Operational guidance, not legal advice. This page distills named public sources (regulator guidance and industry practice). It is not a legal determination, not a notification decision, and not a substitute for your counsel, insurer, or a retained DFIR firm. Verify applicability and current deadlines for your facts and jurisdiction.

How do you get ISO 27001 certified?

Last verified

Build an ISMS under Clauses 4–10, write a SoA for Annex A, run internal audit and management review, then pass Stage 1 and Stage 2 with an accredited body. This page is not legal advice, does not determine YOUR obligations, does not start a clock, and does not file.

How-to, last verified 10 September 2026. ISO 27001 is a voluntary standard, not a law. Mandatory clause work (risk assessment, SoA, internal audit, management review) is different from optional choices (consultants, tooling, a readiness assessment). Only an accredited certification body issues the certificate.

What this page is, and what it is not

Audience: a compliance lead starting from zero who needs the sequence before committing budget.

This page is not legal advice. It does not determine YOUR obligations, does not start a clock, and does not file an application with a certification body. Last verified 10 September 2026.

ISO/IEC 27001 is voluntary. You do not have to get certified unless a contract or other authority says so — and even then, that authority is not this page. Clauses 4–10 are the certifiable ISMS requirements. Annex A is selectable via the SoA. The certification body works to ISO/IEC 17021-1 and ISO/IEC 27006; IAF MD 5 influences audit duration.

Numbered path from scope to certificate

Each row separates what the clause requires from an optional choice you may make. Last verified 10 September 2026. Not legal advice.

Steps to accredited ISO/IEC 27001 certification (not a quote; not legal advice; last verified 10 September 2026)
StepWhat the clause requiresOptional choiceKind of text
1. Scope the ISMS (Clause 4)Define the organisation, boundaries, and interested parties the ISMS covers. Document the scope.Hire a consultant to facilitate workshops. Narrow to one product first.Certification standard (context).
2. Leadership and policy (Clause 5)Top management direction, roles, and an information security policy as documented information.A longer policy suite beyond the mandatory policy.Certification standard (leadership).
3. Risk assessment and treatment (Clause 6)Assess information-security risks and treat them. Produce risk assessment and treatment documented information.ISO/IEC 27005 as a method. A particular scoring scale.Certification standard (planning). 27005 is guidance.
4. Statement of Applicability (Clause 6.1.3)List necessary controls, justify inclusion, justify any Annex A exclusion, state implementation status.Including extra controls beyond Annex A. A readiness (gap) assessment first — best practice, not a mandatory clause.Certification standard (SoA).
5. Support, operate, evaluate, improve (Clauses 7–10)Competence, documented information, operation of the ISMS, monitoring, internal audit, management review, corrective actions.Which tools hold the records. How often you sample between audits.Certification standard (support through improvement).
6. Accredited Stage 1 then Stage 2A certification body accredited for ISO/IEC 27001 reviews documentation/readiness, then implementation/effectiveness.Which IAF-MLA body (for example UKAS or ANAB accredited) you contract. Timing of the Stage 1→2 gap.ISO/IEC 17021-1 and ISO/IEC 27006, with IAF MD 5 for audit days — not a product quote.

Mandatory documented information, in brief

Typical mandatory documented information includes ISMS scope, the information security policy, risk assessment and treatment, the SoA, internal-audit results, management review, and corrective actions. Supporting operating records (access reviews, change tickets, logs) are what Stage 2 samples; they are not all named as the same class of documented information. Last verified 10 September 2026. Not legal advice.

Checklist

This numbered list is the checklist artifact. Last verified 10 September 2026. Not legal advice.

  • Is the ISMS scope written, with boundaries a Stage 1 auditor could test?
  • Do we have risk assessment and treatment records, not only a slide?
  • Does the SoA list necessary controls, justify inclusion, justify Annex A exclusions, and state implementation status?
  • Have internal audit and management review actually run, with results retained?
  • Is the certification body IAF-MLA accredited for ISO/IEC 27001 (check IAF CertSearch)?
  • Have we treated the readiness assessment as optional best practice, not as Stage 1?

What to do now

These steps do not start a clock and do not file an application.

  • Write a one-page scope. If you cannot, you are not ready to buy audit days.
  • Draft the SoA against Annex A (93 controls / four themes) without pretending all 93 are in.
  • Schedule internal audit and management review before you request Stage 1.
  • Read the certification-process and readiness-assessment pages in this cluster.
  • Shortlist accredited bodies using the choose-a-certification-body page — never an unaccredited “certificate.”

Where this shows up in ShipReady Metrics

Only shipped behaviour is described here. ShipReady Metrics does not issue certificates, does not produce an auditor's opinion, and is not a downloadable evidence binder.

If you already have a session: signed-in app → Compliance holds ISO 27001 in the 24-framework library, evidence collection, evidence review with a met-verdict overlay, the obligation map, the policies library, and the cyber risk register. Annex A is crosswalked to about 72 canonical controls with a crosswalk-density honesty layer — coverage, not a pass.

Those surfaces help you assemble artefacts for Clauses 4–10 and selected Annex A controls. An accredited certification body still performs Stage 1 and Stage 2.

Primary sources (last verified 10 September 2026)

ISO/IEC 27001:2022 Clauses 4–10 and Clause 6.1.3. ISO/IEC 27002:2022 as guidance. IAF, ISO/IEC 17021-1, ISO/IEC 27006, and IAF MD 5 for the accredited audit. Not legal advice.

Frequently asked questions