Skip to main content

Elevate

ISO 27001 Certification Process, Explained Milestone by Milestone

The ISO 27001 certification process is often described as a single audit, but it is a sequence of nine milestones that runs across a three-year cycle. Four of them happen before an auditor arrives, three make up the certification audit itself, and two keep the certificate valid afterward. Most delays come from treating the process as one event: organizations prepare for Stage 2 and discover at Stage 1 that the internal audit never happened, or pass certification and miss that the first surveillance audit is due within a year. This guide walks through each milestone in order, what the certification body checks at each one, and the findings that most often hold a certificate back.

Why the ISO 27001 Certification Process Looks Different Now

The 2013 Edition Is No Longer Valid

The transition window from ISO/IEC 27001:2013 to the 2022 edition closed on 31 October 2025. A certificate issued against the 2013 edition is no longer valid, so every organization pursuing certification today does so against the 2022 edition, with its 93 Annex A controls reorganized into four themes: organizational, people, physical, and technological. Amendment 1:2024 also added a climate change consideration to Clauses 4.1 and 4.2, which means the context analysis at the very start of the process now has to address whether climate change is a relevant issue for the management system. Elevate’s overview of what changed in ISO 27001:2022 covers the control changes in detail.

Certification Bodies Now Work Under ISO/IEC 27006-1:2024

The rules that govern how certification bodies audit an information security management system were updated in March 2024. ISO/IEC 27006-1:2024 replaced ISO/IEC 27006:2015 as the ISMS-specific extension of ISO/IEC 17021-1, the general standard for bodies that certify management systems. The core of what auditors examine did not move: the ISMS boundary, the risk assessment, and the chain connecting risk decisions to the treatment plan and the Statement of Applicability, along with the effectiveness of internal audit and management review. What the update means in practice is that audit time, audit programme design, and auditor competence all follow the current version, so planning based on an older certification cycle may not match what the certification body schedules now.

Who Certifies, and Who Does Not

An ISO 27001 certificate is issued by an accredited certification body, never by a consultant. Accreditation matters: a certificate from a body without accreditation for ISO 27001 is unlikely to satisfy the enterprise buyers and regulators most organizations certify to reach. Advisors such as Elevate prepare the organization for the audit, and the certification body performs it. Keeping those two roles separate is what gives the certificate its value, because an auditor who helped build the controls cannot judge them impartially. Elevate’s ISO 27001 audit readiness service works on the preparation side of that line.

Before the Audit: Four Preparation Milestones

Milestone 1: Define the Scope and Context

The process starts with Clause 4: understanding the organization and its context, the needs of interested parties, and the boundary of the information security management system. The scope statement decides everything that follows, because it sets which locations, teams, systems, and processes the auditor will examine. Too narrow a scope produces a certificate that customers do not recognize as covering the service they buy. Too broad a scope multiplies the controls and evidence the organization has to produce. Since Amendment 1:2024, the context analysis also has to record whether climate change is a relevant issue, even if the answer is that it is not.

Milestone 2: Assess Risk and Build the Statement of Applicability

Clause 6.1.2 requires a defined information security risk assessment process, and Clause 6.1.3 requires a risk treatment process that produces the Statement of Applicability. The Statement of Applicability lists each of the 93 Annex A controls, states whether it applies, and justifies every inclusion and exclusion. Auditors read the chain from risk to treatment to control closely: a control included without a risk that justifies it, or a significant risk with no treatment, is a common early finding. Elevate’s guides to performing an ISO 27001 risk assessment and the role of the Statement of Applicability cover both steps.

Milestone 3: Implement Controls and Start Collecting Evidence

With the Statement of Applicability approved, the organization implements the controls it committed to. The milestone that matters here is not implementation alone but the start of evidence collection, because a control that exists without a record of operating cannot be demonstrated at Stage 2. Access reviews need dates and reviewers, change records need approvals, and incident handling needs logged events. Evidence of operation accrues on calendar time and cannot be reconstructed afterward, which is why the gap between implementation and audit is a real constraint rather than a formality. A structured ISO 27001 gap analysis at this point shows what still needs to be built.

Milestone 4: Run the Internal Audit and Management Review

Clause 9.2 requires an internal audit of the ISMS and Clause 9.3 requires a management review, and both must have taken place before the certification audit. This is the milestone most often compressed or skipped, and it is the one most likely to stop an otherwise strong program at Stage 1. The internal audit has to be performed by someone independent of the work being audited, which small teams often cannot staff from inside. The management review has to show that leadership actually considered the results and made decisions, not that a meeting appeared on a calendar. Organizations without internal capacity often outsource the internal audit, and Elevate’s ISO 27001 readiness assessment checks all four preparation milestones before the certification body is booked.

The ISO 27001 Certification Audit: Stage 1, Stage 2, and the Decision

Milestone 5: Stage 1 Audit

Stage 1 is a readiness review of the management system as designed. The auditor examines the scope, the risk assessment, the Statement of Applicability, the core policies, and the evidence that internal audit and management review have taken place. The question at Stage 1 is whether the organization is ready for Stage 2, not whether every control works. Findings at this stage are areas of concern to resolve before Stage 2 rather than formal nonconformities, but an unresolved concern can carry forward and become one. Stage 1 also gives the certification body what it needs to plan Stage 2, including its duration, which is calibrated to the number of people within scope under the audit time tables in ISO/IEC 27006-1:2024. Elevate’s breakdown of Stage 1 versus Stage 2 covers the distinction in depth.

Milestone 6: Stage 2 Audit

Stage 2 tests whether the management system operates as described. The auditor interviews control owners, samples evidence, and observes how processes actually run. This is where the evidence collected since Milestone 3 is examined, and where the distance between documentation and practice becomes visible. A policy that says access is reviewed quarterly is tested against the records of those reviews. A change management procedure is tested against real changes and their approvals. Stage 2 is the iso 27001 audit process most people picture, but it can only succeed if the four preparation milestones and Stage 1 were done properly. Elevate’s guide to evidence mapping for Stage 2 shows how to organize it.

Milestone 7: Nonconformities and the Certification Decision

Stage 2 can end with nonconformities, classified as major or minor. A major nonconformity means a requirement is not met or a control is failing in a way that undermines the system; it must be corrected, and the correction verified, before a certificate can be issued. A minor nonconformity is a lapse that does not break the system as a whole; the organization submits a corrective action plan that the certification body accepts, and the fix is checked at the next audit. The certification decision itself is made by the certification body after reviewing the audit results, separately from the audit team. Once the decision is made, the certificate is issued with a three-year validity, and the clock for the next milestone starts on that date.

After Certification: Keeping the Certificate Valid

Milestone 8: Surveillance Audits in Years One and Two

A certificate is not a finish line. The first surveillance audit must take place no more than twelve months from the date of the certification decision, and a second follows in the next year. Surveillance audits are shorter than Stage 2 and examine a sample of the system rather than all of it. They focus on what has changed since the last audit, the results of internal audit and management review, progress on corrective actions from earlier findings, and the continued operation of selected controls. The most common surprise at this milestone is an organization that stopped running its internal audit and management review after certification, assuming the work was done. Elevate’s analysis of the ISO 27001 surveillance audit covers what to expect.

Milestone 9: ISO 27001 Recertification in Year Three

Before the three-year certificate expires, the organization goes through a recertification audit. It is broader than a surveillance audit, reviewing the performance of the management system across the full cycle and confirming it remains effective for the current scope. ISO 27001 recertification is easier for an organization that kept the system operating through both surveillance years, because the evidence of three years of operation already exists. It is harder for one that treated surveillance as a checkpoint to pass rather than a sign of a working system. A successful recertification issues a new certificate and starts the next three-year cycle.

The Full Cycle at a Glance

[embed: node/25cee27e-35f0]

The certification decision is the accent in the middle of the picture because it is the milestone most organizations plan toward, but it sits between four milestones that must come first and three that keep it valid. For how long each phase typically takes, Elevate’s guide to the ISO 27001 certification timeline covers the durations.

What Most Often Delays an ISO 27001 Certificate

Almost every delay traces back to a specific milestone that was rushed or skipped. The patterns below are the ones that most often push a certification date back.

  • A scope that does not match what customers buy (Milestone 1). A certificate that excludes the service a customer is evaluating does not answer their security review, and rescoping late means repeating work.
  • A broken chain from risk to control (Milestone 2). Controls in the Statement of Applicability without a risk to justify them, or significant risks without a treatment, are among the first things an auditor finds.
  • Controls with no evidence of operation (Milestone 3). A control implemented two weeks before Stage 2 has no operating history to sample, and that history cannot be manufactured after the fact.
  • An internal audit that was skipped or not independent (Milestone 4). Without a completed, independent internal audit and a real management review, Stage 1 cannot clear the organization for Stage 2.
  • A major nonconformity at Stage 2 (Milestone 7). A major finding has to be corrected and the correction verified before a certificate is issued, which adds time that was rarely planned for.
  • A missed first surveillance audit (Milestone 8). The first surveillance audit is due within twelve months of the certification decision, and letting the system lapse after certification puts the certificate itself at risk.

Each of these is cheaper to catch before the certification body is booked than during the audit. If you want to know which milestones your program has actually completed, book a call with an Elevate advisor. For the budget side of the process, Elevate’s guide to ISO 27001 certification cost breaks down where the money goes.

Conclusion

The ISO 27001 certification process rewards organizations that treat it as a sequence rather than an event. The four preparation milestones decide whether Stage 1 clears the way, Stage 2 tests whether the system works as written, and the two surveillance years decide whether the certificate survives to recertification. Most delays and most lost certificates come from a milestone that was compressed: an internal audit run the week before Stage 1, controls switched on too late to show any history, or a system allowed to lapse once the certificate arrived.

The practical move is to plan backward from the certification body’s dates, leaving enough time for evidence of operation to accumulate and for the internal audit and management review to happen properly. Organizations that do that tend to reach the certification decision once rather than twice.

Elevate Consult prepares organizations for every milestone up to the certification audit, which is performed by an accredited certification body. Book a call with an Elevate advisor to map where your program stands against the nine milestones.

Key Takeaways

ISO 27001 certification is a three-year cycle with nine milestones, not a single audit.

  • Four milestones come before any auditor. Scope and context, risk assessment and the Statement of Applicability, implementation with evidence, and the internal audit and management review.
  • Stage 1 checks readiness; Stage 2 checks operation. Stage 1 reviews the system as designed, and Stage 2 samples evidence that it actually runs.
  • Major nonconformities block the certificate. They must be corrected and verified before issue; minor ones need an accepted corrective action plan.
  • The first surveillance audit is due within twelve months of the certification decision, with a second the following year.
  • Recertification restarts the cycle in year three, and it is far easier for organizations that kept the system operating throughout.
  • Consultants prepare, certification bodies certify. Only an accredited certification body issues an ISO 27001 certificate.

Frequently Asked Questions

What is the ISO 27001 certification process?

The ISO 27001 certification process is the sequence an organization follows to have an accredited certification body confirm that its information security management system meets ISO/IEC 27001:2022. It starts with defining scope and context, assessing risk, building the Statement of Applicability, implementing controls, and completing an internal audit and management review. The certification body then performs a Stage 1 readiness review and a Stage 2 implementation audit, and issues a certificate valid for three years if no major nonconformity remains. Surveillance audits in years one and two and a recertification audit in year three keep it valid.

How do you get ISO 27001 certified?

To get ISO 27001 certified, an organization builds and operates an information security management system that meets the standard, then passes a two-stage audit by an accredited certification body. In practice that means defining the scope, completing a risk assessment and Statement of Applicability, implementing the selected controls, collecting evidence that they operate, and running an internal audit and management review before booking the audit. Stage 1 confirms readiness and Stage 2 tests implementation. Any major nonconformity must be corrected and verified before the certificate is issued.

What is the difference between a Stage 1 and a Stage 2 audit?

Stage 1 is a readiness review of the management system as designed: the auditor examines the scope, risk assessment, Statement of Applicability, core policies, and evidence that internal audit and management review took place. Its purpose is to decide whether the organization is ready for Stage 2. Stage 2 tests whether the system actually operates, through interviews, evidence sampling, and observation of real processes. Stage 1 findings are concerns to resolve before Stage 2, while Stage 2 can produce formal major or minor nonconformities.

How often are ISO 27001 surveillance audits required?

An ISO 27001 certificate is valid for three years, and surveillance audits take place in the first and second years of that cycle. The first surveillance audit must occur no more than twelve months from the date of the certification decision. Surveillance audits are shorter than Stage 2 and review a sample of the system, focusing on changes, internal audit and management review results, and corrective actions. In the third year, a recertification audit renews the certificate for a new cycle.

Can a consultant issue an ISO 27001 certificate?

No. Only a certification body issues an ISO 27001 certificate, and it should be accredited for ISO 27001 so the certificate is recognized by customers and regulators. Certification bodies operate under ISO/IEC 17021-1 and the ISMS-specific requirements of ISO/IEC 27006-1:2024. Consultants and advisors prepare the organization for the audit, but they cannot certify it, and a firm that helped build the controls should not be the one auditing them.