ISO 27001 Certification in 2026: What You Need to Prepare and Maintain

Getting ISO 27001 certification is a significant milestone. Keeping the certified information security management system (ISMS) accurate while people, cloud services and risks change is the longer job.

In 2026, organizations work against ISO/IEC 27001:2022 with its 2024 amendment. There is no separate ISO 27001:2026 edition. The accredited transition from the 2013 edition ended on 31 October 2025, so a new certification plan should focus on the current requirements and the actual systems and services in scope.

This guide explains the ISO 27001 certification process, the records teams should prepare, how the external audit works, and what it takes to maintain useful evidence after the certificate is issued.

What does ISO 27001 certification mean?

ISO/IEC 27001 sets requirements for an ISMS: a structured way to identify information security risks, select treatment measures, assign responsibilities, monitor performance and improve. Certification is an independent assessment of an organization’s ISMS against those requirements within a stated scope.

ISO does not issue certificates. An external certification body makes the certification decision. When choosing a body, check its accreditation for the relevant scope and verify a certificate’s current status through the issuing body or an appropriate certification database.

A certificate is not a guarantee that every system is free of vulnerabilities or that every Annex A control is deployed everywhere. Read its scope carefully. It may cover defined services, entities and locations rather than the entire company. For customers and partners, that scope is as important as the certificate itself.

Why pursue certification in 2026?

Organizations pursue certification to establish a repeatable risk management system and demonstrate it through independent assessment. A well-run ISMS can also clarify ownership, improve supplier discussions and make customer security reviews easier. These benefits depend on the system being operated, not merely documented.

The practical challenge is keeping the control picture current. A new application may rely on identities outside existing access reviews. A newly acquired business unit may change the ISMS scope. A cloud deployment may affect logging or backup coverage. Certification provides a governance structure for finding and handling these changes, while the organization’s own controls and follow-through address the underlying risk.

ISO 27001 certification requirements: What to prepare

The exact documents and samples depend on the ISMS scope and certification body’s audit plan. The following work forms a useful preparation path.

1. Define the ISMS scope and leadership responsibilities

Specify which products, services, teams, locations and information are covered. Identify interfaces and dependencies outside the scope, including suppliers and shared platforms. Leadership should establish the information security policy, objectives and responsibilities, and provide resources for operating the ISMS.

A narrow scope can be sensible if it accurately represents the service being certified. An artificial boundary that ignores a critical dependency creates confusion during risk assessment and audit sampling.

2. Assess risks and select controls

Set a repeatable risk assessment method and evaluate threats to confidentiality, integrity and availability. Decide how each material risk will be treated, who owns the decision and which controls are necessary. Review this when systems, suppliers or the business context change.

The Statement of Applicability (SoA) records necessary controls and the rationale for inclusion or exclusion from the Annex A reference set. It should connect a control to its implementation and evidence, rather than operate as a list of 93 boxes to tick. ISO 27001 uses risk treatment to determine necessary controls; it does not require identical control choices for every organization.

3. Put the ISMS into operation

Document and run the processes that support selected controls. Depending on scope, these can include access management, change management, incident response, vulnerability management, supplier oversight, backup and recovery, awareness, and secure development.

A policy is useful only when teams know how it applies. Define the population each control should cover, its owner, the systems that supply evidence and the way gaps will be handled. For example, an access review procedure needs a reliable account inventory and a record of decisions and follow-up actions.

4. Evaluate and improve

Monitor what the ISMS is meant to achieve, conduct internal audits and management reviews, and address nonconformities and improvement opportunities. These activities need enough operating history and evidence to be meaningful before the external audit. A last-minute set of policies with no evidence of use is unlikely to answer how the ISMS functions.

The 2024 amendment adds a climate relevance consideration to clause 4.1 and a note about interested-party requirements in clause 4.2. Determine whether those issues are relevant to the organization’s context and record the decision; the amendment does not add a new Annex A control set.

The ISO 27001 certification process, step by step

StageWhat the organization doesWhat the result should show
Readiness and gap assessmentCompare the current ISMS with the standard and identify missing practicesA scoped plan with owners and priorities
ImplementationTreat risks, operate controls and assemble evidenceWorking processes and traceable records
Internal audit and management reviewEvaluate conformity and performance before the external auditFindings, leadership decisions and corrective actions
Stage 1 external auditPresent the ISMS scope, documented arrangements and readinessFeedback on whether Stage 2 can proceed as planned
Stage 2 external auditDemonstrate implementation through interviews, observation and sampled evidenceAudit findings for the certification body’s decision
Surveillance and recertificationKeep operating and improving the ISMSOngoing assessment across the certification cycle

Stage 1 is commonly a readiness and documented-information review. Stage 2 examines whether the ISMS operates in practice. The auditor samples evidence, so a certification decision does not mean every transaction or asset was individually tested. Findings and corrective actions follow the certification body’s process.

The certification body, not a software vendor or consultant, decides whether to issue the certificate. Ask the body how it schedules stages, handles findings, defines the certified scope and verifies corrective action.

What counts as ISO 27001 audit evidence?

Evidence should show what happened, when, for which systems or people, and what was done about a gap. Depending on scope, examples include risk assessments and treatment decisions, the SoA, access reviews, change approvals, training records, vulnerability findings, incident exercises, backup tests, internal audit results and management review actions.

Link evidence to the requirement or selected control it supports. For privileged access control, the existence of a PAM tool is a starting point. An assessor may also need to understand the in-scope account population, current coverage, approved exceptions, unresolved gaps and follow-up. A record from an operational system can be more useful than a screenshot saved without date or context.

Evidence collection need not become a monthly audit rehearsal. Establish owners and sources during normal operations so the same records support risk decisions, internal oversight and external assessment.

How long does ISO 27001 certification take?

There is no universal schedule. Time depends on the ISMS scope, existing security practices, available owners, remediation work, how long controls need to operate before they can be sampled, and the certification body’s availability.

A smaller organization with mature processes and a focused scope may move faster than a large enterprise with multiple locations and shared services. Set a timeline only after a gap assessment and discussion with the certification body. Include time for internal audit, management review and corrective actions, not just policy writing and the two external audit dates.

How much does ISO 27001 certification cost?

Budget for the full cycle rather than one audit fee. Typical cost categories are internal staff time, control implementation, training, optional advisory or tooling support, the initial Stage 1 and Stage 2 audit, surveillance audits and recertification.

Costs vary with locations, headcount, technical complexity, audit duration, travel arrangements and the amount of remediation required. Obtain quotes against a defined scope from suitable certification bodies. Published generic price ranges may omit internal effort or make a broad scope look comparable to a narrow one.

What happens after certification?

Certificates commonly run on a three-year cycle, with surveillance audits during the cycle and a recertification assessment before renewal. Confirm the exact programme with your certification body.

Between audits, update the risk assessment, SoA and controls when the environment changes. Continue internal audits and management reviews. Investigate control gaps, assign remediation and verify the result. If the certified scope changes materially, speak with the certification body about how that affects the certificate and audit programme.

An access control may be effective at the certification audit and incomplete months later because new accounts were missed. Regular checks help discover that difference while there is still time to fix it.

ISO 27001 versus SOC 2

Organizations may be asked for ISO 27001 certification or a SOC 2 report. ISO 27001 certifies an ISMS within a defined scope. SOC 2 is an attestation report on controls at a service organization against applicable Trust Services Criteria. They serve different assurance requests, although some operational evidence can support both.

Let customer requirements and the services in scope guide the choice. If pursuing both, map shared control evidence carefully; do not assume that one certificate or report automatically satisfies the other’s criteria.

How SPOG.AI supports certification readiness and ongoing assurance

ISMS evidence is spread across identity, endpoint, cloud, vulnerability, ITSM and governance systems. SPOG.AI connects that evidence to assets, controls, risks and owners, helping teams see control coverage, exceptions and remediation in context. Continuous control monitoring can help reveal when a selected control stops working across the intended population, while GRC workflows support accountability and audit preparation.

For example, a control can be marked implemented in the SoA while recent evidence shows that some critical assets are missing protection. A connected view lets the team identify those assets, prioritize the gap, assign an owner and revalidate after remediation. The platform supports the organization’s ISMS; it does not issue or guarantee certification.

See how SPOG.AI connects ISO 27001 controls to current evidence.

Editorial sources: Scrut article used as topic reference; ISO/IEC 27001:2022; ISO certification and verification guidance; 2024 amendment; IAF transition requirements; SGS ISO/IEC 27001:2022 certification process; SPOG.AI GRC; SPOG.AI continuous control monitoring.