Who does what in the ISO 27001 certification process
ISO and IEC publish ISO/IEC 27001, but ISO states that it does not perform certification or issue certificates. Certification is done by external certification bodies, which audit your ISMS against the standard and issue the certificate.
Accreditation is the check on the checkers. An accreditation body assesses whether a certification body works to the relevant international standards; for ISMS certification those are ISO/IEC 17021-1 and ISO/IEC 27006-1, which adds requirements specific to information security. ISO notes that accreditation isn't compulsory. Its certification page also says Global ACI has assumed the former roles of the International Accreditation Forum (IAF) and ILAC; accreditation bodies that sign the Global ACI mutual recognition arrangement recognize each other's accreditation programs.
IAF CertSearch describes itself as the global database for accredited management system certifications, so it is the natural place to confirm a certificate. The table sets out the four roles.
| Role | What they do | Independence point |
|---|---|---|
| Your organization | Defines the ISMS scope, runs risk assessment and treatment, operates the controls, runs internal audits and management reviews, and fixes nonconformities | Can't certify itself |
| Certification body | Plans and performs the audits, makes the certification decision, issues the certificate, and runs surveillance and recertification | May not offer or provide management system consultancy (ISO/IEC 17021-1, 5.2.5) |
| Accreditation body | Assesses certification bodies against ISO/IEC 17021-1 and ISO/IEC 27006-1 | Doesn't audit your ISMS; it oversees the certification body |
| Advisers you hire | Help you build and prepare the ISMS, if you choose to use them | Can't be the certification body or be controlled by it; a related body is a significant threat to impartiality (5.2.7) |
Before the audit: build and run the ISMS
If you're working out how to get ISO 27001 certified, the work starts long before any auditor arrives. A certification body audits a management system that is already operating, so the work below needs to be in place and producing records first.
Set the scope
Clause 4.3 asks you to determine the boundaries and applicability of the ISMS. When setting scope you consider your internal and external issues, the requirements of interested parties, and the interfaces and dependencies between your activities and those performed by other organizations, such as cloud providers. The scope must be documented.
You can scope part of the business, such as one product and the teams that run it. Check that the scope answers what your customers care about, because the certificate states it.
Run risk assessment and treatment
Clause 6.1.2 requires a defined information security risk assessment process with risk criteria, one that produces consistent, valid, and comparable results when repeated. You identify risks to the confidentiality, integrity, and availability of information in scope, then analyze and evaluate them.
Clause 6.1.3 covers treatment: choose treatment options, determine the controls you need, compare them with Annex A, write a risk treatment plan, and get risk owners to approve the plan and accept the residual risks. Keep documented information on both processes.
Write the Statement of Applicability against Annex A
The Statement of Applicability lists the controls you need, why each is included, whether each is implemented, and why any Annex A control is excluded (clause 6.1.3 d). Auditors use it as the map of your control set.
Annex A in the 2022 edition lists 93 controls in four groups, down from 114 controls in 14 groups in the 2013 edition. The standard treats Annex A as a reference list: it isn't exhaustive, you can add controls from any source, and the comparison exists so that no necessary control is overlooked.
Complete an internal audit and a management review
Clause 9.2 covers internal audit and clause 9.3 management review. Both matter early: one stage 1 objective is to evaluate whether internal audits and management reviews are being planned and performed, and stage 2 examines them.
Your internal audit can be done by your own staff or by an outside party. If someone outside does it, ISO/IEC 27006-1 requires the certification body to be independent of whoever provides that internal ISMS audit.
Choosing an accredited certification body
ISO's advice is to evaluate several certification bodies, check that the body uses the relevant CASCO standard, and check whether it is accredited. For ISO/IEC 27001, confirm that the accreditation actually covers ISMS certification, not only other standards, and look the body up in IAF CertSearch or the accreditation body's own directory.
Impartiality rules protect you as well as the market. A certification body, its legal entity, and any entity it controls may not offer or provide management system consultancy (ISO/IEC 17021-1, 5.2.5). Consultancy from a body related to the certification body is a significant threat to impartiality, with a recognized mitigation of not certifying that system for at least two years after the consultancy ends (5.2.7).
- Which accreditation body accredits you for ISO/IEC 27001, and where can we confirm it?
- How do you calculate audit time for our scope and sites?
- What experience do your auditors have with organizations like ours?
- How do you grade and follow up nonconformities?
- What does the full three-year audit program look like, including surveillance and recertification?
Stage 1 audit: checking readiness for stage 2
An initial certification audit is always done in two stages, the stage 1 and stage 2 audits. Stage 1 is largely a readiness check that shapes stage 2, and it ends with documented conclusions, including any areas of concern that could be raised as nonconformities during stage 2.
The interval between the stages should give you time to resolve those concerns, and the certification body may revise its arrangements for stage 2 or repeat all or part of stage 1.
- Review the management system's documented information.
- Evaluate your preparedness for stage 2.
- Review your understanding of the standard's requirements.
- Gather scope details, including sites, processes, and applicable legal and regulatory requirements.
- Agree the details of stage 2 and focus its planning.
- Evaluate whether internal audits and management reviews are being planned and performed.
Stage 2: implementation and effectiveness
Stage 2 evaluates the implementation, including the effectiveness, of your ISMS. Auditors look at evidence of conformity, how you monitor and measure performance against your objectives, how you meet legal, regulatory, and contractual requirements, operational control, internal auditing and management review, and management's responsibility for policy.
Findings that don't meet a requirement are nonconformities. The certification body requires you to analyze each cause and describe the corrections and corrective actions taken or planned, within a defined time, and it reviews whether they are acceptable and effective.
Before a decision, major nonconformities must be closed and minor ones need an accepted plan. If a major nonconformity's correction can't be verified within six months after the last day of stage 2, another stage 2 is needed before certification can be recommended.
The certification decision and the three-year cycle
The decision is made by people acting for the certification body who didn't carry out the audit. The first three-year certification cycle begins with the certification decision.
The audit program then runs as surveillance audits in the first and second years after the decision and a recertification audit in the third year, before the certificate expires. The first surveillance audit must fall no more than 12 months after the certification decision date, and European Accreditation's reading of the standard is that there must be at least one audit, surveillance or recertification, in each calendar year.
A surveillance audit isn't necessarily a full-system audit. Each one reviews internal audits and management review, actions on earlier nonconformities, complaint handling, the ISMS's effectiveness against your objectives, continual improvement, continuing operational control, changes, and how you use certification marks.
Recertification confirms continued conformity and effectiveness, and any major nonconformity must be corrected before the certificate expires. If certification lapses, the certification body can restore it within six months once the outstanding recertification activities are completed; otherwise at least a stage 2 audit is needed.
ISO/IEC 27001:2022 and Amendment 1:2024
ISO/IEC 27001:2022, the third edition, was published in October 2022. Under IAF MD 26, the transition from the 2013 edition ended on October 31, 2025, and all certifications to ISO/IEC 27001:2013 expired or were withdrawn at the end of the transition period.
Besides the new Annex A, the 2022 edition added clause 6.3 on planning changes to the ISMS and a new item in 4.2 on which interested-party requirements the ISMS addresses. IAF MD 26 notes that the impact on organizations that already ran an ISMS need not be significant.
Amendment 1:2024, "Climate action changes," applies to ISO/IEC 27001:2022 and was published in February 2024. It adds a requirement in clause 4.1 to determine whether climate change is a relevant issue, and a note in 4.2 that interested parties can have requirements related to climate change. ISO and IAF say the overall intent of clauses 4.1 and 4.2 is unchanged.
What readiness help should and shouldn't do
Outside help can shorten the path by bringing structure and experience, but the ISMS has to be yours: your scope, your risks, your controls, operated by your people. Readiness help earns its cost when it leaves you able to run the system without it.
It should never blur into certification. ISO/IEC 17021-1 bars a certification body from implying that certification would be simpler, easier, faster, or less expensive if a particular consultancy were used, and requires it to correct consultancies that say so about it (5.2.9). A certification body may not use people who consulted on your ISMS in its audit; the recognized mitigation is a gap of at least two years after the consultancy ends (5.2.10).
- Should: help you set scope, run a gap assessment, design the risk method, and facilitate risk workshops.
- Should: help you write policies with the people who will own them and prepare the Statement of Applicability.
- Should: help you plan and prepare for your clause 9.2 internal audit, and rehearse the evidence you will show auditors. Keep the audit objective: whoever performs it shouldn't be auditing controls they designed or implemented.
- Shouldn't: act as, sell on behalf of, or be controlled by your certification body.
- Shouldn't: promise a certificate, a faster audit, or an easier auditor.