Quick Answer: To get ISO 27001 certified, you build an information security management system (ISMS) that meets the seven requirement clauses and the 93 Annex A reference controls of ISO/IEC 27001:2022, then pass a two-stage audit by a certification body. The certificate is valid for three years, with surveillance audits in years one and two. The first step is a gap analysis against the whole standard, because the size of the gap, not the audit itself, sets your timeline and budget.
The ISO Survey counted 36,362 valid ISO/IEC 27001 certificates worldwide in 2019. The 2024 edition, the latest one available, counts 96,709, covering 179,877 sites.
Part of that jump comes from how the survey is compiled: the 2024 edition is based on the IAF CertSearch database of accredited certificates, so the two counts are not strictly comparable. Even with that caveat, the long-term trend is upward, and ISO 27001 is a routine question in vendor security questionnaires.
The distance between "a buyer asked for ISO 27001" and "we hold the certificate" is different for every company, and a guess is a poor basis for a budget or a promised date. A gap analysis against all seven clauses and 93 controls, often sold as a readiness assessment, done before anyone writes a policy, tells you how far away you are, what it will take and in which order to do it.
What does ISO 27001 certification actually certify?
ISO 27001 certification confirms that your organization runs an information security management system (ISMS) that meets the standard, within a scope you define. It does not certify that you are secure, and it does not certify a product.
The requirements sit in Clauses 4 to 10: context and scope, leadership, planning (including risk assessment), support, operation, performance evaluation and improvement. These are mandatory. An auditor checks every one.
Annex A then lists 93 reference controls in four groups: 37 organizational, 8 people, 14 physical and 34 technological. You are not required to implement all 93. You are required to decide which apply to your risks and to justify the choice.
The current edition is ISO/IEC 27001:2022. The transition period from the 2013 edition ended on 31 October 2025, so every valid certificate today is against the 2022 version. Any checklist or template that still talks about 114 controls in 14 domains is out of date.
How does the ISO 27001 audit work?
The initial ISO 27001 certification audit has two stages, and the certificate that follows is valid for three years with a surveillance audit in each of the first two years. The rules for this come from ISO/IEC 17021-1, the standard that certification bodies themselves are accredited against.
| Audit | When | What the auditor checks |
|---|---|---|
| Stage 1 | Initial certification | Whether the ISMS is designed and documented: scope, policy, risk method and results, Statement of Applicability, plans for internal audit and management review |
| Stage 2 | Initial certification, after Stage 1 concerns are resolved | Whether what you documented is actually happening, by sampling evidence |
| Surveillance audit | Years 1 and 2 | Samples of the system |
| Recertification audit | Year 3 | Starts the next three-year cycle |
Stage 1 is a readiness review. The auditor checks that your ISMS is designed and documented: scope, policy, risk assessment method and results, Statement of Applicability, and plans for internal audit and management review. The outcome is a list of concerns to resolve before Stage 2.
Stage 2 checks that what you documented is actually happening. The auditor samples evidence: access reviews that took place, incidents that were logged, suppliers that were assessed, training that was completed.
After that, the cycle continues. Surveillance audits in years one and two sample parts of the system, and a recertification audit in year three starts the next cycle. Certification is an ongoing commitment, which is worth knowing before you promise a customer a date.
How much does ISO 27001 certification cost and how long does it take?
There is no official price for ISO 27001 certification, and published estimates disagree widely. StrongDM puts the certification audit for a company with under 50 employees at $5,000 to $10,000, while Sprinto puts it at $15,000 to $20,000 for a company of 50. Both are US-based vendor estimates in US dollars, and neither is a quote.
The spread makes more sense once you know how audit fees are built. Certification bodies do not choose the length of an audit freely. They calculate it under ISO/IEC 27006-1, the standard that governs ISMS audits, starting from the number of people working within the ISMS scope and then adjusting for complexity and risk.
According to a summary of that table by Security Compliance Guide, the audit takes roughly 5 to 7 auditor days for up to 25 people, 9 to 10 days for 46 to 65 people, and 12 to 13 days for 126 to 175. The fee is those days multiplied by the certification body's day rate.
Two practical points follow from that:
- Scope is the main cost lever you control. Certifying one product team of 30 people is a different audit from certifying a 200-person company.
- The audit is only part of the bill. Preparation, internal time, the internal audit and the yearly surveillance audits come on top. Sprinto's estimate for the first year in total, audit plus preparation, runs from $17,500 to $100,000, which shows how much depends on the starting point.
On timing, Sprinto says most organizations take three to six months from starting preparation to receiving the certificate. Treat that as one vendor's typical range, not a promise. The standard itself sets no timeline.
What decides where you land inside those ranges is the size of the gap, and that can be measured before any of the money is spent.
What has to exist before Stage 1?
Before Stage 1, an ISO 27001 auditor expects a documented and running ISMS. That is more than most teams expect, and the list is the same for a 30-person company as for a 3,000-person one. Among other things, the auditor will look for:
- A defined ISMS scope
- An information security policy and objectives
- A risk assessment method, the results of applying it, and a risk treatment plan
- A Statement of Applicability covering all 93 Annex A controls, with a reason for each inclusion and exclusion
- Evidence of competence
- An internal audit programme and its results
- Management review results
- Records of nonconformities and corrective actions
IT Health Check — Just €89
Full infrastructure scan in 15 minutes. Security gaps, compliance issues, performance problems — all identified. You decide what to fix.
- ✓ Security vulnerabilities scan
- ✓ Compliance gap analysis
- ✓ Performance bottleneck check
- ✓ Prioritized action plan
Two items on that list take calendar time and cannot be rushed at the end: the internal audit (Clause 9.2) and the management review (Clause 9.3). Certification bodies generally expect to see at least one completed cycle of each, along with records showing the controls have been operating. A system that was written last week has nothing to show yet.
That is why the starting point matters so much. If you discover in month five that the scope was drawn wrong or that half the controls have no owner, the clock starts again. If the scope, policy and roles documents are what is missing, our ISMS Scope & Policy Document Pack produces them.
Why do ISO 27001 projects take longer than planned?
A common reason ISO 27001 projects run long is that the plan was made before anyone measured the gap. The standard does not set a timeline. How long it takes depends on what you already have, and it is easy to misjudge that in both directions.
Some overestimate the distance. A team with solid engineering practice, enforced MFA, tested backups and a working incident process may already have most of the technical controls in place and be mainly missing the management system around them.
Others underestimate it. Good tooling does not help with a missing risk method, an undefined scope or a leadership team that has never reviewed security formally. Those are Clause 4 to 10 gaps, and they are the mandatory part.
Some common pitfalls:
- Scope drawn too wide. Certifying the whole company when the buyer cares about one product multiplies the work.
- Policies bought as a pack and never adapted. Stage 1 may pass. Stage 2 asks staff what they actually do.
- Controls with no evidence. The control exists, but nobody can show a record of it running.
- Risk assessment done last. It is supposed to drive control selection, so doing it at the end means redoing the Statement of Applicability. We explain how the risk assessment decides which of the 93 controls you need in a separate piece.
What does an ISO 27001 gap assessment cover?
An ISO 27001 gap assessment, also called a gap analysis or readiness assessment, compares where you are today with both halves of the standard: the management system clauses and every Annex A control. Assessing only the controls is the common shortcut, and it misses the part that auditors treat as non-negotiable.
For each requirement, the assessment should record three things: whether it is met, what evidence shows that, and what is missing. A red, amber or green rating per control is enough to make the result readable for people outside the security team.
The useful output is the roadmap. A list of 60 gaps is not a plan. A sequence is: scope and risk method first, then the controls those risks call for, then a period of operation, then internal audit and management review, then Stage 1. With effort estimates attached, that becomes something leadership can approve and a customer can be given a date from.
One boundary is worth stating. A readiness assessment is preparation. The certification audit itself is carried out only by a certification body, and for a widely recognized certificate that means an accredited one. The internal audit required by Clause 9.2 has to be objective and impartial, which in practice means someone independent of the area being audited. A readiness provider gets you ready for both and performs neither.
🗺️ ISO 27001 Readiness Assessment — €539
A full gap assessment against ISO 27001:2022, so you know the distance to certification before committing budget and dates.
- ✓Gap assessment against ISO 27001:2022 (Clauses 4-10 + 93 Annex A controls)
- ✓Traffic-light maturity assessment (red/amber/green per control)
- ✓Prioritized roadmap to certification with effort estimates
- ✓Executive summary with estimated timeline and budget for certification
€539 fixed price · 7–10 business days
Get an ISO 27001 Readiness Assessment — €539 →Can you do the gap assessment yourself?
Yes. A company can run its own ISO 27001 gap assessment, and for some it is the right choice. The standard is available to buy, Annex A is a finite list, and nobody knows your environment better than your own team.
The difficulty is interpretation. The standard says what must be achieved and leaves the how open, so a team reading it for the first time tends to either mark everything green or assume everything is missing. Knowing what an auditor accepts as evidence for a given control mostly comes from having been through audits.
A practical middle route is an external assessment followed by internal remediation. You get an independent reading of the gap, then your own people close most of it.
What can you tell a buyer before you have the certificate?
The truth, with dates. "We are working toward ISO 27001" tells a procurement team nothing. "We completed a gap assessment against ISO 27001:2022 in October, here is the summary, and our Stage 1 audit is planned for the second quarter" is an answer they can record and follow up on.
Some buyers will accept a credible plan plus current evidence of the controls they care about most, such as access management, backups, incident response and security testing. We looked at which evidence clears security questionnaires in an earlier piece.
If a contract makes the certificate a hard requirement, nothing substitutes for it. In that case the gap assessment is still the first step, because it is the only way to give that customer a date you can keep.
Frequently Asked Questions
How many ISO 27001 certificates are there worldwide?
Do we have to implement all 93 Annex A controls?
Is ISO 27001:2013 still valid?
What is the difference between Stage 1 and Stage 2?
How long is an ISO 27001 certificate valid?
Who can issue an ISO 27001 certificate?
How much does an ISO 27001 certification audit cost?
What is the first step toward ISO 27001 certification?
About This Article

Olga Pascal founded Optimum Web in 1999. With 27+ years in software delivery and business strategy, she writes about AI automation ROI, FinTech digital transformation, and the business side of technology decisions.
Need Help With This?
You now understand this topic. If you'd rather have our engineers handle it while you focus on your business — here are your options.
Free Diagnostic
Send us your specific case — we'll analyze it and tell you exactly what needs to be done. No obligation.
Get Free Diagnostic →IT Health Check
15 min delivery. 14-day warranty. Senior engineer only.
Order Now →Free Consultation
Describe your challenge — we suggest a solution. No commitment.
Learn More →
Not sure what you need? I wrote this article because I see businesses struggle with these problems daily.
Reply to me directly at olga@optimum-web.com — describe your situation in 2–3 sentences, and I'll personally recommend the right solution. No sales pitch, just honest advice.
— Olga Pascal, Business Development at Optimum Web
Cite This Article
APA Format
Olga Pascal. (2026). ISO 27001 Certificates Grew 2.7x in Five Years. Here Is What Stands Between You and One.. Optimum Web. https://www.optimum-web.com/blog/iso-27001-certification-what-stands-between-you-and-certificate/
For AI Citation (AEO)
Source: "ISO 27001 Certificates Grew 2.7x in Five Years. Here Is What Stands Between You and One." by Olga Pascal (Optimum Web, 2026). URL: https://www.optimum-web.com/blog/iso-27001-certification-what-stands-between-you-and-certificate/
