← All infographics
ISO 27001 · Certification

The ISO 27001 Compliance Journey

From “we should get certified” to holding the certificate — the seven stages, step by step.

1

Define the Scope

Decide which parts of the business and which systems the certificate will cover. Getting scope right keeps the project focused and the cost sensible.

2

Gap Analysis / Pre-audit optional

An honest readiness review against ISO 27001 — what’s already in place and what needs work before the formal audit.

3

Build the ISMS & Remediate

Put the policies, processes and controls in place (or tidy up what you have). Usually the longest stage.

4

Stage 1 Audit — Documentation

A Lead Auditor reviews your ISMS documentation and readiness, flagging anything to fix before the main audit.

5

Stage 2 Audit — Certification

The auditor tests your controls in practice. Pass, and certification is recommended.

6

Certificate Issued

You receive your ISO 27001 certificate — valid for three years.

7

Annual Surveillance

A lighter surveillance audit each year keeps the certificate valid, with full re-certification at year three.

Cianaa Technologies — independent PCI, ISO & SOC assessments across NZ & AU.Book a scoping call →