ISO 27001 Certification: Step-by-Step Guide
A Series C fintech lost a $4.2 million enterprise deal in 2024 because their prospect's procurement team required ISO 27001 certification and would not accept SOC 2 as a substitute. The fintech had a perfectly valid SOC 2 Type II report with zero exceptions. It did not matter. The prospect's security policy specified ISO 27001, full stop. Six months later, the fintech had their certification --- but the deal had gone to a competitor who already held one.
ISO 27001 is the international standard for information security management systems, and it carries weight that no other certification matches in European, APAC, and increasingly North American enterprise procurement. Unlike compliance frameworks that prescribe specific technical controls, ISO 27001 requires you to build a management system --- a structured approach to identifying risks and implementing proportionate controls that evolves with your organization.
This guide walks through the certification process step by step: what the standard actually requires, how the 93 Annex A controls work, realistic timelines and costs, and the ongoing obligations that maintain certification after the initial audit.
The ISMS Structure
An Information Security Management System (ISMS) has four components that the standard requires you to build, document, and continuously improve:
- Context and scope --- Define the boundaries of the ISMS, identify interested parties (customers, regulators, partners), and document the internal and external factors that affect information security
- Risk assessment and treatment --- Identify information security risks systematically and decide how to address each one
- Controls --- Implement security controls to treat identified risks (Annex A provides a reference set of 93 controls you select from based on your risk assessment)
- Continual improvement --- Monitor, measure, and improve the ISMS over time through internal audits, management reviews, and corrective actions
The PDCA Cycle
ISO 27001 is built on the Plan-Do-Check-Act cycle:
- Plan --- Establish the ISMS: scope, risk assessment methodology, risk treatment plan, Statement of Applicability
- Do --- Implement the risk treatment plan and operate the controls
- Check --- Monitor and review the ISMS through internal audits, metrics, and management reviews
- Act --- Take corrective actions and improve based on findings
Here is the contrarian take most ISO consultants avoid stating plainly: the management system is the certification, not the controls. Organizations that focus exclusively on implementing Annex A controls while neglecting the risk assessment methodology, internal audit program, and management review cadence fail their Stage 2 audits at dramatically higher rates than organizations with imperfect controls but a functioning management system. Auditors assess your system for managing security, not a checklist of security measures.
Annex A: The 93 Controls
ISO 27001:2022 Annex A contains 93 controls organized into four themes:
| Theme | Controls | Examples |
|---|---|---|
| Organizational (5) | 37 | Information security policies, roles, threat intelligence, supplier relationships |
| People (6) | 8 | Screening, terms of employment, security awareness, disciplinary process |
| Physical (7) | 14 | Physical security perimeters, equipment maintenance, clear desk/screen |
| Technological (8) | 34 | User endpoint devices, access rights, cryptography, logging, network security |
You are not required to implement all 93 controls. Your risk assessment determines which controls are necessary. The Statement of Applicability (SoA) documents which controls you have selected and provides justification for any exclusions. However, "we do not think this risk applies to us" is not sufficient justification for excluding a control --- you must demonstrate through your risk assessment methodology that the threat is not relevant to your scope.
Notable additions in the 2022 revision include threat intelligence (A.5.7), cloud services security (A.5.23), ICT readiness for business continuity (A.5.30), and data masking (A.8.11). These reflect the evolving threat landscape and are areas where auditors pay particular attention during first certifications under the 2022 standard.
Step-by-Step Certification Process
Step 1: Define Scope
Determine what the ISMS covers. This can be the entire organization, specific business units, specific locations, or specific services. The scope must be documented and justified based on organizational context.
Scope definition is a strategic decision. A narrower scope means faster certification and lower cost but may limit the marketing value of the certificate. A broader scope demonstrates comprehensive security governance but requires more controls, more evidence, and more audit days. Most organizations start with their core product or service and expand scope in subsequent certification cycles.
Step 2: Conduct Risk Assessment
Identify information security risks by considering:
- Assets (information, systems, people, facilities)
- Threats (unauthorized access, data loss, system failure, supply chain compromise)
- Vulnerabilities (technical weaknesses, process gaps, human factors)
- Likelihood and impact of each risk scenario
The risk assessment methodology must be documented, repeatable, and produce consistent results when applied by different people. Auditors will ask how you identified risks, how you determined likelihood and impact, and how the results drove your control selection. A methodology that produces different results depending on who runs it will not pass scrutiny.
Step 3: Create Risk Treatment Plan
For each identified risk, decide to:
- Mitigate --- Implement controls to reduce the risk to an acceptable level
- Transfer --- Pass the risk to a third party (insurance, outsourcing with contractual obligations)
- Accept --- Acknowledge the risk with documented management approval and rationale
- Avoid --- Eliminate the activity that creates the risk
Risk acceptance requires explicit management sign-off. Auditors verify that accepted risks have been reviewed and approved at the appropriate organizational level, not merely documented by the security team.
Step 4: Prepare Statement of Applicability
The SoA lists all 93 Annex A controls and documents:
- Whether each control is applicable to your scope
- Justification for inclusion or exclusion
- How the control is implemented (if applicable)
- Where evidence of implementation exists
The SoA is the single most important document in your certification package. Auditors use it as their roadmap for the Stage 2 audit. An incomplete or inconsistent SoA is the most common cause of major nonconformities at Stage 1.
Step 5: Implement Controls
Deploy the controls identified in the risk treatment plan. Document each control with:
- Policy and/or procedure governing the control
- Implementation evidence (configurations, screenshots, process outputs)
- Owner and review schedule
- Metrics demonstrating effectiveness
Step 6: Conduct Internal Audit
Before the certification audit, conduct an internal audit covering all ISMS requirements (Clauses 4-10) and applicable Annex A controls. The internal audit identifies gaps you can address before the external auditor arrives. Internal auditors must be independent of the areas they audit --- they cannot audit their own work.
Step 7: Management Review
Senior management must review the ISMS performance, including:
- Internal audit results and status of previous corrective actions
- Risk assessment updates and changes to the risk landscape
- Security incident reports and lessons learned
- Resource adequacy and improvement opportunities
- Feedback from interested parties
Management review outputs must include decisions on improvement opportunities and resource allocation. An auditor who sees a management review that produced no actions or decisions will question whether the review was substantive.
Step 8: Certification Audit
The external certification audit occurs in two stages:
Stage 1 (Documentation Review):
- Auditor reviews ISMS documentation against standard requirements
- Assesses readiness for Stage 2
- Identifies any gaps that must be addressed before proceeding
- Typically 1-2 days on-site or remote
Stage 2 (Implementation Audit):
- Auditor verifies controls are implemented and effective through evidence review
- Interviews staff across the organization to assess security awareness and process adherence
- Examines evidence of control operation over time (not just point-in-time)
- Tests processes through observation and sampling
- Typically 2-5 days depending on scope and organization size
Step 9: Address Findings
Audit findings are categorized as:
- Major nonconformity --- Must be corrected before certification is granted (typically within 90 days with evidence of correction)
- Minor nonconformity --- Must be corrected with evidence provided at the next surveillance audit
- Observation/Opportunity for Improvement --- Recommendation for improvement (no corrective action required, but ignoring them consistently signals a stagnant ISMS)
Timeline and Cost
| Phase | Timeline | Cost (SMB) |
|---|---|---|
| ISMS design and implementation | 3-6 months | Internal effort + consulting ($20K-$80K) |
| Internal audit | 1-2 weeks | Internal or consulting ($5K-$15K) |
| Stage 1 audit | 1-2 days | Certification body ($5K-$15K) |
| Gap remediation | 1-3 months | Internal effort |
| Stage 2 audit | 2-5 days | Certification body ($10K-$30K) |
| Annual surveillance audits | 1-3 days each | $5K-$20K per year |
Total first-year cost for a small-to-medium organization: $40K-$140K including consulting, tooling, and certification body fees. Larger organizations with broader scope should expect $100K-$300K+ depending on complexity.
Organizations with existing SOC 2 reports or compliance programs can typically compress the implementation phase by 30-50% because many controls are already in place --- the gap is primarily the management system wrapper (risk methodology, SoA, internal audit program, management review).
Maintaining Certification
Certification is not a one-time achievement. Ongoing requirements include:
- Annual surveillance audits by the certification body (typically covering a subset of controls and the full management system)
- Full re-certification audit every three years (equivalent to the initial Stage 1 + Stage 2)
- Continual risk assessment updates as the environment, threat landscape, and organizational context change
- Internal audits at planned intervals covering the full ISMS scope over time
- Management reviews at least annually with documented outputs
- Corrective actions for any identified nonconformities, tracked to closure
The organizations that struggle with certification maintenance are those that treat it as a project with a finish date rather than an operating model. The ISMS is a system you run, not a milestone you achieve.
ISO 27001 and Other Frameworks
ISO 27001 maps extensively to other compliance frameworks, making it an efficient foundation for multi-framework compliance:
- SOC 2 --- SOC 2 Trust Service Criteria overlap significantly with Annex A controls, particularly in security, availability, and confidentiality
- NIST CSF --- The Cybersecurity Framework functions (Identify, Protect, Detect, Respond, Recover) align with ISMS components and Annex A control themes
- NIST 800-53 --- Annex A controls map to many 800-53 control families, making ISO 27001 a useful foundation for organizations considering FedRAMP
- HIPAA --- HIPAA Security Rule technical safeguard requirements are addressed by relevant Annex A technological controls
- CMMC --- Organizations in the defense industrial base find significant overlap between Annex A and CMMC Level 2 practices
Key Takeaways
- ISO 27001 certifies your management system, not a checklist of controls --- the ISMS methodology matters more than perfect implementation
- The Statement of Applicability is the most important document --- get it right early
- First-year cost for SMB: $40K-$140K with a 3-9 month implementation timeline
- Organizations with existing SOC 2 can compress implementation by 30-50%
- Certification maintenance requires ongoing internal audits, management reviews, and surveillance audits --- it is an operating model, not a project
- Scope strategically: start focused, expand in subsequent cycles
Frequently Asked Questions
How long does ISO 27001 certification take from start to finish?
For a small-to-medium organization with some existing security controls, expect 6-12 months from decision to certification. This includes 3-6 months of ISMS design and implementation, 1-3 months of gap remediation after the Stage 1 audit, and the Stage 2 audit itself. Organizations starting from minimal security maturity should plan for 9-15 months. Having an existing SOC 2 program or other compliance framework in place can compress the timeline by 2-4 months.
Do we need to implement all 93 Annex A controls?
No. Your risk assessment determines which controls are applicable, and the Statement of Applicability documents your selections with justification for exclusions. However, exclusions must be risk-justified --- you cannot exclude a control simply because it is inconvenient or expensive. In practice, most organizations find 70-85 of the 93 controls applicable to their scope. Auditors scrutinize exclusions carefully, particularly for technological controls.
Can we pursue ISO 27001 and SOC 2 simultaneously?
Yes, and many organizations do. The overlap between Annex A controls and SOC 2 Trust Service Criteria is significant --- approximately 60-70% of the control work is shared. A cross-mapped compliance approach lets you implement controls once and satisfy both frameworks, with the primary additional effort being the ISMS management system wrapper (risk methodology, SoA, PDCA cycle) that ISO 27001 requires but SOC 2 does not.
What is the difference between ISO 27001 and ISO 27002?
ISO 27001 is the certifiable standard --- it specifies the requirements for establishing, implementing, maintaining, and improving an ISMS. ISO 27002 is the implementation guidance --- it provides detailed recommendations for how to implement each of the 93 Annex A controls. You certify against 27001; you reference 27002 for implementation best practices. Think of 27001 as the "what" and 27002 as the "how."
How does the 2022 revision differ from the 2013 version?
ISO 27001:2022 reorganized Annex A from 14 categories with 114 controls to 4 themes with 93 controls. Eleven new controls were added (including threat intelligence, cloud security, data masking, and secure coding). The core management system requirements (Clauses 4-10) received minor updates. Organizations certified under the 2013 version had until October 2025 to transition. New certifications are exclusively against the 2022 revision.
How Advisedly Helps
Advisedly supports ISO 27001 certification by providing risk assessment tools, control mapping against all 93 Annex A controls, and automated evidence collection infrastructure that keeps your ISMS documentation current between audits. The platform generates your Statement of Applicability, tracks control implementation status through the certification process, and maintains the continuous monitoring that surveillance audits expect to see. For organizations maintaining ISO 27001 alongside other frameworks, Advisedly maps Annex A controls to every applicable standard in its 500+ framework library --- a single control implementation satisfies ISO 27001, SOC 2, NIST 800-53, and any other mapped framework simultaneously, eliminating the duplicate effort that makes multi-framework compliance expensive. Contact begin@advisedly.ai
<!-- LI hook: ISO 27001 certifies your system, not your controls. Most orgs get this backward. -->