To get ISO 27001 certification, a company defines and records its scope, assesses its risks, writes the Statement of Applicability across all 93 Annex A controls, runs the management system long enough to have records, chooses a certification body accredited for ISO/IEC 27001, and passes a Stage 1 document review followed by a Stage 2 audit of the running system. Four to seven months is realistic for a small software company, then a surveillance audit each year and recertification in year three. The steps are sequenced, and steps taken out of order have to be redone.
1. Define the scope, and write it down
What the certificate covers: which parts of the organisation, which services, which locations. Scope drives everything after it, including the audit fee, because auditor days come from the covered headcount. Write it narrowly and truthfully. A scope that overreaches costs days and invites findings in areas you did not need certified.
2. Context, interested parties, and the risk assessment
Clauses 4 and 6. What affects your ability to run an information security management system, who has a stake in it, and what could go wrong. This is the foundation an auditor tests everything else against.
3. The Statement of Applicability
Clause 6.1.3, and the document a certification body reads first. All 93 Annex A controls, each declared applicable or excluded, each with a justification. Exclusions are legitimate and must be justified. An SoA that marks everything applicable to look thorough creates 93 things to evidence.
4. Run the system, and keep the records
Policies approved, risks treated, suppliers assessed, access reviewed, incidents handled. This is where the calendar matters more than the documents: the auditor will ask for records covering a period, so the system has to have been running, not merely designed.
Minimum before Stage 2: an internal audit and a management review, both with records. These are the two most common reasons a Stage 2 is postponed.
5. Choose an accredited certification body
Separate company, contracted and paid directly. Verify accreditation for ISO/IEC 27001 specifically, in the accreditation body's public register. How to check.
6. Stage 1
A readiness review, usually shorter and often remote. The auditor reads your documented information and decides whether Stage 2 is worth booking. Findings here are cheap. This is the point at which being genuinely ready saves money.
7. Stage 2
The full audit. The auditor samples records and tests whether the system operates as documented. Nonconformities are raised as major or minor; majors must be corrected before a certificate issues.
8. The three years after
Surveillance audits each year at roughly a third of the initial audit time, then recertification at about two thirds. This is most of the cycle and most of the total cost. The arithmetic.
The part that decides it
Whether the evidence exists when it is asked for. Companies that struggle are rarely missing policies. They are missing the twelve months of records showing the policies were followed.