
Key takeaways
- You obtain ISO 27001 certification by building an information security management system, passing a two-stage audit run by an accredited certification body, then holding it through annual surveillance audits on a three-year cycle. Scope sets your audit fee, your timeline, and whether the certificate satisfies the buyer's security review.
- ISO 27001:2022 contains 93 Annex A controls across four themes, and you implement only the subset your risk assessment justifies. Any guide still citing 114 controls predates the October 31, 2025 transition deadline.
- Audit fees are formula-driven. ISO/IEC 27006-1:2024 makes certification bodies calculate audit duration from the number of people working inside your ISMS scope, contractors included, so you can sanity-check a quote before you accept it.
- Your certification body cannot advise you. Under ISO/IEC 17021-1, they assess what you built, so implementation support has to come from your own team or a partner.
- The certificate alone rarely clears procurement, because the same addendum usually names an insurance limit and attaches a security questionnaire.
An enterprise buyer put ISO 27001 in the security addendum, and the contract sits until you produce a certificate. The instinct is to open Annex A and start working through 93 controls. Auditors test those controls, but they also test the management system around them, and that gets shaped before any control is implemented.
What do you need to get ISO 27001 certified?
You need four things in place before implementation starts:
- A named ISMS owner: ISO 27001 puts leadership commitment in Clause 5, and auditors read that as a named individual, so "engineering owns it" will not survive Stage 1. That is usually the CTO at ten people and a dedicated compliance lead past thirty, and whoever holds it needs authority to set scope.
- A platform that carries the evidence: Dated artifacts and access reviews accumulate faster than a spreadsheet can track them. A compliance platform pulls evidence from your cloud infrastructure continuously, so Stage 2 samples what already exists.
- An accredited certification body: Only an accredited body can issue a valid ISO 27001 certificate, and the route to verifying one changed in January 2026, when the International Accreditation Forum ceased operations and merged with ILAC into Global Accreditation Cooperation Incorporated. Certificates issued under the old arrangement remain recognized. Check your certification body against a national accreditation register such as ANAB or UKAS, or use an in-network audit program where that vetting is already done.
- Engineering hours you can protect: Auditors verify controls running in your live environment, so book the time before it disappears into the roadmap.
How to obtain ISO 27001 certification in eight steps
Certification runs from your first scoping decision to a certificate a buyer will accept. Each step has a done condition:
Scope is the decision that prices everything else
Certification bodies calculate audit duration under ISO/IEC 27006-1:2024, whose Annex C maps the number of persons doing work inside your ISMS scope to a baseline number of days for the initial audit. Contractors and freelancers count alongside employees, and the 2024 revision made total headcount the default basis regardless of how many sites they sit across. That baseline is then adjusted for the complexity of your ISMS and the type of business in scope, so it is a starting point rather than a quote, and enough to sanity-check the number a certification body puts in front of you.

The reverse risk is scoping too tight. Your scope statement is printed on the certificate, and the buyer's security team reads it. A certificate covering corporate IT when the buyer is purchasing your product platform fails their diligence, and you have paid for a document that does not unblock the contract. Scope around the systems and people that touch customer data, and no further.
What does the ISO 27001 Stage 1 audit test?
Stage 1 is a documentation review, often remote. The auditor reads your scope statement, risk assessment, Statement of Applicability, policies, internal audit results, and management review minutes, confirming the ISMS exists on paper before anyone tests whether it works.
ISO/IEC 27001:2022/Amd 1:2024 added two sentences to clauses 4.1 and 4.2 requiring you to determine whether climate change is a relevant issue for your ISMS. It was issued as a clarification, so it applied immediately with no transition window, and certification bodies have been checking it since 2024.
When the auditor finds a gap, expect the finding and not the fix. Clause 5.2.5 of ISO/IEC 17021-1 bars a certification body from providing management system consultancy, so it can explain its findings and clarify what a requirement means, but not design your remediation.
What Stage 2 tests, and what happens after
Stage 2 checks whether what you documented is what actually runs. The auditor interviews people named in your policies and samples evidence against the controls in your Statement of Applicability. Findings are graded, and the grade sets your timeline: minor nonconformities close through a corrective action plan without blocking certification, while a major nonconformity blocks it until the fix is made and reverified.
Certification then runs on a three-year cycle, with surveillance audits in years one and two and recertification in year three. Under ISO/IEC 17021-1, your first surveillance audit falls no more than twelve months after the certification decision, which is a shorter runway than most teams expect. Continuous evidence collection closes that gap.
How long does ISO 27001 certification take?
The calendar has three parts: implementation, the two-stage audit, and the certification decision. Implementation moves fastest with centralized cloud infrastructure, automated evidence collection, and an existing framework to build on, and stretches when infrastructure is hybrid, documentation does not exist, and policies start from a blank page. The audit has its own clock: certification bodies book out months ahead, and Stage 2 sits weeks after Stage 1. Approach one before your ISMS is finished, because the date they can offer is often the real constraint.
How much of ISO 27001 does SOC 2 already cover?
SOC 2 covers most of the control work and little of the management system. The overlap sits in access management, logging, change management, incident response, and vendor review, and those controls transfer with modest rework. What does not transfer is the management system. ISO 27001 clauses 4 through 10 require a Statement of Applicability, an internal audit program, and a documented management review, and SOC 2 mandates none of them. Teams that assume SOC 2 gets them most of the way are counting controls and missing the ISMS, which is where the time goes.
How much does ISO 27001 certification cost?
Two of the four components arrive as invoices. The other two are your own team's time, which is why the total lands well above the quote:
- Certification body fees: The one price a third party quotes you, scaling with in-scope headcount under ISO/IEC 27006-1:2024 and covering Stage 1, Stage 2, both surveillance audits, and recertification.
- Tooling: Compliance platform, vulnerability scanning, penetration testing, and security awareness training.
- Implementation time: The largest and least visible line: risk assessment, policy work, control implementation, and evidence collection.
- Maintenance time: Keeping evidence current, reviewing policies, and running the internal audit each year between external audits.
Price the full three-year cycle, because a year-one figure leaves out two surveillance audits and a recertification. Without consolidation, it can take over five separate vendors to assemble a workable program once questionnaires and insurance certificates are in scope, and startups and mid-market companies carry 4.3x the compliance cost of enterprises. Audit fees also arrive as a single invoice, so ask whether the platform and the audit can be paid monthly, and use a budget calculator to price a program against your headcount and frameworks.
What buyers ask for alongside ISO 27001
The addendum that names ISO 27001 usually sets an insurance limit within a page of it, and the buyer's security team attaches a questionnaire on top.
Insurance limits
The limit is set by the buyer's legal team, the certificate of insurance comes from your broker, and additional insured status needs an endorsement only the carrier can issue, usually on a turnaround measured in days. It also recurs because the certificate expires with your policy term and gets requested again at renewal and at every new contract. Forward the insurance clause to your broker as soon as the addendum arrives.
Government contracts
ISO 27001 certifies a management system while federal contracts specify control sets, so selling to the government brings NIST SP 800-171, DFARS, and CMMC into scope depending on the information you handle.
Put ISO 27001 on autopilot with Koop
Two surveillance audits, a stream of questionnaires, and certificates of insurance on procurement's timeline are what consume the year after certification.
- Housekeeper AI Agent keeps evidence current between audits instead of rebuilding it each cycle, cutting 95% of the manual work.
- Requirements Management pulls the security and insurance obligations out of customer contracts and tracks them to completion.
- Compliance, security reviews, and insurance in one place, which is how companies reach compliance 36% faster and save over 44% on vendor spend.
Frequently asked questions
- What is the difference between being ISO 27001 certified and ISO 27001 compliant?
Compliant means you believe your ISMS meets the standard. Certified means an accredited body audited it and said so. Only the second is verifiable, which is why procurement asks for the certificate and its scope statement.
- Should I get ISO 27001 or SOC 2 first?
Follow your buyers. North American procurement usually asks for SOC 2, while European, UK, and public-sector buyers ask for ISO 27001. If your pipeline is split, start with whichever is blocking revenue now, since the overlap makes the second cheaper.
- Who can issue a valid ISO 27001 certificate?
Only a certification body accredited by a recognized national accreditation body. Certificates from unaccredited issuers fail buyer diligence, so check the accreditation register before signing an engagement letter.

