ISO 27001 first certification
The shape of a first certification cycle: scope, risk assessment and treatment, the operating record, and the evidence an accredited body reads.
Compliance3 Sept 20265 min read
On this page
Scope
A first certification is not a documentation exercise with an audit at the end. The management system has to run long enough to leave records, because an auditor reads the operating history rather than the intent.
The standard sets the shape. Clauses 4, 5 and 6 are Context of the organization, Leadership and Planning 1. Clauses 7, 8 and 9 are Support, Operation and Performance evaluation 2. The certifying body is itself governed, by ISO/IEC 27006-1:2024 3.
In scope: the scope determination, risk assessment and treatment, the Statement of Applicability, the operating records, and the internal evaluation that precedes the external audit.
Out of scope: the certification decision, which belongs to the accredited body alone, and control engineering that a security function owns rather than the management system.
Phases
| Phase | Purpose | Planning horizon | Closes when |
|---|---|---|---|
| 1. Context and scope | Settle 4.1, 4.2 and 4.3 | usually planned over 3–5 weeks | An approved scope statement names what sits outside it, and why |
| 2. Risk assessment and treatment | Run 6.1.2, then 6.1.3 | usually planned over 6–10 weeks | Risk owners are named and the Statement of Applicability is approved |
| 3. Build and operate | Stand up clause 7 and clause 8, then let them run | usually planned over 4–6 months | Every included control has produced a record |
| 4. Evaluate | Complete clause 9 and correct what it finds | usually planned over 2–3 months | The evaluation covers the whole scope, and findings are closed or planned |
Deliverables
Each artefact below is named with the clause it belongs to 4.
| Deliverable | Clause | Who maintains it afterwards |
|---|---|---|
| Scope statement, with exclusions and reasons | 4.3 Determining the scope of the information security management system | System owner |
| Information security policy | 5.2 Policy | Top management |
| Roles and authorities record | 5.3 Organizational roles, responsibilities and authorities | System owner |
| Risk method, criteria and results | 6.1.2 Information security risk assessment | Risk owners |
| Treatment plan and Statement of Applicability | 6.1.3 Information security risk treatment | System owner |
| Objectives and the plans to reach them | 6.2 Information security objectives and planning to achieve them | Top management |
| Competence and awareness evidence | 7.2 Competence, 7.3 Awareness | People function |
| Document control register | 7.5 Documented information | System owner |
| Operating records from the treatment plan | 8.1, 8.3 | Control owners |
Roles
| Role | Side | Accountable for |
|---|---|---|
| Top management | Organisation | Policy, objectives, resources, review |
| System owner | Organisation | Scope, documentation, the audit programme |
| Risk owners | Organisation | Their own risks and treatment decisions |
| Internal auditor | Organisation | Independent evaluation before the external audit |
| Certification body | Accredited third party | The audit and the certification decision |
| Adviser | External | Method, assessment design, evidence readiness |
What the auditor asks
Failure modes
Mapping
| Obligation | Clause | Evidence that answers it |
|---|---|---|
| Determine context and interested parties | 4.1, 4.2 | Context record, requirements list |
| Determine the boundary | 4.3 | Scope statement with exclusions |
| Set policy and assign authority | 5.2, 5.3 | Approved policy, roles record |
| Assess information security risk | 6.1.2 | Criteria, method, results, risk owners |
| Treat risk and record applicability | 6.1.3 | Treatment plan, Statement of Applicability |
| Set and plan objectives | 6.2 | Objectives with measures and owners |
| Control documented information | 7.5 | Register with versions, approvals, retention |
| Plan, control and reassess in operation | 8.1, 8.2, 8.3 | Operating records, reassessment, treatment progress |
| Evaluate performance | Clause 9 | Monitoring results, audit reports, review outputs |
References
- ISO/IEC 27001:2022, Information security, cybersecurity and privacy protection — Information security management systems — Requirements, edition 3, 2022-10. Clause titles above come from the free contents listing on the ISO Online Browsing Platform 5.
- ISO/IEC 27006-1:2024 — Requirements for bodies providing audit and certification of information security management systems — Part 1: General, edition 1, 2024-03 6.
- Annex A detail, clause 10 and the audit-time provisions of ISO/IEC 27006-1:2024 sit behind the publisher's paywall, so they are cited at clause level and never quoted.
Sources
- 1ISO OBP, ISO/IEC 27001:2022 clause titles 4 to 6 · verified 2026-09-03
- 2ISO OBP, ISO/IEC 27001:2022 clause titles 7 to 9 · verified 2026-09-03
- 3ISO catalogue, ISO/IEC 27006-1:2024 designation · verified 2026-09-03
- 4ISO OBP, ISO/IEC 27001:2022 sub-clause titles · verified 2026-09-03
- 5ISO OBP, iso.org/obp/ui · verified 2026-09-03
- 6ISO catalogue, iso.org/standard/82908.html · verified 2026-09-03