Certification workflowGlobalISO/IEC 27001

ISO/IEC 27001 Certification Stage Workflow

Move from certification intent to audit-ready evidence by separating scope readiness, Stage 1 readiness work, Stage 2 implementation testing, finding closure, certification decision, and surveillance.

Certification is optional third-party conformity assessment. This workflow does not replace the certification body's audit plan, contract, finding rules, or accreditation requirements.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 24, 2026
Sections
6

Structured answer sets in this page tree.

Primary sources
9

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 24, 2026
Overview

An organization can implement ISO/IEC 27001 without seeking certification. If it chooses , use the certification body's plan as the authority for stage objectives, sampling, timing, finding classification, and closure. Before Stage 1, confirm that the ISMS scope is documented, risks are assessed, treatment decisions and the Statement of Applicability are current, internal audit and management review records exist, and evidence reflects the live environment.

Section 1

Readiness gate before engaging the certification body

Start by deciding whether the ISMS is mature enough for an external certification audit. ISO/IEC 27001 requires a documented scope, risk assessment and treatment, controlled documented information, internal audits at planned intervals, top-management review at planned intervals, and corrective action when nonconformities occur.

Confirm that the certification body is accredited for the relevant ISMS activity and can cover the proposed scope. ISO/IEC 17021-1 sets general requirements for management-system certification bodies, while ISO/IEC 27006-1 adds ISMS-specific requirements. Accreditation and certificate registers are verification tools, not proof that every claim made by a certified organization falls within its certificate scope.

  • Reconcile the proposed certificate scope with the documented ISMS boundary, including legal entities, sites, cloud environments, products, services, interfaces, dependencies, and externally provided processes.
  • Check that risk criteria, risk register, risk treatment plan, Statement of Applicability, control owners, internal-audit results, management-review outputs, and corrective-action records are current.
  • Select an body and record the accreditation body, scheme, scope, audit team competence questions, and certificate-verification method.
  • Do not book Stage 1 as a discovery workshop; treat it as an external review of a management system that already exists.
Section 2

Stage 1: confirm the ISMS is defined and ready for Stage 2

Stage 1 normally tests whether the ISMS definition and readiness support proceeding to Stage 2, but the certification body's plan controls the exact objectives and activities. Prepare controlled documented information and the records needed to show that the management system has operated; do not assume Stage 1 is limited to a desk review.

Translate every Stage 1 concern into an action with an owner, due date, evidence, and closure criterion. The certification body decides whether scope uncertainty, incomplete risk treatment, weak SoA justification, internal-audit gaps, or missing management-review evidence affects Stage 2 scheduling.

  • Provide the ISMS scope statement, context and interested-party analysis, policy, objectives, risk methodology, risk assessment, treatment plan, and Statement of Applicability.
  • Show that internal audits covered the relevant ISMS processes and that management review considered audit results, risk changes, nonconformities, corrective actions, performance, and improvement needs.
  • Record every Stage 1 concern with owner, evidence needed, closure criterion, due date, and whether it blocks Stage 2.
  • If the certification body concludes that the ISMS is not ready, retain its concern and the organization's response, revise the audit plan, and proceed to Stage 2 only when the certification body accepts the next step.
  • Update the certification plan if the auditor finds that the scope, locations, outsourced processes, or control evidence do not match the system being certified.
Section 3

Stage 2: test implementation evidence, not document existence

Stage 2 evaluates conformity and effective implementation inside the proposed certification scope. Expect sampling of management-system processes and necessary controls, including organization-designed or other-source controls where relevant, rather than an audit of Annex A in isolation.

Prepare evidence by process and accountable owner. For a sampled control, show why it is necessary, how it is implemented, where current operating records live, and which exception, risk decision, or corrective action remains open.

  • Map each sampled necessary control to its Statement of Applicability entry, inclusion rationale, implementation status, owner, risk or requirement, procedure, system record, and operating sample.
  • Prepare implementation samples for access control, asset management, supplier services, incident management, logging, vulnerability handling, backup, continuity, secure development, and awareness where they are in scope.
  • Keep interview evidence consistent with the written ISMS: owners should know the process they operate and where current records are kept.
  • Separate a missing record from an ineffective control. The first may require evidence retrieval; the second usually requires root-cause analysis and corrective action.
Section 4

Findings, nonconformities, and corrective actions

The certification body classifies nonconformities under the applicable certification requirements and its documented procedures. Internally, also tag the issue by cause or work type, such as a document gap, implementation failure, scope mismatch, or management-system weakness. Clause 10.2 requires the organization to react to a nonconformity, address consequences, evaluate causes and similar issues, implement needed action, review effectiveness, and retain evidence.

Do not close a nonconformity with a rewritten policy alone unless the root cause was only the policy. Most certification findings need operating evidence that the fix was implemented and that similar issues were considered elsewhere in the ISMS.

  • For each finding, capture requirement, audit evidence, affected scope, severity, owner, root cause, correction, corrective action, effectiveness check, and closure evidence.
  • Use management review or a delegated risk forum when a finding changes resources, risk acceptance, objectives, or certification scope.
  • Keep corrective-action records linked to the original audit report so surveillance auditors can verify closure and recurrence risk.
  • Do not relabel unresolved nonconformities as improvement items to protect the certification schedule.
Section 5

Certification decision, certificate checks, and surveillance

After Stage 2 and the required review of findings, the certification decision should be treated as a governance record. Store the audit report, nonconformity closure evidence, certificate scope, certificate number, certification body, accreditation body, issue and expiry information, and public verification route.

The certification body, not the organization or its consultant, makes the certification decision. A favorable decision supports conformity only for the stated ISMS scope and sampled audit evidence; it is not a guarantee that no incident, control failure, or legal breach can occur.

Certification is not the end of the workflow. Surveillance audits should verify that the ISMS still matches the certified scope, risks and controls remain maintained, corrective actions stay closed, and changes are reflected in risk treatment, the Statement of Applicability, internal audit planning, and management review.

  • Verify the published certificate through the certification body or an accreditation-backed tool, especially before using it in customer assurance or procurement responses.
  • Create a surveillance calendar covering internal audits, management review, risk reassessment, SoA review, supplier/control sampling, evidence refresh, and corrective-action follow-up.
  • Trigger an out-of-cycle review when products, hosting, legal entities, sites, suppliers, cloud architecture, or material risks change.
  • Before recertification, confirm that the full certification cycle has evidence for performance evaluation, improvement, unresolved findings, and scope changes.
Section 6

Transition and recertification considerations

IAF MD 26:2023 Issue 2 set 31 October 2025 as the deadline for bodies to complete certified-client transitions. It states that certifications based on ISO/IEC 27001:2013 expire or are withdrawn at the end of the transition period. A certificate presented as current after that date should identify ISO/IEC 27001:2022 and be checked through its issuing certification body or an applicable accreditation-backed register.

Edition transition and recertification require a substantive ISMS review. When the standard edition, Annex A mapping, certification scope, or audit programme changes, run a gap analysis and update risk treatment, the Statement of Applicability, control evidence, internal-audit coverage, and management-review inputs.

  • Verify that the certificate identifies ISO/IEC 27001:2022, the correct organization and scope, the issuing certification body, validity dates, and a credible verification route.
  • For recertification, review the whole cycle: Stage 1 and Stage 2 findings, surveillance results, internal audits, management reviews, changes in risk, and corrective-action effectiveness.
  • Do not reuse the old Statement of Applicability after a control-set transition without recording the comparison, retained controls, exclusions, new controls, and implementation status.
  • For future amendments or edition changes, record the authoritative publication, certification-body instructions, applicable transition rule, responsible owner, evidence gaps, and decision date rather than assuming the old transition timetable applies.
Primary sources

References and citations

anab.ansi.org
Referenced sections
  • Accreditation-body source for ISO/IEC 27001 certification-body accreditation context.
"ISO/IEC 27001: Information Security Management Systems"
certcheck.ukas.com
Referenced sections
  • Public UKAS-backed tool for checking management-system certificates issued by UKAS-accredited bodies.
"CertCheck"
iaf.nu
Referenced sections
  • IAF certification database used to improve transparency and monitoring of accredited certifications.
"verify and monitor certifications"
iaf.nu
Referenced sections
  • Clause 3 sets 31 October 2025 as the certified-client transition deadline; Clause 4.2 states that 2013-edition certifications expire or are withdrawn at the end of the transition period.
"All certifications based on ISO/IEC 27001:2013 shall expire or be withdrawn at the end of the transition period."
iso.org
Referenced sections
  • ISO/IEC 17021-1 establishes general requirements for competent, consistent, and impartial management-system certification and identifies certification as third-party conformity assessment.
"Certification of management systems is a third-party conformity assessment activity"
iso.org
Referenced sections
  • Primary ISO listing for the ISMS requirements standard that defines the certification target.
"Information security management systems — Requirements"
iso.org
Referenced sections
  • Primary ISO page for information security control guidance used alongside ISO/IEC 27001 Annex A control selection.
"Information security controls"
iso.org
Referenced sections
  • This source supports risk-management planning used in certification readiness evidence.
"Guidance on managing information security risks"
iso.org
Referenced sections
  • Explains the standard used by bodies that audit and certify ISMSs.
"Ensures consistent and impartial audit practices"
Related guides

Explore more topics

ISO/IEC 27001 Annex A Control Evidence Guide
Build useful ISO/IEC 27001:2022 Annex A control evidence: selected controls, SoA rationale, owners, implementation proof, effectiveness checks, audit records, and improvement actions.
ISO/IEC 27001 Annex A Control Ownership FAQ
How to assign practical owners for ISO/IEC 27001 Annex A controls without confusing control ownership with the standard's required risk-owner accountability.
ISO/IEC 27001 Audit Readiness Guide
Prepare ISO/IEC 27001 audit evidence across ISMS scope, risk assessment, risk treatment, Statement of Applicability, Annex A controls, internal audit, management review, and corrective actions.
ISO/IEC 27001 Certification Body Evidence FAQ
What ISO/IEC 27001 certification auditors may sample, how to connect requirements to operating evidence, and what the certification body does not own.
ISO/IEC 27001 Compliance Guide: ISMS Evidence
Build ISO/IEC 27001:2022 conformity evidence for ISMS scope, leadership, risk assessment and treatment, the Statement of Applicability, operations, audits, management review, and corrective action.
ISO/IEC 27001 FAQ: ISMS Scope, Risk and SoA
Practical ISO/IEC 27001 FAQ covering ISMS scope, risk assessment, risk treatment, Statement of Applicability, Annex A controls, certification evidence, audits, management review, and surveillance readiness.
ISO/IEC 27001 Implementation Roadmap Guide
A practical ISO/IEC 27001:2022 roadmap from context and scope through risk treatment, the SoA, control operation, internal audit, management review, corrective action, and optional certification.
ISO/IEC 27001 Internal Audit and Management Review Guide
Keep ISO/IEC 27001 internal audit and management review distinct and connected: independent audit evidence, top-management decisions, corrective actions, resources, and improvement records.
ISO/IEC 27001 Internal Audit FAQ
How should teams run ISO/IEC 27001 internal audits: who should own each step, what evidence is expected, and how findings are resolved.
ISO/IEC 27001 Management Review FAQ
What ISO/IEC 27001 management review must consider, what top management must decide, what evidence to retain, and how to set the cadence.
ISO/IEC 27001 Requirements Guide
Plain-language guide to ISO/IEC 27001:2022 Clauses 4-10: context, leadership, planning, support, operation, performance evaluation, improvement, and Annex A control selection.
ISO/IEC 27001 Risk Acceptance FAQ
How ISO/IEC 27001 risk acceptance works: criteria, risk-owner approval, residual-risk evidence, external obligations, and reassessment triggers.
ISO/IEC 27001 Risk Treatment and Residual Risk Guide
Connect ISO/IEC 27001 risk-treatment choices, necessary controls, the treatment plan, Statement of Applicability, residual-risk acceptance, owners, evidence, and review triggers.
ISO/IEC 27001 Risk Treatment Register Workflow
Build an ISO/IEC 27001 risk-treatment register that links assessed risks to treatment options, controls, SoA entries, actions, owners, residual-risk approval, evidence, and review triggers.
ISO/IEC 27001 SoA Exclusions FAQ
How should teams justify Statement of Applicability exclusions under ISO/IEC 27001? Practical answer with owners, evidence, review triggers, and external source references.
ISO/IEC 27001 SoA: workflow for gathering and documenting control evidence
Operate the ISO/IEC 27001 Statement of Applicability as a live evidence index linking necessary controls, Annex A inclusion and exclusion rationale, implementation status, owners, and proof.
ISO/IEC 27001 Statement of Applicability template: Annex A control selection and justification
Practical ISO/IEC 27001:2022 Statement of Applicability template fields for necessary controls, Annex A applicability, inclusion and exclusion rationale, status, owners, evidence, and review history.
ISO/IEC 27001 Surveillance Audits FAQ
What ISO/IEC 27001 surveillance audits check, how they differ from internal audit and recertification, and what evidence to maintain between audits.
ISO/IEC 27001 vs NIS2 Comparison
Compare voluntary ISO/IEC 27001 ISMS conformity and optional certification with NIS2 legal duties, entity scope, management accountability, incident reporting, supervision, and penalties.
ISO/IEC 27001 vs NIST CSF 2.0 Comparison
Compare ISO/IEC 27001:2022's certifiable ISMS requirements with NIST CSF 2.0's cybersecurity outcomes, Profiles, Tiers, Functions, evidence uses, and adoption choices.
ISO/IEC 27001 vs SOC 2 Comparison
Compare ISO/IEC 27001 certification with SOC 2 examination reports: criteria, scope, assurance period, auditor and certification-body roles, deliverables, evidence reuse, and claim limits.