What Is ISO 27001 Certification?
- Certification is issued by an accredited certification body after a two-stage audit and lasts three years with annual surveillance.
- Your consultancy cannot certify you, and your certification body cannot consult on the system it certifies.
- Check accreditation. A certificate from an unaccredited body is checked and discounted by mature procurement teams.
- Certification body fees commonly run £5,000 to £20,000 for the initial cycle at a small to mid-sized organisation.
- Organisations whose 2013 certificate lapsed now face full initial certification, not a transition audit.
What certification is
ISO 27001 certification is a formal statement by an accredited third party that your information security management system meets the requirements of ISO/IEC 27001:2022. You receive a certificate valid for three years, which you can publish and send to buyers.
That publishability is the practical difference from SOC 2. A SOC 2 report is shared privately under a confidentiality agreement. An ISO 27001 certificate can sit on your website, and buyers can verify it directly with the certification body.
Who issues it
Accredited certification bodies, accredited in turn by a national accreditation body: UKAS in the United Kingdom, ANAB in the United States, DAkkS in Germany, and equivalents elsewhere, all under ISO/IEC 17021.
Two rules follow, and both are structural.
A certification body cannot consult on the ISMS it will certify. If one organisation offers to build and certify, two different legal entities are involved, and you should know which does what.
A certification body cannot perform your internal audit. Clause 9.2 requires one before certification and every year afterwards. This is covered in ISO 27001 - Internal Audit Consultants.
Accreditation is worth verifying
The ISO 27001 certification market is mature, which is good, but it also contains bodies operating without accreditation. Certificates from those bodies look similar and cost less.
Mature procurement teams check. A buyer's vendor risk process will often ask which accreditation body sits behind the certificate, and an unaccredited one produces follow-up questions at exactly the moment you wanted the certificate to end them.
Ask any certification body to name its accreditation body and show its scope entry for ISO/IEC 27001.
The two-stage audit
Stage 1 reviews your documentation and readiness: scope, information security policy, risk assessment, risk treatment plan, Statement of Applicability, internal audit results and management review. The output identifies anything that would prevent a successful Stage 2, which gives you time to fix it.
Stage 2 tests whether the ISMS operates. The auditor interviews people, samples records and checks that the controls listed in your Statement of Applicability are running as described. Findings are recorded as major or minor nonconformities, and major ones must be closed before a certificate is issued.
What it costs
| Component | Typical range |
|---|---|
| Certification body fees, initial cycle, small to mid-sized organisation | £5,000 to £20,000 |
| Certification body fees, larger or multi-site | £20,000 to £60,000 and above |
| Annual surveillance audit | Roughly 20% to 40% of the initial audit fee |
| Recertification at year three | Typically 70% to 90% of the original Stage 2 fee |
| Implementation, separate supplier | £15,000 to £50,000 |
The audit fee and the preparation fee go to two different organisations and should never appear as one number in a proposal. Total first-year cost for a small to mid-sized organisation commonly lands between £20,000 and £70,000.
How long it takes
Three to six months end to end for an organisation with reasonable security practice already in place. Longer from a standing start. Shorter where you already hold SOC 2, because much of the control substance and evidence discipline transfers.
The constraint that sets the floor is that the ISMS has to operate long enough to produce records for the auditor to sample. That period cannot be compressed, and an auditor is specifically looking for whether it was.
If your 2013 certificate lapsed
The transition window closed on 31 October 2025. There is no transition audit route remaining.
An organisation whose 2013 certificate lapsed is treated as a new applicant: full Stage 1 and Stage 2 against ISO/IEC 27001:2022, at full cost. If that is your position, the practical starting point is a gap analysis against the 2022 structure, because the Annex A restructure and the eleven new controls mean your existing Statement of Applicability no longer maps.
What certification proves
That an accredited third party examined your ISMS and found it conformant on the audit date, and that surveillance continues.
It does not prove any specific system is secure, and it does not survive neglect. Surveillance audits find management systems that stopped operating after the certificate arrived, which is the single most common cause of a nonconformity in year two.
What to do next
Get quotes from three accredited certification bodies early, and confirm the accreditation scope of each. Availability affects your timeline as much as price does.
Our free readiness diagnostic gives a first view, and our certification readiness and audit support service covers preparation through both stages.
References
FAQ
Who issues ISO 27001 certification?
An accredited certification body. Your consultancy cannot, and your certification body cannot consult on the system it certifies.
How long is ISO 27001 certification valid?
Three years, with surveillance audits in years two and three and recertification at the end.
What does ISO 27001 certification cost?
Certification body fees commonly £5,000 to £20,000 for a small to mid-sized organisation, with implementation of £15,000 to £50,000 separate.
Does accreditation matter?
Yes. Unaccredited certificates are cheaper and are checked by mature procurement teams, which defeats the purpose of holding one.
Our 2013 certificate lapsed. What now?
Full initial certification against the 2022 edition. The transition route closed on 31 October 2025 and cannot be used.
About Hael
Hael is an advisory firm specialising in AI governance and security compliance. We take companies through ISO 27001 from gap analysis to certificate and maintain the position afterwards. We are not a certification body, we do not issue certificates, and we take no commission from certification bodies. On engagements involving regulated financial services firms we work alongside Buckingham Capital Consulting, the partner firm that has advised payment and e-money firms on FCA authorisation and compliance since 2013.
This guide is general information and is not professional advice on your particular circumstances.