ISO/IEC 27001 is the international standard for information security management, and the certificate most often asked for in enterprise procurement outside North America. This guide covers the whole path — what the standard actually requires, how certification works, what it costs, and the mistakes that delay programmes — and links to detailed guidance at each stage.
What ISO 27001 actually is
The most important thing to understand before spending any money: ISO 27001 certifies a management system, not a set of technical controls. It asks whether your organisation systematically identifies information security risks, decides what to do about them, does it, checks that it worked, and improves. Firewalls and encryption appear inside that, but the certificate is about the system that governs them.
This is why organisations with strong technical security still fail: the controls are present, but there is no evidence of risk assessment driving them, no management review, no internal audit, and no records showing the whole thing operating over time.
Structurally the standard has two parts. The clauses (4–10) are mandatory and cover context, leadership, planning, support, operation, evaluation and improvement. Annex A is a catalogue of 93 controls you compare your risk treatment against — a completeness check, not a checklist to implement wholesale.
Is it the right standard for you?
Choose ISO 27001 when you sell internationally, when buyers ask for a certificate rather than a report, or when you expect to add further frameworks later and want a management system underneath them. Choose SOC 2 instead — or as well — when your buyers are North American enterprises who ask for an auditor's report. Regulatory obligations such as the NCA ECC or SAMA CSF are not substitutable by either.
The path to certification
- Define scope. Which entities, products, systems and locations. This decision drives cost more than any other, and a narrow, defensible scope satisfies most customer requests.
- Inventory assets. Everything downstream depends on it.
- Assess risk using a documented, repeatable method.
- Decide treatment and select controls that address the risks you found.
- Produce the Statement of Applicability — which Annex A controls apply, why, their status, and a justification for every exclusion.
- Implement and document, describing what you actually do.
- Operate long enough to generate records — roughly three months minimum, and quarterly controls must have run at least once.
- Run internal audit and management review. Both must happen before Stage 1. Skipping this is the most common reason Stage 1 goes badly.
- Stage 1 — readiness and documentation review. The resulting report tells you precisely what Stage 2 will examine.
- Stage 2 — operational audit with sampling and interviews, then certification.
- Surveillance in years one and two, recertification in year three.
Start with an honest gap analysis
GRC Copilot scores you against all 93 Annex A controls, holds the evidence for each, and generates your Statement of Applicability with justifications.
Try GRC Copilot free Generate an AI-powered assessment Download checklist Book a demo
Cost and timeline, realistically
Six to twelve months is typical for a first certification. The floor is set not by budget but by evidence: controls that run quarterly need to have run, and internal audit and management review must have happened. Money can compress remediation, not the calendar.
On cost, certification body fees are the smaller component. Internal effort dominates, followed by remediation. Price the full three-year cycle — surveillance visits in years one and two and recertification in year three all carry fees — rather than the initial audit alone.
Where programmes fail
- Committing to an audit date before the gap analysis. The fastest route to a public failure.
- Template policies that describe an organisation you are not. Auditors interview the people doing the work, and the contradiction surfaces immediately.
- Compliance performing the controls. If the compliance function runs access reviews itself, the business never takes ownership and you have no independence to review anything.
- Working from Annex A backwards instead of deriving controls from risk — it produces a control set visibly disconnected from the organisation.
- Stopping after the certificate. Most failures happen at the first surveillance visit, when a year of recurring activities turns out not to have happened.
After certification
The certificate is the start of an operating commitment. Recurring activities — access reviews, risk register reviews, internal audits, management review, policy review — must run on a schedule with named owners, because the evidence they produce cannot be created retrospectively. Organisations that treat the certificate as a finish line discover this twelve months later.
Detailed guidance
Everything below goes deeper on a specific part of the path:
Audit
- The compliance evidence matrix: what each framework actually asks you to produce — Auditors do not ask for controls, they ask for artefacts. A control-domain-by-framework matrix of the evidence ISO 27001, SOC 2, the NCA ECC…
Buyer Guides
- How much does ISO 27001 certification really cost? — A breakdown of every cost line in ISO 27001 certification - audit fees, tooling, internal time, remediation and ongoing surveillance - and t…
- Which compliance framework should you actually do first? — The right answer is usually decided by your customers and regulators, not by which standard is best. A decision procedure, the sequencing th…
Checklists
- ISO 27001 checklist: every step from scoping to certification — A complete, practical ISO 27001 implementation checklist - the mandatory documents, the risk work, the Annex A controls and the audit stages…
Comparisons
- Essential Eight vs ISO 27001: which one does your organisation need? — One is eight prescriptive technical controls with fixed timeframes; the other is a management system across a scope you define. What each pr…
- ISO 27001 vs ISO 27002: which one do you certify against? — One is a certifiable standard, the other is guidance you cannot certify against. How they relate, why 27002 is where the practical detail li…
- ISO 27001 vs NIST: which framework do you actually need? — ISO 27001 and the NIST Cybersecurity Framework solve different problems. A direct comparison of certification, structure, cost and audience…
- Mapping ISO 27001 to NIS2: what carries over and what does not — A measure-by-measure crosswalk from ISO 27001:2022 Annex A to the ten NIS2 minimum measures, plus the four obligations certification will ne…
- SOC 2 vs ISO 27001: which one does your buyer actually want? — SOC 2 and ISO 27001 prove security in different ways - an attestation report versus a certificate. A direct comparison of scope, cost, timel…
Frameworks
- Getting started with ISO 27001 — A practical, jargon-free introduction to ISO/IEC 27001 - what the standard is, why certification matters, and the concrete steps from first…
- ISO 27001 Annex A: the 93 controls, and what actually changed in 2022 — Four themes instead of fourteen domains, 93 controls instead of 114, and eleven genuinely new ones. What the restructure means for your Stat…
- ISO 27001 mandatory documents: what you must have, and what you do not — The standard names a specific, surprisingly short list of required documents and records. What is genuinely mandatory, what is optional, and…
- Transitioning from ISO 27001:2013 to 2022: what actually has to change — The control set was restructured and eleven controls are new. What the transition genuinely requires, what can stay as it is, and the sequen…
Saudi & GCC
- NCA ECC vs ISO 27001: regulation or certification? — The ECC is a regulatory obligation you report on; ISO 27001 is a certificate you earn. How they differ in purpose, structure and assessment…
Frequently asked questions
How long does ISO 27001 certification take?
Six to twelve months for a first certification. The constraint is accumulated evidence and the requirement that internal audit and management review happen before Stage 1 — neither of which money shortens.
Do we have to implement all 93 Annex A controls?
No. You implement what your risk assessment justifies, then compare against Annex A and document exclusions with reasons in the Statement of Applicability. Genuine exclusions usually number in the single digits.
Is ISO 27001 better than SOC 2?
Neither is better; they answer different buyer requests. ISO certifies a management system and is the international default; SOC 2 is an auditor's report favoured by North American enterprises. Many organisations end up doing both, and the control work overlaps heavily.
Can a small company get certified?
Yes — the standard scales. Small organisations define a narrower scope and use documented compensating controls where segregation of duties is impractical. Auditors expect that and prefer it stated honestly.
What is the single most common cause of delay?
Missing evidence rather than missing controls. Activities happen but leave no dated record, and records cannot be produced after the fact.
Key takeaways
- ISO 27001 certifies a management system — technical controls alone do not pass.
- Scope is the decision that drives cost; narrow and defensible beats broad and thin.
- Internal audit and management review must precede Stage 1.
- Evidence accumulates over time, so the timeline has a floor money cannot lower.