Hael
Book a meeting
ISO 27001 · Programme

How Best to Proceed with ISO 27001

Hael · Published 7 August 2026 · Last reviewed 7 August 2026 · 8 min read
Key takeaways
  • Proceed in this order: buyer requirement, scope, gap analysis, build, operate, internal audit, management review, Stage 1, Stage 2, then maintain.
  • Scope is the hardest decision to reverse and belongs at the start.
  • Let control selection follow from the risk assessment, not the other way round.
  • Book the certification body early. Availability moves dates more than internal delay does.
  • Plan the annual cycle at the same time as the certificate, because surveillance samples the year.

Stage 1: The requirement

Proceed in this order: establish what your buyer actually needs, set the scope, run a gap analysis, build the ISMS, operate it long enough to produce records, complete the internal audit and management review, then Stage 1 and Stage 2, then maintain it. The common mistake is writing documentation before scope is agreed, which produces work that has to be redone.

Each stage below carries a decision that is hard to reverse.

Three questions.

Who is asking, and would something else satisfy them? Some buyers accept SOC 2, a completed security questionnaire, or Cyber Essentials for UK public work. Knowing this can save the entire programme cost.

What must the certificate's scope statement cover? That statement is what a buyer reads. If it does not name the service they care about, it does not answer them.

What is the real deadline? Contractual and aspirational deadlines lead to very different plans.

Decision: whether to certify at all, and what the certificate must say.

Stage 2: Scope

Which organisational units, which services, which locations, which information. Name exclusions as well as inclusions.

Scope drives audit days and internal hours, which are the two largest costs. It is also the thing that cannot easily change once an audit is booked.

Decision: the scope statement.

Stage 3: Ownership

Name the person who owns the ISMS and protect their hours. Decide now whether you need external help, and answer honestly: do they have both management system experience and available time.

Bring a firm in at this point rather than after the gap analysis. A consultant who joins after scope is set inherits decisions they would have advised against.

Decision: internal, external, or both, and who specifically.

Stage 4: Gap analysis

A clause-by-clause position against Clauses 4 to 10, a control-by-control position against the 93 Annex A controls, a draft Statement of Applicability, and a remediation plan.

Do this before booking the certification body, so remediation happens on your timetable rather than between Stage 1 and Stage 2.

Decision: the remediation plan and who does each item.

Stage 5: Build

Scope statement, information security policy, roles and responsibilities. The risk assessment method, the risk register, the risk treatment plan. Then the Statement of Applicability, which records which controls apply and why, following from the treatment plan rather than preceding it.

Then the controls themselves: access management, change control, logging and monitoring, supplier security, incident response, business continuity, secure development, and the eleven controls new in the 2022 edition.

Two items take longest and should start first. Anything requiring an engineering change, because it sits in someone else's backlog. And supplier security assessment, because it depends on third parties responding.

Decision: which processes genuinely change, as opposed to which documents get written.

Stage 6: Operate

The ISMS has to run long enough to generate records: access reviews performed, risks reviewed, suppliers assessed, incidents handled, changes approved, corrective actions closed.

This is the constraint that sets your floor. It cannot be assembled retrospectively, and a Stage 2 auditor is specifically looking for whether it was.

Decision: none, if the earlier stages were done properly.

Stage 7: Internal audit and management review

The Clause 9.2 internal audit, performed by someone competent and independent of building the ISMS. Then the Clause 9.3 management review, where leadership considers the results and records decisions.

The order matters: audit, then review, then certification audit. A management review that rubber-stamps a report is itself a common finding.

Decision: who performs the internal audit, and how independence is preserved.

Stage 8: Stage 1 and Stage 2

Stage 1 reviews documentation and readiness and reports anything that would prevent a successful Stage 2. Stage 2 tests whether the ISMS operates, through interviews and sampling.

Brief the people who will be interviewed. What they say should match what the documents claim, and where it does not, the document is usually what is wrong.

Book the body early. Audit slots are booked ahead and availability is a real constraint.

Stage 9: Maintain

Surveillance audits in years two and three, recertification at year three, and an internal audit every year. Risk reviews, access reviews, supplier assessments and incident records continuing throughout.

Plan this at the same time as the certificate. Surveillance samples the year, and a system that stopped in month three is found in month fourteen. Our continuous governance and assurance service covers it.

The order in one table

StageOutputDecision that is hard to reverse
1. RequirementWritten statement of what is neededWhether to certify
2. ScopeThe scope statementThe scope itself
3. OwnershipA named owner with protected hoursInternal, external or both
4. Gap analysisClause and control position, remediation planThe remediation plan
5. BuildPolicy, risk method, Statement of Applicability, controlsWhich processes change
6. OperateRecords across a periodNone
7. Internal audit and reviewFindings, corrective actions, management decisionsWho audits, and independence
8. Stage 1 and Stage 2The certificateNone
9. MaintainA running ISMSWho owns the annual cycle

What sets the timeline

Three to six months for an organisation with reasonable security practice in place. Faster where SOC 2 already exists. Slower from nothing.

Two things you cannot compress: the operating period needed to produce records, and the certification body's availability. Plan both early rather than discovering them late.

What to do next

Settle the requirement and the scope. Those two decisions determine cost, timeline and whether the certificate does its job.

Our free readiness diagnostic gives a first view, and the ISO 27001 service page sets out how we run each stage.

References

FAQ

What is the first step in an ISO 27001 programme?

Establishing what your buyer actually needs, including whether something other than ISO 27001 would satisfy them, and what the certificate's scope statement must cover.

When should we contact certification bodies?

Early, for availability and quotes, but commit to an audit window only after the gap analysis so remediation happens on your timetable.

How long does certification take?

Three to six months for an organisation with reasonable security practice, limited by the operating period and certification body availability.

Can we shorten the operating period?

Not meaningfully. The auditor samples records across a period, and assembling them afterwards is what Stage 2 is designed to detect.

What happens after the certificate?

Annual internal audit, management review, surveillance audits in years two and three, and recertification at year three.

About Hael

Hael is an advisory firm specialising in AI governance and security compliance. We do the work, hold the deadline and stand behind the evidence, taking companies through ISO 27001 from gap analysis to certificate and maintaining the position afterwards. We are not a certification body and we take no commission from certification bodies. On engagements involving regulated financial services firms we work alongside Buckingham Capital Consulting, the partner firm that has advised payment and e-money firms on FCA authorisation and compliance since 2013.

This guide is general information and is not professional advice on your particular circumstances.

Free check

See where you stand on ISO 27001, free.

Answer a short set of questions and see what ISO 27001 expects of your AI systems and where you stand today. No sign-up to see your result.

Applicability

Whether ISO 27001 applies to how you use AI, and to which systems.

What is expected

Risk classification, governance, documentation and human oversight.

Where you stand

A banded result, pointed at the gaps that matter most.

What you get

On screen in about five minutes, pre-scoped to ISO 27001.

Or speak to us about your deadline. Book a meeting.