ISO 27001 certification opens enterprise procurement doors, satisfies regulatory requirements, and gives your customers independent verification that you manage information security systematically. It also takes 6-18 months and significant internal resource to achieve. This guide explains what the standard actually requires, where organizations typically stall, and how to run a certification project that does not collapse under scope creep.
What ISO 27001 Requires
ISO 27001:2022 defines requirements for establishing, implementing, maintaining, and continually improving an Information Security Management System (ISMS). The standard has two parts: the main body (clauses 4-10) which specifies the management system requirements, and Annex A which contains 93 security controls organized into four themes: Organizational, People, Physical, and Technological.
The critical distinction that confuses first-time implementers: ISO 27001 does not require you to implement all 93 Annex A controls. It requires you to determine which controls are applicable based on your risk assessment and document justification for any controls you exclude — this is the Statement of Applicability (SoA). An organization might legitimately exclude physical security controls for a fully remote company, for example.
2022 revision key changes: The 2022 update reduced controls from 114 to 93 and added 11 new controls including: threat intelligence, information security for cloud services, ICT readiness for business continuity, physical security monitoring, configuration management, information deletion, data masking, web filtering, and secure coding. If you have ISO 27001:2013 certification, transition to the 2022 standard was required by October 2025.
Phase 1: Gap Assessment (Weeks 1-4)
Before planning the implementation, assess where you are against where you need to be. A gap assessment maps your current controls against the ISO 27001:2022 requirements and Annex A controls, identifies what is already in place (even informally), and estimates the effort to close each gap.
Run the gap assessment internally using the ISO 27001:2022 checklist available from your national standards body, or engage an external ISO consultant for an independent view. External assessment adds credibility when presenting to leadership and avoids blind spots from internal familiarity with existing processes.
Scope definition is critical: Your ISMS scope defines what is in and out of certification. Too narrow (just one product) and the certificate does not satisfy customer requirements. Too broad (the entire organization) and the implementation complexity becomes unmanageable. Define scope based on what customers actually ask about and what assets matter most.
Phase 2: Risk Assessment and Treatment (Weeks 4-12)
ISO 27001 is fundamentally a risk management framework. The risk assessment identifies information assets, threat sources, vulnerabilities, likelihood, and impact to produce a risk register. Your risk treatment plan then maps each unacceptable risk to an Annex A control or other treatment option (accept, avoid, share).
Choose a risk methodology before starting. ISO 27005 provides guidance; common approaches include asset-based risk assessment (enumerate assets, identify threats and vulnerabilities per asset) and scenario-based assessment (define threat scenarios and assess their likelihood and impact). The methodology matters less than consistency — apply it uniformly across all assets in scope.
Phase 3: Policy and Control Implementation (Months 2-6)
The policy framework required by ISO 27001 includes a top-level Information Security Policy, an ISMS scope document, and supporting policies for: access control, asset management, cryptography, physical security, operations security, communications security, supplier relationships, incident management, business continuity, and compliance.
These policies do not need to be long. They need to be accurate descriptions of what your organization actually does or will do. A policy that describes an idealized process no one follows is worse than no policy — it creates a gap between documented controls and actual practice that auditors will find and flag as a nonconformity.
High-priority Annex A controls for most organizations
- A.5.15 — Access control: Define and enforce access policies based on least privilege
- A.5.23 — Information security for cloud services: Govern cloud service use, assess provider security, include security requirements in contracts
- A.8.7 — Protection against malware: Deploy and maintain malware protection, user awareness for vectors
- A.8.15 — Logging: Generate, store, protect, and review logs for security-relevant events
- A.8.24 — Use of cryptography: Define policy for encryption use, key management, and approved algorithms
- A.5.29 — Information security during disruption: Plan for security control availability during incidents and disasters
Phase 4: Internal Audit (Month 6-8)
Before the certification audit, run a full internal audit of your ISMS against all applicable clauses and controls. The internal audit must be conducted by someone independent of the area being audited — not by the person who implemented the control. Findings from the internal audit are inputs to management review and corrective action.
Take internal audit findings seriously. A finding from your internal audit is an opportunity to fix something before the external auditor finds it. An external auditor finding the same issue is a nonconformity in your audit report, which creates certification delay and remediation overhead.
Phase 5: The Certification Audit
Certification audits are conducted by accredited Certification Bodies (CBs) in two stages:
- Stage 1 (Documentation review): The auditor reviews your ISMS documentation, scope, policies, risk assessment, and Statement of Applicability. Typically 1-2 days. Output: readiness determination and list of concerns to address before Stage 2.
- Stage 2 (Implementation audit): The auditor tests that your documented controls are actually implemented and effective. Reviews evidence: logs, access control records, training records, incident tickets, supplier agreements. Typically 2-5 days depending on scope. Output: audit report with any nonconformities (major or minor) that must be addressed for certification to be granted.
Major nonconformities prevent certification until resolved and re-audited. Minor nonconformities must have a corrective action plan within 90 days. The difference: major nonconformities indicate the requirement is not met at all; minor nonconformities indicate the requirement is partially met or evidence is insufficient.
Takeaway: ISO 27001 is achievable for most organizations with 6-18 months of focused effort. The organizations that stall do so at risk assessment (scope too broad, methodology unclear) and policy implementation (writing policies that describe desired state rather than actual practice). Fix both by keeping scope narrow for your first certification and writing policies that describe what you actually do today, then improving from there. See our Security Tools page for GRC platforms that automate evidence collection and audit management.
🔗 Further Reading
Frequently Asked Questions
What is ISO 27001?
ISO 27001 is the international standard for Information Security Management Systems (ISMS), published by the International Organization for Standardization (ISO) and the International Electrotechnical Commission (IEC). It specifies requirements for establishing, implementing, maintaining, and continuously improving an ISMS. Certification is achieved through a third-party audit by an accredited certification body. The current version, ISO 27001:2022, contains 93 security controls organized into four themes: Organizational, People, Physical, and Technological.
How long does ISO 27001 certification take?
ISO 27001 certification typically takes 6-18 months depending on organizational size, existing security maturity, and scope. Small organizations with strong existing controls can achieve certification in 6 months. Large enterprises with complex environments typically need 12-18 months. The process includes: gap assessment (4-6 weeks), risk assessment and treatment (6-12 weeks), policy and control implementation (2-4 months), internal audit (4-6 weeks), and the two-stage certification audit (Stage 1 documentation review + Stage 2 implementation audit).
What is the difference between ISO 27001 and SOC 2?
ISO 27001 is an international standard certifying that an organization has implemented a defined ISMS. It is globally recognized and results in a certificate valid for 3 years with annual surveillance audits. SOC 2 is a US-based reporting framework (AICPA) assessing controls around security, availability, processing integrity, confidentiality, and privacy. ISO 27001 defines specific controls to implement; SOC 2 evaluates whether your controls effectively meet defined criteria. Many organizations pursue both: ISO 27001 for international markets, SOC 2 for US enterprise customers.
What is the Statement of Applicability in ISO 27001?
The Statement of Applicability (SoA) is a mandatory ISO 27001 document that lists all 93 Annex A controls, indicates whether each is applicable to the organization, provides justification for inclusion or exclusion, and describes how included controls are implemented. The SoA is reviewed during the certification audit and must accurately reflect the organization's risk treatment decisions. Controls can be excluded from the ISMS scope if they are not applicable — for example, physical security controls for a fully remote organization — provided the exclusion is justified.

