Skip to content

The ISO 27001 certification process

By Sam Rivera, Founder, SentinelPanda · June 19, 2026 · 1 min read · ISO 27001

ISO 27001 certification is a two-stage external audit on top of your own internal audit. Knowing the sequence keeps the timeline honest.

Build and self-check first

Before any external auditor, you stand up the ISMS — scope, risk assessment, Statement of Applicability, policies, and controls — and then exercise the management machinery: at least one internal audit and one management review. ISO 27001 requires you to audit yourself before the certification body audits you.

Stage 1: documentation review

The certification body first reviews your ISMS documentation — is the system designed correctly, is the scope sensible, is the Statement of Applicability coherent. Stage 1 surfaces gaps before the deeper audit, so you can fix them rather than fail. Think of it as a readiness check by the people who will certify you.

Stage 2: implementation review

Stage 2 tests whether the ISMS actually operates: the auditor samples evidence that controls run, interviews people, and checks that internal audit and management review happened. Findings are graded — minor and major nonconformities — and majors must be closed before the certificate is issued.

Then maintain it

Certification covers a three-year cycle: the initial certification, then annual surveillance audits to confirm the ISMS keeps running, then recertification at year three. The work does not stop at the certificate — the surveillance audits keep you honest. SentinelPanda keeps the evidence and the audit cadence flowing across the whole cycle.

Running an ISO 27001 internal audit ISO 27001 timeline What is an ISMS?

Run your compliance program in one workspace.