Compliance & GRC

ISO 27001 Explained: What Certification Actually Requires

ISO 27001 is the most widely recognised international standard for information security management, and it is frequently misunderstood by the organisations pursuing it. It does not certify that your systems are secure. It certifies that you operate an information security management system — a documented, evidence-producing process for identifying risks and doing something about them.

ISO 27001 Explained: What Certification Actually Requires

What an ISMS actually is

The management system is the substance of the standard. It requires you to define a scope, identify information security risks, decide how to treat them, implement controls, monitor whether they work, and improve based on what you find.

That cycle must be genuine and repeatable, because certification is evidence-based. An auditor is not primarily assessing whether your firewall configuration is elegant — they are assessing whether you can demonstrate that risks were identified, decisions were taken by someone with authority, and the resulting controls are operating.

The structure of the standard

The main clauses cover the management system itself: context of the organisation, leadership, planning, support, operation, performance evaluation and improvement. These are mandatory.

Annex A provides a catalogue of controls, restructured in the 2022 revision into four themes — organisational, people, physical and technological. Annex A controls are not all mandatory. You select what is applicable based on your risk assessment, and document the reasoning in a Statement of Applicability, which is one of the documents auditors examine most closely.

Scope definition shapes cost more than any other decision
Scope definition shapes cost more than any other decision

Scope is the decision that matters most

Scope determines cost, effort and how useful the certificate is. Too narrow and customers will notice the certificate does not cover the service they buy. Too broad and you are implementing controls across parts of the business that carry little risk.

The scope statement appears on the certificate, so a sophisticated customer will read it. Defining it around the products and services customers actually care about, plus the infrastructure and teams supporting them, is usually the right balance.

How certification works

  1. Gap analysis — compare current practice against the standard to size the work honestly.
  2. Build the ISMS — scope, risk methodology, risk assessment, treatment plan, policies and the Statement of Applicability.
  3. Implement and operate — controls must run long enough to generate evidence, which is why this stage cannot be compressed indefinitely.
  4. Internal audit — required by the standard, and genuinely useful for finding problems before the external auditor does.
  5. Management review — documented leadership engagement, which auditors check specifically.
  6. Stage 1 audit — largely documentation, confirming the ISMS is designed appropriately.
  7. Stage 2 audit — the substantive audit, testing whether the system operates as described.
  8. Surveillance and recertification — ongoing audits across a three-year cycle, so certification is a commitment rather than an event.
Auditors look for evidence that a process actually runs
Auditors look for evidence that a process actually runs

What commonly goes wrong

  • Buying a policy template set and stopping there. Policies nobody follows fail immediately, because auditors ask for evidence of operation.
  • A risk assessment written once and never revisited. The standard expects it to be live.
  • Absent leadership involvement. Management review is explicitly required, and its absence is a common non-conformity.
  • No evidence trail. If access reviews happened but were never recorded, they cannot be audited.
  • Treating it as a security project rather than a business one. HR, legal, procurement and facilities all sit inside a typical scope.
  • Confusing certification with security. A certified organisation with a badly configured perimeter is entirely possible, which is why technical testing remains necessary alongside.

Related from TechBiz Security

Sources & further reading

Frequently asked questions

What is ISO 27001?
It is an international standard for information security management. Certification demonstrates that an organisation operates a documented information security management system — a repeatable process for assessing risk and managing controls — rather than certifying any specific product or configuration.
How long does ISO 27001 certification take?
It depends heavily on scope and starting maturity, but the controls must operate long enough to generate evidence before the Stage 2 audit, so the timeline cannot be compressed indefinitely. A gap analysis is the only reliable way to estimate it for your organisation.
Are all Annex A controls mandatory?
No. Annex A is a catalogue from which controls are selected based on your risk assessment. Exclusions are permitted provided the reasoning is documented in the Statement of Applicability, which auditors examine closely.
Does ISO 27001 certification mean we are secure?
It means you have a functioning system for managing security risk, which is valuable but not the same thing. Certification does not validate technical configuration, so penetration testing and technical assessment remain necessary alongside it.

Related reading

0 comments

Leave a comment

Comments are moderated before appearing.