← All infographics
ISO 27001 · Certification

The ISO 27001 Compliance Journey

From “we should get certified” to holding the certificate — the seven stages, step by step.

1

Define the Scope

Decide which parts of the business and which systems the certificate will cover. Getting scope right keeps the project focused and the cost sensible.

2

Pre-audit optional, separate

Sits alongside the journey rather than inside it. An independent check against ISO 27001 that tells you what is solid and what is not, before any formal audit is booked. The trade-off is timing, because Stage 1 cannot be held within three months of a pre-audit.

3

Build the ISMS & Remediate

Put the policies, processes and controls in place (or tidy up what you have). Usually the longest stage.

4

Stage 1 Audit — Documentation

A Lead Auditor reviews your ISMS documentation and preparation, flagging anything to fix before the main audit.

5

Stage 2 Audit — Certification

The auditor tests your controls in practice. Pass, and certification is recommended.

6

Certification Decision

The accredited certification body reviews the recommendation and decides. If granted, the certificate is valid for three years.

7

Annual Surveillance

A lighter surveillance audit each year keeps the certificate valid, with full re-certification at year three.

Cianaa — independent PCI, ISO & SOC assessments across NZ & AU.Book a scoping call →