Operational guidance, not legal advice. This page distills named public sources (regulator guidance and industry practice). It is not a legal determination, not a notification decision, and not a substitute for your counsel, insurer, or a retained DFIR firm. Verify applicability and current deadlines for your facts and jurisdiction.
How do you get ISO 27001 certified?
Last verifiedBuild an ISMS under Clauses 4–10, write a SoA for Annex A, run internal audit and management review, then pass Stage 1 and Stage 2 with an accredited body. This page is not legal advice, does not determine YOUR obligations, does not start a clock, and does not file.
How-to, last verified 10 September 2026. ISO 27001 is a voluntary standard, not a law. Mandatory clause work (risk assessment, SoA, internal audit, management review) is different from optional choices (consultants, tooling, a readiness assessment). Only an accredited certification body issues the certificate.
What this page is, and what it is not
Audience: a compliance lead starting from zero who needs the sequence before committing budget.
This page is not legal advice. It does not determine YOUR obligations, does not start a clock, and does not file an application with a certification body. Last verified 10 September 2026.
ISO/IEC 27001 is voluntary. You do not have to get certified unless a contract or other authority says so — and even then, that authority is not this page. Clauses 4–10 are the certifiable ISMS requirements. Annex A is selectable via the SoA. The certification body works to ISO/IEC 17021-1 and ISO/IEC 27006; IAF MD 5 influences audit duration.
Numbered path from scope to certificate
Each row separates what the clause requires from an optional choice you may make. Last verified 10 September 2026. Not legal advice.
| Step | What the clause requires | Optional choice | Kind of text |
|---|---|---|---|
| 1. Scope the ISMS (Clause 4) | Define the organisation, boundaries, and interested parties the ISMS covers. Document the scope. | Hire a consultant to facilitate workshops. Narrow to one product first. | Certification standard (context). |
| 2. Leadership and policy (Clause 5) | Top management direction, roles, and an information security policy as documented information. | A longer policy suite beyond the mandatory policy. | Certification standard (leadership). |
| 3. Risk assessment and treatment (Clause 6) | Assess information-security risks and treat them. Produce risk assessment and treatment documented information. | ISO/IEC 27005 as a method. A particular scoring scale. | Certification standard (planning). 27005 is guidance. |
| 4. Statement of Applicability (Clause 6.1.3) | List necessary controls, justify inclusion, justify any Annex A exclusion, state implementation status. | Including extra controls beyond Annex A. A readiness (gap) assessment first — best practice, not a mandatory clause. | Certification standard (SoA). |
| 5. Support, operate, evaluate, improve (Clauses 7–10) | Competence, documented information, operation of the ISMS, monitoring, internal audit, management review, corrective actions. | Which tools hold the records. How often you sample between audits. | Certification standard (support through improvement). |
| 6. Accredited Stage 1 then Stage 2 | A certification body accredited for ISO/IEC 27001 reviews documentation/readiness, then implementation/effectiveness. | Which IAF-MLA body (for example UKAS or ANAB accredited) you contract. Timing of the Stage 1→2 gap. | ISO/IEC 17021-1 and ISO/IEC 27006, with IAF MD 5 for audit days — not a product quote. |
Legal requirement, regulatory guidance, best practice, or our recommendation
Do not treat optional programme choices as clause requirements. Last verified 10 September 2026. Not legal advice.
| Statement | Which kind of authority | What it does not mean |
|---|---|---|
| Clauses 4–10 must be fulfilled for an accredited certificate. | Certification standard. | Does not make certification a legal duty for organisations that have not sought it. |
| Annex A controls are selected in the SoA; they are not all mandatory. | Certification standard (planning / SoA). | Does not let you skip Clauses 4–10. |
| A gap or readiness assessment before Stage 1. | Industry best practice. Not a mandatory clause. | Does not replace Stage 1. |
| IAF MD 5 and ISO/IEC 27006 influence how long the audit takes. | Accreditation guidance / CB standard. | Does not quote your fee or guarantee a date. |
| Record evidence against a crosswalk and keep a named human verdict on manual rows before you book Stage 2. | ShipReady Metrics recommendation. | Does not issue a certificate and does not file. |
Mandatory documented information, in brief
Typical mandatory documented information includes ISMS scope, the information security policy, risk assessment and treatment, the SoA, internal-audit results, management review, and corrective actions. Supporting operating records (access reviews, change tickets, logs) are what Stage 2 samples; they are not all named as the same class of documented information. Last verified 10 September 2026. Not legal advice.
Checklist
This numbered list is the checklist artifact. Last verified 10 September 2026. Not legal advice.
- Is the ISMS scope written, with boundaries a Stage 1 auditor could test?
- Do we have risk assessment and treatment records, not only a slide?
- Does the SoA list necessary controls, justify inclusion, justify Annex A exclusions, and state implementation status?
- Have internal audit and management review actually run, with results retained?
- Is the certification body IAF-MLA accredited for ISO/IEC 27001 (check IAF CertSearch)?
- Have we treated the readiness assessment as optional best practice, not as Stage 1?
What to do now
These steps do not start a clock and do not file an application.
- Write a one-page scope. If you cannot, you are not ready to buy audit days.
- Draft the SoA against Annex A (93 controls / four themes) without pretending all 93 are in.
- Schedule internal audit and management review before you request Stage 1.
- Read the certification-process and readiness-assessment pages in this cluster.
- Shortlist accredited bodies using the choose-a-certification-body page — never an unaccredited “certificate.”
Where this shows up in ShipReady Metrics
Only shipped behaviour is described here. ShipReady Metrics does not issue certificates, does not produce an auditor's opinion, and is not a downloadable evidence binder.
If you already have a session: signed-in app → Compliance holds ISO 27001 in the 24-framework library, evidence collection, evidence review with a met-verdict overlay, the obligation map, the policies library, and the cyber risk register. Annex A is crosswalked to about 72 canonical controls with a crosswalk-density honesty layer — coverage, not a pass.
Those surfaces help you assemble artefacts for Clauses 4–10 and selected Annex A controls. An accredited certification body still performs Stage 1 and Stage 2.
Primary sources (last verified 10 September 2026)
ISO/IEC 27001:2022 Clauses 4–10 and Clause 6.1.3. ISO/IEC 27002:2022 as guidance. IAF, ISO/IEC 17021-1, ISO/IEC 27006, and IAF MD 5 for the accredited audit. Not legal advice.