Learn about steps towards certification, risk assessment, gap analysis, Stage 1 & 2 audits, nonconformities, internal audit, management review, and more, through the Frequently Asked Questions (FAQs) below. Please schedule a meeting if you are looking for an authorized certifying body for your ISO 27001 Certification.
Table of Contents
What are the steps to achieve ISO 27001 certification?
Summary: Achieving ISO 27001 certification involves seven broad phases, scoping, gap analysis, risk assessment, ISMS implementation, internal audit, management review, and a two, stage external audit.
The ISO 27001 certification process unfolds as follows. First, the organization defines its ISMS scope. Second, a gap analysis compares current security practices against ISO 27001:2022 requirements. Third, a formal risk assessment identifies threats, vulnerabilities, and risks to in, scope assets. Fourth, a risk treatment plan and Statement of Applicability are produced. Fifth, the organization implements controls and develops required policies, procedures, and training programs. Sixth, the ISMS operates for a period sufficient to generate audit evidence, typically at least three months. Seventh, the organization conducts an internal audit and management review. Finally, the organization undergoes a Stage 1 documentation audit and a Stage 2 operational audit by an accredited certification body, after which, if no major nonconformities are found, the certificate is issued.
What is a gap analysis in ISO 27001?
An ISO 27001 gap analysis is a structured assessment comparing an organization’s current information security practices, controls, policies, and documentation against the requirements of ISO/IEC 27001:2022, identifying areas where the organization does not yet meet the standard. The output is a gap report that prioritizes remediation and provides input to the ISMS implementation project plan. A gap analysis evaluates current ISMS governance, policy alignment with ISO 27001 requirements, risk assessment maturity, documentation completeness, Annex A control coverage, and the existence of internal audit and management review programs. A gap analysis can be conducted internally or by an external consultant. The output should be a prioritized roadmap telling the organization exactly what must be built, fixed, or documented before the certification audit. While not required by the standard, a gap analysis is considered essential preparation.
What is a risk assessment in ISO 27001?
An ISO 27001 risk assessment is the systematic, documented process required under Clause 6.1.2 of ISO 27001:2022 through which an organization identifies information security risks, evaluates their likelihood and impact, and determines which require treatment.
The process begins by establishing a methodology, defining how risks are identified, how likelihood and impact are scored, and what the organization’s risk acceptance threshold is. Information assets within the ISMS scope are catalogued. For each asset, relevant threats and weaknesses are identified. Each risk is assigned a severity level, and those exceeding the acceptance threshold are escalated for treatment. The risk assessment must be documented, repeatable, and comparable across assessment cycles, and must be refreshed at planned intervals or when significant changes occur. It is the foundation of the entire ISMS, every control selection and SoA entry should trace back to it. Common audit failures arise from risk assessments that are generic, undocumented, or not genuinely linked to the organization’s actual environment.
What is a risk treatment plan in ISO 27001?
A risk treatment plan is a formal document required under Clause 6.1.3 of ISO 27001:2022 that records how the organization addresses each identified information security risk that exceeds its risk acceptance threshold.
For each risk, the plan specifies the chosen treatment option, mitigate (implement controls), accept (acknowledge and monitor with documented justification), transfer (such as through cyber insurance), or avoid (discontinue the risky activity). Where mitigation is chosen, the plan identifies specific controls selected from Annex A, assigns a risk owner, sets an implementation timeline, and records the expected residual risk after controls are in place. The risk treatment plan requires formal management approval and must be maintained as a living document. Auditors treat it as a key document linking the risk assessment to the SoA and to the operational controls the organization has actually implemented.
What is a Stage 1 audit in ISO 27001?
The Stage 1 audit, also called the documentation review or readiness audit, is the first of two stages in the ISO 27001 certification audit process. During Stage 1, the auditor from the accredited certification body reviews the organization’s ISMS documentation, including the scope statement, Information Security Policy, risk assessment outputs, risk register, risk treatment plan, Statement of Applicability, internal audit records, and management review records, to assess whether the ISMS has been designed in conformance with ISO 27001:2022. Stage 1 typically takes one to two days and may be conducted remotely. It results in a report identifying documentation gaps or areas of concern. Based on Stage 1 findings, the auditor develops the audit plan for Stage 2. Passing Stage 1 does not result in certification, it confirms readiness to proceed to the operational assessment.
What is a Stage 2 audit in ISO 27001?
The Stage 2 audit, also called the certification audit, is the comprehensive, on, site assessment in which the accredited certification body evaluates whether the organization’s ISMS is not only designed correctly but actually implemented, operational, and effective.
Stage 2 auditors verify that policies and procedures documented in the ISMS are genuinely practiced, that selected Annex A controls are implemented and working as intended, and that management system processes including risk assessment, internal audit, and management review are functioning as required by ISO 27001:2022. Auditors conduct interviews with employees at multiple levels, review operational evidence such as access logs, vulnerability scan reports, training records, and incident logs, and test whether practices align with documented procedures. Stage 2 audits are typically conducted on, site and may span multiple days depending on organizational size and complexity. A successful Stage 2 audit results in issuance of the ISO 27001 certificate. Major nonconformities identified during Stage 2 must be resolved before the certificate is issued.
Is a pre-assessment or readiness assessment required before an ISO 27001 audit?
A readiness assessment is not required by ISO 27001 but is strongly recommended as a best practice, particularly for organizations pursuing initial certification. A readiness assessment reviews the organization’s ISMS against ISO 27001:2022 requirements before the formal certification audit, identifying documentation gaps, control weaknesses, and process deficiencies that would likely result in audit findings if left unresolved. Organizations that invest in a readiness assessment typically experience smoother Stage 1 and Stage 2 audits, fewer findings, and a shorter overall path to certification. Readiness assessments can be conducted by an ISO 27001 consultant, the certification body as a pre-audit service, or an internal team with sufficient standard knowledge.
What is an internal audit in ISO 27001, and when must it be conducted?
An ISO 27001 internal audit is a planned, independent review of the organization’s ISMS, required by Clause 9.2 of ISO 27001:2022, that verifies the ISMS conforms to the standard’s requirements and is effectively implemented.
Internal audits must be conducted at planned intervals, interpreted by most certification bodies as at minimum annually. The auditor must be competent in ISO 27001 requirements and independent of the area being audited, meaning the person responsible for a control cannot audit that same control. Findings must be documented, reported to management, and followed up with corrective actions where nonconformities are identified. Evidence of internal audits, including plans, checklists, findings report, and corrective action records, is reviewed by external auditors during Stage 2, surveillance, and recertification audits. A functioning internal audit program is one of the most scrutinized elements of any ISO 27001 audit.
What is a management review in ISO 27001?
A management review is a formal, documented meeting required by Clause 9.3 of ISO 27001:2022 in which top management evaluates the ISMS performance, suitability, and effectiveness at planned intervals, at minimum annually.
The agenda must address: the status of actions from previous reviews, changes in internal and external context relevant to the ISMS, feedback on security performance including incidents and audit results, the status of the risk treatment plan, and opportunities for continual improvement. The output must include decisions and actions related to improvement opportunities, resource needs, and required ISMS changes. Management review records must be retained as documented evidence. External auditors will review management review minutes during Stage 2 and surveillance audits to confirm that top management is genuinely engaged in ISMS governance, a rubber, stamped management review with no substantive discussion is a recognized audit weakness.
What happens if a nonconformity is found during the ISO 27001 audit?
When a nonconformity is identified during an ISO 27001 audit, it is classified as either a major or minor nonconformity, each with different consequences for the certification timeline.
A major nonconformity represents a significant failure affecting the ISMS’s ability to achieve its intended outcomes, for example, the complete absence of a risk assessment, no internal audits ever conducted, or systemic breakdown of a critical control. A major nonconformity must be resolved before the ISO 27001 certificate can be issued or maintained. The organization must submit a corrective action plan with root cause analysis and evidence of remediation, which the certification body reviews and may verify through a follow, up audit. A minor nonconformity is a less critical gap, a lapse within an otherwise functioning process. Minor nonconformities must be corrected within a defined timeframe (typically 90 days) with evidence submitted to the certification body; they do not prevent initial certification.
What is the difference between a major and minor nonconformity in ISO 27001?
In ISO 27001 audits, a major nonconformity is a finding representing a significant ISMS breakdown, either the absence of a required element or a systemic failure indicating the ISMS is not achieving its intended purpose. Examples include: no documented risk assessment process, no internal audit having been conducted, or a critical Annex A control with no implementation. Major nonconformities block certification until the organization demonstrates corrective action verified by the certification body, sometimes through a special follow, up audit. A minor nonconformity is an isolated weakness or partial implementation within an otherwise functioning process, for example, one department not yet trained when the overall training program is operating, or a control implemented but not documented as required. Minor nonconformities must be addressed within approximately 90 days with supporting evidence submitted to the certification body.
What is a surveillance audit in ISO 27001?
A surveillance audit is a periodic, interim audit required to verify that a certified organization continues to operate its ISMS in conformance with ISO 27001:2022 requirements between full recertification cycles. Surveillance audits are conducted at least annually, typically at the end of the first year and second year after initial certification. They are generally shorter and less intensive than the full certification audit, focusing on highest, risk areas, verifying correction of previous nonconformities, and confirming that internal audits and management reviews are being conducted. Failure to maintain adequate surveillance audit results can result in suspension or withdrawal of the ISO 27001 certificate. Organizations should treat surveillance audits with the same preparation discipline as the initial certification audit, maintaining current documentation and control operation evidence throughout the year.
What is a recertification audit in ISO 27001?
A recertification audit is the comprehensive audit conducted at the end of the three, year ISO 27001 certificate validity period to determine whether the organization’s ISMS continues to meet ISO 27001:2022 requirements and whether the certificate should be renewed for another three, year cycle. Unlike surveillance audits, which are partial reviews, the recertification audit covers the full ISMS scope, comparable in depth to the original Stage 2 certification audit, though the organization benefits from the established audit history from the preceding surveillance audits. The recertification audit reviews overall ISMS performance, effectiveness of corrective actions, internal audit and management review results, continual improvement evidence, and any changes to the organization or its risk environment. A new three, year certificate is issued upon successful completion. Organizations should begin planning for recertification at least six months before their current certificate expiry.
How long is an ISO 27001 certificate valid?
An ISO 27001 certificate is valid for three years from the date of issuance. During this three, year period, the certified organization must undergo surveillance audits at least annually to maintain the certificate, certification is not passively maintained. Failure to cooperate with surveillance audits, significant ISMS breakdowns, or withdrawal of cooperation with the certification body can result in suspension or withdrawal of the certificate before the three, year expiry. At the end of the three, year cycle, a recertification audit renews the certificate for a further three years. ISO 27001 certification is therefore both a milestone achievement and an ongoing operational obligation, it signals not just that the organization passed an audit at a point in time, but that it maintains a functioning ISMS continuously.
How do you choose an accredited ISO 27001 certification body?
Summary: Selecting an ISO 27001 certification body requires verifying accreditation status, assessing industry experience, confirming geographic coverage, evaluating auditor qualifications, and comparing pricing transparency across multiple providers.
The most critical criterion is accreditation: the certification body must be accredited by a recognized national accreditation authority, in the United States, the ANSI National Accreditation Board (ANAB), the International Accreditation Service (IAS), or another IAF MLA signatory body. Certificates from non, accredited bodies are not globally recognized. Beyond accreditation, evaluate: the certification body’s experience in your specific industry, auditor qualifications and track record, geographical presence for multi, site programs, scheduling availability, clarity of audit day pricing, and the quality of Stage 1 reporting. Organizations should request itemized quotes from at least two to three accredited certification bodies rather than accepting the first quote received. In the United States, databrackets is accredited by the International Accreditation Service (IAS) and the American Association for Laboratory Accreditation (A2LA) to issue ISO/IEC 27001:2022 certificates.
What documents does an auditor review during an ISO 27001 certification audit?
During an ISO 27001 certification audit, auditors review a comprehensive set of ISMS documents across Stage 1 (documentation review) and Stage 2 (operational assessment).
At Stage 1, key documents reviewed include: the ISMS scope statement, Information Security Policy, risk assessment methodology and risk register, risk treatment plan, Statement of Applicability, asset inventory, internal audit records and reports, management review minutes, and corrective action records. At Stage 2, the auditor additionally reviews operational evidence: topic, specific policies (access control, cryptography, acceptable use, supplier security), training and awareness completion records, incident logs, vulnerability scan and penetration test reports, access control configurations and reviews, change management records, supplier contract security clauses, business continuity and disaster recovery plans, and ISMS measurement records. The SoA is a pivotal document at both stages, the auditor cross, references it against the risk register to verify that control selections are genuinely risk, driven, not template, generated.
What is an ISO 27001 audit checklist?
An ISO 27001 audit checklist is a structured reference tool that maps each auditable requirement of ISO/IEC 27001:2022, covering Clauses 4, 10 and all 93 Annex A controls, to specific evidence requirements and evaluation criteria.
An internal audit checklist serves the same purpose for the organization’s own internal audit team. A well, structured checklist covers for each Clause 4, 10 requirements, the specific obligation, the type of evidence expected, and the questions to ask; for each applicable Annex A control, the implementation requirements and operational tests to perform. Organizations can build checklists from the standard’s text or use templates from GRC platforms. Internal audit checklists should be used at minimum annually and updated whenever the ISMS scope changes, new controls are added, or the standard is revised. A comprehensive checklist ensures no control area is overlooked and provides a consistent, repeatable audit framework year over year.
What is the difference between a first-party, second-party, and third-party ISO 27001 audit?
ISO 27001 audits are classified by who conducts them and for what purpose. A first-party audit is an internal audit conducted by the organization itself to verify its own ISMS conformance, required by Clause 9.2 and used to drive internal improvement. A second-party audit is conducted by one organization on another with whom it has a business relationship, for example, a customer auditing a supplier before awarding a contract. Second-party audits serve vendor due diligence purposes and are not part of the formal ISO 27001 certification process. A third-party audit is conducted by an independent, accredited certification body, the external audit that results in the ISO 27001 certificate and carries the highest credibility because no commercial relationship exists between auditor and auditee.
What is an ISO 27001 corrective action plan?
An ISO 27001 corrective action plan is a formal, documented response to an identified nonconformity that records the root cause, the corrective actions taken, the responsible person, the completion timeline, and the method used to verify effectiveness.
Required by Clause 10.2 of ISO 27001:2022, the organization must react to every nonconformity, whether from an internal audit, external certification audit, security incident, or management review, evaluate its root cause, implement actions to prevent recurrence, and verify effectiveness. Evidence of the full corrective action cycle must be retained as documented information. Certification bodies review corrective action records during surveillance and recertification audits as evidence of continual improvement. A common ISMS weakness is treating corrective actions as one, time fixes without root cause analysis, allowing the same nonconformity to recur, which auditors identify as a systemic problem.
Explore Blogs, Webinars and other Resources
Trusted by Reputed Companies
What Our Clients Say
We used databrackets (formerly EHR 2.0) in our small medical practice for our risk analysis assessment to be in compliance with meaningful use. Their response was fast, the final report is detailed but simple and easy to follow. They were always available to answer our questions.
E. Compres
Pulmonary and Sleep Center of the Valley
I never miss the opportunity to learn something new …that’s why I am always registering to all free seminars offered on the web. databrackets (formerly EHR 2.0) happened to be the friendliest, comprehensive and up-to- date source of HIPAA Privacy and Security updates.
Alexandra V.
Community Healthcare Network
Today’s presentation was great! Thank you for sending the slides. My only feedback is that it would be fabulous to have the slides ahead of time so I could print them and take notes on the slides.Thanks for your time and knowledge today!
T.B., PM
Community Health Network
Particularly interesting was the flow chart on Administrative Simplification. I utilize all of the Security subcategories you list under the Security tile and appreciate knowing that I am hitting all of the relevant topics during my employee training.
Jessica B.
JD, CHC
I have re-worked our original risk assessment….We are using databrackets' (formerly EHR 2.0) Meaningful Use Security Risk Analysis Toolkit and it meets our needs. It was easy to use and I believe that it very beneficial to our meeting meaningful use.
Bill Curtis
Neurosurgical Associates Of Texarkana, TX
Information (webinars) presented by databrackets (formerly EHR 2.0) highlights some of today’s most demanding healthcare topics. The webinars help to direct those operating in today’s rapidly changing environment in the right direction.
Candace M.
Privacy and Security Officer, Springhill Medical Center
Our Growing List of Credentials
0
+
Assessments
0
+
Clients
0
+
Assessment Libraries
0
+
Years of Experience
0
+
No. of Staff Trained
0
+
HIPAA
0
+
SOC 2 Readiness
0
+
Pen Testing
0
+
ISO 27001 Certifications
0
+
Dollars Saved in Compliance Penalties