How Best to Proceed with ISO 27001
- Proceed in this order: buyer requirement, scope, gap analysis, build, operate, internal audit, management review, Stage 1, Stage 2, then maintain.
- Scope is the hardest decision to reverse and belongs at the start.
- Let control selection follow from the risk assessment, not the other way round.
- Book the certification body early. Availability moves dates more than internal delay does.
- Plan the annual cycle at the same time as the certificate, because surveillance samples the year.
Stage 1: The requirement
Proceed in this order: establish what your buyer actually needs, set the scope, run a gap analysis, build the ISMS, operate it long enough to produce records, complete the internal audit and management review, then Stage 1 and Stage 2, then maintain it. The common mistake is writing documentation before scope is agreed, which produces work that has to be redone.
Each stage below carries a decision that is hard to reverse.
Three questions.
Who is asking, and would something else satisfy them? Some buyers accept SOC 2, a completed security questionnaire, or Cyber Essentials for UK public work. Knowing this can save the entire programme cost.
What must the certificate's scope statement cover? That statement is what a buyer reads. If it does not name the service they care about, it does not answer them.
What is the real deadline? Contractual and aspirational deadlines lead to very different plans.
Decision: whether to certify at all, and what the certificate must say.
Stage 2: Scope
Which organisational units, which services, which locations, which information. Name exclusions as well as inclusions.
Scope drives audit days and internal hours, which are the two largest costs. It is also the thing that cannot easily change once an audit is booked.
Decision: the scope statement.
Stage 3: Ownership
Name the person who owns the ISMS and protect their hours. Decide now whether you need external help, and answer honestly: do they have both management system experience and available time.
Bring a firm in at this point rather than after the gap analysis. A consultant who joins after scope is set inherits decisions they would have advised against.
Decision: internal, external, or both, and who specifically.
Stage 4: Gap analysis
A clause-by-clause position against Clauses 4 to 10, a control-by-control position against the 93 Annex A controls, a draft Statement of Applicability, and a remediation plan.
Do this before booking the certification body, so remediation happens on your timetable rather than between Stage 1 and Stage 2.
Decision: the remediation plan and who does each item.
Stage 5: Build
Scope statement, information security policy, roles and responsibilities. The risk assessment method, the risk register, the risk treatment plan. Then the Statement of Applicability, which records which controls apply and why, following from the treatment plan rather than preceding it.
Then the controls themselves: access management, change control, logging and monitoring, supplier security, incident response, business continuity, secure development, and the eleven controls new in the 2022 edition.
Two items take longest and should start first. Anything requiring an engineering change, because it sits in someone else's backlog. And supplier security assessment, because it depends on third parties responding.
Decision: which processes genuinely change, as opposed to which documents get written.
Stage 6: Operate
The ISMS has to run long enough to generate records: access reviews performed, risks reviewed, suppliers assessed, incidents handled, changes approved, corrective actions closed.
This is the constraint that sets your floor. It cannot be assembled retrospectively, and a Stage 2 auditor is specifically looking for whether it was.
Decision: none, if the earlier stages were done properly.
Stage 7: Internal audit and management review
The Clause 9.2 internal audit, performed by someone competent and independent of building the ISMS. Then the Clause 9.3 management review, where leadership considers the results and records decisions.
The order matters: audit, then review, then certification audit. A management review that rubber-stamps a report is itself a common finding.
Decision: who performs the internal audit, and how independence is preserved.
Stage 8: Stage 1 and Stage 2
Stage 1 reviews documentation and readiness and reports anything that would prevent a successful Stage 2. Stage 2 tests whether the ISMS operates, through interviews and sampling.
Brief the people who will be interviewed. What they say should match what the documents claim, and where it does not, the document is usually what is wrong.
Book the body early. Audit slots are booked ahead and availability is a real constraint.
Stage 9: Maintain
Surveillance audits in years two and three, recertification at year three, and an internal audit every year. Risk reviews, access reviews, supplier assessments and incident records continuing throughout.
Plan this at the same time as the certificate. Surveillance samples the year, and a system that stopped in month three is found in month fourteen. Our continuous governance and assurance service covers it.
The order in one table
| Stage | Output | Decision that is hard to reverse |
|---|---|---|
| 1. Requirement | Written statement of what is needed | Whether to certify |
| 2. Scope | The scope statement | The scope itself |
| 3. Ownership | A named owner with protected hours | Internal, external or both |
| 4. Gap analysis | Clause and control position, remediation plan | The remediation plan |
| 5. Build | Policy, risk method, Statement of Applicability, controls | Which processes change |
| 6. Operate | Records across a period | None |
| 7. Internal audit and review | Findings, corrective actions, management decisions | Who audits, and independence |
| 8. Stage 1 and Stage 2 | The certificate | None |
| 9. Maintain | A running ISMS | Who owns the annual cycle |
What sets the timeline
Three to six months for an organisation with reasonable security practice in place. Faster where SOC 2 already exists. Slower from nothing.
Two things you cannot compress: the operating period needed to produce records, and the certification body's availability. Plan both early rather than discovering them late.
What to do next
Settle the requirement and the scope. Those two decisions determine cost, timeline and whether the certificate does its job.
Our free readiness diagnostic gives a first view, and the ISO 27001 service page sets out how we run each stage.
References
FAQ
What is the first step in an ISO 27001 programme?
Establishing what your buyer actually needs, including whether something other than ISO 27001 would satisfy them, and what the certificate's scope statement must cover.
When should we contact certification bodies?
Early, for availability and quotes, but commit to an audit window only after the gap analysis so remediation happens on your timetable.
How long does certification take?
Three to six months for an organisation with reasonable security practice, limited by the operating period and certification body availability.
Can we shorten the operating period?
Not meaningfully. The auditor samples records across a period, and assembling them afterwards is what Stage 2 is designed to detect.
What happens after the certificate?
Annual internal audit, management review, surveillance audits in years two and three, and recertification at year three.
About Hael
Hael is an advisory firm specialising in AI governance and security compliance. We do the work, hold the deadline and stand behind the evidence, taking companies through ISO 27001 from gap analysis to certificate and maintaining the position afterwards. We are not a certification body and we take no commission from certification bodies. On engagements involving regulated financial services firms we work alongside Buckingham Capital Consulting, the partner firm that has advised payment and e-money firms on FCA authorisation and compliance since 2013.
This guide is general information and is not professional advice on your particular circumstances.