How to get ISO 27001 certified (step by step)
ISO 27001 certification means an accredited body audits your information security management system against the standard and, if it holds up, issues a certificate that is valid for three years with a surveillance audit each year. That is the destination. The work that gets you there is building an ISMS that actually runs, and for most organizations that takes six to twelve months.
Here is the honest version the ten-step checklists tend to skip: the certificate is the easy part. Passing the audit becomes a formality the day the management system genuinely works. Almost everything hard, and almost all of the cost, sits in the months before the auditor arrives.
Many organizations do not arrive here by choice: a customer contract, a public procurement or an EU law such as NIS2 put certification on the table. If that is you, it is worth five minutes to understand how NIS2 and ISO 27001 fit together before you commit to a scope.
Start with a mandate and a scope, not a document
The first real decision is how much of the organization the certificate should cover. Scope is the single biggest lever on both cost and effort, because everything downstream (risk assessment, controls, evidence) is sized by it. A certificate that covers one product and the team behind it is a completely different project from one that covers the whole company.
Get leadership committed before that. ISO 27001 is a management-system standard, which in plain terms means clauses 5 and 9.3 require top management to set objectives, allocate resources and review the system on a schedule. An auditor will want to see that review actually happening. Projects stall when the security function runs certification as its own project and management treats it as the security function's problem.
Gap analysis: know your starting point
Before you build anything, measure the distance between what you have and what the standard wants. That inventory is the gap analysis, and it is how you scope and budget the project before committing to it. We wrote a full guide to running one: how to run an ISO 27001 gap analysis.
The trap here is measuring only Annex A, the 93 controls, and ignoring clauses 4 to 10, the management-system requirements. An organization can score well on the controls and still have no documented scope, no internal audit programme and no management review. None of those are optional, and they are exactly what a certification auditor checks first.
The risk assessment is the mandatory step
ISO 27001 doesn't actually require a gap analysis. It requires a risk assessment, and this is where certification projects are won or lost. You identify what could go wrong with the information in your scope, judge how likely and how serious each risk is, and decide how to treat it. The controls you then put in place have to trace back to those decisions, not to a generic list someone copied out of the standard.
This is also the difference between a gap analysis and a risk assessment, which people conflate constantly. The gap analysis measures how far you are from the standard. The risk assessment decides what your organization actually needs. You need both, and the risk assessment is the one the auditor treats as non-negotiable.
The Statement of Applicability
Out of the risk work comes the document an auditor reads before any other: your Statement of Applicability. It lists every one of the 93 Annex A controls, says whether each one applies to you, why, and whether it is implemented. Excluding a control is perfectly legitimate when the justification holds. 'Not done yet' dressed up as 'not applicable' is the fastest way to turn a gap into a nonconformity. There is a separate guide on getting the SoA right: what the Statement of Applicability is and how to write one.
Internal audit and management review, the parts everyone forgets
When a certification fails at Stage 2, it is rarely because a firewall was missing. It is because clause 9 was not done. Before an external auditor will certify you, ISO 27001 wants you to audit yourself (an internal audit covering the whole ISMS) and to hold a documented management review where leadership looks at the results and decides what to change.
Both have to have genuinely happened, with records, before the external audit. You can't run the internal audit the week before and call it a programme. In practice that means starting the internal audit two to three months ahead, fixing what it finds, and holding the management review with real inputs: audit findings, incidents, the status of your objectives. The teams that build an ISMS but skip these two habits are the ones who get a surprise at Stage 2.
The external audit, in two stages
Certification itself is two visits. Stage 1 is a documentation review: the auditor checks that your ISMS exists on paper and hangs together, that your SoA, risk assessment and policies agree with each other. Stage 2, usually a few weeks later, tests whether reality matches the paperwork. They sample controls, interview the people who operate them, and look for the gap between what the documents claim and what actually happens.
Findings come as nonconformities, major or minor. A minor one you usually close with a corrective action plan; a major one has to be fixed before the certificate issues. Pass, and you hold a certificate for three years, with a lighter surveillance audit in years one and two and recertification in year three.
What it costs and how long it takes
Straight answer, for a mid-sized Swedish company: expect six to twelve months and a total first-year cost somewhere in the range of 200,000 to 600,000 SEK once you count internal time, any consulting, tooling and the audit itself. The external certification audit on its own is commonly 60,000 to 150,000 SEK, with annual surveillance audits running lower.
The number that surprises people is that the audit fee is the small part. The big cost is internal hours, and the second is keeping the system alive after year one. Two things bring the total down more than anything else: scoping tightly so you are not certifying the whole world, and reusing documentation you already have instead of writing every policy from a blank page.
After the certificate, keep the ISMS alive
A certificate lasts three years. The surveillance audits in years one and two exist to check one thing: that the ISMS you were certified on is still running. A gap analysis from last spring describes a company that no longer exists, so the management system has to be a living thing rather than a binder you reopen before each audit. We make that case here: your gap analysis should be a living thing.
That standing model is what Aquil's Compliance Assistant is built for. It tracks all 93 Annex A controls with a status and a written justification each, and links the documents and runnable processes used as evidence. An approval step on every answer ties it to a named person and a date. Your SoA exports straight out of that assessment when the auditor asks. If you're not that far yet, the free GDPR tier is an easy way to see how the model works before you commit to the ISO 27001 build.