The ISO 27001 certification process
By Sam Rivera, Founder, SentinelPanda · June 19, 2026 · 1 min read · ISO 27001
ISO 27001 certification is a two-stage external audit on top of your own internal audit. Knowing the sequence keeps the timeline honest.
Build and self-check first
Before any external auditor, you stand up the ISMS — scope, risk assessment, Statement of Applicability, policies, and controls — and then exercise the management machinery: at least one internal audit and one management review. ISO 27001 requires you to audit yourself before the certification body audits you.
Stage 1: documentation review
The certification body first reviews your ISMS documentation — is the system designed correctly, is the scope sensible, is the Statement of Applicability coherent. Stage 1 surfaces gaps before the deeper audit, so you can fix them rather than fail. Think of it as a readiness check by the people who will certify you.
Stage 2: implementation review
Stage 2 tests whether the ISMS actually operates: the auditor samples evidence that controls run, interviews people, and checks that internal audit and management review happened. Findings are graded — minor and major nonconformities — and majors must be closed before the certificate is issued.
Then maintain it
Certification covers a three-year cycle: the initial certification, then annual surveillance audits to confirm the ISMS keeps running, then recertification at year three. The work does not stop at the certificate — the surveillance audits keep you honest. SentinelPanda keeps the evidence and the audit cadence flowing across the whole cycle.