Bangalore · Riyadh · Delaware | hello@nazztec.com
Compliance & Regulation

ISO 27001 Certification: A Practical Guide for 2026

What the 2022 edition actually asks of you, how the certification audit works, and the six decisions that determine whether you certify in five months or fifteen.

22 September 20269 min readNAZZTEC Editorial Team
ISO 27001 Certification: A Practical Guide for 2026 — cover illustration

Key takeaways

  • Every certificate is now issued against ISO/IEC 27001:2022 — the 2013 transition period has ended.
  • Scope is the single most important decision; get it wrong and every later step costs more.
  • Annex A now has 93 controls in four themes, including 11 that are new since 2013.
  • Most mid-sized organisations reach certification in four to eight months with focused effort.

Why ISO 27001 still matters

ISO/IEC 27001 remains the most widely recognised information security standard in the world. For many organisations it is no longer a differentiator but a condition of doing business: enterprise procurement questionnaires, public-sector tenders and partner due diligence increasingly ask for a valid certificate rather than a description of your controls.

The standard does not prescribe a technology stack. It requires an Information Security Management System (ISMS) — a documented, risk-based way of deciding which controls you need, operating them, measuring them and improving them. That is why a certificate carries weight: it shows that security is managed as a system, not as a collection of tools.

What changed with the 2022 edition

ISO/IEC 27001:2022 restructured Annex A. The previous 114 controls in 14 domains were consolidated into 93 controls grouped into four themes: organisational (37), people (8), physical (14) and technological (34). Eleven controls are new, reflecting how estates actually operate today:

  • Threat intelligence
  • Information security for use of cloud services
  • ICT readiness for business continuity
  • Physical security monitoring
  • Configuration management
  • Information deletion
  • Data masking
  • Data leakage prevention
  • Monitoring activities
  • Web filtering
  • Secure coding

The transition period for certificates issued against the 2013 edition ended on 31 October 2025, so any organisation certifying or recertifying now does so against the 2022 edition. A 2024 amendment also asks organisations to consider whether climate change is a relevant issue when defining their context — usually a short, documented judgement rather than new controls.

The six decisions that set your timeline

Certification programmes rarely fail on technical controls. They slip because early decisions were deferred or made badly. Settle these six before you write a single policy:

  • Scope. Which legal entities, locations, services, systems and teams are in the ISMS? A tightly defined scope around the services your customers buy is faster to certify and easier to defend.
  • Risk methodology. How you identify, score and treat risk. Keep it simple enough that business owners can use it without a consultant in the room.
  • Ownership. Name an ISMS owner with authority, and control owners in each function. Security teams cannot own HR screening or supplier contracts on their own.
  • Evidence approach. Decide now whether evidence lives in shared folders or a GRC platform. Retrofitting later is painful.
  • Certification body. Choose a body accredited by a recognised national accreditation body. An unaccredited certificate may be rejected by the very customers you are trying to satisfy.
  • Target date. Work backwards from it. A Stage 2 audit needs evidence that controls have operated for a meaningful period — typically at least two to three months.

A realistic programme, step by step

PhaseWhat happensTypical duration
Gap assessmentCurrent practice compared against the clauses and Annex A; prioritised gap register3–4 weeks
ISMS designScope statement, policy, risk methodology, risk assessment, Statement of Applicability4–6 weeks
ImplementationControls introduced or formalised, procedures written, owners trained8–12 weeks
Operation and evidenceControls run and produce records — access reviews, change approvals, training, supplier checks8–12 weeks (overlaps)
Internal audit and management reviewIndependent internal audit of the whole ISMS; leadership review of results2–3 weeks
Stage 1 auditCertification body reviews documentation and readiness1–3 days
Stage 2 auditCertification body tests whether controls operate effectively2–6 days depending on scope

After certification the cycle continues: surveillance audits in years one and two, and a full recertification audit in year three. The organisations that find surveillance audits easy are the ones that built evidence into daily work rather than assembling it before each visit.

The documents auditors expect to see

Clauses 4 to 10 require specific documented information. As a minimum, expect to present:

  • ISMS scope and information security policy
  • Risk assessment and risk treatment methodology, with the current results
  • Statement of Applicability, justifying the inclusion or exclusion of each Annex A control
  • Information security objectives and how they are measured
  • Evidence of competence and awareness
  • Operational records for the controls you have selected
  • Internal audit programme and results
  • Management review minutes
  • Nonconformities and corrective actions

Common reasons for nonconformities

  • A Statement of Applicability that does not match what is actually in place.
  • Risk assessments completed once and never revisited after significant change.
  • Access reviews scheduled but not performed, or performed without recorded outcomes.
  • Supplier security requirements agreed in contracts but never checked.
  • An internal audit carried out by the same people who designed the controls.
  • Management review treated as a formality, with no decisions recorded.

How to keep the cost proportionate

Certification cost is driven by scope, headcount and how much already exists. The cheapest route is almost never the one with the fewest consulting days — it is the one that reuses what you already do. Most organisations already run change control, joiners-and-leavers processes and backup routines; the work is formalising them, assigning owners and keeping records.

If you also answer to SOC 2, PCI DSS, NIST CSF or regional regulators, design one control library mapped to all of them. Testing a control once and reporting it against several frameworks is where the real saving sits.

Frequently asked questions

How long does ISO 27001 certification take?
For a mid-sized organisation with some existing security practice, four to eight months from kick-off to a Stage 2 audit is realistic. Larger scopes, multiple locations or a very low starting point extend this.
Is ISO 27001 certification mandatory?
It is not a legal requirement in most jurisdictions, but it is frequently a contractual one. Many enterprise customers and public bodies require a valid certificate from their suppliers.
Can we certify only part of the organisation?
Yes. The scope can be limited to specific services, locations or entities, provided the boundaries and interfaces are clearly defined and the scope is meaningful to the people relying on the certificate.
Keep reading

More insights

NIST CSF 2.0: What Changed and What It Means for You — cover illustration
Compliance & Regulation

NIST CSF 2.0: What Changed and What It Means for You

The new Govern function, a broader audience, stronger supply chain expectations — and a practical method for turning the framework into a programme your board can follow.

8 September 20267 min read
PCI DSS v4.0: The Requirements That Catch People Out — cover illustration
Compliance & Regulation

PCI DSS v4.0: The Requirements That Catch People Out

All future-dated requirements have been mandatory since March 2025. These are the ones assessors most often find incomplete — and what good evidence looks like.

25 August 20268 min read

Talk to the team behind this briefing

Tell us what you are working on. A senior NAZZTEC consultant will come back within one business day with a practical view.

We respond to every enquiry within one business day.