Everything about getting — and keeping — your ISO 27001 certificate. This hub covers the full lifecycle: choosing an accredited certification body, the internal audit and management review you must run first, the two-stage certification audit, and then the surveillance and recertification audits that keep your certificate valid across the three-year cycle. Plus honest guidance on timelines and the nonconformities that trip organizations up.
← Back to ISO 27001: The Complete Guide
The certification journey
Guide | Stage |
|---|---|
The whole path, start to finish | |
Accreditation, cost, and avoiding cert mills | |
The documentation/readiness review | |
The implementation-effectiveness audit | |
What to expect by size and readiness |
Audits you run yourself
Guide | What it covers |
|---|---|
The Clause 9.2 internal audit program | |
A complete audit reference | |
The findings auditors raise most |
After certification
Guide | What it covers |
|---|---|
The annual check-ins in years 1 and 2 | |
Renewing before your certificate expires | |
Moving a legacy certificate to the current standard |
Related resources
Certification Readiness Checklist
Internal Audit Report Template
Internal Audit Interview Question Script
