[{"data":1,"prerenderedAt":14},["ShallowReactive",2],{"article:en:how-to-get-iso-27001-certification-for-company":3},{"locale":4,"slug":5,"title":6,"description":7,"published":8,"answer":9,"body":13},"en","how-to-get-iso-27001-certification-for-company","How to get ISO 27001 certification for a company, in the order it actually happens","The path from nothing to a certificate, what happens at Stage 1 and Stage 2, and the records an auditor asks for at each point.","2026-08-20",{"who":10,"when":11,"do":12},"A company going from nothing to an ISO 27001 certificate: the steps run in one order, scope, risk assessment, Statement of Applicability, a period of running the system with records, an accredited certification body, then the Stage 1 document review and the Stage 2 audit of the running system.","Four to seven months before the date the certificate is needed for a small software company, since the system has to run long enough to have records before Stage 2, and audit slots are booked weeks ahead; then a surveillance audit each year and recertification in year three.","Write the scope down first, assess the risks against it, decide every Annex A control in the Statement of Applicability, run the system and keep the records, choose a body accredited for ISO\u002FIEC 27001, and book Stage 1 only when the records exist, because steps taken out of order are redone.","\nTo get ISO 27001 certification, a company defines and records its scope, assesses its risks, writes the Statement of Applicability across all 93 Annex A controls, runs the management system long enough to have records, chooses a certification body accredited for ISO\u002FIEC 27001, and passes a Stage 1 document review followed by a Stage 2 audit of the running system. Four to seven months is realistic for a small software company, then a surveillance audit each year and recertification in year three. The steps are sequenced, and steps taken out of order have to be redone.\n\n## 1. Define the scope, and write it down\n\nWhat the certificate covers: which parts of the organisation, which services, which locations. Scope drives everything after it, including the audit fee, because auditor days come from the covered headcount. Write it narrowly and truthfully. A scope that overreaches costs days and invites findings in areas you did not need certified.\n\n## 2. Context, interested parties, and the risk assessment\n\nClauses 4 and 6. What affects your ability to run an information security management system, who has a stake in it, and what could go wrong. This is the foundation an auditor tests everything else against.\n\n## 3. The Statement of Applicability\n\nClause 6.1.3, and the document a certification body reads first. All 93 Annex A controls, each declared applicable or excluded, each with a justification. Exclusions are legitimate and must be justified. An SoA that marks everything applicable to look thorough creates 93 things to evidence.\n\n## 4. Run the system, and keep the records\n\nPolicies approved, risks treated, suppliers assessed, access reviewed, incidents handled. This is where the calendar matters more than the documents: the auditor will ask for records covering a period, so the system has to have been running, not merely designed.\n\nMinimum before Stage 2: an internal audit and a management review, both with records. These are the two most common reasons a Stage 2 is postponed.\n\n## 5. Choose an accredited certification body\n\nSeparate company, contracted and paid directly. Verify accreditation for ISO\u002FIEC 27001 specifically, in the accreditation body's public register. [How to check](\u002Fiso-27001\u002Fcertification-bodies).\n\n## 6. Stage 1\n\nA readiness review, usually shorter and often remote. The auditor reads your documented information and decides whether Stage 2 is worth booking. Findings here are cheap. This is the point at which being genuinely ready saves money.\n\n## 7. Stage 2\n\nThe full audit. The auditor samples records and tests whether the system operates as documented. Nonconformities are raised as major or minor; majors must be corrected before a certificate issues.\n\n## 8. The three years after\n\nSurveillance audits each year at roughly a third of the initial audit time, then recertification at about two thirds. This is most of the cycle and most of the total cost. [The arithmetic](\u002Fiso-27001\u002Fcost).\n\n## The part that decides it\n\nWhether the evidence exists when it is asked for. Companies that struggle are rarely missing policies. They are missing the twelve months of records showing the policies were followed.\n",1789383986374]