- Accreditation-body source for ISO/IEC 27001 certification-body accreditation context.
"ISO/IEC 27001: Information Security Management Systems"
Move from certification intent to audit-ready evidence by separating scope readiness, Stage 1 readiness work, Stage 2 implementation testing, finding closure, certification decision, and surveillance.
Certification is optional third-party conformity assessment. This workflow does not replace the certification body's audit plan, contract, finding rules, or accreditation requirements.
Structured answer sets in this page tree.
Cited legal and guidance references.
An organization can implement ISO/IEC 27001 without seeking certification. If it chooses , use the certification body's plan as the authority for stage objectives, sampling, timing, finding classification, and closure. Before Stage 1, confirm that the ISMS scope is documented, risks are assessed, treatment decisions and the Statement of Applicability are current, internal audit and management review records exist, and evidence reflects the live environment.
Start by deciding whether the ISMS is mature enough for an external certification audit. ISO/IEC 27001 requires a documented scope, risk assessment and treatment, controlled documented information, internal audits at planned intervals, top-management review at planned intervals, and corrective action when nonconformities occur.
Confirm that the certification body is accredited for the relevant ISMS activity and can cover the proposed scope. ISO/IEC 17021-1 sets general requirements for management-system certification bodies, while ISO/IEC 27006-1 adds ISMS-specific requirements. Accreditation and certificate registers are verification tools, not proof that every claim made by a certified organization falls within its certificate scope.
Stage 1 normally tests whether the ISMS definition and readiness support proceeding to Stage 2, but the certification body's plan controls the exact objectives and activities. Prepare controlled documented information and the records needed to show that the management system has operated; do not assume Stage 1 is limited to a desk review.
Translate every Stage 1 concern into an action with an owner, due date, evidence, and closure criterion. The certification body decides whether scope uncertainty, incomplete risk treatment, weak SoA justification, internal-audit gaps, or missing management-review evidence affects Stage 2 scheduling.
This workflow helps name accountable owners for readiness, Stage 1 actions, Stage 2 evidence, finding closure, certificate verification, surveillance, and recertification planning.
Create scoped tasks, evidence requests, finding-closure work, and surveillance reminders.
Review scope, Stage 1 document gaps, Stage 2 evidence, and corrective-action closure before the external audit.
Stage 2 evaluates conformity and effective implementation inside the proposed certification scope. Expect sampling of management-system processes and necessary controls, including organization-designed or other-source controls where relevant, rather than an audit of Annex A in isolation.
Prepare evidence by process and accountable owner. For a sampled control, show why it is necessary, how it is implemented, where current operating records live, and which exception, risk decision, or corrective action remains open.
The certification body classifies nonconformities under the applicable certification requirements and its documented procedures. Internally, also tag the issue by cause or work type, such as a document gap, implementation failure, scope mismatch, or management-system weakness. Clause 10.2 requires the organization to react to a nonconformity, address consequences, evaluate causes and similar issues, implement needed action, review effectiveness, and retain evidence.
Do not close a nonconformity with a rewritten policy alone unless the root cause was only the policy. Most certification findings need operating evidence that the fix was implemented and that similar issues were considered elsewhere in the ISMS.
After Stage 2 and the required review of findings, the certification decision should be treated as a governance record. Store the audit report, nonconformity closure evidence, certificate scope, certificate number, certification body, accreditation body, issue and expiry information, and public verification route.
The certification body, not the organization or its consultant, makes the certification decision. A favorable decision supports conformity only for the stated ISMS scope and sampled audit evidence; it is not a guarantee that no incident, control failure, or legal breach can occur.
Certification is not the end of the workflow. Surveillance audits should verify that the ISMS still matches the certified scope, risks and controls remain maintained, corrective actions stay closed, and changes are reflected in risk treatment, the Statement of Applicability, internal audit planning, and management review.
IAF MD 26:2023 Issue 2 set 31 October 2025 as the deadline for bodies to complete certified-client transitions. It states that certifications based on ISO/IEC 27001:2013 expire or are withdrawn at the end of the transition period. A certificate presented as current after that date should identify ISO/IEC 27001:2022 and be checked through its issuing certification body or an applicable accreditation-backed register.
Edition transition and recertification require a substantive ISMS review. When the standard edition, Annex A mapping, certification scope, or audit programme changes, run a gap analysis and update risk treatment, the Statement of Applicability, control evidence, internal-audit coverage, and management-review inputs.
"ISO/IEC 27001: Information Security Management Systems"
"CertCheck"
"verify and monitor certifications"
"All certifications based on ISO/IEC 27001:2013 shall expire or be withdrawn at the end of the transition period."
"Certification of management systems is a third-party conformity assessment activity"
"Information security management systems — Requirements"
"Information security controls"
"Guidance on managing information security risks"
"Ensures consistent and impartial audit practices"