Plan certification
How to plan an ISO 27001 certification engagement
Sources reviewed October 1, 2026 ยท By Software Compliance Directory
Plan ISO 27001 certification around an agreed ISMS scope, accountable management, working processes, a qualified certification body, and the full audit cycle. Compare proposals using the same organization and service boundary, including follow-up work and ongoing reviews.
ISO/IEC 27001:2022 sets requirements for an information security management system. ISO publishes standards; external certification bodies perform certification. ISO's certification guidance explains how certification and accreditation differ and how to evaluate bodies and verify certificates. The steps below are an editorial planning checklist to discuss with your chosen provider.
Define the intended certification scope
Start with the customer requirement and the service your organization actually provides. Record legal entities, services, locations, systems, interfaces, and important dependencies. Ask the certification body how that boundary will be described and which evidence it needs to assess it.
Keep the certification scope visible in proposal comparisons. A certificate for one part of a business may not address a customer's request about another service. Resolve ambiguous wording before making a delivery commitment.
Assign program responsibilities
Identify the management sponsor, ISMS owner, control owners, and people responsible for records and improvement work. Separate implementation advice, internal review, software support, and certification activities. Ask how impartiality is handled when several services appear in the same proposal.
Use one practical example in provider conversations: a known risk, the decision about it, the implemented action, and the record showing review. Ask advisers what they will deliver and what your team must maintain. A document package or software subscription should not be treated as the entire operating system.
Evaluate the certification body
Ask for the exact legal entity that will issue the certificate, its applicable accreditation information, and a way to verify the resulting certificate. Check relevant accreditation with the named accreditation body or the verification routes identified by ISO. Confirm whether the proposed certification meets your customer's expectations.
- Who is assigned to audit your organization, and what relevant experience do they have?
- How are scope, locations, remote work, and audit time established?
- Which records and interviews are needed at each stage?
- How are findings, review decisions, and changes communicated?
- What happens if readiness, access, or scheduling assumptions change?
Plan the stages and dependencies
SGS describes Stage 1 and Stage 2 audits followed by certification and ongoing surveillance. LRQA describes a two-stage certification process, with training and optional gap analysis as separate service areas. Confirm the proposed sequence and deliverables directly with the body responsible for your engagement.
Work backward from the customer date using actual dependencies: scope agreement, preparation, available operating records, internal reviews, audit scheduling, findings, and certification decisions. Ask what must be ready for each stage and what can delay the next step. Keep the target date conditional until those assumptions are resolved.
For any corrective action, record the issue, responsible owner, expected response, supporting records, and provider review. Confirm deadlines and any additional audit or follow-up work in writing.
Compare the complete engagement
Request separate lines for preparation services, optional assessments, initial audit stages, travel, additional locations, follow-up work, certificate decisions, surveillance, and recertification. Mark exclusions and unanswered conditions explicitly. Ask how changes in organization size or scope affect the quote.
Compare the same intended scope and audit cycle across providers. Use the cost planning tool to organize assumptions, then replace them with written quotes. This guide does not supply a universal price or audit duration.
Maintain the program and certificate record
Agree the surveillance and recertification schedule with the certification body. Assign owners for recurring records, changes in scope, findings, and certificate status checks. Build those activities into your evidence collection plan so work continues after the initial certificate is issued.
When sharing certification information, confirm the named entity, standard edition, scope, dates, and current status. Use an approved copy and verification link where available. Follow the issuer's rules for certification marks and claims, and keep your customer-facing trust center current when the certificate changes.
Explore directory profiles
Examples from the directory to review against your scope. These are starting points, not a quality ranking.