ISO/IEC 27001:2022
ISO 27001
ISO 27001 certifies an Information Security Management System, not a checklist. That distinction is where most programs underestimate the work: the auditor is assessing whether you run a managed system, including the risk treatment, the internal audits and the management reviews.
What the engagement covers
Organisations selling internationally or to enterprise buyers. Typical timeline: 6 to 12 months to certification.
- Scoping the ISMS so the boundary is defensible and no larger than it needs to be
- Risk assessment and risk treatment plan, with the Statement of Applicability that follows from it
- Annex A control implementation against the 2022 control set
- Internal audit programme and management review, which certification bodies check and clients routinely forget
- Stage 1 and Stage 2 audit support, and the surveillance cycle afterwards
Phases
Where an engagement sits at any point, in the language your assessor uses.
- Scoping and gap assessment
- Risk treatment and control implementation
- Internal audit and management review
- Stage 2 passed, certificate issued
Related reading
- Placeholder: ISO 27001 article
Pulled from the legacy archive until this section is migrated.
- Placeholder: ISO 27001 article
Legacy URL preserved.
Common questions
Is ISO 27001 the same as SOC 2?
No. SOC 2 produces an attestation report from a CPA firm about controls over a period. ISO 27001 produces a certificate from an accredited body confirming you operate a management system. Buyers in the US usually ask for SOC 2, buyers outside it usually ask for ISO 27001, and organisations selling to both often need both. The underlying control work overlaps heavily.
What is the Statement of Applicability?
The document listing every Annex A control, whether it applies to you, and why. It is the spine of the certification and the first thing an auditor reads. Written properly it makes the audit shorter; written as a formality it makes it longer.
Does certification expire?
Certificates run on a three year cycle with surveillance audits in between. The system has to keep running, which is why organisations that treat certification as a project rather than a programme struggle at the first surveillance audit.
START HERE
Do not guess how far away you are.
A scored assessment against the ISO 27001 control set gives you your gap, your timeline and your cost. Fixed price from $15,000, two to four weeks, quoted before any work starts. Most clients then continue into a Virtual CISO engagement or managed compliance, but nothing obliges you to.
Start with a scope
Bring the deadline and who is asking for it. Thirty minutes.