the issuing certification body and its accreditation body. You can also confirm the certification body's accreditation and scope with its accreditation body. IAF CertSearch doesn't cover certificates held by individuals, such as lead auditor credentials.

Can a consultant who helped us later audit us for a certification body?

ISO/IEC 17021-1 (5.2.10) says people who provided management system consultancy to a client shouldn't take part in that client's audits or certification activities, with two years after the consultancy ends as the recognized mitigation. The certification body also can't outsource audits to a consultancy organization (5.2.8).

Educational information, not legal advice

Information on this website is general and educational. It isn't legal advice, and it doesn't create a client relationship.

Primary sources

Talk to a practitioner about ISO/IEC 27001 readiness

Tell us what’s driving the work and who’s asking for it, and we’ll help you judge where you stand and whether readiness support makes sense.

What happens next

  1. Tell us about your environment and the formal outcome you're working toward.
  2. Talk through scope, timing, and options with a practitioner.
  3. Review the proposal and decide whether to go ahead.