ISO 27001 Certification Explained Simply: Process & Costs

What ISO 27001 certification means, who actually needs it, and how the process runs from Stage 1 to recertification, explained clearly for beginners.

ISO 27001 Certification Explained Simply: Process & Costs
Julian Köhn
|Read time: 10 minutes

A customer suddenly asks for an ISO 27001 certificate during a procurement process. Or leadership reads that the NIS2 directive will require suppliers to provide evidence of their information security. Both are typical triggers that push companies to look seriously at ISO 27001 certification for the first time, usually under time pressure and without a clear picture of what actually lies ahead.

This article brings structure to the topic: what the certification is, who really needs it, what it costs, and how the path from the first workshop to the certificate actually looks.

What is ISO 27001 certification?

ISO 27001 is an international standard for information security management systems, or ISMS. The certification confirms that a company has implemented such a system and demonstrably operates it, not just on paper, but in day-to-day business.

At its core, the standard requires you to systematically protect three objectives for your information:

  • Confidentiality: Only authorised people have access to data.
  • Integrity: Data stays complete and unaltered, and tampering gets noticed.
  • Availability: Systems and information are available when they are needed.

A certified ISMS is therefore not a single security product, but a framework of policies, roles, processes and technical controls that gets reviewed and improved on an ongoing basis. An independent auditor ultimately confirms that this framework actually works. For a deeper introduction to the ISMS concept, including practical examples from different industries, see our guide to information security management systems.

ISO 27001, ISO/IEC 27001, or the local national standard: is it all the same thing?

In practice these names get mixed up constantly, but they almost always refer to the same standard:

  • ISO/IEC 27001 is the correct international designation. It is published jointly by the International Organization for Standardization (ISO) and the International Electrotechnical Commission (IEC).
  • ISO 27001 is the shortened, colloquial form used most commonly in everyday conversation.
  • National editions, such as the German DIN EN ISO/IEC 27001, are local adoptions of the same standard through national and European standardisation bodies. The content does not change, it is the same requirements published as a nationally recognised edition.

Important for your research: the currently valid edition is ISO/IEC 27001:2022. The previous version from 2013 was revised, among other things the controls in Annex A were restructured and grouped thematically. Anyone certified today is assessed against the 2022 edition. For details on the technical requirements and control areas, see our ISO 27001 overview page.

The core components of an ISMS under ISO 27001

Before certification is even possible, the ISMS has to exist as a working system. The standard requires several components that work together:

  • Policies: Documented rules covering topics such as access control, passwords, mobile devices, or supplier management.
  • Roles and responsibilities: Who is accountable for information security, who owns which assets, who approves exceptions?
  • Asset management: An inventory of everything that needs protecting, from servers and applications to contracts and data holdings.
  • Risk assessment and treatment: A systematic evaluation of which risks apply to which assets and how they are treated, accepted, reduced, transferred, or avoided.
  • Annex A controls: A catalogue of 93 controls, from which you select the ones relevant to you and justify why others do not apply. The result is the Statement of Applicability (SoA), a central document reviewed during the audit.
  • Training and awareness: Employees need to know and apply the rules that are relevant to them.
  • Incident response: A defined process for detecting, reporting, and handling security incidents.

To see what such a control catalogue looks like in practice, and how the selection of controls can be documented, take a look at our pages on ISO 27001 controls and the Statement of Applicability.

What benefits does the certification bring?

Certification is more than proof for auditors. For most companies it serves several goals at once:

  • Trust with customers and partners: A recognised certificate often answers security questionnaires and tender requirements faster than any individual explanation could.
  • Structured risk management: Instead of isolated fixes, you get a systematic overview of risks and how they are treated, which also gives leadership real visibility.
  • Preparation for regulatory requirements: A working ISMS covers a large share of what GDPR, NIS2, or industry-specific rules demand in terms of technical and organisational measures.
  • Competitive factor: In larger tenders and B2B sales, ISO 27001 is often a hard requirement. Without it, you may not even make the shortlist.
  • Internal cleanup: The process itself forces you to clarify responsibilities, access rights, and documentation, which is valuable independent of the certificate.

Who needs ISO 27001?

There is no general legal obligation to certify against ISO 27001. Still, it has become practically unavoidable for a growing number of companies:

  • SaaS and cloud providers whose enterprise customers require security evidence as a contract precondition.
  • Suppliers and service providers embedded in the supply chains of regulated industries, such as automotive, financial services, or healthcare.
  • Companies within scope of the NIS2 directive, which does not itself mandate ISO 27001 but sets comparable requirements for risk management and technical measures, often across the entire supply chain. We cover how to think about NIS2, GDPR, and ISO 27001 together in our article on NIS2, GDPR, and ISO 27001 in practice.
  • Public sector buyers and larger mid-market companies, which increasingly use information security as an evaluation criterion in tenders and supplier audits.

In short: as soon as customers, regulation, or a growing supply chain start demanding evidence, a voluntary improvement quickly turns into a business-critical necessity.

What does ISO 27001 certification cost?

Blanket figures are misleading here, because costs depend heavily on company size, scope, and starting point. Roughly, there are three cost blocks:

  1. Internal effort: Time spent on risk assessment, documentation, training, and implementing controls. For most first-time certifications, this is the largest cost block.
  2. External support: Consulting, if internal capacity or experience is not sufficient. This does not contradict a self-service approach, many companies combine a platform-based solution with targeted support from partners.
  3. Certification body fees: The actual audit fees for Stage 1, Stage 2, and the annual surveillance audits, tiered by company size and number of sites.

Depending on the starting point, the range spans from low five-figure amounts for small, clearly scoped organisations up to significantly higher sums for complex, multi-site organisations. For a detailed breakdown of the individual cost items, see our page on ISO 27001 costs. For a first estimate tailored to your company size, use our audit cost calculator.

The certification process step by step

The path to certification follows a clear sequence, even though the timeline varies by company.

1. Preparation and scope definition

The first question is which parts of the company should actually be certified. A scope that is too broad drags out the project and drives up cost unnecessarily; a scope that is too narrow can raise questions with customers and auditors. In parallel, roles get assigned, for example an information security officer, and a rough project plan is drawn up.

2. Risk assessment

Based on the asset inventory, you systematically assess which risks apply to which assets, how likely they are, and how severe the impact would be. The result determines which Annex A controls are actually needed and feeds directly into the Statement of Applicability.

3. Implementing controls

The risk assessment produces an implementation plan: policies get written and approved, technical controls get rolled out, training gets delivered, responsibilities get documented. This step usually takes up the largest share of the project timeline.

4. Internal audit

Before the external certification body gets involved, the company reviews its own ISMS, ideally through someone who is not responsible for the areas being reviewed. The goal is to find gaps before they become a problem in the external audit. Our glossary entry on the internal audit plan explains how to plan an internal audit effectively.

5. Stage 1 audit: documentation review

The certification body checks whether the documentation is complete and conforms to the standard: ISMS scope, risk assessment, Statement of Applicability, policies. Stage 1 typically surfaces formal gaps before the substantive review begins. For a focused walkthrough of how to prepare for the ISO 27001 Stage 1 audit, see our audit preparation page.

6. Stage 2: on-site audit

In the Stage 2 audit, the auditor checks whether the documented controls are actually followed in daily operations. This includes interviews with staff, sampling of individual controls, and reviewing evidence. Our glossary entry on the auditor describes exactly what an auditor does and what they look for.

7. Certificate, surveillance audits, and recertification

After a successful Stage 2 audit, the certificate is issued, and it is typically valid for three years. During this period, annual surveillance audits sample parts of the ISMS. After the three years expire, a full recertification is due. Our glossary entry on the ISO audit explains the general structure of the review process, and our page on ISO 27001 certification offers a structured overview of the whole path.

Common challenges and how to solve them

Documentation grows faster than your overview of it. If you keep policies, risks, and evidence scattered across Word and Excel files, you lose track by the second surveillance audit at the latest. A central platform that links controls, risks, and evidence together keeps this effort manageable.

Scope is unclear or grows during the project. A cleanly defined scope from the start saves later discussions with the auditor. Using Kopexa as a frameworks platform, you can structure controls and assets through an interactive control explorer, documenting scope in a traceable way from day one.

Evidence is missing when it matters. Many companies know a control is implemented but cannot prove it during the audit. Structured evidence management, where evidence is attached directly to controls, prevents the classic pre-audit scramble.

Internal capacity is not enough. Not every company has a dedicated information security officer. This is where it pays to combine self-service tools with targeted support from specialised partners, rather than either doing everything internally or outsourcing the entire project.

Auditors need access without opening up sensitive systems. Read-only access for auditors to the relevant evidence, risks, and controls speeds up the audit significantly and reduces coordination overhead during the on-site review.

This is exactly where Kopexa, as ISMS software, comes in: frameworks and controls, risk management, policies, IT asset management, vendor management, evidence management, and incident management are all linked together, so you stay audit-ready on an ongoing basis instead of scrambling right before the appointment. That works equally well in self-service mode or in collaboration with a partner CISO.

Conclusion and next step

ISO 27001 certification is not a one-off project with an end date, it is the visible milestone of a process that continues after the certificate: annual surveillance audits, ongoing risk assessment, periodic recertification. Building a clear structure for controls, risks, and evidence early on gets you through the first audit faster and keeps the effort manageable afterwards too.

If you are planning how ISO 27001 fits together with other certifications such as ISO 9001, take a look at our certification roadmap for ISO 9001 and ISO 27001. And for a concrete starting point for your own project, our ISO 27001 roadmap page offers a structured overview of the next steps.

Frequently Asked Questions

What does ISO 27001 certification actually mean?
ISO 27001 certification confirms, through an independent audit, that a company has implemented an information security management system (ISMS) and demonstrably operates it. The audit checks whether policies, roles, risk management, and technical controls are actually applied in daily operations, not just documented.
Is ISO 27001 the same as ISO/IEC 27001?
Yes. ISO/IEC 27001 is the correct international designation of the standard, ISO 27001 is the common short form. National editions, such as the German DIN EN ISO/IEC 27001, are the same standard with identical content requirements.
Which version of ISO 27001 is currently in force?
The currently valid edition is ISO/IEC 27001:2022. It replaced the previous 2013 version and, among other changes, restructured the controls in Annex A. Certifications today are assessed against the 2022 edition.
Is ISO 27001 certification a legal requirement?
There is no general legal obligation to get certified. For many companies it still becomes practically necessary, for example due to customer requirements, tenders, or pressure from supply chains in regulated industries and the NIS2 directive.
How long does the path to ISO 27001 certification take?
The timeline depends heavily on company size, scope, and starting point. It includes preparation, risk assessment, implementing controls, an internal audit, and the external Stage 1 and Stage 2 audits from the certification body.
How long is an ISO 27001 certificate valid?
An issued certificate is typically valid for three years. During this period, annual surveillance audits sample parts of the ISMS. After the three years expire, a full recertification is required.
What is the difference between a Stage 1 and a Stage 2 audit?
In the Stage 1 audit, the certification body reviews the documentation for completeness and conformity with the standard, such as scope, risk assessment, and the Statement of Applicability. In the Stage 2 audit, on-site reviewers check whether the documented controls are actually followed, including through interviews and sampling.
What does ISO 27001 certification cost?
Costs consist of internal effort, optional external consulting, and certification body fees. Depending on company size and scope, the range spans from low five-figure amounts up to significantly higher sums. Our audit cost calculator gives a first estimate.