ISO 27001 Implementation & Certification Readiness — Guide
- Version 1.1
- Updated
- Next review
ISO 27001 Implementation & Certification Readiness
A customer asks for a certificate, so someone buys a toolkit, writes forty policies and books an audit. At Stage 1 the auditor finds a scope nobody can explain, controls copied from Annex A instead of chosen from risk, and no records. This pack sets realistic expectations for a first certification: what it costs, how long it takes, and which decisions determine whether it goes well.
Is this for you?
This pack is for you if:
- a customer, tender or board has asked for ISO/IEC 27001 certification;
- you have controls but no management system around them;
- you need a date you can defend, not a sales estimate.
How long it really takes
For 100 to 300 people with some controls in place, the phases take about 38 weeks of work. Allow 9 to 12 months from approval to certificate, once you include waiting for audit dates.
| Phase | Weeks | You’re done when |
|---|---|---|
| 1 Decide and scope | 3 | Management has approved the scope, policy and resources |
| 2 Assess risk | 5 | Risks are assessed and a treatment plan agreed |
| 3 Select and document controls | 6 | The Statement of Applicability, policies and procedures are approved |
| 4 Implement and operate | 12 | Controls are working and producing records |
| 5 Check | 4 | An internal audit and a management review are complete |
| 6 Certify | 8 | Stage 1, fixes and Stage 2 are done |
Phase 4 cannot be compressed. The ISMS must run for at least three months before Stage 2 (IS-05), because the auditor samples records over time: access reviews, incidents, supplier checks, training. More writing does not create a history.
What it costs
Every figure here is an estimate, not a price: confirm each with your own figures and with quotes from accredited certification bodies.
- Internal effort: an ISMS manager at half to full time for the project, plus a few days a month from each control owner. An estimated 150 to 300 person-days in total.
- Certification body fees: set by audit days, which depend mainly on headcount and scope. For this size, an estimated 10 to 15 days across Stage 1 and Stage 2, or an estimated €10,000 to €25,000; surveillance audits in years two and three cost an estimated third of that each.
- Optional: consultancy, a contracted internal auditor or compliance software.
The decisions that decide it
- Scope: name the organisation, locations, services and interfaces covered, and justify every exclusion (IS-02). A vague scope is a common Stage 1 finding.
- Controls from risk: choose controls from your risk assessment, not the Annex A list, and justify each inclusion and exclusion in the Statement of Applicability (IS-03).
- Records, not documents: most required documented information is evidence that something happened. Policies without records fail.
- Audit yourself first: complete a full internal audit and management review before Stage 2 (IS-06), with auditors who are not checking their own work (IS-07).
Start with these three
- ISO 27001 Implementation Methodology & Project Plan — the phases, rules and plan.
- Certification Readiness Self-Assessment — where you stand, requirement by requirement.
- Statement of Applicability Template — the 93 Annex A controls, each with a decision and reason.
Four numbers to report
Report these to top management monthly from Phase 4 (IS-10).
| Number | Target |
|---|---|
| Blocking items operating | All, before the Stage 2 date |
| Requirements operating | Rising monthly |
| Gaps overdue | Zero on the critical path |
| Weeks to certification | On or before the planned date |
You may already have half of it
Other CISO Times packs supply much of this: the policy set, the risk method and register, supplier assessments and access reviews. Once running, their records are evidence.
Everything in the pack
| Document | What it does | Format |
|---|---|---|
| ISO 27001 Implementation Methodology & Project Plan | Phases, rules and the plan | Word |
| Annex A Control Implementation Library | How to implement each control | Excel |
| Statement of Applicability Template | Every control’s decision and reason | Excel |
| Mandatory ISMS Documentation Checklist | Required documents and records, by clause | Excel |
| Certification Readiness Self-Assessment | Readiness scored per requirement | Excel |
| ISMS Gap & Remediation Tracker | Every gap with an owner and date | Excel |
| ISMS Internal Audit Programme & Procedure | Planning and running internal audits | Word |
| Management Review Meeting Pack | Agenda, inputs and decisions | Word |
| Stage 1 and Stage 2 Audit Preparation Guide | What auditors ask and sample | Word |
Adapting it
- Small organisation: fewer people shorten phases 1 to 3, not the three-month operating period.
- Regulated entity: certification supports NIS2 or DORA compliance but does not equal it. Those laws set obligations, such as incident reporting, that a certificate does not prove.
- IT run by providers: check that each provider’s certificate covers the service you buy, and manage them under your supplier controls.
Where it maps
- ISO/IEC 27001:2022 — Clauses 4 to 10 and Annex A.
- NIST CSF 2.0 — GV.OC-01 and GV.OC-03.