8.1 The ISMS Certification Process

Key Takeaways

  • ISO/IEC 27001 organizational certification follows a three-year cycle: Stage 1 documentation review, Stage 2 on-site audit, annual surveillance, and recertification, governed by ISO/IEC 17021-1
  • Stage 1 confirms the ISMS is ready (scope, SoA, policies, risk assessment, RTP); Stage 2 tests whether it actually works through interviews, observation, and record sampling
  • Accreditation bodies (UKAS, ANAB, DAkkS) authorize certification bodies per ISO/IEC 17021-1; they do not issue ISO/IEC 27001 certificates themselves
  • Major nonconformities must be closed before a certificate is issued; unresolved majors at surveillance can lead to suspension or withdrawal
  • PECB Foundation is an individual knowledge credential, NOT organizational ISMS certification; the exam tests this distinction
Last updated: July 2026

Why ISO/IEC 27001 Certification Matters

ISO/IEC 27001 certification is a formal, independent confirmation that an organization's Information Security Management System (ISMS) meets every requirement of Clauses 4-10 of the standard. Certification is voluntary — the standard can be adopted internally without it — but it is increasingly demanded in B2B contracts, public-sector tenders, cloud-provider due diligence, and regulator expectations. A certificate issued by an accredited body is portable proof that the organization has implemented, documented, and continually improves an ISMS, not merely written security policies.

Two concepts are often confused and the exam tests the difference:

  • Certification body — an independent organization that audits clients and issues ISO/IEC 27001 certificates (e.g., BSI, DNV, Bureau Veritas, TÜV, SGS).
  • Accreditation body — a national authority that assesses and authorizes the certification body itself (e.g., UKAS in the UK, ANAB in the US, DAkkS in Germany). Accreditation is the "audit the auditor" layer.

The conformity assessment chain is: organization → certification body → accreditation body. The accreditation body validates that the certification body is competent, impartial, and operates per ISO/IEC 17021-1 (Conformity assessment — Requirements for bodies providing audit and certification of management systems).

The Certification Cycle

A typical ISO/IEC 27001 certification follows a three-year cycle built on four audit events.

StagePurposeTypical DurationOutcome
Stage 1Documentation review1-3 daysReadiness confirmed, or gaps to fix before Stage 2
Stage 2On-site implementation audit3-10 daysRecommendation for certification, or major/minor nonconformities
SurveillanceAnnual (or per programme) check1-3 daysCertificate maintained, or new nonconformities raised
RecertificationFull re-audit before expiry3-year markNew 3-year certificate issued

Stage 1 — Documentation Review (Readiness Audit)

Stage 1 is performed off-site or on-site at the certifier's discretion, and its purpose is to confirm the ISMS is ready for a full implementation audit. The auditor reviews:

  • the scope statement (Clause 4.3) — what is in, what is out, and the boundary justification;
  • the Statement of Applicability (SoA) (Clause 6.1.3 d) — includes/excludes, justification, and control implementation status;
  • the information security policies (Clause 5.2) and the supporting topic-specific policies;
  • the information security risk assessment (Clause 6.1.2) — methodology, risk register, risk owners;
  • the Risk Treatment Plan (RTP) (Clause 6.1.3 e) and how each residual risk is being treated;
  • the legal, regulatory, and contractual register (Clause 4.2);
  • evidence that top management has demonstrated leadership and approved the framework (Clause 5.1).

Stage 1 is not a pass/fail audit — the auditor produces a gap report. Major gaps (e.g., no SoA, missing risk assessment) delay Stage 2. Minor gaps can be closed before Stage 2 starts.

Loading diagram...
The ISO/IEC 27001 Three-Year Certification Cycle (ISO/IEC 17021-1)

Stage 2 — On-Site Implementation Audit

Stage 2 is the on-site audit where the auditor tests whether the documented ISMS is actually working. The auditor gathers objective evidence through three techniques:

  • Interviews with managers, asset owners, risk owners, HR, IT, and end users;
  • Observation of activities (e.g., access provisioning, change management, physical security controls);
  • Document and record sampling — incident logs, risk reviews, internal audit reports, management review minutes, training records, backup logs, cryptographic key inventories.

The auditor checks each Clause 4-10 requirement and samples controls from Annex A against the SoA. Findings are classified as a major nonconformity (systemic failure, missing requirement, or breakdown that prevents the ISMS from achieving its objectives) or a minor nonconformity (isolated lapse, no systemic impact). Observations may also be raised — these are not nonconformities but opportunities for improvement.

A certificate is issued only after all major nonconformities are closed (usually within 90 days) and minors are addressed through a corrective action plan.

Surveillance Audits

Surveillance audits are conducted at least once per year (the standard cycle is "surveillance 1" at year 1 and "surveillance 2" at year 2). They are not full re-audits — the auditor samples a subset of clauses, controls, and sites, and always reviews:

  • the status of nonconformities from the previous audit;
  • the results of internal audits and management review;
  • the updated risk assessment and SoA;
  • any changes to scope, organization, or context;
  • continual improvement actions (Clause 10).

If a major nonconformity is not resolved within the agreed timeframe, the certificate can be suspended and, ultimately, withdrawn.

Recertification

Before the three-year cycle ends, the organization undergoes a full recertification audit. The recertification audit re-verifies the entire ISMS against the current version of the standard and confirms the management system continues to meet the requirements. On successful completion, a new three-year certificate is issued and the surveillance cycle restarts. The three-year cycle is defined by ISO/IEC 17021-1, the same standard that governs the accreditation of certification bodies.

Foundation Trap: Two Different "Certifications"

A common exam trap is conflating two completely different uses of the word "certified":

  • Organizational ISMS certification — issued to a company by an accredited certification body after a successful Stage 1 + Stage 2 audit. This is what ISO/IEC 27001 is designed for.
  • PECB individual certification — issued to a person (you) after passing a PECB exam, such as the ISO/IEC 27001 Foundation credential. This certifies knowledge of the standard, not conformity of an organization.

You do not certify an organization by passing the Foundation exam. You do not need your employer to be ISO/IEC 27001 certified to earn the PECB Foundation credential. They are independent concepts that share the word "certification," and exam questions deliberately probe whether you can keep them straight.

Test Your Knowledge

What is the primary purpose of the Stage 1 audit in an ISO/IEC 27001 certification?

A
B
C
D
Test Your Knowledge

Under ISO/IEC 17021-1, how often must an organization undergo a full recertification audit to maintain its ISO/IEC 27001 certificate?

A
B
C
D
Test Your Knowledge

Which of the following best describes the role of an accreditation body such as UKAS or ANAB?

A
B
C
D