iso27001partnersUK certification, costed Get a cost estimate

The ISO 27001 certification process, end to end

Written from the standards themselves · Editor-reviewed · Checked against the current editions on 20 September 2026
By the iso27001partners.co.uk editorial team · Published 20 September 2026 · Last reviewed 20 September 2026 · 10 min read
5 primary sources cited on this page. How we check what is on this site
The constraint nobody mentions on the first call Clauses 9.2 and 9.3

You cannot sit Stage 2 until you have run an internal audit and held a management review, and neither is meaningful unless the management system has actually been operating. That is the floor under your timeline, and money does not move it.

The audit is the part with a published length and it is the short part. Everything before it is your work, has no fixed duration, and is where both the cost and the delay actually live.

The ISO 27001 certification cycle over three years A timeline running from gap analysis through implementation, internal audit and management review — all your own work — to Stage 1, Stage 2 and the certificate, which are the certification body's, then two annual surveillance audits and recertification in year three. Your work, or your consultant’s No fixed length. This is the part the calculator estimates. The certification body’s work Days set by the published table. Not negotiable. Gap analysis where you are vs the standard Implementation risk assessment, SoA, controls Internal audit clause 9.2 — required Management review clause 9.3 — required Stage 1 documentation and readiness Stage 2 the certification audit Certificate valid three years Surveillance year 1 Surveillance year 2 Recertify year 3, then repeat Stage 1 and Stage 2 are separate visits with a gap between them, so the certificate always arrives some weeks after the last audit day.
Everything left of the dashed line has no fixed length and is where the cost varies. Everything right of it runs to a published day count.
The same diagram as a table
The certification cycle
StepWhose workRequired by
Gap analysisYou or a consultantNothing — optional, but usual
Implementation: risk assessment, risk treatment, Statement of ApplicabilityYou or a consultantClause 6
Internal auditYou or a consultant — never your certification bodyClause 9.2
Management reviewYour managementClause 9.3
Stage 1 auditCertification bodyISO/IEC 17021-1
Stage 2 auditCertification bodyISO/IEC 17021-1
Certificate issued, valid three yearsCertification body
Surveillance audit, year 1Certification bodyOne third of the initial audit time
Surveillance audit, year 2Certification bodyOne third of the initial audit time
Recertification, year 3Certification bodyTwo thirds of the initial audit time

What you are certified against

A common and expensive misreading is that ISO 27001 is a list of 93 security controls. It is not. You are audited against clauses 4 to 10, which describe a management system. Annex A is a reference set you select from, and the selection is justified in a Statement of Applicability.

ISO/IEC 27001:2022, clauses 4 to 10 — what you are actually audited against
ClauseNameWhat it asks for
4Context of the organisationWho you are, who cares, and what is in scope.
5LeadershipA policy, assigned roles, and management that owns the thing.
6PlanningRisk assessment, risk treatment, the Statement of Applicability, objectives.
7SupportResources, competence, awareness, communication, documented information.
8OperationRunning the risk assessment and treatment you planned in clause 6.
9Performance evaluationMonitoring, internal audit, management review.
10ImprovementNonconformity, corrective action, continual improvement.

The distinction matters commercially as well as technically. Two organisations of identical size can have honestly different amounts of work ahead of them, because the work is driven by what their risk assessment produced and not by a fixed checklist. It is also why “how many controls have you got left?” is the wrong question to put to a consultant.

Every step, and whose job it is

The full sequence, with the clause or rule behind each step
StepRequired byWhose workWhat it is
Gap analysisOptionalYou, or a consultantWhere you are against clauses 4 to 10 and Annex A. Produces the plan, not the ISMS.
ScopeClause 4.3YouWhat is in and what is out. This decides the headcount, so it decides the audit fee.
Risk assessment and treatmentClause 6.1You, or a consultantThe core of the standard. Everything in Annex A flows from what this produced.
Statement of ApplicabilityClause 6.1.3 d)YouWhich Annex A controls apply, why, and — the part people forget — why the excluded ones do not.
Documented informationClause 7.5You, or a consultantPolicies and records. The part a toolkit genuinely accelerates.
Operate itClause 8YouThe system has to actually run. This is the floor under the timeline.
Internal auditClause 9.2You, a consultant, or a contractor — never your certification bodyRequired before Stage 2. Your certification body is barred from doing this for you.
Management reviewClause 9.3Your managementRequired before Stage 2, with named inputs. Minutes are the evidence.
Stage 1 auditISO/IEC 17021-1Certification bodyReadiness and documentation. Produces findings you have to close.
Stage 2 auditISO/IEC 17021-1Certification bodyThe certification audit proper. Evidence that the system is operating.
CertificateCertification bodyIssued after the body's own review, some weeks after the last audit day. Valid three years.
Surveillance, years 1 and 2one third of the initial auditCertification bodyAnnual. Not optional, and not usually in the first quote.
Recertification, year 3two thirds of the initial auditCertification bodyThen the cycle repeats.

The two-supplier rule

Read the third column again. Everything above Stage 1 is yours or a consultant's; everything from Stage 1 down is the certification body's; and the internal audit row says explicitly that it cannot be the certification body. You are buying from two separate suppliers, and the standard requires them to be separate.

The floor under the timeline

Ask how fast ISO 27001 can be done and you will be quoted a number of months. The useful answer is structural rather than numeric.

Clause 9.2 requires internal audits at planned intervals covering whether the ISMS conforms to your own requirements and to the standard, and whether it is effectively implemented and maintained. An internal audit of a management system that has been running for a fortnight has almost nothing to examine.

Clause 9.3 requires a management review with specified inputs — the status of actions from previous reviews, changes in issues relevant to the ISMS, feedback on performance including nonconformities, audit results, and the results of risk assessment. Most of those inputs do not exist until the system has run for a while and produced them.

So the binding constraint is not how many consultant days you buy. It is that the system has to operate long enough to generate the evidence that the internal audit and the management review then consume. A Stage 2 audit arriving before that finds a set of documents rather than a management system, and auditors are practised at spotting the difference.

The second constraint is external and frequently forgotten: certification bodies have waiting lists, and the gap between Stage 1 and Stage 2 is scheduled around their availability, not yours. If you have a contractual date, ask about lead times on the first call — before price, because it is more often the thing that decides whether the date is achievable.

Stage 1 and Stage 2 are one audit with a gap in it

Both stages come out of the same day count in the published table — they are not separately priced events. Stage 1 looks at readiness: scope, documented information, the risk assessment, the Statement of Applicability, and evidence that the internal audit and management review have happened. It produces findings.

The gap exists so you can close those findings. Then Stage 2 looks for evidence that the system operates as documented: it samples, it interviews, it asks people who are not in the compliance team what they actually do. A system that exists only as documents tends to come apart at this point, which is the entire reason the two stages are separate.

The certificate itself arrives after that, once the certification body completes its own independent review of the audit outcome. That review is not a formality and it takes time, so the certificate is always some weeks behind the last audit day. If a contract has a date on it, work backwards from the certificate, not from Stage 2.

Then it never stops

A certificate is valid for three years, but the audits are annual. One third of the initial audit in year one, the same in year two, and two thirds at recertification in year three. Add an internal audit every year, from somebody who is not your certification body, and a management review.

Taken together, the three years after certification contain more audit time than certifying did. That is a knowable number on day one and it belongs in the business case. The cost page has the full table, or the calculator does it for your headcount.

The edition trap

ISO/IEC 27001:2022 was published on 25 October 2022, and ISO/IEC 27001:2022/Amd 1:2024, Climate action changes followed in February 2024. Two climate-change additions to clause 4: whether climate change is a relevant issue must be determined, and interested parties may have climate-related requirements. It changed no Annex A control and added no new control.

Certificates against ISO/IEC 27001:2013 ceased to be valid on 31 October 2025. Certificates issued against the 2013 edition ceased to be valid after that date. Any certificate you are shown today that still names ISO/IEC 27001:2013 is expired, whoever issued it. If you are collecting supplier certificates as part of your own Annex A supplier controls, this is worth a pass through the folder.

Where to go next

Common questions

How long does ISO 27001 certification take?

The audit is the short part and the only part with a published length. What sets the timeline is clauses 9.2 and 9.3: you cannot sit Stage 2 without having run an internal audit and held a management review, and neither is meaningful unless the management system has been operating long enough to produce evidence. That is the floor, and no budget removes it. Beyond that the variables are how much documented information you already have, how quickly your own people can make the decisions only they can make, and how long your chosen certification body's waiting list is — which is frequently the binding constraint and is worth asking about on the first call.

What is the difference between Stage 1 and Stage 2?

Stage 1 examines whether you are ready: the scope, the documented information, the risk assessment, the Statement of Applicability, and whether the internal audit and management review have actually happened. It produces findings. Stage 2 is the certification audit proper, and looks for evidence that the system is operating as documented. They are separate visits with a gap between them precisely so you can close what Stage 1 found. Both are inside the single day count the published table gives you.

Can we skip the gap analysis?

Yes. Nothing in the standard requires one. It is a planning exercise, and whether it is worth buying depends on whether you already know what you are missing. A team that has run ISO 9001 for a decade usually does. A team that has never operated a management system usually does not, and a gap analysis is the cheapest way to find out how big the job is before committing to a route or a date.

Who can do our internal audit?

Anyone competent and sufficiently independent of the activity being audited — an internal person from another team, a contractor, or a consultancy. What you cannot use is your certification body. BS EN ISO/IEC 17021-1:2015, clause 5.2 (Management of impartiality), full text clause 5.2.6 bars it from providing internal audits to its certified clients and says that doing so locks it out of certifying that management system for 2 years. It is an annual requirement, not a one-off.

What happens if we fail?

Stage 2 rarely produces a flat failure; it produces nonconformities graded minor or major. A major nonconformity has to be closed before a certificate can be issued, and closing it often needs the auditor to come back — a chargeable visit that is not in the original quote. Minor nonconformities are usually closed by submitting evidence of corrective action. The practical risk is the delay, which in a tender is usually more expensive than the extra visit.

Does the certificate expire?

It is valid for three years, with surveillance audits in years one and two and recertification in year three. Miss a surveillance audit and the certificate can be suspended or withdrawn. Separately, certificates issued against the withdrawn ISO/IEC 27001:2013 edition ceased to be valid on 31 October 2025.

What is the Statement of Applicability actually for?

It is the document that connects your risk assessment to Annex A, and it is the one an auditor reaches for first. For each of the 93 controls in ISO/IEC 27001:2022 it records whether the control applies, the justification, and whether it is implemented. The part organisations under-do is the justification for exclusions: “not applicable” on its own is a finding waiting to happen, because the standard asks for the reasoning, not the conclusion.

Do we need to be certified to the amendment as well?

ISO/IEC 27001:2022/Amd 1:2024, Climate action changes was published in February 2024 and is part of the current standard. Two climate-change additions to clause 4: whether climate change is a relevant issue must be determined, and interested parties may have climate-related requirements. It changed no Annex A control and added no new control. In practice it means clause 4 has to show you considered whether climate change is a relevant issue for your organisation, and recorded the answer. The answer may legitimately be that it is not material to your ISMS. What an auditor is looking for is that the question was asked.

Sources cited on this page

  1. ISO/IEC 27001:2022, Information security, cybersecurity and privacy protection — Information security management systems — Requirements
  2. ISO/IEC 27001:2022/Amd 1:2024, Climate action changes
  3. BS EN ISO/IEC 17021-1:2015, clause 5.2 (Management of impartiality), full text
  4. ISO/IEC 27006-1:2024, Requirements for bodies providing audit and certification of information security management systems — Part 1
  5. IAF MD 26:2023, Transition requirements for ISO/IEC 27001:2022

Every figure above was read from the source it is attributed to on 20 September 2026. Figures that are our own arithmetic rather than a published rule are labelled as estimates wherever they appear. How we check this.

Have a date to hit?

Say when the certificate is needed and what triggered it. Those two answers decide whether the date is achievable, and a consultancy can tell you on the first reply.

Step 1 of 6
What has made this a live question?

Almost nobody certifies for its own sake. Whatever is pushing this usually also sets the deadline, so it is worth saying first.

When do you need the certificate in your hand?

Stage 1 and Stage 2 are separate visits with a gap between them, so the certificate always lands some weeks after the last audit day. A date inside three months is a different piece of work from a date inside a year.

How many people would be inside the scope?

Not your whole payroll — everyone doing work under your control inside the certified scope, contractors included. This is the number the audit-day table in ISO/IEC 27006-1 runs on, so it decides the audit fee before anything else does.

What exists already?

There is no wrong answer here and nothing to be embarrassed about. Most enquiries are at the first option.

How do you want the work done?

The three routes cost very different amounts and suit very different teams. If you have not decided, say so — it is the most common answer.

Where should the consultancy reach you?

This is the only step that asks you to type anything.

By clicking “Send my enquiry” I agree that iso27001partners.co.uk may pass the details above to up to three ISO 27001 consultancies that advertise for my sector, so that they can contact me at the business details I have given. Consent is not a condition of anything — every page, table and calculator on this site works without it. You can withdraw consent at any time by replying to any message you receive, or by writing to contact@iso27001partners.co.uk. We are not a certification body, not an accreditation body and not a consultancy; the disclaimer linked in the footer sets out the whole arrangement.

  • Your details go to consultancies only, and to no more than three
  • Free to you — consultancies pay us a fixed fee per enquiry, set in advance
  • No obligation, and no certification body is involved at this stage

Your enquiry is ready to send

Here is what happens after you submit:

  1. Your answers go to ISO 27001 consultancies that advertise for your sector.
  2. No more than three of them may contact you, using the details you gave.
  3. You decide who, if anyone, you speak to. You are committed to nothing.

We are not a certification body and cannot issue, arrange or influence a certificate. Only a UKAS-accredited certification body can do that, and you appoint it yourself.

Free enquiryFive clicks · no obligation Start now