ISO 27001 certification: steps, timeline and who does what
5 min read Last checked on
ISO 27001 certification is a two-stage external assessment by a certification body. Stage 1 checks whether you are ready, stage 2 whether your ISMS works. The certificate is valid for three years, with at least one surveillance audit per calendar year. In the Netherlands, the Dutch Accreditation Council (RvA) accredits the bodies that may certify.
ISO 27001 certification is a two-stage audit by a certification body, followed by a certificate that is valid for three years. During those three years the body returns at least once per calendar year for a surveillance audit. The certificate says your ISMS meets the standard within the scope stated on it, not that your organisation cannot be breached.
Who does what
| Party | Role |
|---|---|
| Your organisation | Sets up and runs the ISMS and supplies the evidence. |
| Consultant (optional) | Helps with set-up and preparation. Cannot be the same party that certifies you. |
| Certification body | Carries out the audits and takes the certification decision. |
| Dutch Accreditation Council (RvA) | Assesses whether certification bodies work competently and impartially, based on ISO/IEC 17021-1 and, for information security, ISO/IEC 27006-1. |
| ISO | Writes the standard, but certifies no one. |
Accreditation is not a legal requirement for a certification body, but customers and contracting authorities almost always ask for an accredited certificate in practice. The RvA website has a searchable register of accredited bodies, and ISO points to the IAF CertSearch database for certificates worldwide.
The steps
- Define the scope. Which part of the company, which services and which locations. For a SaaS supplier this is often the platform, the development pipeline and support.
- Baseline. Where you stand against clauses 4 to 10 and Annex A.
- Assess and treat risks. Including the Statement of Applicability.
- Implement controls and let them run. An auditor wants to see controls working, not just described. That takes some time in which evidence builds up.
- Internal audit and management review. Both should have been carried out at least once before stage 2 makes sense.
- Choose a certification body. Request quotes, check accreditation and experience with your sector.
- Stage 1 audit. Review of documentation and readiness.
- Stage 2 audit. Assessment of how things work in practice.
- Certification decision. Once any nonconformities are dealt with, the body takes its decision. The three-year cycle runs from that date.
Stage 1
In stage 1 the auditor looks at your documented ISMS: scope, policy, risk assessment, Statement of Applicability, internal audit and management review. They assess whether you understand the requirements of the standard and whether stage 2 can go ahead. Stage 1 often produces points of attention you can pick up before stage 2, which is why there are usually a few weeks between the two stages.
Stage 2
In stage 2 the auditor assesses whether the ISMS works in practice. They talk to people, look at systems and take samples: access reviews, backup tests, handled incidents, changes in the development pipeline. At a software company part of this happens remotely, with screen sharing.
Findings come in two kinds. A major nonconformity means a requirement has not been met, or not effectively; the certificate follows only once you have demonstrably resolved it. A minor nonconformity is an isolated shortcoming; a correction plan the auditor accepts is usually enough.
The three-year cycle
| Moment | What happens |
|---|---|
| Certification decision | The cycle starts, the certificate is valid for three years. |
| Year 1 | Surveillance audit, no later than twelve months after the certification decision. |
| Year 2 | Surveillance audit, at least one per calendar year. |
| Year 3 | Recertification audit, planned in time for the new decision to fall before expiry. |
A surveillance audit is shorter than the initial audit and looks at part of the system each time, plus in any case the internal audit, the management review and the follow up of earlier findings. Organisations that go quiet between audits notice it at the first surveillance.
Timeline
There is no guaranteed timeline. For an IT or software company of 10 to 100 people, six months to a year from start to certificate is a common experience. What makes the difference:
- Starting point. A company that already works with code reviews, access management and backup tests mainly needs to record what it does. A company that does not yet do those things has to introduce them first.
- Scope. One product is quicker than the whole company across three offices.
- People's time. Someone with a fixed part of the week for it moves faster than someone doing it on the side.
- The body's schedule. Auditors are not always available at short notice. Ask for dates early.
Choosing a certification body
- Check with the RvA that the body is accredited for ISO/IEC 27001.
- Ask whether the auditors have experience with software companies, SaaS or your sector, for example healthcare if you are also considering NEN 7510.
- Compare quotes on the number of audit days for the whole cycle, not just the first year.
- Ask how the body handles remote audits if your team largely works from home.
What certification costs and which items it involves is covered in the article on cost. Preparation per phase is in the checklist.
Frequently asked questions
Who issues an ISO 27001 certificate?
A certification body. ISO itself does not certify. In the Netherlands, the Dutch Accreditation Council (Raad voor Accreditatie, RvA) accredits the bodies that may issue accredited ISO 27001 certificates.
How long is an ISO 27001 certificate valid?
Three years. During that period the certification body returns at least once per calendar year for a surveillance audit, and a recertification audit takes place before the certificate expires.
What is the difference between the stage 1 and stage 2 audit?
In stage 1 the auditor checks whether your documentation and preparation are in order and whether you are ready for stage 2. In stage 2 they assess whether the ISMS works in practice and is effective.
How long does an ISO 27001 project take?
It depends on scope, starting point and available time. For a software company of 10 to 100 people, six months to a year is a common experience, but that is neither a rule nor a promise.
Can I fail the audit?
There is no grade, only findings. With major nonconformities, a certificate follows only once you have demonstrably resolved them. Minor nonconformities are handled with a plan the auditor accepts.
Read next
ISO 27001
Internal audit and management review without the theatre
Read more
Management system and policy
What an ISMS is, and why a spreadsheet stops at the second standard
Read more
ISO 27001
ISO 27001 checklist for IT and software companies
Read more
ISO 27001
What ISO 27001 certification costs in the Netherlands
Read more
ISO 27001
ISO 27001 in plain language: what it is and what it asks of a software supplier
Read more
ISO 27001
Statement of Applicability: what goes in it and how to keep it current
Read more
Sources
- ISO, certification and accreditation
- ISO, ISO/IEC 17021-1:2015 requirements for bodies certifying management systems
- IAS, text of ISO/IEC 17021-1:2015 section 9 (process requirements)
- Dutch Accreditation Council (RvA), management system certification bodies
- Dutch Accreditation Council (RvA), register of accredited organisations
- Dutch Accreditation Council (RvA), ISO/IEC 27006-1:2024 published
Trustbird is being built with two certified design partners, and we are looking for more companies to join them at co-founder pricing.
Become a design partner