certifications8 min read

How to get ISO 27001 certified in 2026: the concrete steps

ISO/IEC 27001 certification attests that an organisation manages information security through a structured management system audited by a third party: the ISMS. Required in a growing number of IT tenders and security questionnaires, it concerns software vendors, hosting providers, IT services firms, fintech and health companies — and any organisation handling sensitive customer data. Here is the complete path, step by step, under the edition currently in force: ISO/IEC 27001:2022.

Step 1 — Set the scope and secure management commitment

Everything starts with two structuring decisions. First, the ISMS scope: which activities, sites and systems the management system covers. Too broad a scope makes every later step heavier; an artificially narrow one (certifying a single team just to “get the logo”) is easy to spot and weakens the certificate’s commercial value. Second, top-management commitment: the standard makes it a requirement in its own right — a security policy owned at the highest level, resources allocated, objectives tracked. The auditor will interview management, not just the security officer.

The hub profile for ISO 27001 certification summarises the scheme: voluntary status, certification bodies, three-year cycle.

Step 2 — Assess your information-security risks

This is the foundation of the whole system. You inventory your information assets (data, applications, infrastructure, suppliers), identify threats and vulnerabilities, then rate the risks using a defined, documented and repeatable method. The standard does not prescribe a particular method: it demands consistency — two successive assessments must produce comparable results.

The classic trap is rolling out a list of “standard” controls without a serious risk assessment: the resulting system misses the point, and the auditor sees it as soon as the statement of applicability is examined.

Step 3 — Select controls and write the statement of applicability

Based on the risks, you build the risk treatment plan and select your security controls. Annex A of the 2022 edition lists 93 of them, grouped into four themes: organisational, people, physical and technological. You are not obliged to implement them all, but you must review every one and record your choices — controls adopted, controls excluded, and the justifications — in the statement of applicability (SoA), one of the most closely examined documents at audit. For the details of what changed in 2022, see our article on Annex A and the transition to ISO 27001:2022.

Deployment is then very concrete: access and identity management, tested backups, incident management, endpoint and cloud security, security clauses with subcontractors, staff awareness.

Step 4 — Run the system before the audit

A brand-new ISMS cannot be audited: the audit assesses operation, not intent. Allow several months of real practice: incidents detected, handled and logged; indicators tracked; awareness sessions delivered; access reviews performed. Academic research points the same way: the study by Podrecca, Culot, Nassimbeni and Sartor published in 2022 in Computers in Industry on the performance implications of ISO/IEC 27001 shows that the benefits of certification depend on its genuine integration into operations, beyond the signalling effect (see the study).

Two formal prerequisites must be completed before certification:

  • the internal audit, covering all requirements and the whole scope, carried out by someone competent and independent of the activities audited (an external auditor is allowed);
  • the management review, which examines the ISMS results (risks, incidents, objectives, resources) and closes with recorded decisions.

Step 5 — The two-stage certification audit

The initial audit runs in two phases. Stage 1 checks that the system is ready: documented scope, risk assessment, statement of applicability, internal audit and management review completed. Stage 2 assesses actual implementation: interviews with management and staff, examination of evidence, verification of controls in the field. Any findings are addressed through corrective actions before the certificate is issued — valid for three years, subject to annual surveillance audits.

Request several quotes on a strictly identical scope from accredited bodies: the number of audit days depends on the headcount in scope, the number of sites and the complexity of activities. To anticipate the full budget, read our article on the price of ISO 27001 certification.

Special cases: GDPR, healthcare, training

Watch out for three common confusions. ISO 27001 strongly supports GDPR compliance (security of processing) but does not guarantee it: the regulation carries its own legal requirements — lawful bases, data-subject rights — outside the standard’s scope; our guide to GDPR obligations for training providers illustrates that legal side well. In healthcare, France’s certification for hosting health data builds on ISO 27001 but is a distinct scheme: see the HDS certification profile. Finally, for a French training provider, ISO 27001 does not count towards access to vocational-training funding — that is the territory of Qualiopi, the mandatory French quality certification.

Take action

ISO 27001 certification is earned with a system that genuinely runs: a solid risk assessment, a coherent statement of applicability, a few months of proven operation. Start with the ISO 27001 certification profile — it also offers our free ebook to structure your project — then set your scope this week.

FAQ

Frequently asked questions

+How long does it take to obtain ISO 27001 certification?

Usually several months between ISMS scoping and the audit, sometimes more than a year: it all depends on the size of the scope and your existing security maturity. The system must have genuinely operated (internal audit, management review, logged incidents) before it can be audited — that, far more than writing documents, is the limiting factor.

+Who issues ISO 27001 certification in France?

Third-party certification bodies such as AFNOR Certification, Bureau Veritas or LNE. ISO writes the standard but certifies no one. Choose a body accredited by Cofrac (the French accreditation committee) or an equivalent national body: accreditation is what makes the certificate recognised in tenders and supply chains.

+Do you have to implement all 93 Annex A controls?

No. Annex A is a reference list: you must review every control, adopt those your risk assessment justifies, and document the exclusions in the statement of applicability. A poorly justified exclusion, however, is one of the most common audit findings.

Read next