How to prepare for an ISO 27001 certification?
ISO/IEC 27001:2022, published by the International Organization for Standardization, does not require a state of perfect security. It requires proof that information security is genuinely managed: identified risks, proportionate controls, documented continuous improvement. During mock audits, most non-conformities found are not about technical flaws but about missing evidence: a security policy that was never put in writing, an untracked access review, a business continuity plan that has never been tested under real conditions.
ISMS scope: the starting point of any preparation
Everything starts with the scope of the ISMS, the information security management system: which systems, which teams, which sites fall within the certification. A scope that is too broad adds unnecessary weight to the preparation, forcing the documentation of activities the auditor would never have examined anyway. A scope that is too narrow, conversely, risks rejection by the auditor, who will judge it unrepresentative of the actual business, or a certificate that reassures clients less than it should, because it does not cover the systems they actually care about.

The steps of a certification preparation
- Define the ISMS scope and have it validated by management, consistent with what clients and partners actually expect to see covered.
- Carry out a risk assessment on the information assets within scope: plausible threats, likelihood, impact, treatment measures.
- Select the relevant Annex A controls and draft the statement of applicability, which justifies each control retained or excluded.
- Implement the missing controls and document the associated procedures (access management, backups, incident response).
- Carry out an internal audit and a management review, both required by the standard before any certification audit.
- Go through the certification audit in two stages: the documentation audit (stage 1), then the on-site implementation audit (stage 2).
The 93 Annex A controls, across four themes
Since the 2022 revision, Annex A no longer groups its controls into fourteen chapters but into four themes, which makes it easier to split ownership across the teams responsible for each.
| Theme | Number of controls | Examples |
|---|---|---|
| Organizational | 37 | Security policy, supplier management, incident management |
| People | 8 | Awareness, contractual clauses, disciplinary process |
| Physical | 14 | Premises security, protection against disasters, secure disposal |
| Technological | 34 | Access control, encryption, logging, vulnerability management |
The domains most often underestimated
In practice, the domains most regularly underestimated ahead of an audit are access management, logging, incident management and business continuity. A shallow mock audit often stops at statements of intent and misses these blind spots, which surface as soon as concrete evidence is requested.
Cybersecurity Diagnostic·See a diagnostic preview
- An access log export covering several weeks, not just an isolated screenshot.
- An access rights review, dated and signed by the person responsible, not a raw export of the user database.
- A backup restore test report, with the date, duration and outcome obtained.
- A concrete example of an incident handled end to end, from detection to closure, with the decisions made at each step.
How much time and budget to plan for
For an SME starting from an organized but not yet formalized base, budget generally between six and twelve months between the project launch and the certification audit, with most of that time spent collecting evidence rather than on the technical implementation itself. Certification is not a finish line: it is followed by surveillance audits every year, then a full recertification audit after three years. An ISMS built to pass the audit once, without any anchoring in day to day operations, typically runs out of steam by the first surveillance audit.
What the growth in certifications shows
According to the ISO Survey 2024, published by the International Organization for Standardization, the number of valid ISO/IEC 27001 certificates worldwide reached 96,709, up from 48,671 a year earlier, a jump partly driven by better data coverage but which confirms an underlying trend: the standard has grown by roughly 20 to 25% a year for several years. It is no longer a differentiator reserved for large groups, but an increasingly common prerequisite in tenders and acquisition due diligences.
Common mistakes to avoid
- Launching the effort without involving management, when the standard explicitly requires visible management commitment.
- Drafting a statement of applicability for show, excluding relevant controls without serious justification.
- Collecting evidence only in the weeks before the audit rather than producing it continuously throughout the year.
- Treating certification as a one-off project, when it requires a documented cycle of continuous improvement from one audit to the next.
Certification carries a real cost, both in preparation time and audit fees, and it does not remove the need for ongoing upkeep: a certified ISMS left unattended loses its value well before the next surveillance audit. For a company under no contractual obligation to certify, measuring the gap against the standard without pursuing certification itself is often the more rational choice in the short term.
Related diagnostic
Ready to assess your organization?
Try for free