ISO 27001 certification evaluates an ISMS within a defined scope against the standard. Preparation includes scope, risk assessment, treatment implementation, internal audit, management review and corrective action before the certification audit.
valid ISO/IEC 27001 certificates in 2023
ISO research published in 2026 reports 83,016 valid certificates across 165 countries in 2023, up from 4,073 in 2006. Certification still does not guarantee a fixed security level.
ISO — Research Grant 2024 / ISO SurveyDefine scope before setting dates
Scope should map to identifiable activities, sites, systems and interfaces. Too broad and effort is diluted; artificially narrow and critical external dependencies remain unresolved.
Name the sponsor, ISMS lead, risk owners and control owners early. The schedule depends on the real gap between current operations and requirements.
Build a living delivery register
Map each requirement and risk to an action, owner, date and evidence. Evidence should come from operation: a closed ticket, access review, test result, backup record or decision minute.
Avoid idealized policies that contradict the field. A modest process that runs and is measured is stronger than an ambitious document nobody follows.

Prepare the audit stages
Certification normally includes readiness and implementation assessment according to the certification body’s program. Internal audit and management review must first identify weaknesses, make decisions and track corrections.
Select a competent accredited body for the sector and clarify scope, sites, duration and required expertise.
Manage beyond the certificate
Certification is not the end of the ISMS. Change, incidents, surveillance audits and objectives sustain improvement. Align risk review with business and technology cycles rather than an annual documentation rush.
- Scope and interfaces
- Risk and treatment
- Statement of Applicability
- Metrics and evidence
- Internal audit and management review
- Corrective action
Operational decision matrix
| Stage | Question to resolve | Expected outcome |
|---|---|---|
| Gap review | Compare practices, requirements and scope. | Prioritize gaps |
| Build | Deploy governance, risk and controls. | Produce evidence |
| Internal audit | Test conformity and effectiveness. | Correct nonconformities |
Avoid a showcase project
Durable certification comes from routines people actually use. Documents should describe the operating system, not an imaginary organization.
The right control level depends on context, exposed assets and business impact: document assumptions, measure the outcome and reassess after every material change.
Frequently asked questions
How long does certification take?
It depends on scope, maturity and resources. An initial gap assessment provides a better estimate than a generic timeline.
Who issues certification?
A competent certification body, preferably accredited for that activity.
Does a certificate cover the whole company?
Only the scope stated on the certificate. Always read the certified scope carefully.
Official sources
Achraf Hachimi
CISSP-certified Senior SOC / CSIRT Engineer specializing in Incident Response, Threat Hunting and Detection Engineering. Eight years of experience in critical environments with Splunk ES, Microsoft Defender XDR, SentinelOne and Cybereason.
