Back to blog
Frameworks

ISO 27001: the complete guide

Everything needed to go from "we should get certified" to holding the certificate: what the standard requires, what it costs, how the audit cycle works, and where programmes fail. With links to detailed guidance on every stage.
GRC Copilot Team
ISO 27001: the complete guide

ISO/IEC 27001 is the international standard for information security management, and the certificate most often asked for in enterprise procurement outside North America. This guide covers the whole path — what the standard actually requires, how certification works, what it costs, and the mistakes that delay programmes — and links to detailed guidance at each stage.

What ISO 27001 actually is

The most important thing to understand before spending any money: ISO 27001 certifies a management system, not a set of technical controls. It asks whether your organisation systematically identifies information security risks, decides what to do about them, does it, checks that it worked, and improves. Firewalls and encryption appear inside that, but the certificate is about the system that governs them.

This is why organisations with strong technical security still fail: the controls are present, but there is no evidence of risk assessment driving them, no management review, no internal audit, and no records showing the whole thing operating over time.

Structurally the standard has two parts. The clauses (4–10) are mandatory and cover context, leadership, planning, support, operation, evaluation and improvement. Annex A is a catalogue of 93 controls you compare your risk treatment against — a completeness check, not a checklist to implement wholesale.

Is it the right standard for you?

Choose ISO 27001 when you sell internationally, when buyers ask for a certificate rather than a report, or when you expect to add further frameworks later and want a management system underneath them. Choose SOC 2 instead — or as well — when your buyers are North American enterprises who ask for an auditor's report. Regulatory obligations such as the NCA ECC or SAMA CSF are not substitutable by either.

The path to certification

  1. Define scope. Which entities, products, systems and locations. This decision drives cost more than any other, and a narrow, defensible scope satisfies most customer requests.
  2. Inventory assets. Everything downstream depends on it.
  3. Assess risk using a documented, repeatable method.
  4. Decide treatment and select controls that address the risks you found.
  5. Produce the Statement of Applicability — which Annex A controls apply, why, their status, and a justification for every exclusion.
  6. Implement and document, describing what you actually do.
  7. Operate long enough to generate records — roughly three months minimum, and quarterly controls must have run at least once.
  8. Run internal audit and management review. Both must happen before Stage 1. Skipping this is the most common reason Stage 1 goes badly.
  9. Stage 1 — readiness and documentation review. The resulting report tells you precisely what Stage 2 will examine.
  10. Stage 2 — operational audit with sampling and interviews, then certification.
  11. Surveillance in years one and two, recertification in year three.

Start with an honest gap analysis

GRC Copilot scores you against all 93 Annex A controls, holds the evidence for each, and generates your Statement of Applicability with justifications.

Cost and timeline, realistically

Six to twelve months is typical for a first certification. The floor is set not by budget but by evidence: controls that run quarterly need to have run, and internal audit and management review must have happened. Money can compress remediation, not the calendar.

On cost, certification body fees are the smaller component. Internal effort dominates, followed by remediation. Price the full three-year cycle — surveillance visits in years one and two and recertification in year three all carry fees — rather than the initial audit alone.

Where programmes fail

  • Committing to an audit date before the gap analysis. The fastest route to a public failure.
  • Template policies that describe an organisation you are not. Auditors interview the people doing the work, and the contradiction surfaces immediately.
  • Compliance performing the controls. If the compliance function runs access reviews itself, the business never takes ownership and you have no independence to review anything.
  • Working from Annex A backwards instead of deriving controls from risk — it produces a control set visibly disconnected from the organisation.
  • Stopping after the certificate. Most failures happen at the first surveillance visit, when a year of recurring activities turns out not to have happened.

After certification

The certificate is the start of an operating commitment. Recurring activities — access reviews, risk register reviews, internal audits, management review, policy review — must run on a schedule with named owners, because the evidence they produce cannot be created retrospectively. Organisations that treat the certificate as a finish line discover this twelve months later.

Detailed guidance

Everything below goes deeper on a specific part of the path:

Audit

Buyer Guides

Checklists

Comparisons

Frameworks

Saudi & GCC

Frequently asked questions

How long does ISO 27001 certification take?

Six to twelve months for a first certification. The constraint is accumulated evidence and the requirement that internal audit and management review happen before Stage 1 — neither of which money shortens.

Do we have to implement all 93 Annex A controls?

No. You implement what your risk assessment justifies, then compare against Annex A and document exclusions with reasons in the Statement of Applicability. Genuine exclusions usually number in the single digits.

Is ISO 27001 better than SOC 2?

Neither is better; they answer different buyer requests. ISO certifies a management system and is the international default; SOC 2 is an auditor's report favoured by North American enterprises. Many organisations end up doing both, and the control work overlaps heavily.

Can a small company get certified?

Yes — the standard scales. Small organisations define a narrower scope and use documented compensating controls where segregation of duties is impractical. Auditors expect that and prefer it stated honestly.

What is the single most common cause of delay?

Missing evidence rather than missing controls. Activities happen but leave no dated record, and records cannot be produced after the fact.

Key takeaways

  • ISO 27001 certifies a management system — technical controls alone do not pass.
  • Scope is the decision that drives cost; narrow and defensible beats broad and thin.
  • Internal audit and management review must precede Stage 1.
  • Evidence accumulates over time, so the timeline has a floor money cannot lower.
#iso-27001 #complete-guide #pillar #isms #certification