Skip to Content

ISO 27001: how certification unfolds

Aim for certification ISO 27001, means committing to a structured approach to information security management. To move through it with confidence, it is better to understand the main steps, from the scope to theaudit, and then over the long term.

BCIT Formation logo
BCIT Formation is rated Excellent
4.7 · Trustpilot
+1,000 learners trained

What exactly is certified?

Certification ISO 27001 does not apply to a product, but to an information security management system (ISMS): the full set of governance, processes and controls through which an organization manages its security risks within a defined scope.

The certification audit is performed by an accredited body, independent from the consultant supporting you. Our role is to prepare you so you can approach that audit with confidence: see our page on ISO 27001 certification support.

The main steps

Define the scope

Define what the ISMS covers (activities, sites, systems) and formalize the security policy.

Analyze risks

Identify, assess and treat risks (for example with EBIOS), then select the controls.

Write the SoA

The statement of applicability justifies the controls selected (and excluded) in relation to Annex A of the standard.

Deploy & keep it alive

Implement the controls, raise awareness, conduct internal audits and management review.

A two-stage audit, then a 3-year cycle

The certification audit takes place in two stages: stage 1 (document review and assessment of ISMS maturity), followed by stage 2 (on-site audit of the actual effectiveness of controls). If successful, the certificate is issued for three years, with annual surveillance audits and a recertification audit at the end of the cycle. Certification is therefore not an end point, but the beginning of continuous improvement.

The key factor: preparation

Most audit findings come from an ISMS that is not sufficiently embedded: policies not applied, missing evidence, internal audits not performed. The key is therefore to build a realistic and operational system, not a binder of documents. A mock audit before the certification audit helps close the remaining gaps without stress.

Toward certification, step by step

1

Frame the scope & policy

Define what is covered and secure management commitment.

2

Conduct the risk assessment

Assess risks and define the treatment plan.

3

Establish the SoA & controls

Write the statement of applicability and deploy the selected controls.

4

Operate the ISMS

Raise awareness, produce evidence, conduct internal audits and management review.

5

Perform a mock audit

Identify and correct gaps before the certification audit.

6

Pass the audit & maintain

Pass stages 1 and 2, then maintain the ISMS throughout the 3-year cycle.

Approach audit day with confidence

Document readiness

The auditor asks for evidence, not intentions: up-to-date policies, management review minutes, internal audit results, incident register. Prepare an organized and easy-to-navigate evidence file before the audit, rather than reconstructing it under pressure.

Continuous improvement mindset

A mature ISMS is not an ISMS with no gaps: it is an ISMS that knows how to detect and correct them. Show the auditor a history of internal audits, corrective actions and management reviews proving that the system is alive and improving, not that it was created for the occasion.

Nonconformity management

A nonconformity raised during an audit is not a failure: the standard provides for a corrective action plan within a defined timeframe. What matters to the certification body is your ability to analyze the root cause, correct it and provide evidence of correction within the allotted time.

Why work with BCIT?

A realistic ISMS

We build an operational system tailored to you, not a mountain of paperwork.

Certified experts

We use the frameworks and training courses from PECB to develop your teams' skills.

Through to the certificate

Discover our ISO 27001 support, from scoping to the audit.

Aim for ISO 27001 methodically

Let's take 15 minutes to assess your maturity and build a roadmap toward certification ISO 27001.