ISO 27001 first certification
The shape of a first certification cycle: scope, risk assessment and treatment, the operating record, and the evidence an accredited body reads.
Compliance3 Sept 20265 min readUpdated 5 Sept 2026
On this page
Scope
The management system has to run long enough to leave records, because an auditor reads the operating history rather than the intent.
Clauses 4, 5 and 6 are Context of the organization, Leadership and Planning 1. Clauses 7, 8 and 9 are Support, Operation and Performance evaluation 2. The certifying body is itself governed, by ISO/IEC 27006-1:2024 3.
In scope: the scope determination, risk assessment and treatment, the Statement of Applicability, the operating records, and the internal evaluation that precedes the external audit.
Out of scope: the certification decision, which belongs to the accredited body alone, and control engineering that a security function owns rather than the management system.
Phases
| Phase | Purpose | Planning horizon | Closes when |
|---|---|---|---|
| 1. Context and scope | Settle 4.1, 4.2 and 4.3 | usually planned over 3–5 weeks | An approved scope statement names what sits outside it, and why |
| 2. Risk assessment and treatment | Run 6.1.2, then 6.1.3 | usually planned over 6–10 weeks | Risk owners are named and the Statement of Applicability is approved |
| 3. Build and operate | Stand up clause 7 and clause 8, then let them run | usually planned over 4–6 months | Every included control has produced a record |
| 4. Evaluate | Complete clause 9 and correct what it finds | usually planned over 2–3 months | The evaluation covers the whole scope, and findings are closed or planned |
Deliverables
Each artefact below is named with the clause it belongs to 4.
| Deliverable | Clause | Who maintains it afterwards |
|---|---|---|
| Scope statement, with exclusions and reasons | 4.3 Determining the scope of the information security management system | System owner |
| Information security policy | 5.2 Policy | Top management |
| Roles and authorities record | 5.3 Organizational roles, responsibilities and authorities | System owner |
| Risk method, criteria and results | 6.1.2 Information security risk assessment | Risk owners |
| Treatment plan and Statement of Applicability | 6.1.3 Information security risk treatment | System owner |
| Objectives and the plans to reach them | 6.2 Information security objectives and planning to achieve them | Top management |
| Competence and awareness evidence | 7.2 Competence, 7.3 Awareness | People function |
| Document control register | 7.5 Documented information | System owner |
| Operating records from the treatment plan | 8.1, 8.3 | Control owners |
Roles
| Role | Side | Accountable for |
|---|---|---|
| Top management | Organisation | Policy, objectives, resources, review |
| System owner | Organisation | Scope, documentation, the audit programme |
| Risk owners | Organisation | Their own risks and treatment decisions |
| Internal auditor | Organisation | Independent evaluation before the external audit |
| Certification body | Accredited third party | The audit and the certification decision |
| Adviser | External | Method, assessment design, evidence readiness |
What the auditor asks
Failure modes
Mapping
| Obligation | Clause | Evidence that answers it |
|---|---|---|
| Determine context and interested parties | 4.1, 4.2 | Context record, requirements list |
| Determine the boundary | 4.3 | Scope statement with exclusions |
| Set policy and assign authority | 5.2, 5.3 | Approved policy, roles record |
| Assess information security risk | 6.1.2 | Criteria, method, results, risk owners |
| Treat risk and record applicability | 6.1.3 | Treatment plan, Statement of Applicability |
| Set and plan objectives | 6.2 | Objectives with measures and owners |
| Control documented information | 7.5 | Register with versions, approvals, retention |
| Plan, control and reassess in operation | 8.1, 8.2, 8.3 | Operating records, reassessment, treatment progress |
| Evaluate performance | Clause 9 | Monitoring results, audit reports, review outputs |
Related
- Running the external audit — the audit itself, week by week.
- Control ownership and the control catalogue — who owns each included control.
- Policy architecture people can find — the clause 7.5 document set.
References
- ISO/IEC 27001:2022, Information security, cybersecurity and privacy protection — Information security management systems — Requirements, edition 3, 2022-10. Clause titles above come from the free contents listing on the ISO Online Browsing Platform 5.
- ISO/IEC 27006-1:2024 — Requirements for bodies providing audit and certification of information security management systems — Part 1: General, edition 1, 2024-03 6.
- Annex A detail, clause 10 and the audit-time provisions of ISO/IEC 27006-1:2024 sit behind the publisher's paywall, so they are cited at clause level and never quoted.
Sources
- 1ISO OBP, ISO/IEC 27001:2022 clause titles 4 to 6 · verified 2026-09-03
- 2ISO OBP, ISO/IEC 27001:2022 clause titles 7 to 9 · verified 2026-09-03
- 3ISO catalogue, ISO/IEC 27006-1:2024 designation · verified 2026-09-03
- 4ISO OBP, ISO/IEC 27001:2022 sub-clause titles · verified 2026-09-03
- 5ISO OBP, iso.org/obp/ui · verified 2026-09-03
- 6ISO catalogue, iso.org/standard/82908.html · verified 2026-09-03