Contents
- What Does the ISO 27001 Certification Process Look Like?
- How Long Does ISO 27001 Certification Take?
- What Does ISO 27001 Certification Cost?
- The ISO 27001 Checklist: From Preparation to the Audit
- How Do You Choose a Certification Body?
- What Happens After the Certificate?
- What Questions Come Up Before Certification?
- Is ISO 27001 certification legally required?
- How long is an ISO 27001 certificate valid?
- Can only part of a company be certified?
- Does the internal audit have to be outsourced?
- Is software enough for certification?
ISO 27001 certification usually takes three to twelve months and runs through eight phases: define the scope, gap analysis, risk assessment, implement controls, internal audit, engage a certification body, external audit in two stages, certificate. This fuentis guide shows the process, the checklist up to the audit and what to look for when choosing a certification body.
Whether you need a certificate at all is covered in Who Needs ISO 27001 Certification?. This guide is about the path to get there.
What Does the ISO 27001 Certification Process Look Like?
Certification to ISO/IEC 27001 confirms that an information security management system (ISMS) meets the requirements of the standard and works in operation. The assessment is not carried out by ISO but by an external certification body. Before that comes the build-up of the ISMS, which makes up most of the work.
| Phase | Result | Typical effort focus |
|---|---|---|
| 1. Preparation and scope | Responsible person, team, scope | Alignment with senior management |
| 2. Gap analysis | Current state against the standard's requirements | Interviews, document review |
| 3. Risk assessment | Risk assessment, risk treatment plan, Statement of Applicability | Business units and IT |
| 4. Implementation | Policies, processes, technical measures, training | Longest phase |
| 5. Internal audit and management review | Audit report, management decision | Independent auditor |
| 6. Engage a certification body | Quote, audit plan | Selection and scheduling |
| 7. External audit | Stage 1 (document review, readiness), Stage 2 (effectiveness review) | Evidence and auditor interviews |
| 8. Certificate and surveillance | Certificate, annual surveillance audits | Ongoing operation |
The Statement of Applicability defines which controls from Annex A of the standard you apply and why. The current edition, ISO/IEC 27001:2022, lists 93 controls there. You do not have to implement all of them, but you must justify every exclusion.
How Long Does ISO 27001 Certification Take?
Plan for three to twelve months until the first certificate. Smaller organizations that prioritize the project reach audit readiness after about three months; complex structures with several sites or service providers take longer. This is a rule of thumb, not a guarantee: the duration depends on the scope, the maturity of your processes and how much time your team actually sets aside.
Three factors determine the duration most:
- Scope: A narrow scope (one product, one site) shortens the path. A certificate only covers the assessed area, though.
- Starting point: Organizations that already have policies, an access concept and a continuity plan save months in implementation.
- Resources: The ISMS is a project with named owners, not a by-product of daily business.
The schedule after the certificate is fixed: accredited certification bodies work under ISO/IEC 17021-1 in a three-year cycle of initial certification, annual surveillance audits and recertification before expiry. The BSI certification scheme for ISO 27001 based on IT-Grundschutz likewise provides for three years of validity with annual surveillance audits. The timeline in detail, including follow-up audits, is described in How Long Does ISO Certification Take?.
What Does ISO 27001 Certification Cost?
There is no universal figure, and quotes from certification bodies differ by size and scope. The cost drivers are clear, though:
- effort of your own staff to build and maintain the ISMS, usually the largest item
- external consulting, if you use it
- the certification body's fee for the initial audit, surveillance audits and recertification
- tools for documentation, risk management and evidence
- training and technical measures that follow from the gap analysis
Request quotes from several certification bodies based on the same scope so that they are comparable.
The ISO 27001 Checklist: From Preparation to the Audit
The checklist condenses the phases into 14 steps. Work through them in this order and record every result in writing, because auditors assess evidence, not intentions.
- Form the ISMS team: Name a responsible person and two to three employees who cover the technical and organizational view.
- Define the scope: Specify organizational units, sites, systems, key assets and the suppliers involved.
- Collect legal and contractual requirements: These include data protection, sector law and customer requirements.
- Draft basic policies: Information security policy, incident handling, workplace and device use.
- Set data rules: Classification, retention, records of processing activities and protection of personal data.
- Regulate access and encryption: Identity and access management, encryption, backups.
- Secure development and recovery: Secure software development, continuity and recovery planning.
- Connect HR processes: Integrate hiring, training and offboarding into the ISMS processes.
- Carry out the risk assessment: Assess risks, create the treatment plan and the Statement of Applicability.
- Implement and test controls: Verify technical effectiveness through an IT assessment and close vulnerabilities.
- Train employees: Build security awareness and document attendance.
- Conduct the internal audit: An independent auditor reviews the entire ISMS, and nonconformities are corrected.
- Hold the management review: Management evaluates the ISMS, decides on actions and documents the outcome.
- Prepare the external audit: Bundle evidence, name contact persons and agree the audit plan with the certification body.
"Most delays do not arise in the audit but before it: the scope is chosen too large, or nobody has time for implementation. Clarifying both early saves months."
Srdan Manasijevic, CEO of fuentis AG
How Do You Choose a Certification Body?
The certification body performs the external audit and issues the certificate. Pay attention to these points:
- Accreditation: The body should be accredited for ISO/IEC 27001 so that customers recognize the certificate.
- Sector experience: Auditors who know your sector assess more practically.
- Audit plan and quote: Ask about audit scope, follow-up costs for surveillance audits and dates.
- Independence: Under ISO/IEC 17021-1 (clause 5.2), a certification body must not itself offer or provide management system consultancy. Consultancy from closely related bodies also threatens impartiality; ask about it.
If you have to choose between ISO 27001 and the German route, the differences are laid out in BSI IT-Grundschutz vs. ISO 27001. The BSI also certifies ISO 27001 on the basis of IT-Grundschutz.
What Happens After the Certificate?
The certificate marks the start of ongoing operation. In surveillance audits, the certification body checks annually whether the ISMS is actually practiced, and recertification follows in the third year. Plan continuously: update risks, repeat internal audits, hold management reviews, track measures.
ISMS software helps because it keeps evidence, risks and measures in one place and gives auditors access to current proof. The ISMS module of the fuentis Suite offers gap analyses, risk management and audit readiness for this. The comparison of ISMS tools from Germany gives an overview of suitable tools, and the pricing overview shows the packages.
And what does the effort pay off in? The effects a certificate has on sales, compliance and operations are shown in 9 Benefits of ISO 27001 Certification.
What Questions Come Up Before Certification?
Is ISO 27001 certification legally required?
No, there is no legal obligation to certify in Germany. The BSI Act requires essential and important entities to implement risk management measures in line with the state of the art (Section 30 BSIG), not a specific standard. When a certificate is still demanded, for example as KRITIS evidence or by customers, is explained in Who Needs ISO 27001 Certification?.
How long is an ISO 27001 certificate valid?
Three years, with annual surveillance audits and recertification before expiry, following the cycle under ISO/IEC 17021-1. The BSI certification scheme for ISO 27001 based on IT-Grundschutz also names three years.
Can only part of a company be certified?
Yes. The certificate covers the area defined in the scope, such as a product, a site or a business unit. The scope must match what customers or assessors expect as evidence.
Does the internal audit have to be outsourced?
No. A qualified, independent employee who is not responsible for the audited area may carry out the internal audit. Alternatively, you can engage an external consultant.
Is software enough for certification?
No. Software supports documentation, risk management and evidence, but it replaces neither management decisions nor practiced processes. The audit assesses how the ISMS operates, not the tool.

CEO, fuentis AG
Expert in information security, data protection and risk management with extensive experience advising enterprises and public-sector organizations. Specialized in ISO 27001, BSI standards and modern risk-analysis methods.