ISO 27001 is the internationally recognised standard for information security management. This guide walks you through everything from your first gap assessment to passing your Stage 2 certification audit — without the jargon.
ISO 27001 is a management system standard, not a one-time audit. Certification requires ongoing operation of an Information Security Management System (ISMS). Before starting, confirm senior management support, assign ownership, and set a realistic timeline — typically 6–12 months for a first certification.
ISO 27001 requires demonstrable leadership commitment — the standard explicitly mandates it. Assign an ISMS owner with authority to act and a budget to match.
Decide upfront what the ISMS will cover: the whole organisation, a specific department, a product line, or a set of services. Broader scope means more controls and more evidence.
Realistically, 6 months is achievable for a small organisation starting from scratch. Larger or more complex environments often need 9–12 months before Stage 1 audit.
What they look for
Your auditor will look for evidence of management commitment at Stage 1: signed terms of reference for the ISMS project, an assigned ISMS owner with documented authority, and minutes from a management meeting where the ISMS scope and objectives were agreed. Without these, you cannot demonstrate that Clause 5 (Leadership) is met.
ISO 27001:2022 has 93 controls across four themes: Organisational, People, Physical, and Technological. A gap assessment identifies which controls you already have in place, which are partially implemented, and which are missing entirely. This shapes your project plan.
Policies, supplier relationships, asset management, information classification, incident management, and business continuity planning.
Screening, terms of employment, security awareness training, and responsibilities during and after employment.
Physical security perimeters, clear desk and clear screen, equipment security, and off-site working.
Access control, cryptography, endpoint security, network security, vulnerability management, and secure development.
What they look for
Your gap assessment must be dated, scoped, and systematic — not a list of things you thought of. Auditors expect to see all 93 Annex A controls assessed, with a status for each: implemented, partially implemented, not applicable, or not implemented. A spreadsheet mapping each control to evidence references is what Stage 1 auditors actually work from.
The scope statement is a formal document that defines the boundaries of your ISMS. It must be written before you can complete a risk assessment, and it will be reviewed by your auditor at Stage 1. Be specific about what is and is not included.
Systems, locations, departments, services, and processes that process or store information assets within scope. Third-party services used to deliver in-scope activities.
Systems or sites not in scope must be named and the exclusion justified. Auditors look for scope creep — be clear about the boundary.
Clause 4 requires you to document internal and external issues that affect your ISMS, and to identify interested parties (regulators, clients, insurers) and their requirements.
What they look for
The scope statement is the first document reviewed at Stage 1. It must name the assets, locations, departments, and services in scope. Any exclusions must be named and justified. Auditors look for scope creep — systems that obviously should be in scope but are not. A narrow scope needs a credible justification, not just a decision.
Clause 6.1 requires a documented risk assessment methodology. You must identify information assets, assess the threats and vulnerabilities relevant to each, score the likelihood and impact, and decide how to treat each risk. This becomes your Risk Register.
List your information assets: databases, applications, physical documents, laptops, servers. Each asset needs an owner and a classification.
For each asset, identify credible threats (ransomware, accidental disclosure, supplier failure) and vulnerabilities that make those threats exploitable.
Score likelihood and impact. Most organisations use a 1–5 scale for each, producing a 1–25 risk score. Document the scoring rationale — auditors will ask.
For each risk: mitigate (implement a control), accept (document the decision and owner), transfer (insurance or contract), or avoid (stop the activity).
What they look for
Your risk register must document: the risk, the asset it relates to, the threat and vulnerability that create it, likelihood and impact scores, and the treatment decision with rationale. Auditors will sample entries and ask the risk owner to explain them. Risk register entries that cannot be explained by their owner are a finding.
The Statement of Applicability (SoA) is one of the most important documents in ISO 27001. It lists all 93 Annex A controls, states whether each is applicable to your ISMS, and if applicable — whether it is implemented. Exclusions must be justified. The SoA is formally reviewed during Stage 2 audit.
For each control you include, state the justification (legal requirement, contractual obligation, risk treatment, business requirement) and implementation status.
Any of the 93 controls you exclude must have a written justification. "Not applicable to our business" is not sufficient without explanation.
Controls selected as risk treatments must be traceable back to your risk register. Your auditor will check this traceability.
What they look for
The SoA is reviewed in detail at Stage 2. Auditors will pick controls from Annex A and ask: is this applicable? If yes, show me the evidence of implementation. If excluded, why? Every exclusion must have a written justification. Saying 'not applicable' for a control that auditors consider relevant will result in a nonconformity.
ISO 27001 specifies a minimum set of documented information that must exist. These are not optional — auditors will check for each one. The level of detail required is proportionate to the size and complexity of your organisation.
Formalises what is in and out of scope. Referenced throughout the audit.
Top-level policy signed by leadership, covering the purpose of the ISMS and the organisation's commitment to information security.
Documents how you identify and score risks, and what risks were identified.
For each risk requiring treatment: what control addresses it, who owns it, and the target implementation date.
All 93 controls, inclusion/exclusion justification, and implementation status.
Evidence that internal audits have been planned and conducted before Stage 2.
Minutes or notes from a formal management review of the ISMS — required at least annually and before certification.
What they look for
Auditors check for the presence of each mandatory document and then sample-test whether they reflect actual practice. A policy document that describes a process no one follows is a nonconformity. The question is not 'does this document exist' but 'does this document describe what actually happens'.
Before your Stage 2 certification audit, you must complete at least one internal audit of your ISMS and a management review. The internal audit checks that your ISMS is operating as intended. The management review is a formal senior-level review of ISMS performance.
The internal audit must cover all ISMS requirements — not just controls, but also the management system requirements in clauses 4–10.
Any nonconformities found in the internal audit must be formally recorded and addressed through your corrective action process before Stage 2.
The standard specifies what must be reviewed: audit results, risk treatment progress, ISMS performance, incident statistics, and objectives.
What they look for
Your internal audit programme must be documented before Stage 2 — planned dates, scope, and the auditor's name. Internal audit results must show findings (including nonconformities), and your corrective action register must show how you addressed them. A clean internal audit with no findings looks suspicious; auditors expect organisations to find issues internally first.
ISO 27001 certification is issued by an accredited certification body (CB). The process involves two audits: Stage 1 (a documentation review, typically half a day to a day) followed by Stage 2 (an on-site audit of your ISMS in operation). Certification is typically valid for three years with annual surveillance audits.
Use an accredited body — UKAS-accredited in the UK. Check that they have experience in your sector. Get at least two quotes. Costs vary significantly by organisation size.
The auditor reviews your ISMS documentation — scope, SoA, risk register, policies. They produce a Stage 1 report and confirm readiness for Stage 2. Gaps found at Stage 1 must be addressed before proceeding.
The full on-site audit. Auditors sample your controls in operation — interviewing staff, checking access controls, reviewing logs, and testing whether your procedures are actually followed.
Minor nonconformities allow certification once you submit a corrective action plan. Major nonconformities require re-audit. The goal is to have no nonconformities — your internal audit should catch them first.
What they look for
Your Stage 1 auditor provides a list of pre-conditions for Stage 2. Every item on that list must be addressed before proceeding. Stage 2 auditors sample controls in operation: they interview staff, review access control configurations, check system logs, and verify that procedures are actually followed — not just documented.
Where people go wrong
Starting documentation before completing the gap assessment
Many organisations jump straight to writing policies before understanding where they stand. A thorough gap assessment tells you which of the 93 controls you already have in place — so you do not document policies for controls you already implement informally.
Risk register entries that are vague or cannot be explained by their owner
A risk register entry like 'cyber attack — high' with no asset, no threat, and no owner is not a risk register entry. Auditors will ask the named risk owner to walk them through specific risks. If the owner has never seen the register, that is a major finding.
Statement of Applicability that excludes controls without sufficient justification
Excluding 'secure development' controls because your team does not write code is reasonable. Excluding 'access control' controls because they seem complex is not. Every exclusion needs a clear, documented reason that an auditor will accept.
Internal audit conducted by the ISMS owner
The internal auditor must be independent of the area being audited. If the ISMS owner conducts the internal audit of the ISMS, this is a conflict of interest and a nonconformity. Use a different internal auditor or a consultant for the pre-certification internal audit.
Going straight to Stage 2 without addressing all Stage 1 findings
Stage 1 produces a list of pre-conditions. Proceeding to Stage 2 with open Stage 1 findings is almost guaranteed to result in major nonconformities. Address every Stage 1 finding before scheduling Stage 2, regardless of how minor it seems.
How long does ISO 27001 certification take?
For a small organisation (under 50 people) starting from scratch, 6–9 months is realistic if the project is properly resourced. Larger or more complex organisations typically need 9–18 months. The biggest delays are usually documentation completion and corrective action on internal audit findings.
How much does ISO 27001 certification cost?
Costs vary significantly. Certification body audit fees for a small organisation typically start at £2,000–£4,000 for the initial Stage 1 and Stage 2 combined, plus £1,000–£2,000 for annual surveillance audits. Add internal staff time, any consultant support, and tooling. Total project cost for a 20-person company is often £8,000–£25,000 depending on how much external support is used.
Do we need all 93 Annex A controls?
No — controls can be excluded if there is a justified reason. For example, a company with no physical offices can exclude some physical security controls; a company with no custom software development can exclude secure development controls. All exclusions must be documented in the Statement of Applicability with justification.
What is the difference between ISO 27001 and Cyber Essentials?
Cyber Essentials is a simpler, UK government-backed scheme focused on five technical controls to defend against common cyber attacks. ISO 27001 is an internationally recognised management system standard covering the full scope of information security — governance, risk management, physical security, personnel security, and technology controls. Cyber Essentials takes weeks; ISO 27001 takes months. Both are complementary — many organisations hold both.
Can we achieve ISO 27001 without a consultant?
Yes, but it requires significant internal resource and someone who is prepared to become an expert in the standard. The most common approach is a hybrid: use a consultant for the gap assessment, SoA, and audit preparation, while internal staff own the day-to-day documentation and evidence. Fortify's portal can significantly reduce the documentation and tracking effort.
Fortify's free ISO 27001 readiness check walks you through the key clauses and Annex A control themes, giving you a scored gap report and a prioritised action list in around 15 minutes.