Live Founding Cohort open, limited seats remaining Back to main site →

The certification lifecycle

Stage 1 documentation review, Stage 2 operating effectiveness, surveillance audits Years 1 and 2, recertification Year 3. This lesson walks the three-year cycle every certified organisation runs and where the majority of nonconformities come from.

Free preview 10 min read Verified
Legal basis
ISO/IEC 27001 primary-source stack current to 29 August 2026. Core: ISO/IEC 27001:2022 (published October 2022, current base standard), ISO/IEC 27001:2022/Amd 1:2024 (published February 2024, climate action changes to Clauses 4.1 and 4.2), ISO/IEC 27002:2022 (published February 2022, 93 Annex A controls across four themes: Organizational 37, People 8, Physical 14, Technological 34 with 11 new controls including threat intelligence, cloud services, ICT readiness, physical security monitoring, configuration management, information deletion, data masking, DLP, monitoring activities, web filtering, secure coding), ISO/IEC 27005:2022 (risk management guidance), ISO/IEC 27006:2015 + A1:2020 (CB requirements), ISO/IEC 27000:2018 (overview and vocabulary), ISO/IEC 27003:2017 (ISMS implementation guidance), ISO/IEC 27004:2016 (monitoring and measurement), ISO/IEC 27017:2015 (cloud code of practice), ISO/IEC 27018:2019 (cloud PII protection), ISO/IEC 27701:2025 (standalone privacy management system published 14 October 2025 with three-year transition to October 2028 for 27701:2019 certificate holders), ISO 31000:2018 (risk management guidelines), ISO 19011:2018 (auditing management systems guidelines). India-specific: NABCB (National Accreditation Board for Certification Bodies, Quality Council of India, IAF MLA member) accreditation regime, NABCB Policy on Transition to ISO/IEC 27701:2025 (published January 2026), NABCB Accreditation Symbol mandatory on accredited certificates from 1 July 2026, BIS adoption as IS/ISO/IEC 27001:2022 identical to ISO text. Related frameworks: NIST Cybersecurity Framework 2.0 (February 2024) for cross-mapping, SOC 2 Trust Services Criteria 2017 with 2022 Revised Points of Focus for the SOC 2 versus ISO 27001 comparison, DPDP Act 2023 and DPDP Rules 2025 for the Privacy overlay under Annex A.5.34 and ISO 27701:2025, CERT-In Directions dated 28 April 2022 (effective 27 June 2022) for the Indian incident reporting overlay under A.5.24 through A.5.27, RBI Cybersecurity Framework 2016 and Master Direction on IT Governance April 2024 for the BFSI overlay. Personal certification schemes referenced (not primary): PECB Lead Implementer (31 CPD credits, 3-year cert validity, USD 100 annual maintenance, operates under ISO/IEC 17024), IRCA Lead Auditor (CQI subsidiary), BSI Lead Implementer and Lead Auditor. Certification body landscape referenced: Bureau Veritas India, BSI India, TÜV SÜD South Asia, TÜV Nord India, DNV Business Assurance India, SGS India, Intertek India, IRQS. Vendor tooling landscape referenced in Module 6: Vanta, Drata, Sprinto (India-headquartered Bengaluru), Secureframe, AuditBoard, Archer, ServiceNow GRC, MetricStream. Items requiring ongoing verification and flagged inside the relevant lessons: any ISO/IEC 27001 next-edition timeline (currently no revision announced), any further amendments to 27001:2022 beyond Amd 1:2024, IAF Mandatory Document updates applicable to ISMS audits, NABCB transition policy for future ISO 27001 revisions, current vendor pricing on Vanta, Drata, Sprinto, Secureframe, AuditBoard.

ISO 27001 certification runs on a three-year cycle. Initial certification (Stage 1 + Stage 2) issues a certificate valid three years. Two annual surveillance audits follow. Recertification at Year 3 resets the cycle. This lesson walks each stage: what the auditor tests, what evidence you produce, how sample sizes scale, and where the majority of nonconformities land.

The three-year cycle

Month 0    Contract with CB, agree audit plan
Month 1-2  Stage 1 audit (documentation review)
Month 3    Fix Stage 1 findings
Month 4-5  Stage 2 audit (operating effectiveness)
Month 6    Fix Stage 2 findings, receive certificate
Year 1     First surveillance audit (30 to 60 percent of initial scope)
Year 2     Second surveillance audit (30 to 60 percent of initial scope)
Year 3     Recertification audit (full scope, similar to initial)
Year 4+    Cycle repeats

The initial certification workstream (Stage 1 + Stage 2 through certificate issuance) typically runs 4 to 8 months in elapsed time once the CB is engaged, assuming the ISMS is already built. Building the ISMS from scratch adds 6 to 12 months of internal work before Stage 1.

Stage 1: documentation review

Stage 1 is a documentation and readiness audit. The CB auditor reviews your documented information (scope, ISMS policy, risk assessment and treatment process, Statement of Applicability, risk register, internal audit results, management review minutes, incident records) and evaluates readiness for Stage 2 [L4-C1]. Typically delivered as a 1 to 3 day audit, commonly performed remotely under IAF MD 4 [L4-C2].

What the Stage 1 auditor tests:

  1. Scope statement (Clause 4.3): is it clear, unambiguous, aligned with the actual organisation and its interested parties? Does it include or exclude specific locations, services, populations?
  2. ISMS policy (Clause 5.2): is it approved by top management, does it include a commitment to continual improvement, is it available and communicated?
  3. Risk assessment methodology (Clause 6.1.2): is it documented, does it produce consistent and comparable results, are risk acceptance criteria defined?
  4. Risk treatment approach (Clause 6.1.3): are treatment options selected with justification, is the Statement of Applicability complete and correct against Annex A?
  5. Documented information (Clause 7.5): are the four mandatory items present and controlled? Are additional documented information items required by other clauses present (competence records, monitoring results, internal audit programme and results, management review results, nonconformity records)?
  6. Internal audit programme (Clause 9.2): is a programme defined, are results available? For a first-time filer, at least one full internal audit cycle covering the ISMS should have been completed.
  7. Management review (Clause 9.3): has at least one management review been conducted with the mandatory agenda inputs and outputs?

Common Stage 1 findings:

  • Vague scope statement ("all information at the company") — CB requests specific boundaries
  • ISMS policy generic corporate speak — CB requests information-security-specific content
  • Risk methodology narrative-only — CB requests documented steps with defined scoring scales
  • Statement of Applicability with justifications missing or copy-paste boilerplate — CB requests unique justification per control
  • Internal audit programme not yet run for first-time filer — CB requests completion before Stage 2
  • No management review record yet — CB requests one before Stage 2

Stage 1 findings are typically not counted as nonconformities in the formal sense. They are readiness findings that must be closed before Stage 2 can proceed. The CB will schedule Stage 2 typically 4 to 12 weeks after Stage 1 depending on the findings' severity.

Stage 2: operating effectiveness

Stage 2 tests whether the ISMS is operating effectively across the scope [L4-C3]. Typically delivered as a 4 to 15 day audit for a single-site organisation, longer for multi-site scopes under IAF MD 1. Substantially on-site (though hybrid remote-plus-onsite is now common under IAF MD 4). Includes interviews with control owners, walkthroughs of controls in operation, evidence sampling.

Audit day count is calculated per ISO/IEC 27006 Annex B based on effective number of personnel in scope, adjusted for complexity factors [L4-C4]. Example bands (approximate; each CB has firm-specific tables):

  • Up to 25 effective personnel: 5 to 6 initial audit days (Stage 1 + Stage 2 combined)
  • 26 to 45 effective personnel: 6 to 8 initial audit days
  • 46 to 85 effective personnel: 8 to 10 initial audit days
  • 86 to 170 effective personnel: 10 to 12 initial audit days
  • 171 to 350 effective personnel: 12 to 14 initial audit days
  • Above 350: additional day counts per ISO 27006 Table B.1

Complexity adjustments (multi-site, high-risk sector, custom development environment, extensive outsourcing) can add 20 to 50 percent to the base count. Simplifying factors (single-site, low-risk sector, standardised operations) can reduce by 10 to 30 percent.

Sample sizes for Stage 2: the auditor samples operating evidence for each applicable control. Typical sample sizes:

  • Continuously operating controls (change management tickets, access reviews, deployment approvals): 15 to 30 items across the period
  • Monthly controls (monthly access reviews, monthly vulnerability scans): 3 to 6 items depending on period length
  • Quarterly controls: 1 to 2 items
  • Annual controls (annual risk assessment, annual management review, annual internal audit programme): 1 item plus review of the operating record

Common Stage 2 findings:

  • Access review evidence exists but not for all periods in the review cycle
  • Change management tickets missing approver evidence or missing tester evidence
  • Incident records lack root cause analysis or lack lessons-learned integration back into the risk register
  • Internal audit findings lack CAPA closure evidence
  • Supplier reviews for A.5.19 / A.5.22 not conducted at planned intervals
  • Awareness training completion rate below the ISMS objective threshold
  • Documented information version-control gaps (draft version circulating alongside approved version)
  • Annex A control operating evidence exists in ticketing system but not linked back to the SoA control ID

Nonconformities and CAPA

Stage 2 findings are categorised as:

  • Major nonconformity: absence, systemic failure or significant deviation of a required control or clause. Blocks certificate issuance until closed. Typically requires 60 to 90 days for CAPA closure and verification.
  • Minor nonconformity: isolated or one-off deviation. Does not block certificate issuance if a credible CAPA plan is submitted and accepted, but must be closed by the next surveillance audit.
  • Opportunity for improvement (OFI): not a nonconformity. CB observation the organisation may act on voluntarily.

Closure of a nonconformity requires (1) correction (fix the immediate issue), (2) root cause analysis, (3) corrective action (fix the underlying cause), (4) effectiveness verification. The CAPA process is required by Clause 10.2 and is one of the most-audited process areas across the ISMS.

Certificate issuance and content

After Stage 2 nonconformities are closed to the CB's satisfaction, the CB issues the certificate. Certificate content typically includes:

  • Certificate number
  • Organisation name and address
  • Scope of certification (a paragraph summarising the ISMS scope)
  • Reference to ISO/IEC 27001:2022
  • Reference to the Statement of Applicability version and date
  • Issue date, expiry date (three years from issue)
  • CB name, logo, accreditation body logo (NABCB Symbol mandatory from 1 July 2026)
  • Signature of CB certificate authoriser

The certificate plus the Statement of Applicability is what you present to procurement, tender panels and auditors. Both are usually shareable under NDA; some organisations publish the certificate publicly and share the SoA under NDA.

Surveillance audits Years 1 and 2

Two annual surveillance audits during the certificate's three-year validity. Surveillance is not a full re-audit; the CB samples a subset of the ISMS covering 30 to 60 percent of the initial audit scope. Focus areas: nonconformity closure from prior audits, any significant changes to the ISMS, sampled Annex A controls (typically rotating so all controls are surveyed across the two surveillance audits and the recertification), management review and internal audit programme continued operation, incident records and their handling.

Surveillance findings are categorised the same as Stage 2 (major, minor, OFI). Major nonconformities can suspend or withdraw the certificate.

Recertification Year 3

At Year 3 the certificate expires. Recertification is a full-scope audit similar to initial Stage 2. If the ISMS has been maintained well through the three years, recertification is a lighter process (many CBs share auditor between annual surveillance and recertification for continuity). If the ISMS has drifted, recertification can find substantial nonconformities.

Certificate renewal issues a new three-year certificate. The cycle repeats.

Next lesson: the operating timeline for a first-time filer. Zero to certificate in 12 to 18 months for an Indian SaaS, enterprise or GCC.

Every claim in this lesson is cited. Yellow markers like [L1-C1] are clickable. Click any to see the verbatim text of the Section, Rule or judgment we're relying on. Learn how we verify content ›

Preview in progress 7 more modules waiting behind enrolment

Enjoying the preview? Here's what enrolment unlocks.

  • All 7 paid modules (35 lessons)
  • Complete citation register — every claim linked to the primary source
  • Final exam: 40 questions, unlimited retakes
  • Verifiable certificate with public verify URL and LinkedIn share
  • Founding-cohort badge on your certificate
Founding-cohort price. List: ₹19,999. Certificate on pass. LinkedIn-shareable. Lifetime access. Course updates included.
Citations
ISO/IEC 27006, ISO/IEC 27006:2015 + A1:2020 (Requirements for ISMS certification bodies) L4-C1
ISO/IEC 27006 sets requirements for bodies providing audit and certification of ISMS. Governs CB competence, audit day calculations, impartiality and independence rules. NABCB accredits Indian CBs against ISO/IEC 27006 read with IAF Mandatory Documents.
IAF Mandatory Document, IAF MD 4 (use of ICT for auditing) (Remote and hybrid audit rules) L4-C2
IAF MD 4 governs the use of information and communication technology (remote audits, video conferencing, screen sharing, document sharing platforms) in management system certification audits. Formalised post-pandemic. Applies to ISO 27001 Stage 1 and surveillance audits routinely; Stage 2 typically requires on-site component.
ISO/IEC 27001:2022, Clause 8 Operation (Operational planning, risk assessment, treatment) L4-C3
Clause 8 covers operational planning and control (8.1), operational execution of the risk assessment (8.2) and operational execution of the risk treatment plan (8.3). This is where the design of Clause 6 becomes operating reality. Stage 2 audit tests operating effectiveness of Clause 8.
IAF Mandatory Document, IAF MD 5 (audit duration) (Duration of ISMS audits) L4-C4
IAF MD 5 governs the calculation of audit duration for QMS and EMS. ISMS audit duration is governed by ISO/IEC 27006 tables based on effective number of personnel adjusted for complexity and risk. Together these ensure CBs cannot underbid audit day counts.
Free preview
Reading Module 1. Enrol to unlock the rest of the course.
Module 1: The ISO 27001 story
Module 2: Clauses 4 to 6: Context, Leadership, Planning
  • Clause 4 Context of the organisation (including Amendment 1:2024 climate change)
  • Clause 5 Leadership and the ISMS Policy
  • Clause 6.1 Actions to address risks and opportunities
  • Clauses 6.1.2 and 6.1.3 — Risk assessment and treatment methodology
  • Clauses 6.2 and 6.3 — ISMS objectives and Planning of changes
Module 3: Clauses 7 to 10: Support, Operation, Evaluation, Improvement
  • Clause 7 Support — Resources, competence, awareness, communication
  • Clause 7.5 Documented information — the four mandatory items + ISMS Manual TOC
  • Clause 8 Operation — Executing the plan
  • Clause 9 — Monitoring, Internal Audit, Management Review
  • Clause 10 Improvement — Nonconformity and CAPA
Module 4: Annex A controls Part 1: Organizational + People
  • A.5 Organizational controls Part 1 (A.5.1 through A.5.20)
  • A.5 Organizational controls Part 2 (A.5.21 through A.5.37)
  • A.6 People controls (8 controls, A.6.1 through A.6.8)
  • The 11 new controls in ISO/IEC 27002:2022 walkthrough
  • Building the Statement of Applicability (all 93 controls)
Module 5: Annex A controls Part 2: Physical + Technological
  • A.7 Physical controls (14 controls, A.7.1 through A.7.14)
  • A.8 Technological controls Part 1 (A.8.1 through A.8.17)
  • A.8 Technological controls Part 2 (A.8.18 through A.8.34)
  • Cloud-specific controls and ISO 27017 / 27018 alignment
  • Control Ownership Matrix and evidence sources
Module 6: The risk assessment operating layer
  • Choosing a risk methodology (asset-based, scenario-based, hybrid)
  • Asset inventory and information classification
  • Threat identification, vulnerability identification, likelihood + impact scoring
  • Risk treatment options (Modify, Retain, Avoid, Share) and the Risk Treatment Plan
  • GRC tooling — buy vs build (Sprinto, Vanta, Drata, Secureframe, AuditBoard, Archer)
Module 7: Certification body selection + Stage 1 + Stage 2 audits
  • What NABCB accreditation means (and why IAF MLA matters)
  • CB RFP process + Selection Matrix (Bureau Veritas, BSI, TÜV SÜD, TÜV Nord, DNV, SGS, Intertek, IRQS)
  • Stage 1 audit — documentation review
  • Stage 2 audit — operating effectiveness testing
  • Handling nonconformities, CAPA closure, certificate issuance
Module 8: Post-certification + adjacent standards
  • Surveillance Years 1 + 2, and recertification Year 3
  • Publishing certification status + answering VSAQ / CAIQ / SIG questionnaires
  • ISO/IEC 27701:2025 privacy add-on + DPDP Act 2023 crosswalk
  • ISO/IEC 27017 (cloud) + ISO/IEC 27018 (cloud PII) extensions
  • ISO/IEC 42001 AI Management System as the next horizon