LRQA describes ISO 27001 certification, training, and optional gap analysis. Evaluate the issuing entity, proposed audit scope, delivery arrangements, findings process, and ongoing program before comparing a proposal.
Documented services
LRQA's ISO 27001 service page describes a two-stage certification process, training, and optional gap analysis. It also discusses remote or on-site delivery and integrated audits. Confirm which arrangements are suitable and included for your organization.
Engagement considerations
Explain the intended ISMS boundary and the customer requirement behind certification. Identify relevant legal entities, locations, processes, and dependencies. Ask how the proposed team determines audit coverage and handles records or interviews that cannot be reviewed remotely.
If considering an integrated audit or a certificate transfer, request a distinct scope and the conditions the body must evaluate. Discuss the actual assigned team and schedule. Have the provider walk through an anonymized finding, response, review, and decision.
Questions to verify in a consultation
- Which issuing entity and relevant accreditation apply?
- How are the audit stages, time, and locations established?
- Which delivery methods and optional assessments are proposed?
- What findings response and additional review are required?
- Which fees and responsibilities continue after initial certification?
Scope to confirm
Itemize initial audits, optional services, remote and on-site work, follow-up, surveillance, and recertification. Verify accreditation and certificate status directly for the issuing entity. A published description of flexible delivery does not establish that every activity can be performed remotely or that certification will be issued on a promised date.
Plan ISO 27001 certification · Explore ISO 27001 resources · Plan evidence collection
Buying content reviewed October 1, 2026. Public sources; no firsthand service evaluation.