ISO 27001 implementation and certification readiness

Most organisations do not fail an ISO 27001 audit because their security is weak. They fail, or delay, because the evidence that their controls operate does not exist in a form an auditor can accept.

Get an ISO 27001 readiness review

ISMS

Statement of Applicability

27001certified

Our job

When the auditor arrives, there is nothing left to discover.

ISMSStatement of ApplicabilityRisk treatmentInternal auditManagement reviewCertification
ISMSStatement of ApplicabilityRisk treatmentInternal auditManagement reviewCertification

What ISO 27001 certification involves

What ISO 27001 certification involves

Stage 1 audit

Documentation and readiness review. The auditor checks that the management system exists on paper and that its scope, risk assessment, Statement of Applicability and mandatory documents are coherent.

Stage 2 audit

Implementation audit. The auditor tests whether the system actually operates: whether risks were treated as decided, whether controls run and whether records exist.

Annual audits

Surveillance audits in years one and two confirm that the system keeps running after the certificate is issued, not only on audit day.

Renewal

A full recertification audit at the end of the three-year cycle. A system assembled for the certificate and abandoned afterwards becomes visible here.

ISO 27001:2022 and what changed

Four themes — The 2022 revision restructured Annex A into four themes: organisational, people, physical and technological controls.

93 controls — Annex A now lists 93 controls instead of 114. Most were merged or regrouped rather than removed.

11 new controls — including threat intelligence, information security for cloud services, data masking, secure coding and monitoring activities.

Transition — The 2013 version has been retired. Certificates issued against it had to move to the 2022 edition by 31 October 2025.

Mapping, not rebuilding — If your ISMS was built against the 2013 structure, the controls largely persist. The Statement of Applicability and internal documentation need to be updated.

ISO 27001: key questions

Who issues the ISO 27001 certificate?

An accredited certification body, independent of the organisation that helped you implement the system. That independence is a requirement, not a formality: the same company cannot both build your ISMS and certify it.

We prepare you for that audit and support you during it. Where certification is the goal, we tell you at the start which body will be involved and what they will expect, so there are no surprises about who does what.

How long is an ISO 27001 certificate valid?

Three years. The certificate is issued after the Stage 2 audit, confirmed by surveillance audits in years one and two, and renewed through a recertification audit at the end of the cycle.

Our ISMS was built on ISO 27001:2013. Do we start again?

No. The work is mapping rather than rebuilding: the controls largely persist, but the Statement of Applicability and internal documentation need to reflect the 2022 structure of Annex A.

Why do organisations fail or delay certification?

Rarely because their security is weak. More often because the evidence that controls operate does not exist in a form an auditor can accept: scope defined too widely, a Statement of Applicability written last, records never collected, an internal audit treated as a formality.

Is ISO/IEC 27001 certification mandatory?

No. ISO/IEC 27001 is a voluntary international standard. In practice it is often required by customers, partners and tenders as proof that information security is managed systematically, and it helps show regulators that you take a risk-based approach to security.

How long does ISO/IEC 27001 certification take?

It depends on the scope and on how much of the management system already runs. The limiting factor is rarely documentation: before the Stage 2 audit the system has to operate long enough to produce evidence, including an internal audit and a management review. We give you a realistic timeline after the gap analysis.

How much does ISO/IEC 27001 certification cost?

It depends on the scope, the number of locations and people covered, and how mature your current controls are. The fee of the certification body is separate from implementation support. After the gap analysis we give you an estimate for our part of the work, so you can plan the budget before you commit.

What is a Statement of Applicability?

The document that lists the Annex A controls, states which ones apply to you and justifies every exclusion. It connects your risk assessment to the controls you selected, and it is one of the first documents an auditor reads.

Where to start?

For more information, reach out to us now.

Active Audit Agency provides extensive cybersecurity services for businesses, ensuring robust protection and compliance for organizations of various sizes.

footer-logo

You can copy our materials only after making sure that your services are safe.
This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.