CBUAE Cybersecurity Compliance Checklist 2026: 10 Things CISOs Should Do Now
The Central Bank of the UAE (CBUAE) Operational Risk Management Regulation C 1/2026, effective from 14 September 2026,...
Getting ISO 27001 certification is a significant milestone. Keeping the certified information security management system (ISMS) accurate while people, cloud services and risks change is the longer job.
In 2026, organizations work against ISO/IEC 27001:2022 with its 2024 amendment. There is no separate ISO 27001:2026 edition. The accredited transition from the 2013 edition ended on 31 October 2025, so a new certification plan should focus on the current requirements and the actual systems and services in scope.
This guide explains the ISO 27001 certification process, the records teams should prepare, how the external audit works, and what it takes to maintain useful evidence after the certificate is issued.
ISO/IEC 27001 sets requirements for an ISMS: a structured way to identify information security risks, select treatment measures, assign responsibilities, monitor performance and improve. Certification is an independent assessment of an organization’s ISMS against those requirements within a stated scope.
ISO does not issue certificates. An external certification body makes the certification decision. When choosing a body, check its accreditation for the relevant scope and verify a certificate’s current status through the issuing body or an appropriate certification database.
A certificate is not a guarantee that every system is free of vulnerabilities or that every Annex A control is deployed everywhere. Read its scope carefully. It may cover defined services, entities and locations rather than the entire company. For customers and partners, that scope is as important as the certificate itself.
Organizations pursue certification to establish a repeatable risk management system and demonstrate it through independent assessment. A well-run ISMS can also clarify ownership, improve supplier discussions and make customer security reviews easier. These benefits depend on the system being operated, not merely documented.
The practical challenge is keeping the control picture current. A new application may rely on identities outside existing access reviews. A newly acquired business unit may change the ISMS scope. A cloud deployment may affect logging or backup coverage. Certification provides a governance structure for finding and handling these changes, while the organization’s own controls and follow-through address the underlying risk.
The exact documents and samples depend on the ISMS scope and certification body’s audit plan. The following work forms a useful preparation path.
Specify which products, services, teams, locations and information are covered. Identify interfaces and dependencies outside the scope, including suppliers and shared platforms. Leadership should establish the information security policy, objectives and responsibilities, and provide resources for operating the ISMS.
A narrow scope can be sensible if it accurately represents the service being certified. An artificial boundary that ignores a critical dependency creates confusion during risk assessment and audit sampling.
Set a repeatable risk assessment method and evaluate threats to confidentiality, integrity and availability. Decide how each material risk will be treated, who owns the decision and which controls are necessary. Review this when systems, suppliers or the business context change.
The Statement of Applicability (SoA) records necessary controls and the rationale for inclusion or exclusion from the Annex A reference set. It should connect a control to its implementation and evidence, rather than operate as a list of 93 boxes to tick. ISO 27001 uses risk treatment to determine necessary controls; it does not require identical control choices for every organization.
Document and run the processes that support selected controls. Depending on scope, these can include access management, change management, incident response, vulnerability management, supplier oversight, backup and recovery, awareness, and secure development.
A policy is useful only when teams know how it applies. Define the population each control should cover, its owner, the systems that supply evidence and the way gaps will be handled. For example, an access review procedure needs a reliable account inventory and a record of decisions and follow-up actions.
Monitor what the ISMS is meant to achieve, conduct internal audits and management reviews, and address nonconformities and improvement opportunities. These activities need enough operating history and evidence to be meaningful before the external audit. A last-minute set of policies with no evidence of use is unlikely to answer how the ISMS functions.
The 2024 amendment adds a climate relevance consideration to clause 4.1 and a note about interested-party requirements in clause 4.2. Determine whether those issues are relevant to the organization’s context and record the decision; the amendment does not add a new Annex A control set.
| Stage | What the organization does | What the result should show |
|---|---|---|
| Readiness and gap assessment | Compare the current ISMS with the standard and identify missing practices | A scoped plan with owners and priorities |
| Implementation | Treat risks, operate controls and assemble evidence | Working processes and traceable records |
| Internal audit and management review | Evaluate conformity and performance before the external audit | Findings, leadership decisions and corrective actions |
| Stage 1 external audit | Present the ISMS scope, documented arrangements and readiness | Feedback on whether Stage 2 can proceed as planned |
| Stage 2 external audit | Demonstrate implementation through interviews, observation and sampled evidence | Audit findings for the certification body’s decision |
| Surveillance and recertification | Keep operating and improving the ISMS | Ongoing assessment across the certification cycle |
Stage 1 is commonly a readiness and documented-information review. Stage 2 examines whether the ISMS operates in practice. The auditor samples evidence, so a certification decision does not mean every transaction or asset was individually tested. Findings and corrective actions follow the certification body’s process.
The certification body, not a software vendor or consultant, decides whether to issue the certificate. Ask the body how it schedules stages, handles findings, defines the certified scope and verifies corrective action.
Evidence should show what happened, when, for which systems or people, and what was done about a gap. Depending on scope, examples include risk assessments and treatment decisions, the SoA, access reviews, change approvals, training records, vulnerability findings, incident exercises, backup tests, internal audit results and management review actions.
Link evidence to the requirement or selected control it supports. For privileged access control, the existence of a PAM tool is a starting point. An assessor may also need to understand the in-scope account population, current coverage, approved exceptions, unresolved gaps and follow-up. A record from an operational system can be more useful than a screenshot saved without date or context.
Evidence collection need not become a monthly audit rehearsal. Establish owners and sources during normal operations so the same records support risk decisions, internal oversight and external assessment.
There is no universal schedule. Time depends on the ISMS scope, existing security practices, available owners, remediation work, how long controls need to operate before they can be sampled, and the certification body’s availability.
A smaller organization with mature processes and a focused scope may move faster than a large enterprise with multiple locations and shared services. Set a timeline only after a gap assessment and discussion with the certification body. Include time for internal audit, management review and corrective actions, not just policy writing and the two external audit dates.
Budget for the full cycle rather than one audit fee. Typical cost categories are internal staff time, control implementation, training, optional advisory or tooling support, the initial Stage 1 and Stage 2 audit, surveillance audits and recertification.
Costs vary with locations, headcount, technical complexity, audit duration, travel arrangements and the amount of remediation required. Obtain quotes against a defined scope from suitable certification bodies. Published generic price ranges may omit internal effort or make a broad scope look comparable to a narrow one.
Certificates commonly run on a three-year cycle, with surveillance audits during the cycle and a recertification assessment before renewal. Confirm the exact programme with your certification body.
Between audits, update the risk assessment, SoA and controls when the environment changes. Continue internal audits and management reviews. Investigate control gaps, assign remediation and verify the result. If the certified scope changes materially, speak with the certification body about how that affects the certificate and audit programme.
An access control may be effective at the certification audit and incomplete months later because new accounts were missed. Regular checks help discover that difference while there is still time to fix it.
Organizations may be asked for ISO 27001 certification or a SOC 2 report. ISO 27001 certifies an ISMS within a defined scope. SOC 2 is an attestation report on controls at a service organization against applicable Trust Services Criteria. They serve different assurance requests, although some operational evidence can support both.
Let customer requirements and the services in scope guide the choice. If pursuing both, map shared control evidence carefully; do not assume that one certificate or report automatically satisfies the other’s criteria.
ISMS evidence is spread across identity, endpoint, cloud, vulnerability, ITSM and governance systems. SPOG.AI connects that evidence to assets, controls, risks and owners, helping teams see control coverage, exceptions and remediation in context. Continuous control monitoring can help reveal when a selected control stops working across the intended population, while GRC workflows support accountability and audit preparation.
For example, a control can be marked implemented in the SoA while recent evidence shows that some critical assets are missing protection. A connected view lets the team identify those assets, prioritize the gap, assign an owner and revalidate after remediation. The platform supports the organization’s ISMS; it does not issue or guarantee certification.
See how SPOG.AI connects ISO 27001 controls to current evidence.
Editorial sources: Scrut article used as topic reference; ISO/IEC 27001:2022; ISO certification and verification guidance; 2024 amendment; IAF transition requirements; SGS ISO/IEC 27001:2022 certification process; SPOG.AI GRC; SPOG.AI continuous control monitoring.
The Central Bank of the UAE (CBUAE) Operational Risk Management Regulation C 1/2026, effective from 14 September 2026,...
Organizations invest heavily in security tools, compliance programs, and risk management processes. Yet many security leaders still struggle...
Introduction — When the Cloud Shakes, Compliance Crumbles When AWS’s US-east-1 region went dark, so did thousands of...