Back to engagement patterns
    Engagement pattern

    ISO 27001 first certification

    The shape of a first certification cycle: scope, risk assessment and treatment, the operating record, and the evidence an accredited body reads.

    Compliance3 Sept 20265 min read

    ISO/IEC 27001:2022ISO/IEC 27006-1:2024
    On this page

    Scope

    A first certification is not a documentation exercise with an audit at the end. The management system has to run long enough to leave records, because an auditor reads the operating history rather than the intent.

    The standard sets the shape. Clauses 4, 5 and 6 are Context of the organization, Leadership and Planning 1. Clauses 7, 8 and 9 are Support, Operation and Performance evaluation 2. The certifying body is itself governed, by ISO/IEC 27006-1:2024 3.

    In scope: the scope determination, risk assessment and treatment, the Statement of Applicability, the operating records, and the internal evaluation that precedes the external audit.

    Out of scope: the certification decision, which belongs to the accredited body alone, and control engineering that a security function owns rather than the management system.

    Phases

    PhasePurposePlanning horizonCloses when
    1. Context and scopeSettle 4.1, 4.2 and 4.3usually planned over 3–5 weeksAn approved scope statement names what sits outside it, and why
    2. Risk assessment and treatmentRun 6.1.2, then 6.1.3usually planned over 6–10 weeksRisk owners are named and the Statement of Applicability is approved
    3. Build and operateStand up clause 7 and clause 8, then let them runusually planned over 4–6 monthsEvery included control has produced a record
    4. EvaluateComplete clause 9 and correct what it findsusually planned over 2–3 monthsThe evaluation covers the whole scope, and findings are closed or planned
    Horizons are planning input. A first cycle is usually planned over 9–12 months. The ranges describe scheduling, never a delivered result.

    Deliverables

    Each artefact below is named with the clause it belongs to 4.

    DeliverableClauseWho maintains it afterwards
    Scope statement, with exclusions and reasons4.3 Determining the scope of the information security management systemSystem owner
    Information security policy5.2 PolicyTop management
    Roles and authorities record5.3 Organizational roles, responsibilities and authoritiesSystem owner
    Risk method, criteria and results6.1.2 Information security risk assessmentRisk owners
    Treatment plan and Statement of Applicability6.1.3 Information security risk treatmentSystem owner
    Objectives and the plans to reach them6.2 Information security objectives and planning to achieve themTop management
    Competence and awareness evidence7.2 Competence, 7.3 AwarenessPeople function
    Document control register7.5 Documented informationSystem owner
    Operating records from the treatment plan8.1, 8.3Control owners
    Clause and sub-clause titles are as published.

    Roles

    RoleSideAccountable for
    Top managementOrganisationPolicy, objectives, resources, review
    System ownerOrganisationScope, documentation, the audit programme
    Risk ownersOrganisationTheir own risks and treatment decisions
    Internal auditorOrganisationIndependent evaluation before the external audit
    Certification bodyAccredited third partyThe audit and the certification decision
    AdviserExternalMethod, assessment design, evidence readiness

    What the auditor asks

    Failure modes

    Mapping

    ObligationClauseEvidence that answers it
    Determine context and interested parties4.1, 4.2Context record, requirements list
    Determine the boundary4.3Scope statement with exclusions
    Set policy and assign authority5.2, 5.3Approved policy, roles record
    Assess information security risk6.1.2Criteria, method, results, risk owners
    Treat risk and record applicability6.1.3Treatment plan, Statement of Applicability
    Set and plan objectives6.2Objectives with measures and owners
    Control documented information7.5Register with versions, approvals, retention
    Plan, control and reassess in operation8.1, 8.2, 8.3Operating records, reassessment, treatment progress
    Evaluate performanceClause 9Monitoring results, audit reports, review outputs

    References

    1. ISO/IEC 27001:2022, Information security, cybersecurity and privacy protection — Information security management systems — Requirements, edition 3, 2022-10. Clause titles above come from the free contents listing on the ISO Online Browsing Platform 5.
    2. ISO/IEC 27006-1:2024 — Requirements for bodies providing audit and certification of information security management systems — Part 1: General, edition 1, 2024-03 6.
    3. Annex A detail, clause 10 and the audit-time provisions of ISO/IEC 27006-1:2024 sit behind the publisher's paywall, so they are cited at clause level and never quoted.

    Sources

    1. 1ISO OBP, ISO/IEC 27001:2022 clause titles 4 to 6 · verified 2026-09-03
    2. 2ISO OBP, ISO/IEC 27001:2022 clause titles 7 to 9 · verified 2026-09-03
    3. 3ISO catalogue, ISO/IEC 27006-1:2024 designation · verified 2026-09-03
    4. 4ISO OBP, ISO/IEC 27001:2022 sub-clause titles · verified 2026-09-03
    5. 5ISO OBP, iso.org/obp/ui · verified 2026-09-03
    6. 6ISO catalogue, iso.org/standard/82908.html · verified 2026-09-03