The ISO 27001 Compliance Journey
From “we should get certified” to holding the certificate — the seven stages, step by step.
Define the Scope
Decide which parts of the business and which systems the certificate will cover. Getting scope right keeps the project focused and the cost sensible.
Pre-audit optional, separate
Sits alongside the journey rather than inside it. An independent check against ISO 27001 that tells you what is solid and what is not, before any formal audit is booked. The trade-off is timing, because Stage 1 cannot be held within three months of a pre-audit.
Build the ISMS & Remediate
Put the policies, processes and controls in place (or tidy up what you have). Usually the longest stage.
Stage 1 Audit — Documentation
A Lead Auditor reviews your ISMS documentation and preparation, flagging anything to fix before the main audit.
Stage 2 Audit — Certification
The auditor tests your controls in practice. Pass, and certification is recommended.
Certification Decision
The accredited certification body reviews the recommendation and decides. If granted, the certificate is valid for three years.
Annual Surveillance
A lighter surveillance audit each year keeps the certificate valid, with full re-certification at year three.
