ISO 27001 FAQ
Sixteen straight answers on certification, costs, timelines, accreditation, and choosing a CB.
What is ISO 27001 certification?
ISO/IEC 27001 is the international standard for an Information Security Management System (ISMS). Certification means an accredited certification body audited your ISMS (Stage 1 + Stage 2) and issued a certificate valid for three years, with annual surveillance audits.
Who can issue an ISO 27001 certificate?
Only an accredited certification body (CB) — accredited by a national accreditation body like UKAS, ANAB, DAkkS, or RvA. Consultants, auditors-for-hire, and software platforms cannot issue certificates.
What is the difference between Stage 1 and Stage 2 audits?
Stage 1 is a documentation review: the CB checks your scope, policies, risk assessment, SoA, internal audit, and management review. Stage 2 tests effectiveness: interviews, sampling, and evidence that the ISMS actually operates.
How much does ISO 27001 certification cost?
Published 2026 ranges: Stage 1 + Stage 2 audit fees around $8,000–$25,000 for a small-to-mid company; first-year all-in $15,000–$50,000 for SMBs. See the cost guide for sourced figures.
How long does certification take?
3–9 months from kickoff to certificate for a first certification, plus annual surveillance audits in years two and three and recertification in year four.
What is ISO 27001:2022?
The current version of the standard, published October 2022, replacing the 2013 version. Its Annex A restructured 114 controls into 93 across four themes: organizational, people, physical, and technological.
Do I need a consultant, or can I do it myself?
Many small companies self-implement with templates or an automation platform, then hire only the CB for audits. Consultants help when you lack internal security expertise or time — but a consultant cannot certify you.
Can the same firm consult and certify me?
No — not for the same ISMS. Accreditation rules require the certification body to be independent of the consulting. A CB that also does consulting must keep the teams and decisions separate; verify this in the proposal.
What is the Statement of Applicability (SoA)?
The document listing which of the 93 Annex A controls apply to your ISMS, which don't (with justification), and how each is implemented. Stage 1 audits scrutinize it.
What happens if I fail the audit?
There is no pass/fail — there are findings. Minor nonconformities must be addressed within an agreed window; major nonconformities block certification until a follow-up audit closes them, typically adding $1,500–$6,000 and 1–3 months.
Is an unaccredited ISO 27001 certificate worth it?
Usually not for B2B: enterprise procurement routinely rejects unaccredited certificates. Accredited audits cost more because of oversight requirements — that premium buys the only certificate that counts.
Can I transfer my certificate to a different CB?
Yes. Certificates can be transferred between accredited CBs, usually at a surveillance or recertification point. The new CB reviews your audit history before accepting the transfer.
ISO 27001 vs SOC 2 — which should I get?
US customers ask for SOC 2; international and enterprise customers ask for ISO 27001. Many SaaS companies get both, often in a combined program. See our comparison guide.
How are audit fees calculated?
Audit days are set by ISO/IEC 27006 tables based on in-scope headcount and complexity, multiplied by the CB's day rate (published ranges: $1,500–$2,200/day US, £1,000–£1,500/day UK in 2026). That's why scoping tightly is the cheapest lever.
What should I ask a certification body before signing?
Accreditation for ISO 27001, named audit team, audit-day calculation, fixed fee and what breaks it, surveillance pricing, and transfer policy. See our RFP guide.
How do I check a CB's accreditation?
Search the accreditation body's directory (UKAS, ANAB, DAkkS, RvA) for the CB's name and confirm ISO 27001 is in its accredited scope. IAF CertSearch (iafcertsearch.org) also verifies issued certificates.
Still deciding?
Get matched with accredited CBs and ask them directly — free, 2 minutes.
How it works: tell us once (4 questions, 2 min) → we match licensed auditors to your size and scope → they send scoped quotes directly. Free, no obligation.