Independent thinking. Informed defence.

CISO Times

Intelligence for the people behind the defence.

The CISO Decision Brief

ISO 27001 Implementation & Certification Readiness — Guide

ISO 27001 Implementation & Certification Readiness

A customer asks for a certificate, so someone buys a toolkit, writes forty policies and books an audit. At Stage 1 the auditor finds a scope nobody can explain, controls copied from Annex A instead of chosen from risk, and no records. This pack sets realistic expectations for a first certification: what it costs, how long it takes, and which decisions determine whether it goes well.

Is this for you?

This pack is for you if:

  • a customer, tender or board has asked for ISO/IEC 27001 certification;
  • you have controls but no management system around them;
  • you need a date you can defend, not a sales estimate.

How long it really takes

For 100 to 300 people with some controls in place, the phases take about 38 weeks of work. Allow 9 to 12 months from approval to certificate, once you include waiting for audit dates.

PhaseWeeksYou’re done when
1 Decide and scope3Management has approved the scope, policy and resources
2 Assess risk5Risks are assessed and a treatment plan agreed
3 Select and document controls6The Statement of Applicability, policies and procedures are approved
4 Implement and operate12Controls are working and producing records
5 Check4An internal audit and a management review are complete
6 Certify8Stage 1, fixes and Stage 2 are done

Phase 4 cannot be compressed. The ISMS must run for at least three months before Stage 2 (IS-05), because the auditor samples records over time: access reviews, incidents, supplier checks, training. More writing does not create a history.

What it costs

Every figure here is an estimate, not a price: confirm each with your own figures and with quotes from accredited certification bodies.

  • Internal effort: an ISMS manager at half to full time for the project, plus a few days a month from each control owner. An estimated 150 to 300 person-days in total.
  • Certification body fees: set by audit days, which depend mainly on headcount and scope. For this size, an estimated 10 to 15 days across Stage 1 and Stage 2, or an estimated €10,000 to €25,000; surveillance audits in years two and three cost an estimated third of that each.
  • Optional: consultancy, a contracted internal auditor or compliance software.

The decisions that decide it

  • Scope: name the organisation, locations, services and interfaces covered, and justify every exclusion (IS-02). A vague scope is a common Stage 1 finding.
  • Controls from risk: choose controls from your risk assessment, not the Annex A list, and justify each inclusion and exclusion in the Statement of Applicability (IS-03).
  • Records, not documents: most required documented information is evidence that something happened. Policies without records fail.
  • Audit yourself first: complete a full internal audit and management review before Stage 2 (IS-06), with auditors who are not checking their own work (IS-07).

Start with these three

  1. ISO 27001 Implementation Methodology & Project Plan — the phases, rules and plan.
  2. Certification Readiness Self-Assessment — where you stand, requirement by requirement.
  3. Statement of Applicability Template — the 93 Annex A controls, each with a decision and reason.

Four numbers to report

Report these to top management monthly from Phase 4 (IS-10).

NumberTarget
Blocking items operatingAll, before the Stage 2 date
Requirements operatingRising monthly
Gaps overdueZero on the critical path
Weeks to certificationOn or before the planned date

You may already have half of it

Other CISO Times packs supply much of this: the policy set, the risk method and register, supplier assessments and access reviews. Once running, their records are evidence.

Everything in the pack

DocumentWhat it doesFormat
ISO 27001 Implementation Methodology & Project PlanPhases, rules and the planWord
Annex A Control Implementation LibraryHow to implement each controlExcel
Statement of Applicability TemplateEvery control’s decision and reasonExcel
Mandatory ISMS Documentation ChecklistRequired documents and records, by clauseExcel
Certification Readiness Self-AssessmentReadiness scored per requirementExcel
ISMS Gap & Remediation TrackerEvery gap with an owner and dateExcel
ISMS Internal Audit Programme & ProcedurePlanning and running internal auditsWord
Management Review Meeting PackAgenda, inputs and decisionsWord
Stage 1 and Stage 2 Audit Preparation GuideWhat auditors ask and sampleWord

Adapting it

  • Small organisation: fewer people shorten phases 1 to 3, not the three-month operating period.
  • Regulated entity: certification supports NIS2 or DORA compliance but does not equal it. Those laws set obligations, such as incident reporting, that a certificate does not prove.
  • IT run by providers: check that each provider’s certificate covers the service you buy, and manage them under your supplier controls.

Where it maps

  • ISO/IEC 27001:2022 — Clauses 4 to 10 and Annex A.
  • NIST CSF 2.0 — GV.OC-01 and GV.OC-03.