Security & Compliance · ISO 27001

How to Get ISO 27001 Certified: The Step-by-Step Roadmap

What actually happens between deciding you need it and holding the certificate: the steps in order, a realistic timeline by company size, what it costs, and how to tell an accredited certification body from one that isn’t.

A security questionnaire comes back naming ISO 27001 specifically, or a customer’s procurement team asks for it outright, and someone inside the company gets handed the job of getting there. The mandate is usually one sentence long. What doesn’t come with it is the actual sequence of work between that sentence and a real assessor signing off on a real audit.

Most guides answer with either a ten-thousand-foot list or a compliance-software vendor’s sales page dressed up as a roadmap. Neither says how long each stage actually takes, what a certification body is really checking for, or how the process changes shape once the company is a hundred people instead of ten. Getting the sequence wrong costs more than a delayed certificate. It’s a Stage 2 finding nobody caught at Stage 1, a deal stalled waiting on a report, or months of policy-writing that turns out to describe a system the company never actually built.

The Certification Path, Step by Step

Every accredited path runs through the same ten stages, in the same order. The work inside each one scales with company size and how much of it already exists, but the sequence itself doesn’t change.

  1. 01
    Define the ISMS scopeDecide which parts of the business, which systems, sites, and services, the information security management system actually covers. Get this wrong and every later step audits the wrong boundary.
  2. 02
    Run a gap assessmentAudit current practice against the Annex A controls to find out what already exists, what’s partial, and what’s missing outright, before writing a single policy.
  3. 03
    Build the risk assessment and Statement of ApplicabilityIdentify risks against the defined scope, decide how each will be treated, and document which Annex A controls apply and why.
  4. 04
    Write the ISMS documentationProduce the policies and procedures the standard requires, matched to what the organization will actually run, not a template nobody follows.
  5. 05
    Implement the missing controlsClose the gaps the assessment found: access control, logging, vendor management, incident response, whatever came back weak or absent.
  6. 06
    Operate the system and let evidence accumulateRun the ISMS long enough to generate real operating evidence, not a paper policy dated the week before the audit.
  7. 07
    Complete an internal audit and management reviewSomeone independent of the process tests the ISMS against the standard, then leadership formally reviews the results. Both are required before Stage 1 gets scheduled.
  8. 08
    Pass the Stage 1 auditThe certification body reviews the ISMS documentation to confirm it’s ready for the operational audit.
  9. 09
    Pass the Stage 2 auditThe certification body tests whether the controls actually operate as documented, through interviews, evidence sampling, and system or site review.
  10. 10
    Maintain itAnnual surveillance audits in years one and two, then a full recertification audit before the three-year certificate expires.

Steps two and three are where most first-time certifications either find their footing or lose months. A short conversation with someone who’s run this before usually settles which.

Book a free gap assessment

How Long Each Stage Actually Takes

Company size changes this more than anything else. A small, already-organized team, clear ownership, existing access controls, decent documentation habits, can move from kickoff to certificate in three to four months. Most first-time companies building the ISMS largely from scratch land in the six-to-nine-month range: three to five months on scope, risk assessment, documentation, and control implementation, then two to four months for internal audit, gap closure, and the two-stage certification audit itself. Larger or multi-site organizations, or ones with a genuinely complex system boundary, more commonly run nine to twelve months or longer, mostly because Stage 2 scales with headcount and site count, not company ambition.

None of that clock starts moving until scope is actually defined. Teams that jump straight to writing policy before agreeing what the ISMS covers routinely rewrite half of what they produced once scope gets settled properly at the gap assessment stage.

What It Actually Costs

Certification body audit fees are priced by auditor-days, not a flat number off a rate card. The day count is driven by headcount, site count, and system complexity, which is why two companies of similar revenue can see genuinely different quotes for the same standard. On top of audit fees, budget the internal time the ISMS build actually takes, and, for most first-time efforts, either a consultant or a gap assessment to shorten the learning curve.

The number that catches people off guard isn’t the certification audit itself. It’s that the certificate isn’t a one-time purchase. Years one and two each carry a surveillance audit, smaller than the original but still billed, and year three is a full recertification audit before the three-year cycle resets. Budget it as a three-year program from the start, or the year-two and year-three invoices read like scope creep instead of the standard’s normal maintenance cycle.

Choosing an Accredited Certification Body

Not everyone issuing an ISO 27001 certificate is accredited to do it. Training providers and consultancies can run an assessment and hand over a document that looks the part, but it only carries weight with a buyer’s procurement team, an auditor, or a regulator if it was issued by a body accredited under the international accreditation framework, through a national accreditation body such as UAF, UKAS, ANAB, or NABCB depending on the market.

The check takes five minutes and almost nobody runs it: search the relevant accreditation body’s public register for the certification body’s name, instead of trusting the accreditation logo on the certification body’s own homepage. A logo can be copied. A register entry can’t.

Where First-Time Certifications Lose Months

The most common time sink isn’t a hard control. It’s sequencing: teams start writing policy before scope is defined, then rewrite half the documentation once the ISMS boundary is actually agreed. A close second is treating the gap assessment as optional, then discovering at Stage 1 that the Statement of Applicability doesn’t hold up, which pushes the whole audit back a full cycle while gaps get closed under time pressure instead of on a normal schedule.

The other version of this is choosing on price alone and ending up with a body that isn’t actually accredited, or an assessor unfamiliar with the organization’s industry. The certificate might still get issued. It just won’t carry the weight it’s supposed to the first time a customer’s procurement team checks who issued it.

What Certified Actually Looks Like

A company that got scope and the gap assessment right doesn’t experience Stage 2 as a surprise. The auditor asks for access review evidence, and it’s sitting where the ISMS says it should be, generated by a process the team was already running, not assembled the week before the audit. A company that skipped that step is still writing policy at Stage 1, discovers the real gaps at Stage 2, and spends the weeks it takes to close them explaining the delay to whoever’s waiting on the certificate.

Getting the sequence right the first time is the difference between an audit and a fire drill.

Free ISO 27001 gap assessment

Find out exactly where you stand before the audit clock starts.

Accredify Global runs ISO 27001 certification audits under UAF accreditation, from gap assessment through Stage 1, Stage 2, and the ongoing surveillance cycle, so you’re working with the body that actually issues the certificate from day one, not a consultant handing you off to one later.

Book your free gap assessment →

Frequently Asked Questions

How long does it take to get ISO 27001 certified?
Most first-time organizations take six to nine months from kickoff to certificate. A small, already-organized team can close in three to four months. A larger or multi-site organization building an ISMS from scratch often takes nine to twelve months or more.

How much does ISO 27001 certification cost?
Certification body audit fees are priced by auditor-days and scale with headcount, site count, and complexity, not a flat rate. Budget internal ISMS-build time on top, plus an optional consultant or gap assessment. The certificate also isn’t one-time: annual surveillance audits in years one and two, and a full recertification audit in year three, are part of the real three-year cost.

What’s the difference between the Stage 1 and Stage 2 audits?
Stage 1 is a documentation review confirming the ISMS, risk assessment, and Statement of Applicability are ready for audit. Stage 2 tests whether the controls actually operate as documented, through interviews, evidence sampling, and system or site review. Certification follows only after passing both.

Do I need a consultant, or can we do ISO 27001 ourselves?
Neither is required by the standard. A team with someone who already understands information security management systems can build it internally. Most first-time organizations bring in outside help for the gap assessment and initial documentation, since it’s usually faster than learning Annex A by trial and error against a live audit clock.

What happens if we fail the Stage 2 audit?
The certification body issues findings by severity and gives a defined window, typically 90 days for a major nonconformity, to correct them before certification is granted. It isn’t a full restart. Most Stage 2 findings trace back to a control that was documented but not consistently followed in practice.

How do I know if a certification body is actually accredited?
Check the public register of the national accreditation body overseeing certification bodies in your market, such as UAF, UKAS, ANAB, or NABCB, rather than trusting a logo on the certification body’s own website. Only an accredited body’s certificate is recognized by the framework buyers and auditors actually check against.

Should we get ISO 27001 or SOC 2?
It depends on who’s asking. US enterprise SaaS security teams usually ask for SOC 2 first. International buyers, government tenders, and regulated industries often require ISO 27001 specifically. A full breakdown of the two, and how to run both without duplicating the work, is in our ISO 27001 vs. SOC 2 comparison.

Request Proposal - ISO, SOC & Compliance Services
Please select at least one option
08P19

Ready to Start Your Certification or Compliance Journey?

Tell us your requirement — we'll help identify the right certification, framework, and timeline. Free 15-minute consultation available.