ISO/IEC 27001:2022

The road to ISO/IEC 27001:2022 certification

A management system, not a control checklist. What the standard actually requires, why Stage 1 audits fail, and the records auditors ask for that nobody thinks to keep.

The 2013 version is gone

The transition window closed on 31 October 2025. Certificates against ISO/IEC 27001:2013 are no longer valid, and every new or renewed certificate is against the 2022 revision: 93 Annex A controls organized into four themes rather than 114 across fourteen domains. If a supplier shows you a 2013 certificate today, it has expired.

ISO 27001 certifies a management system. The 93 controls in Annex A get most of the attention, but they are the appendix. Clauses 4 through 10 are the standard, and they are where certification is won or lost.

Read this if

  • You sell into Europe, the UK, or to enterprises that ask for ISO rather than SOC 2
  • You want a certificate rather than an attestation report
  • You already hold SOC 2 and want to reuse the work
  • You are being asked for ISO by a customer who will not accept anything else
The roadmap

What the program actually looks like.

Durations assume a first attempt with a team that has other work to do. They are the numbers we would give you on a call, not the ones in a sales deck.

Define scope and context

3 to 5 weeks

Clauses 4 and 5. Determine the boundary of the management system, identify interested parties and their requirements, and secure genuine leadership commitment. A scope statement that is too broad is the most expensive mistake available at this stage, and it is nearly impossible to narrow later.

You come out with: A written scope statement, context analysis, and an information security policy signed by top management.

Risk assessment and Statement of Applicability

4 to 6 weeks

Clause 6. Establish a repeatable risk methodology, run it, and produce a risk treatment plan. The Statement of Applicability then records all 93 Annex A controls with a decision and a justification for each, including the ones you exclude.

You come out with: A risk register with owners and treatment decisions, and an SoA you can defend line by line.

Build the management system

6 to 12 weeks

Clause 7 and the Annex A controls you have accepted. Policies, procedures, competence and awareness, documented information control. This is the bulk of the build, and the point where most organizations discover their existing documentation does not meet the requirement.

You come out with: A working ISMS: policies people follow, defined roles, training records, and controlled documents with version history.

Operate and generate records

3 to 6 months

Clause 8 and 9. The system has to run and produce evidence. Auditors will ask what you did, when, and who approved it. Records created retrospectively are visible as such and will be treated accordingly.

You come out with: Operational records, monitoring results, and measurable objectives with actual measurements against them.

Internal audit and management review

3 to 5 weeks

Clause 9.2 and 9.3. Both are mandatory and both must happen before Stage 2. The internal audit must be performed by someone independent of the area being audited, which usually means not the person who built the ISMS.

You come out with: An internal audit report with findings, corrective actions raised and closed, and management review minutes covering every required input.

Stage 1 audit

1 to 2 days, then 4 to 8 weeks

The certification body reviews your documentation and readiness. Failures here are almost always missing management system records rather than missing technical controls. You then get a gap to close whatever they found.

You come out with: A Stage 1 report and a corrective action plan for anything raised.

Stage 2 audit and certification

3 to 5 days

The full assessment of implementation and effectiveness. Findings are graded as minor or major nonconformities; majors must be closed before the certificate issues.

You come out with: The certificate, valid three years, with surveillance audits in years one and two and recertification in year three.
Where the time goes

The five things that consume the calendar.

None of these are the parts people budget for, and all of them are the parts that slip.

  • The risk assessment, done properly rather than as a spreadsheet completed in an afternoon.
  • The Statement of Applicability, because 93 justifications is genuinely a lot of writing.
  • Accumulating operational records, which is calendar time and cannot be compressed.
  • Internal audit, which needs a competent and independent person you may not have.
  • Certification body scheduling, which can add six to ten weeks if you leave it late.
Cost drivers

What moves the number.

Two organizations of the same size can differ several-fold on price. This is usually why.

  • Scope: number of locations, legal entities and systems included
  • Headcount, which drives certification body audit days directly
  • How much documented management system already exists
  • Whether you need an external internal auditor
  • Certification body choice, where accreditation matters more than price
Deliverables

What you have to produce.

Every one of these will be asked for. Missing any of them is a finding.

ArtifactWhat it has to contain
Scope statementThe boundary of the ISMS, precise enough to appear on the certificate
Information security policyApproved by top management, not by IT
Risk assessment methodology and registerRepeatable, documented, with owners and treatment decisions
Statement of ApplicabilityAll 93 Annex A controls, each included or excluded with justification
Risk treatment planWhat you are doing about the risks you did not accept
Objectives and measurementsSecurity objectives with actual numbers against them
Internal audit program and reportsIndependent, covering the whole ISMS over the cycle
Management review minutesCovering every input the standard lists
Corrective action recordsFindings raised, root cause, action, verification
How it goes wrong

Five failures we see repeatedly.

Each of these turns a manageable program into an expensive one. All five are avoidable at the start and very hard to fix in the middle.

Treating Annex A as the standard

Teams implement 93 controls beautifully and fail Stage 1 because there is no management review, no internal audit, and no evidence the risk assessment drove any of it. Clauses 4 to 10 are the certifiable part.

A scope statement written too wide

Certifying the whole organization when the customer only cares about one platform multiplies the audit, the evidence and the ongoing burden. Narrowing scope after certification means a new scope and effectively starting over.

Copying someone else's Statement of Applicability

The SoA has to reflect your risk assessment. An auditor who finds justifications that do not match your own risk register has found a systemic problem, not a paperwork one.

Internal audit performed by the ISMS owner

Clause 9.2 requires objectivity and impartiality. Auditing your own work is a nonconformity in itself, regardless of how well the audit was done.

Retrospective records

A year of management review minutes written the week before Stage 2 is obvious to anyone who has audited before. The dates, the language and the absence of any disagreement all give it away.

Questions

What people ask us about ISO 27001.

How long from a standing start?
Six to twelve months for most organizations. Under six is possible only where a real management system already exists and only the ISO framing is missing. The floor is set by needing enough operational records to audit.
Is ISO 27001 harder than SOC 2?
Different, not harder. SOC 2 asks whether your controls worked. ISO asks whether you have a system that decides which controls you need, checks that it is working, and improves itself. The documentation burden is heavier; the technical bar is often lower.
Can one program cover both ISO 27001 and SOC 2?
Yes, and it should. The control overlap is substantial and most evidence serves both. Run the risk assessment and control design once, map to both, and collect evidence once. Doing them as separate projects is the expensive way.
What is the difference between accredited and unaccredited certification?
An accredited certificate comes from a body overseen by a national accreditation authority. An unaccredited one is a company's opinion. Sophisticated buyers check, and the price difference is not worth the risk of being caught with a certificate that does not count.
What happens after we are certified?
Surveillance audits in years one and two, recertification in year three, and the management system has to keep running throughout. The certificate can be suspended if surveillance finds the ISMS has stopped operating.

Want this run for you?

We run these programs end to end: scoping, control design, evidence, auditor management, and the operating rhythm that keeps year two boring.