ISO 27001 certification runs on a three-year cycle. Initial certification (Stage 1 + Stage 2) issues a certificate valid three years. Two annual surveillance audits follow. Recertification at Year 3 resets the cycle. This lesson walks each stage: what the auditor tests, what evidence you produce, how sample sizes scale, and where the majority of nonconformities land.
The three-year cycle
Month 0 Contract with CB, agree audit plan Month 1-2 Stage 1 audit (documentation review) Month 3 Fix Stage 1 findings Month 4-5 Stage 2 audit (operating effectiveness) Month 6 Fix Stage 2 findings, receive certificate Year 1 First surveillance audit (30 to 60 percent of initial scope) Year 2 Second surveillance audit (30 to 60 percent of initial scope) Year 3 Recertification audit (full scope, similar to initial) Year 4+ Cycle repeats
The initial certification workstream (Stage 1 + Stage 2 through certificate issuance) typically runs 4 to 8 months in elapsed time once the CB is engaged, assuming the ISMS is already built. Building the ISMS from scratch adds 6 to 12 months of internal work before Stage 1.
Stage 1: documentation review
Stage 1 is a documentation and readiness audit. The CB auditor reviews your documented information (scope, ISMS policy, risk assessment and treatment process, Statement of Applicability, risk register, internal audit results, management review minutes, incident records) and evaluates readiness for Stage 2 [L4-C1]. Typically delivered as a 1 to 3 day audit, commonly performed remotely under IAF MD 4 [L4-C2].
What the Stage 1 auditor tests:
- Scope statement (Clause 4.3): is it clear, unambiguous, aligned with the actual organisation and its interested parties? Does it include or exclude specific locations, services, populations?
- ISMS policy (Clause 5.2): is it approved by top management, does it include a commitment to continual improvement, is it available and communicated?
- Risk assessment methodology (Clause 6.1.2): is it documented, does it produce consistent and comparable results, are risk acceptance criteria defined?
- Risk treatment approach (Clause 6.1.3): are treatment options selected with justification, is the Statement of Applicability complete and correct against Annex A?
- Documented information (Clause 7.5): are the four mandatory items present and controlled? Are additional documented information items required by other clauses present (competence records, monitoring results, internal audit programme and results, management review results, nonconformity records)?
- Internal audit programme (Clause 9.2): is a programme defined, are results available? For a first-time filer, at least one full internal audit cycle covering the ISMS should have been completed.
- Management review (Clause 9.3): has at least one management review been conducted with the mandatory agenda inputs and outputs?
Common Stage 1 findings:
- Vague scope statement ("all information at the company") — CB requests specific boundaries
- ISMS policy generic corporate speak — CB requests information-security-specific content
- Risk methodology narrative-only — CB requests documented steps with defined scoring scales
- Statement of Applicability with justifications missing or copy-paste boilerplate — CB requests unique justification per control
- Internal audit programme not yet run for first-time filer — CB requests completion before Stage 2
- No management review record yet — CB requests one before Stage 2
Stage 1 findings are typically not counted as nonconformities in the formal sense. They are readiness findings that must be closed before Stage 2 can proceed. The CB will schedule Stage 2 typically 4 to 12 weeks after Stage 1 depending on the findings' severity.
Stage 2: operating effectiveness
Stage 2 tests whether the ISMS is operating effectively across the scope [L4-C3]. Typically delivered as a 4 to 15 day audit for a single-site organisation, longer for multi-site scopes under IAF MD 1. Substantially on-site (though hybrid remote-plus-onsite is now common under IAF MD 4). Includes interviews with control owners, walkthroughs of controls in operation, evidence sampling.
Audit day count is calculated per ISO/IEC 27006 Annex B based on effective number of personnel in scope, adjusted for complexity factors [L4-C4]. Example bands (approximate; each CB has firm-specific tables):
- Up to 25 effective personnel: 5 to 6 initial audit days (Stage 1 + Stage 2 combined)
- 26 to 45 effective personnel: 6 to 8 initial audit days
- 46 to 85 effective personnel: 8 to 10 initial audit days
- 86 to 170 effective personnel: 10 to 12 initial audit days
- 171 to 350 effective personnel: 12 to 14 initial audit days
- Above 350: additional day counts per ISO 27006 Table B.1
Complexity adjustments (multi-site, high-risk sector, custom development environment, extensive outsourcing) can add 20 to 50 percent to the base count. Simplifying factors (single-site, low-risk sector, standardised operations) can reduce by 10 to 30 percent.
Sample sizes for Stage 2: the auditor samples operating evidence for each applicable control. Typical sample sizes:
- Continuously operating controls (change management tickets, access reviews, deployment approvals): 15 to 30 items across the period
- Monthly controls (monthly access reviews, monthly vulnerability scans): 3 to 6 items depending on period length
- Quarterly controls: 1 to 2 items
- Annual controls (annual risk assessment, annual management review, annual internal audit programme): 1 item plus review of the operating record
Common Stage 2 findings:
- Access review evidence exists but not for all periods in the review cycle
- Change management tickets missing approver evidence or missing tester evidence
- Incident records lack root cause analysis or lack lessons-learned integration back into the risk register
- Internal audit findings lack CAPA closure evidence
- Supplier reviews for A.5.19 / A.5.22 not conducted at planned intervals
- Awareness training completion rate below the ISMS objective threshold
- Documented information version-control gaps (draft version circulating alongside approved version)
- Annex A control operating evidence exists in ticketing system but not linked back to the SoA control ID
Nonconformities and CAPA
Stage 2 findings are categorised as:
- Major nonconformity: absence, systemic failure or significant deviation of a required control or clause. Blocks certificate issuance until closed. Typically requires 60 to 90 days for CAPA closure and verification.
- Minor nonconformity: isolated or one-off deviation. Does not block certificate issuance if a credible CAPA plan is submitted and accepted, but must be closed by the next surveillance audit.
- Opportunity for improvement (OFI): not a nonconformity. CB observation the organisation may act on voluntarily.
Closure of a nonconformity requires (1) correction (fix the immediate issue), (2) root cause analysis, (3) corrective action (fix the underlying cause), (4) effectiveness verification. The CAPA process is required by Clause 10.2 and is one of the most-audited process areas across the ISMS.
Certificate issuance and content
After Stage 2 nonconformities are closed to the CB's satisfaction, the CB issues the certificate. Certificate content typically includes:
- Certificate number
- Organisation name and address
- Scope of certification (a paragraph summarising the ISMS scope)
- Reference to ISO/IEC 27001:2022
- Reference to the Statement of Applicability version and date
- Issue date, expiry date (three years from issue)
- CB name, logo, accreditation body logo (NABCB Symbol mandatory from 1 July 2026)
- Signature of CB certificate authoriser
The certificate plus the Statement of Applicability is what you present to procurement, tender panels and auditors. Both are usually shareable under NDA; some organisations publish the certificate publicly and share the SoA under NDA.
Surveillance audits Years 1 and 2
Two annual surveillance audits during the certificate's three-year validity. Surveillance is not a full re-audit; the CB samples a subset of the ISMS covering 30 to 60 percent of the initial audit scope. Focus areas: nonconformity closure from prior audits, any significant changes to the ISMS, sampled Annex A controls (typically rotating so all controls are surveyed across the two surveillance audits and the recertification), management review and internal audit programme continued operation, incident records and their handling.
Surveillance findings are categorised the same as Stage 2 (major, minor, OFI). Major nonconformities can suspend or withdraw the certificate.
Recertification Year 3
At Year 3 the certificate expires. Recertification is a full-scope audit similar to initial Stage 2. If the ISMS has been maintained well through the three years, recertification is a lighter process (many CBs share auditor between annual surveillance and recertification for continuity). If the ISMS has drifted, recertification can find substantial nonconformities.
Certificate renewal issues a new three-year certificate. The cycle repeats.
Next lesson: the operating timeline for a first-time filer. Zero to certificate in 12 to 18 months for an Indian SaaS, enterprise or GCC.