ISO 27001 certification is independent, formal proof that your company’s information security management system (ISMS) meets the ISO/IEC 27001 standard, granted by an accredited certification body after a two-stage audit. A company earns the certification; a person earns a qualification, such as Lead Implementer or Lead Auditor, so the two credentials are not interchangeable.
The journey follows a consistent shape: build the ISMS, close the gaps a risk assessment turns up, pass Stage 1 and Stage 2 with an accredited body, then hold the certificate through a three-year cycle with annual surveillance in between. This guide covers what certification is, why companies pursue it, what the standard requires, the roadmap, gap analysis, cost, the audit, internal audit, and staying certified, the full path a compliance and risk management platform like Copla walks clients through.
What ISO 27001 certification is
ISO 27001 certification confirms that an organisation has built and operates an ISMS conforming to ISO/IEC 27001:2022, the current version of the standard, verified by an independent, accredited certification body. A certificate represents:
- An ISMS covering a clearly defined scope of systems, data, and locations
- A risk-based selection of Annex A controls, recorded in a Statement of Applicability
- Evidence the controls actually operate over time, not just exist on paper
- A pass verdict from the certification body’s own audit, not a self-assessment
The certificate is issued by the certification body, never by software or a consultant, and it holds for three years subject to annual surveillance audits.
Company certification vs individual certification
A company is certified to ISO 27001 when its ISMS passes an accredited audit. A person becomes qualified, as a Lead Implementer or Lead Auditor, for instance, by completing training and passing an exam instead.
One credential belongs to the organisation; the other belongs to the individual who holds it.
Companies often have qualified people on the team, sometimes several, but a qualified employee doesn’t make the company certified, and a certified company doesn’t mean every employee holds a qualification. If you’re weighing the individual route instead, get ISO 27001 certified as an individual covers training providers, exam format, and what the credential actually qualifies you to do.
Why companies pursue ISO 27001 certification
Enterprise and public-sector buyers increasingly gate deals behind security due diligence, and ISO 27001 certification answers that gate with one recognised credential instead of a fresh questionnaire every time. Pointing to a current certificate settles most of a security review that would otherwise run for weeks over email. Beyond sales, it forces a structured, risk-based way of running information security in place of ad hoc fixes. More than 70,000 certificates have been issued worldwide, per ISO’s own count, across over 150 countries.
Regulated financial entities in the EU carry this alongside DORA‘s regulatory requirements, the NIS2 directive, PCI DSS’s contractual controls, or a SOC 2 attestation. The ISMS work overlaps heavily across all of them, so one well-run programme can serve several obligations at once instead of rebuilding the same policy four times.
Certification itself is rarely a legal requirement: it’s overwhelmingly a contractual one, set by whoever is on the other side of the deal.
That’s why mapping DORA to ISO 27001 is worth doing early, not after a second audit is already on the calendar.
What ISO 27001 certification requires
The requirements split into two parts. Clauses 4 to 10 are the mandatory management-system requirements: context and scope, leadership, planning and risk, support, operation, performance evaluation, and improvement. Every certified company satisfies all seven, regardless of size or sector.
Annex A is different: a reference set of 93 controls across four themes, organisational, people, physical, and technological. Which ones apply, and why, gets recorded in a Statement of Applicability, the document an auditor checks first.
None of it applies wholesale: controls get selected based on your own risk assessment, not a template.
A handful of outputs are non-negotiable regardless of how the rest of the programme runs:
- A defined scope
- An ISMS policy
- A risk assessment and treatment plan
- The Statement of Applicability
- Internal audit records
- Management review minutes
The full ISO 27001 requirements list breaks down every clause and control in the set.
The path to ISO 27001 certification
The sequence stays consistent across companies, even though the effort inside each step scales with size and scope:
- Define the scope: which systems, data, people, and locations the ISMS covers.
- Run a gap analysis against the clauses and Annex A controls.
- Assess risk and select the controls that address it.
- Build and document the ISMS: policies, procedures, the risk register, the Statement of Applicability.
- Operate it and collect evidence that it’s actually running, not just written down.
- Run an internal audit and a management review.
- Go through Stage 1 and Stage 2 with an accredited certification body.
One honest point worth stating plainly: certification isn’t a document exercise.
An auditor expects to see the ISMS operating before Stage 2: evidence collected over weeks or months, not assembled the night before.
The ISO 27001 implementation roadmap covers the timing and effort behind each step.
Start with a gap analysis, and size controls to real risk
A gap analysis compares your current setup against the ISO 27001 clauses and Annex A controls, then turns the difference into a prioritised task list. Done properly, it’s the first real work of the programme: you start knowing exactly what’s missing, rather than guessing.
The harder discipline sits underneath it. The goal isn’t ticking every control on a template, it’s understanding what matters first: list the assets, run a business impact analysis to work out which systems and data are genuinely critical, build a risk register from that, and only then choose the controls that reduce those specific risks.
Skip that order and you get the checklist-first habit: controls retrofitted to a generic template, effort spent efficiently on the wrong things.
A control that traces to no named risk is a control nobody can defend when a supervisor or an auditor asks why it’s set the way it is.
Copla’s programmes start the same way, from the business impact analysis and risk register, not the control list, so automated risk management sizes each control to what the business actually stands to lose. The ISO 27001 gap analysis guide covers how to run one, control by control.
The ISO 27001 certification audit: Stage 1 and Stage 2
Two stages, run by an accredited certification body, decide whether ISO 27001 certification is granted. Stage 1 is a documentation and readiness review: does the ISMS exist, and does it cover the requirements. Stage 2 is the main event: testing whether the controls actually operate, through interviews, evidence review, and direct observation.
What matters is design versus operating effectiveness. Stage 1 checks the ISMS was designed properly; Stage 2 checks it ran, over time, the way it was designed to.
Continuous, timestamped evidence beats a pre-audit scramble: an auditor sampling six months of access reviews wants six months of dated records, not one produced the morning they arrive.
Does the audit run itself? No. Copla’s automated evidence collection and audit room validate, version, and map each record to a control, which makes Stage 2 far less of a fire drill, but a person still confirms the evidence is sufficient, and the accredited body still runs the audit. The ISO 27001 audit guide covers both stages, and audit automation software is usually where the evidence trail lives.
Internal audit: A requirement, not an optional extra
An internal audit is a clause 9 requirement, not a nice-to-have: you complete one before certification, and again on a regular schedule to keep it. It’s your own independent check that the ISMS actually works, run by someone impartial to the area under review, and its job is to surface nonconformities before the external auditor does.
It’s distinct from the certification body’s Stage 2 and surveillance audits, both external: internal audit is yours to run, on your own schedule.
Often that means a fractional or in-house CISO team supplying the resource behind it. The ISO 27001 internal audit guide covers how to plan and run one.
Staying certified: Surveillance audits and recertification
The certificate holds for three years. Inside that window, the certification body runs annual surveillance audits, typically at the end of years one and two, sampling the ISMS and its controls to confirm you’re still maintaining what got certified. A full recertification audit before expiry reassesses the whole ISMS and restarts the three-year cycle.
ISO 27001 certification is a state you maintain, not a milestone you finish.
The ISMS has to keep running and improving between audits, not go dormant until the next one is booked. The ISO 27001 surveillance audit guide covers what each visit checks and how to prepare.
How much ISO 27001 certification costs, and how long it takes
Start with the manual baseline, based on Copla’s own analysis across client programmes: a first-time ISO 27001 certification typically runs 800+ hours of internal effort without automation, spread across gap and risk analysis, policies, evidence, internal audit, and certification-body coordination. For a company under 50 people, that commonly means 4 to 6 months; larger scopes take longer. Audit fees from the certification body sit outside that figure entirely, separate from internal effort and from any platform or advisory cost.
Automation and expert support change that curve, not the fact that judgment still has to happen somewhere. On Copla’s client implementations, that typically means 40 to 70 percent faster and lower-cost delivery; for ISO 27001 specifically, clients have reached audit readiness from kickoff in under two months, with ongoing effort down to minutes a day once the ISMS is live.
Treat these as averages, not a guarantee for any given scope.
The ISO 27001 certification cost guide breaks the baseline down stage by stage, ISO 27001 compliance software covers how the delivery model works, and current plans sit at current pricing.
Choosing how to get certified
Three shapes recur once you start comparing options, and each assumes something different about who supplies the judgment once the software or the consultant’s invoice stops talking.
| Model | Strength | The catch |
|---|---|---|
| Self-serve evidence tools | Fast, comparatively cheap | ISMS build and every judgment call stay with you |
| Consultancy-led delivery | Thorough, hands-on | Slower and pricier, and the knowledge leaves when the engagement ends |
| Platform plus expert | Automation plus a named senior person for judgment calls | Only as good as how deeply that person is actually involved |
Two questions cut through most of the rest: who owns the judgment once the platform or the consultant is gone, and is audit readiness maintained continuously, or rebuilt from scratch every year.
Copla helps you build, run, and keep an audit-ready ISMS: automation for the repeatable work, a senior CISO for the calls that need one. Book a consultation to see what that looks like for your scope.
FAQ
-
Is ISO 27001 certification legally mandatory? +
For most companies, no. ISO 27001 certification isn’t a legal requirement in itself, but it’s frequently a contractual one, set by enterprise customers, partners, or procurement teams in regulated sectors. Regulated financial entities may carry separate legal obligations, such as DORA, that certification supports but doesn’t replace.
-
Who can issue an ISO 27001 certificate? +
Only an accredited certification body. Ideally one accredited by a national accreditation body operating under the Global Accreditation Cooperation framework, which replaced the International Accreditation Forum in January 2026, so the certificate carries international recognition. Neither software nor a consultant can issue one.
-
How do you choose an ISO 27001 certification body? +
Confirm accreditation first, then match for fit. Check that the body holds accreditation from a national accreditation body under the Global Accreditation Cooperation framework, since that is what makes the certificate internationally recognised. From there, compare relevant sector experience and typical Stage 1 to Stage 2 scheduling, since turnaround varies meaningfully between bodies.
-
How can you verify an ISO 27001 certificate is genuine? +
Check it against the certification body’s public register. Most accredited certification bodies maintain a searchable directory where anyone can confirm a certificate number, scope, and expiry date against what an organisation is claiming. A certificate whose scope excludes the systems or data you actually care about is not full coverage, even if the certification itself is genuine.
-
What is the difference between ISO 27001 and ISO 27002? +
ISO 27001 is the certifiable standard; ISO 27002 is guidance. ISO 27001 is what an accredited body audits you against. ISO 27002 explains how to implement the Annex A controls in practice, and you can’t be certified against it. Most programmes use ISO 27002 as a working reference alongside the certification itself.
-
Do we need ISO 27001:2022 or the 2013 version? +
ISO 27001:2022. The transition period from the 2013 revision closed on 31 October 2025, so every new certification now runs against the 2022 version and its 93 Annex A controls. If your company still holds a 2013 certificate, your certification body has already handled the transition or has it scheduled.
-
Can a small team get ISO 27001 certified? +
Yes. Effort scales with the size and complexity of what’s in scope, not headcount on its own, so a small SaaS company with a tight, well-defined scope can certify with a modest team, especially with automation handling the repeatable work.
-
Can you get ISO 27001 certified without a consultant? +
Yes, but someone still has to own the judgment. Certification doesn’t require a consultant, though the standard demands calls on scope, control adequacy, evidence sufficiency, and risk acceptance that need an accountable person behind them. Platform-plus-expert models keep that judgment in-house rather than renting it fresh for every cycle.