What Does It Actually Take to Get Your Own Business ISO 27001 Certified?
Last updated 23 July 2026 · 6 min read
Direct Answer
Getting your own business ISO 27001 certified — not evaluating whether a vendor holds it, but earning the certificate yourself — means building and documenting an information security management system (ISMS): defining its scope, running a risk assessment, producing a Statement of Applicability that maps which of the standard's Annex A controls apply and why, and putting those controls into actual practice across the business. An accredited certification body then audits in two stages — Stage 1 reviews the documentation, Stage 2 checks that the controls are genuinely operating — before issuing the certificate. That certificate is not permanent: it requires annual surveillance audits and a full recertification audit roughly every three years to stay valid. As of mid-2026, every currently valid certificate is against the ISO/IEC 27001:2022 edition, since the transition period for the prior 2013 edition closed on 31 October 2025.
Detailed Explanation
What do SOC 2 and ISO 27001 mean when choosing an AI vendor explains both certifications from a buyer's side — reading someone else's certificate before trusting their product with company data. This page covers the opposite direction: what it actually takes for your own business to earn an ISO/IEC 27001 certificate, typically because a customer, regulator, or a competitive deal requires it.
ISO/IEC 27001 certifies an information security management system (ISMS) — an ongoing, documented process for identifying and managing information-security risk — not a single product or a one-time checklist. That distinction shapes the whole process: certification is earned by building and operating a management system, then proving it, not by completing a form.
The Certification Process
1. Define the ISMS scope. Decide which parts of the business — which locations, systems, departments, and data — the management system actually covers. A narrower, accurate scope is more manageable and just as valid as a company-wide one; scope creep here is a common source of delay.
2. Run a risk assessment. Identify information-security risks relevant to the defined scope — unauthorized access, data loss, vendor risk, and similar categories — and assess their likelihood and impact. This assessment is what the rest of the ISMS is built to address, not a document produced once and set aside.
3. Produce a Statement of Applicability (SoA). The SoA maps which of ISO 27001's Annex A controls the business applies, which it excludes, and why, tied directly back to the risk assessment. This is one of the certification's central documents — an auditor uses it to understand what the business committed to and then checks whether that commitment is actually being met.
4. Implement the controls in practice, not just on paper. Access management, incident response procedures, employee security training, vendor risk review, and whatever else the SoA commits to need to actually be operating — a policy document that nobody follows fails the audit just as surely as having no policy at all.
5. Run an internal audit and management review. Before the external audit, the standard requires the business to check its own ISMS is working and have leadership formally review it — catching gaps before an accredited auditor does is both cheaper and faster than failing a Stage 1 or Stage 2 audit.
6. Pass the two-stage external audit. An accredited certification body's Stage 1 audit reviews the ISMS documentation (scope, risk assessment, SoA, policies) for completeness and readiness. Stage 2 is the substantive audit — the auditor checks for actual evidence that the documented controls are operating: log reviews, training records, incident tickets, access reviews. Passing both results in certification.
Staying Certified
Certification is not a one-time achievement. A certified business undergoes annual surveillance audits — lighter-touch checks that the ISMS is still operating — and a full recertification audit roughly every three years. Falling short at a surveillance audit can result in a corrective action requirement or, in serious cases, suspension of the certificate.
The 2022 edition is now the only valid one. ISO published the 2022 revision of 27001 with updated Annex A controls, and the transition period for organizations still certified against the 2013 edition closed on 31 October 2025 — as of mid-2026, any currently valid ISO/IEC 27001 certificate is against the 2022 edition. A business starting certification now builds directly against 2022's control set.
Things to Consider
- This is a materially bigger undertaking than reading a vendor's certificate. Evaluating whether a vendor's ISO 27001 is meaningful (see the vendor-side page) takes minutes; building and passing your own ISMS audit typically takes months of sustained work across the business, not a single project sprint.
- Most first-time certifications bring in outside help. A security consultant or a dedicated ISO 27001 implementation platform (Vanta and Drata are common examples in this space, alongside traditional consultants) often accelerates the risk assessment, SoA, and evidence-collection work — confirm current service scope and cost directly with any provider, since this is a competitive and fast-changing market.
- The audit checks practice, not paperwork. A Statement of Applicability describing controls that aren't genuinely followed is the single most common reason a Stage 2 audit fails — build the actual operating habit before the audit date, not just the document describing it.
- Certification is a credible answer to the exact question this site's vendor-evaluation page raises. If your own customers ask the questions that page describes buyers asking of AI vendors, your own ISO 27001 certificate is the credible answer to give them.
- Scope honestly, not aspirationally. Certifying a narrower, accurately described scope that the business can genuinely operate and evidence is a stronger outcome than an ambitious company-wide scope that strains to pass its Stage 2 audit.
Common Mistakes
- Treating the Statement of Applicability as a one-time document instead of a living commitment. An SoA written once and never revisited as the business changes drifts out of sync with what's actually happening, which surfaces at the next surveillance audit.
- Underestimating the evidence-collection burden. Passing Stage 2 requires genuine evidence — access logs, training completion records, incident tickets — not just a policy stating the control exists; businesses that start evidence collection late scramble in the weeks before the audit.
- Scoping the ISMS too broadly for a first certification. An overly ambitious scope multiplies the amount of the business that has to demonstrate mature, evidenced controls — a narrower, well-run first certification is usually a better outcome than a broad one that barely passes.
- Assuming certification is permanent once achieved. Treating the certificate as a finished project rather than an ongoing commitment leads to a lapsed or suspended certification at the next surveillance audit, which is a worse outcome — reputationally and practically — than never having certified at all.
Frequently Asked Questions
- Is this the same thing as the SOC 2 and ISO 27001 page already on this site?
- No — that page (see what do SOC 2 and ISO 27001 mean when choosing an AI vendor) is written for a buyer evaluating whether a vendor's certification is meaningful. This page is the mirror image: your own business going through the certification process, which is a materially bigger and longer undertaking than reading someone else's certificate.
- How long does ISO 27001 certification typically take for a small or mid-sized business?
- It varies significantly by how mature the business's existing security practices already are, but a first-time certification commonly takes several months to a year from starting the ISMS build to passing the Stage 2 audit — largely because the risk assessment, Statement of Applicability, and evidence that controls have actually been operating (not just documented) all take real time to establish. Verify a realistic timeline with a certification body or implementation consultant for your specific starting point rather than assuming a fixed duration.
- Does certification mean the business is now fully secure?
- No — the same caveat that applies to evaluating a vendor's certificate applies to holding one yourself. ISO 27001 certifies that a management system for identifying and managing information-security risk exists and is being followed, not that every possible security failure has been eliminated. A certified business can still have an incident; the certification is evidence of a disciplined process, not a guarantee of outcome.
References
Related Questions
What Do SOC 2 and ISO 27001 Actually Mean When You're Choosing an AI Vendor?
SOC 2 and ISO 27001 are real security certifications, but neither guarantees an AI tool is safe to use — here's what each one actually verifies.
How Do You Evaluate an AI Vendor's Data Processing Agreement?
Before adopting an AI tool, check its DPA for subprocessors, data residency, retention, training defaults, and certifications — here's what to look for.
Does Business Insurance Cover Mistakes Made by an AI Tool or AI Agent?
Traditional general liability and E&O policies increasingly exclude AI-related errors as of 2026 — confirm what your specific policy actually covers.
How Do You Get Your Business ISO 9001 Certified?
Getting ISO 9001 certified means building a documented quality management system, running internal audits, then passing a two-stage external audit.
How Do You Prepare for a SOC 2 Type II Audit?
Preparing for SOC 2 Type II means picking Trust Services Criteria, closing control gaps, running an observation period, then a CPA firm audits the evidence.
How Do You Automate PCI-DSS Compliance Monitoring and Self-Assessment?
Small merchants automate PCI-DSS compliance with a payment processor that shields them from most of the standard, then continuous SAQ tracking.