Guide · ISO 27001

The ISO 27001 certification process, step by step

ISO 27001 certification isn't a single exam — it's a defined path from building your ISMS to passing a two-stage audit, then staying certified. Here's each step.

The path to certification

  1. Define your ISMS scope & context. Decide what parts of the business the Information Security Management System covers, and set objectives and leadership commitment.
  2. Run a risk assessment & treatment plan. Identify and score information-security risks, then decide how you'll treat each — mapped to the Annex A controls.
  3. Produce your Statement of Applicability (SoA). Document which Annex A controls apply and why. This is a defining ISO 27001 artifact.
  4. Implement controls & collect evidence. Put the controls in place and start gathering evidence that they're operating — continuously, not once.
  5. Internal audit & management review. Audit yourself against the standard and review results at the leadership level before the external body arrives.
  6. Stage 1 audit (documentation review). The certification body checks that your ISMS documentation is in place and sound.
  7. Stage 2 audit (implementation review). They verify the ISMS is actually operating. Pass, and you're certified.
  8. Surveillance & recertification. Annual surveillance audits keep the certificate valid; full recertification happens about every three years.
Roughly how long?Readiness commonly takes a few weeks to a few months depending on your starting point, followed by the Stage 1 and Stage 2 audits. The single biggest accelerator is continuous evidence — if your controls are already producing evidence automatically, the audits go much faster.

What makes it easier

  • Automate evidence so surveillance audits are a non-event, not an annual fire drill.
  • Map controls across frameworks so ISO 27001 and SOC 2 share the same evidence.
  • Keep data in your region — a self-hosted ISMS is a natural fit for EU, NIS2 and DORA obligations.

General guidance, not audit advice. ISO 27001 certification is issued by an accredited certification body, not by Vallorix.

See Vallorix on your own infrastructure

Continuous evidence, auditor-ready reports, and controls that stay in your boundary.

Get a demo →
V
Vallorix AssistantAI · answers about compliance & the product
AI assistant · not a human · answers may be imperfect