ISO 27001:2022 Certification Process: Step-by-Step Guide
Getting ISO 27001:2022 certified isn’t a single event — it’s a sequence of well-defined phases, each building on the last, that ends with an accredited auditor confirming your Information Security Management System (ISMS) actually works. This guide walks through every phase of that journey: what you’ll build, what auditors look for, and how long each step typically takes.
Quick idea: ISO 27001:2022 helps organizations build a risk-based Information Security Management System (ISMS) to protect confidentiality, integrity, and availability of information, while proving it through a two-stage audit and ongoing surveillance.
ISO 27001:2022 Clauses at a Glance
Before diving into the certification process itself, it helps to know the shape of the standard you’re certifying against. ISO 27001:2022 is built around 11 clauses — the first three are introductory (scope, references, definitions), and clauses 4 through 10 contain the actual certifiable requirements.
ISO 27001:2022 Certification Process in 6 Steps
At a high level, every certification journey compresses into six recognizable steps. The detailed phase breakdown further down expands on each of these.
Stage 1 vs. Stage 2: What's the Difference?
| Aspect | Stage 1 Audit | Stage 2 Audit |
|---|---|---|
| Also called | Documentation review | Certification audit / main audit |
| Focus | Is the ISMS designed correctly and ready? | Does the ISMS actually work in practice? |
| Typical length | 1–2 days | Several days, depending on scope |
| Method | Document and policy review | Interviews, evidence review, process observation |
| Common findings | Missing SoA, incomplete risk assessments, no internal audit evidence | Gaps between documented policy and actual practice |
| Outcome | Proceed, proceed with observations, or delay Stage 2 | Certification recommendation, subject to closing any nonconformities |
Timing tip: Stage 2 is usually scheduled 2–8 weeks after Stage 1 to give you time to close any findings. Booking both stages together with your certification body tends to keep the overall timeline tighter.
Maintaining Certification After You're Certified
| Milestone | When | What Happens |
|---|---|---|
| Certificate issued | After a successful Stage 2 audit | Valid for 3 years, subject to surveillance |
| Surveillance audit — Year 1 | 6–12 months after certification | Sampled review of controls and continual improvement evidence |
| Surveillance audit — Year 2 | Annually | Same as Year 1, different control sample |
| Recertification audit | Before the 3-year certificate expires | Full reassessment, similar in depth to Stage 2 |
Common Mistakes During Certification
Starting evidence collection only right before the audit instead of building it into day-to-day operations.
Treating the Statement of Applicability as a one-time document instead of keeping it current as controls change.
Under-scoping security training so staff can’t answer an auditor’s questions about their own responsibilities.
Skipping the internal audit before the certification audit, which is exactly where Stage 1 gaps tend to surface first.
Losing executive sponsorship midway through the project once the initial certification push loses momentum.
How B4Q Assurance Helps
B4Q Assurance works with organizations preparing for ISO 27001:2022 certification — running gap assessments, helping build the Statement of Applicability and Risk Treatment Plan, and getting teams audit-ready before Stage 1 and Stage 2.
Ready to Start Your Certification Journey?
If you’re weighing how much work stands between where your ISMS is today and a certification audit, a short gap assessment is usually the fastest way to find out.
Book a free strategy call to scope your ISO 27001:2022 certification project.
ISO 27001:2022 Resources
ISO 27001 Transition Requirements – Review the IAF guidance for transitioning from ISO 27001:2013 to ISO 27001:2022.
Information Security Management Standards – Explore ISO’s information security standards and related publications.
ISO 27001 Certification Guidance – Understand the latest certification requirements and implementation best practices.
FAQs
How long does ISO 27001:2022 certification take?
Most organizations take 3‒6 months from kickoff to certification audit, depending on how mature their existing security practices are and how much of the ISMS needs to be built from scratch.
Do we need a consultant to get certified?
No, but many organizations use one or a compliance automation platform to speed up gap analysis, evidence collection, and SoA drafting — particularly for a first-time certification.
What happens if we fail Stage 2?
Certification isn’t pass/fail in the traditional sense. If nonconformities are found, you’re given time to complete corrective actions; certification proceeds once those are verified.
How long is an ISO 27001:2022 certificate valid?
Three years, provided you pass the annual surveillance audits in Years 1 and 2 and complete a recertification audit before expiry.
Can we skip Stage 1 on recertification?
Typically yes — recertification usually begins with a full audit similar in depth to Stage 2, rather than repeating the Stage 1 documentation review.